Skip to main content
Home Features Download Sign in Sign up

Privacy policy

Last updated: 12 August 2026

In short

Volta is a free, personal project. Your data is never sold, rented or used for advertising — there is no advertising, no ad network and no business model behind this service.

Only the data required for the application to work is processed.

Who processes your data

The data controller is the publisher of Volta, a private individual publishing on a non-professional basis. For any question, or to exercise your rights: [email protected].

This website

This site has no form, no account and no analytics. No cookies are set.

Nothing is stored in your browser’s local storage. The language shown is inferred from the one your browser declares, on every visit. A switcher at the bottom of the page lets you change it: that choice lasts for the visit only, it is neither kept nor transmitted, and detection takes over again on the next reload.

This site sets no cookie of its own. If you are signed in to your Volta account, it queries account.volta-music.com to show your username and profile picture in the header; the session cookie used for that belongs to the account area and is never readable by this site. With no session, no data about you is requested.

Typefaces are served by this site itself: no request is made to Google Fonts, so your IP address is never sent to them.

The lyrics panel on the home page refreshes from our own servers, without sending them anything about you. The artwork of the track shown is, however, served by Spotify’s or Deezer’s image CDN depending on its source: displaying that image sends your IP address to the CDN operator concerned.

Your IP address is also processed by Cloudflare, which hosts the site, in order to deliver the pages and keep the service secure.

The Volta application

The application, hosted on a separate domain, processes the data required for it to work:

  • account: username, email address and password — the password is never stored in clear text, only hashed;
  • profile picture, if you add one;
  • usage: library, playlists, likes, history and playback position — required to sync across devices;
  • sharing: when you open a collaborative playlist or a shared listening session, the link between your account and the participants’ accounts is recorded, for as long as the sharing lasts;
  • technical: device type and connection logs, for security and diagnostics.

Your IP address is used to rate-limit requests and prevent abuse. It is never written to the database: it stays in memory for a few minutes, then disappears.

Authentication

Account management runs on Zitadel, an open-source identity solution that we host ourselves. Your credentials are therefore not entrusted to any third-party provider: they stay on the same infrastructure as the rest of the service.

You can also sign in with a Google, Apple or Discord account. In that case only, the provider concerned is contacted at sign-in time: it learns that you are signing in to Volta, and sends us the information needed to create the account — identifier, email address, display name and, where applicable, profile picture. These providers are established in the United States and apply their own privacy policies.

Importing from another service

Importing from Spotify works by file: you export your library from Spotify and send us that file. Volta never accesses your Spotify account and keeps no authorisation relating to it.

For Apple Music, YouTube, Last.fm and Tidal, importing does go through an authorisation: you let Volta access your account with that service, and Volta then keeps the access token issued by the provider, along with the associated refresh token.

That is more than a copy of your playlists: for as long as it is valid, this token grants real access to your account with the service concerned. It is kept so the import can be resumed or refreshed without asking for your authorisation again each time.

You can remove it at any time from your account area. Volta then erases it from its servers and, where the provider exposes a revocation mechanism — YouTube does —, asks for it to be invalidated immediately.

Apple Music, Tidal and Last.fm offer no such mechanism: the token disappears from our servers and Volta stops using it, but only a revocation from your account with the provider ends it for certain. The relevant link is shown in your account area.

API keys

If you create keys from your account area, Volta keeps their name, description, public identifier, granted permissions, and the dates of creation and last use. That last date is what lets us point out keys you no longer use.

The matching secret is never kept in the clear: only a one-way fingerprint is stored, along with its first few characters so you can recognise the key in the list. It therefore appears neither in your data export nor anywhere else.

This information is kept for as long as the key exists. Deleting the key erases it, together with any tokens issued from it.

Bug reports

If you report a problem from the application, the report contains your description, the device type and version in use, an excerpt of the server and client logs at the time of sending, and the screenshot you may choose to attach.

A screenshot captures everything displayed at that moment. Check what it contains before sending it: it may reveal information unrelated to the problem being reported.

Once approved by an administrator, the report — screenshot included — is sent to GitHub, in the United States, to open a tracking issue. A report that is not approved is never sent.

Why, and on what basis

Each processing operation rests on a legal basis:

  • providing the service and syncing: performance of the service you requested;
  • security and abuse prevention: the publisher’s legitimate interest;
  • signing in with Google, Apple or Discord: your consent, given by choosing that button;
  • importing from a third-party service, and keeping the corresponding token: your consent, which can be withdrawn at any time;
  • sending a bug report: your consent, given at the moment you send it;
  • retention required by law: legal obligation.

Who else has access

Nobody, beyond what is technically indispensable. As Zitadel is self-hosted, no third-party identity provider holds your credentials.

That leaves Cloudflare, which hosts the site, the email relay described below, the identity providers you choose to use, and GitHub for approved bug reports only. Your data may be disclosed to authorities where the law requires it.

Service emails — address verification, password reset — are sent from a Proxmox Mail Gateway that we host ourselves, then delivered through Google’s SMTP relay. Google therefore processes the recipient address and the message content at delivery time.

Several of these parties are established in the United States: Cloudflare for hosting, Google for email delivery, GitHub for approved bug reports, and Google, Apple or Discord if you choose to sign in through them. These transfers outside the European Union are covered by the safeguards provided for in the GDPR.

For how long

Account data is kept for as long as the account exists. A deletion request opens a thirty-day window: nothing is erased during that period, and you can cancel the request from your account area. After that, deletion is carried out and becomes irreversible. Technical logs are kept for thirty days.

An account with no sign-in for three years is deleted, along with the data attached to it. A warning email is sent to the associated address thirty days beforehand: simply signing in during that period resets the counter.

Access tokens for third-party services are kept until you revoke the authorisation. A bug report sent to GitHub follows the lifetime of the corresponding issue.

Your rights

You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to issue instructions regarding its fate after your death.

Most of these rights can be exercised directly from your account area, at account.volta-music.com: viewing and editing your information, exporting your data — library, playlists, connected services and API keys, with no secret of any kind —, revoking connected third-party services, deleting your account. Deleting the account also erases your sign-in identity, not just the data attached to your Volta account.

For anything else, write to [email protected] and the request will be handled as soon as possible. You may also lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or with your local supervisory authority.

Security

Reasonable measures are in place to protect your data against loss and unauthorised access. As no system is infallible, they are not an absolute guarantee — do not store anything in Volta whose disclosure would harm you.

Changes

This policy may change. The date of the last update appears at the top of the page; substantial changes are notified to account holders.

Music at full power. Ad-free, without limits.

PRODUCT Features Download Web app ↗
LEGAL Legal noticeTerms of usePrivacy policy
© 2026 VOLTA Français