Privacy — Spola
Last updated 23 September 2026
The principle
Spola moves your music between Apple Music, Spotify, Amazon Music and Shazam. It has no account with us and no server of ours — but it does talk to the services you connect it to, and this page says exactly what they receive. We never receive, store or see any of your data. There is nothing for us to sell, lose or hand over, because there is nothing on our side to begin with.
What the app keeps
Spola records what you put into it:
- your tracks and playlists — title, artist, album, ISRC, service identifiers, cover URL
- which service each track came from, and the date you captured it
- the links between a playlist here and the same playlist on a service
Where it lives
On your device. If you turn iCloud on, it also syncs through your own private iCloud database, which Apple encrypts and which we cannot open, read or list. We have no key and no access of any kind.
What it asks permission for
Every one of these is optional. Refuse any of them and the rest of the app keeps working.
- Microphone
- Only while you are identifying a song. Spola uses Apple’s ShazamKit, which turns what it hears into a fingerprint. No audio is recorded and none is kept.
- iCloud
- To sync your library between your devices, through your own iCloud account.
What leaves the device
The app has no analytics, no crash reporting, no advertising and no third-party kit of any kind. What it does send, it sends only to the services below, and only for what you asked it to do:
- Spotify
- When you connect your account: the title and artist of a track, or its ISRC, to find the match; the name and description of a playlist you push; and the track identifiers to add. Spola also reads your Spotify display name and identifier, to show you which account is connected.
- Apple Music
- The title and artist of a track, its ISRC or its catalogue identifier, to find the match; and the name of a playlist you create.
- Shazam, which is Apple
- The fingerprint of what the microphone hears, for as long as you are listening. If you ask, the match is also written back to your own Shazam library.
- Apple and Spotify image servers
- The address of a cover you are looking at, so the image can be displayed.
None of it reaches us. We have no server in any of these paths, and we never receive a copy.
Signing in
Signing in happens in Apple’s own secure browser window, with PKCE and no client secret: we never see your password, and neither does the app. The resulting token is kept in the iPhone’s Keychain, unlocked only after you first unlock the device. No token is ever written to iCloud, to a file, or to our side of anything — we do not have a side. Disconnect a service and its token is deleted.
Amazon Music appears in the app but is not connected: the code is written and the credentials are empty, so nothing is sent there at all today. This page will change before that does.
Your data is yours
Export everything, whenever you want, without asking us. Delete the app and what was only on the device is gone; what synced to iCloud goes when you remove it from your iCloud settings. We cannot recover any of it for you, because we never had it.
Children
The app is not directed at children and collects nothing about anyone, of any age.
Changes to this page
If the app ever starts doing something this page does not describe, this page changes first. The date at the top says when it last did.
Your rights
Quebec’s Law 25 and similar laws elsewhere give you the right to access, correct and delete the personal information a business holds about you. In our case the answer is the same every time: we hold none. Your information is on your device and in your own iCloud, where you can already read, change and delete all of it yourself.
Contact
Nidello — Canada — [email protected]