Privacy Policy

Last updated: January 14, 2026

Introduction

SC Toolkit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.

Authentication & Account Access

SC Toolkit uses SoundCloud's official OAuth 2.0 authentication system with PKCE (Proof Key for Code Exchange) for secure login. This means:

  • We never see, store, or have access to your SoundCloud password
  • Authentication is handled entirely through SoundCloud's secure servers
  • We only receive temporary access tokens that you can revoke at any time
  • All tokens are encrypted at rest using AES-256-GCM encryption

Data We Access

SC Toolkit requests the minimum permissions necessary to function:

  • Read access to your playlists: To display and manage your playlists
  • Read access to your likes: To convert liked tracks into playlists
  • Write access to playlists: To create, modify, and organize playlists
  • Read access to your profile: To display your username and basic account information

We do not access your private messages, comments, reposts, or any other SoundCloud data beyond what is necessary for playlist management.

How We Store Your Data

When you authenticate with SC Toolkit, we store the following information in our database:

  • Your SoundCloud user ID (numeric identifier)
  • Your SoundCloud username and display name
  • Your profile avatar URL
  • Encrypted access and refresh tokens (AES-256-GCM encryption)
  • Token expiration timestamps

All sensitive data (access tokens) is encrypted at rest using industry-standard AES-256-GCM encryption with a 32-character encryption key. Session cookies are HMAC-signed and marked as HttpOnly and Secure in production.

Data Usage

We use your data solely to:

  • Provide playlist management features (merge, organize, modify playlists)
  • Convert your liked tracks into playlists
  • Resolve SoundCloud links to extract metadata
  • Maintain your session while using the application

We do not:

  • Sell, rent, or share your data with third parties
  • Use your data for advertising or marketing purposes
  • Analyze your listening habits or preferences
  • Store your playlist content or track information beyond what's necessary for API calls

Data Retention

We retain your account information and encrypted tokens as long as your account is active. If you wish to delete your data, you can:

  • Log out of SC Toolkit (this clears your session but keeps account data)
  • Revoke access through your SoundCloud account settings (this prevents future access)
  • Contact us to request complete data deletion

Cookies & Session Management

SC Toolkit uses secure, HttpOnly cookies to maintain your session. These cookies:

  • Are signed with HMAC to prevent tampering
  • Are marked as Secure in production (HTTPS only)
  • Use SameSite=None for cross-site cookie support (with proper CORS configuration)
  • Do not contain sensitive information (only session identifiers)

Third-Party Services

SC Toolkit integrates with:

  • SoundCloud API: For authentication and playlist management
  • Vercel Analytics: For anonymous usage analytics (no personal data collected)

We do not share your personal data with any third-party services beyond what is necessary for the application to function.

Your Rights

You have the right to:

  • Access your stored data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Revoke access to your SoundCloud account at any time
  • Export your data (where technically feasible)

Security Measures

We implement industry-standard security measures to protect your data:

  • AES-256-GCM encryption for sensitive data at rest
  • HTTPS/TLS encryption for all data in transit
  • HMAC-signed session cookies
  • Secure CORS configuration with allowlist
  • Regular security audits and updates

Children's Privacy

SC Toolkit is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us to have that information removed.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us through the appropriate channels. We are committed to transparency and will respond to your inquiries promptly.

Disclaimer: SC Toolkit is not affiliated with, endorsed by, or connected to SoundCloud. This is an independent tool created to enhance the SoundCloud user experience. Your use of SC Toolkit is subject to SoundCloud's Terms of Service and this Privacy Policy.