Melos

Privacy Policy

Last updated September 9, 2026

Melos reads the YouTube music you choose to share so your friends can play a guessing game. It does not post to or change your YouTube account. Live game data is temporary, and a small technical record of how each game went is kept briefly so problems can be fixed.

What Melos accesses

Melos uses YouTube API Services and asks for read-only access to your YouTube account. With your permission, Melos may read:

Melos does not upload videos, edit playlists, subscribe to channels, post comments, or otherwise write to your YouTube account.

Melos’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How the data is used

Melos uses this data only to find music, create a temporary room library, choose songs for rounds, and play those songs through the YouTube player. Players in your room can see the song and artist used in a round. At the reveal, they can see which player or players had that song. Melos does not show other players your complete library or the playlist a song came from.

Temporary live game data

Deleting the data Melos holds does not delete your videos, playlists, likes, or any other information YouTube itself keeps — that data lives in your YouTube account and is governed by Google.

Melos does not sell Google user data or use it for advertising.

Diagnostic record

Separately from the live room, Melos keeps a technical record of what happened during games so that failures can be investigated and recurring problems found. This record is different from the live data above: it is written to the server’s disk and kept after the room is gone.

What it may contain. Each entry is a short, named event with a time, the release of Melos, and identifiers that link events together: the room code, a game number, a round number, a shortened seat identifier, and the random session identifier from your browser. Depending on the event it may also contain: game settings (target score, music or video mode, which sources were read); how many videos were imported and how many were left out and why; whether a library read was cached, delayed, or failed; connection events and their close codes; the video ID chosen for a round and its start position; ballot counts before the reveal and, after the reveal, each seat’s number of picks, hits, and score movement; your own device’s playback observations (player state, error codes, autoplay prompts, seek and pause commands, measured drift); coarse device facts (browser and operating system family, viewport size, touch support); and the message and location of script errors, with query strings, e-mail addresses, and token-like strings removed.

What it never contains. The automatically collected fields never include OAuth tokens, seat tokens, e-mail addresses, player nicknames, song titles or artist names, your library, playlist names, or who you voted for. The text you type into Report a problem is the one exception: it is yours, and it may contain anything you choose to write.

What the identifiers mean. The room code, game number and seat identifier are scoped to one room and mean nothing outside it. The random session identifier is scoped to one browser tab: it is created when the tab opens, survives a refresh, and is discarded when the tab closes, so within that tab it can link your activity across several rooms until then. Melos does not link any of these identifiers to your Google account or your name.

Why. To see whether games complete, where people get stuck, why a library came back empty, why playback failed on a device, and to answer a problem report. The record is used only for operating and improving Melos.

Retention. Diagnostic events and problem reports are kept for 14 days by default, then deleted automatically; the whole record is also capped in size, with the oldest days deleted first. Live room data still expires after about three hours regardless.

Hosting logs. In production the same events may be mirrored to the hosting provider’s log stream (Render), and so may the room’s plain-text game log, which names the player nicknames and the song of each round while a game is being run. Those log lines follow the provider’s own retention and are readable by the Melos operator through the provider’s console.

Who can see it. The record is readable only by the Melos operator, through a password-protected operator page on the server and the hosting console. It is not shared with other players or with third parties, and it is not sold.

Problem reports. Earlier versions of Melos offered a Report a problem link that attached this technical record to a player’s note. That submission path is closed: the server no longer accepts or stores new problem reports, and Send feedback (see Feedback you send below) is the way to reach us; a bug report there carries only the four values the form shows. Problem reports made before the change remain readable by the operator until their 14 days pass, like the rest of the diagnostic record.

What this browser remembers

In video rooms, Melos keeps a small record on this device of the videos it has shown you: the video and channel identifiers, when the round was dealt, whether it was delivered to this tab, how long it played here, and whether the reveal was shown here. Nothing about who liked a video is stored. The record lives in your browser’s IndexedDB, is limited to 90 days and 2,000 rounds, and is never written to the server’s disk.

While you are seated in a video room, a summary of that record (identifiers, small counts and ages only) is sent to the room’s server so the game can prefer videos the table has not seen recently. The server keeps that summary only for your seat, discards it when you leave or the room ends, and never shows it to other players. It is a preference, never an answer: it does not say who liked a video and cannot add or remove anyone as a video’s owner. It can make a video the table has seen less likely to come up soon, which can shift which round comes when; at any single moment it changes whose video is dealt only slightly.

You can delete the record at any time. Deleting it takes effect from the next game: a game already in progress keeps the snapshot it started with. Melos tabs open on this device pass the deletion on to the rooms they are seated in.

Feedback you send

Melos has a Send feedback form. When you use it, Melos sends what you typed to the people who make Melos: the topic you picked, your note (up to 2,000 characters), and an email address only if you choose to give one so we can reply. For a “Something broke” report you can also tick Include basic game details; the form shows exactly what that adds before you send, and it is limited to the screen you were on, whether the room was a music or video room, the round number, and the app version. If the box is not ticked, none of that is sent. Feedback never includes player names, other players, your liked videos or playlists, browser history, Google or YouTube tokens, seat credentials, screenshots or logs.

Feedback is delivered by email to the operator’s inbox through a transactional email provider and is kept there until it has been read and acted on, after which it may be deleted at any time. Your note and address are not written to Melos’s server logs, not sent to analytics, and not shown to other players. To limit misuse, the server keeps a short-lived, one-way hash of the sending connection’s address and of the note’s content in memory for a few minutes; neither identifies you and neither is stored. A draft you have not sent stays only in the open page.

Product analytics

Melos uses PostHog to understand whether the game and playback work. It records limited product events such as route type, player count, round number, general playback status, and error codes. It is configured not to send player names, room codes, song or video details, playlist information, or OAuth material. A small sample of landing-page sessions may be recorded with text, images, attributes, and inputs masked; session recording is disabled inside game-room and TV routes. PostHog stores a random device identifier in your browser (cookies or local storage) so events from the same browser can be counted together; Melos does not link that identifier to your name or Google account.

Service providers

Melos relies on Google and YouTube for authorization, library data, and playback; Render for hosting and the log stream described above; and PostHog for the limited analytics described above. Songs play through YouTube’s embedded player, which may show video content and advertising from YouTube. Their processing is also governed by their own policies, including the Google Privacy Policy and the YouTube Terms of Service.

Your choices and control

You choose whether to connect YouTube. Inside Melos, the Disconnect YouTube action asks Google to revoke Melos’s access, always clears the token from your browser, and immediately discards the server’s cached copy of your library; a read already in progress at that moment is discarded when it completes and is never stored or used. If Google does not confirm the revocation, Melos says so, and you can confirm the removal yourself in your Google security settings. You can also revoke Melos’s access at any time from your Google security settings. Revoking access stops future reads; the library cache expires within about 45 minutes and room data within about three hours in any case.

To ask for earlier deletion of diagnostic events or a problem report, or to ask any privacy question, email ismailkoseorg@gmail.com. Quoting your room code, the date, or a problem-report reference helps find the entries; Melos can delete every event for a room or a session identifier on request.

Changes

If Melos changes what it accesses, what the diagnostic record contains, or how Google user data is used, this policy will be updated before that new use begins. The date at the top shows the latest revision.