About musiccloud
musiccloud is a music link sharing service that converts any track link into a universal share page — linking to all major streaming platforms at once.
How it works
Paste a link from Spotify, Apple Music, YouTube, Tidal, Deezer, or any other supported service. musiccloud identifies the track and finds it across all platforms, generating a single shareable URL.
Why musiccloud?
Music fans use different streaming services. Instead of sending a link that only works for some people, share a musiccloud link and let everyone open the track in their preferred app.
Privacy
musiccloud does not track listeners or store personal data. Shared links are public and permanent.
Supported Services
musiccloud resolves tracks across the following streaming platforms:
Tier 1 — Major Platforms
- Apple Music — Search, ISRC1 lookup, full metadata
- Audius — Decentralized music platform
- Deezer — Search, ISRC lookup, full metadata
- Pandora — US streaming service
- Qobuz — Search, ISRC lookup, Hi-Fi quality links
- SoundCloud — Stream and track URL resolution
- Spotify — Search, ISRC lookup, full metadata
- Tidal — Search, ISRC lookup, Hi-Fi quality links
- YouTube — Video search and direct URL resolution
- YouTube Music — Derived from YouTube video links
Tier 2 — Regional & Specialist Platforms
- Audiomack — Hip-hop and R&B platform
- Bandcamp — Independent artist platform
- Beatport — Electronic music store, ISRC lookup
- BoomPlay — African streaming service
- Bugs! — Korean streaming service
- JioSaavn — Indian music streaming
- Melon — Korean streaming service
- NetEase Cloud Music — Chinese streaming service
- QQ Music — Chinese streaming service
Footnotes
-
ISRC (International Standard Recording Code) is a unique identifier assigned to each audio or music video recording. musiccloud uses it to find the exact same recording across different platforms — more reliably than matching by title and artist name alone. ↩
Imprint
Frank Gregor
Landstrasse 21c
6900 Bregenz
Austria
Email: phranck@phranck.dev
Information in accordance with Section 5 of the ECG.
musiccloud.io is a private, non-commercial project.
Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how musiccloud processes personal data when you use musiccloud.io and the musiccloud Developer Portal at developer.musiccloud.io. The additional rules for the use of the Developer Portal and the musiccloud API are set out in the Terms of Service.
Data controller
Frank Gregor
Landstrasse 21c
6900 Bregenz
Austria
Email: support@musiccloud.io
1. musiccloud website
Server logs
When you access the website, the hosting provider, Zerops (EU), processes technical access data: IP address, timestamp and the URL accessed. These logs are retained for a maximum of 7 days.
We process this data to operate, secure and troubleshoot the service. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in the security and reliable operation of musiccloud.
Analytics
musiccloud uses Umami Analytics, operated on EU infrastructure. Umami does not set cookies. IP addresses are anonymised before they are used for analytics. We use aggregated information such as page views and device category to understand how the service is used; we do not create user profiles from this information or pass it to third parties.
The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in improving the service.
2. Developer Portal and API
This section applies when you create or use a developer account, request or manage API access, or use the musiccloud API with an API key.
Developer account and authentication
To create and operate a developer account, we process your email address, optional display name, account status, assigned API tier, account creation and update timestamps, and the time of your last successful login. If you use email and password sign-in, we store only a password hash, not your plaintext password.
We also create time-limited, single-use verification and password-reset tokens. Their values are stored only as hashes. A browser session is maintained with an HTTP-only session cookie for up to 7 days.
We process this data to create and secure your account, authenticate you, provide the Developer Portal and communicate about your account. The legal basis is Art. 6(1)(b) GDPR, performance of the contract or steps taken at your request before entering into a contract, and Art. 6(1)(f) GDPR for account security and abuse prevention.
GitHub sign-in
If you choose to sign in with GitHub, we receive your GitHub user ID, GitHub username, name where available, avatar URL and verified primary email address. We store the GitHub user ID as the authentication identity and may store the returned name and avatar URL in your developer account.
GitHub provides this sign-in service as an independent controller. Its processing is governed by GitHub's own privacy documentation. The legal basis for our processing is Art. 6(1)(b) GDPR.
API access, keys and usage metadata
When you request API access, we process your account email address, app name, app description, estimated request volume, request status and any review note. For approved apps, we process the app configuration, assigned limits, API key status, safe key prefix, creation, rotation, revocation and last-use timestamps, and audit events for relevant account and key-management actions.
We use this data to review access requests, provision and administer API access, apply limits, investigate misuse and maintain an audit trail. API key secrets are not included in audit events or application logs.
The legal basis is Art. 6(1)(b) GDPR for providing the requested API service and Art. 6(1)(f) GDPR for security, fraud prevention and protection of the API and its users.
Security and rate limiting
The Developer Portal and API process technical request data, including IP address, timestamp and requested URL, in server logs as described in section 1. IP addresses may also be used temporarily in memory to apply rate limits and protect login, OAuth and API-management endpoints from abuse. We do not use IP addresses for device fingerprinting.
Transactional email
We send account-verification, password-reset and relevant account or API-key notifications to your email address. For this purpose, we use SMTP2GO's EU email endpoint. The provider processes the recipient address, optional display name, subject line and email content solely to deliver the message.
The legal basis is Art. 6(1)(b) GDPR where an email is necessary to provide the account or requested service, and Art. 6(1)(f) GDPR for security-related notifications.
3. Recipients and international transfers
We use the following service providers to operate the service:
- Zerops (EU) for hosting and infrastructure.
- SMTP2GO (EU endpoint) for transactional email delivery.
- GitHub, only when you actively choose GitHub sign-in.
We disclose personal data only where this is necessary to provide the service, where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. Where a provider processes data outside the EEA, we will use an appropriate transfer mechanism required by applicable data-protection law.
4. Retention and deletion
- Server logs are retained for a maximum of 7 days.
- Verification and password-reset tokens expire after a short period and cannot be used after expiry or consumption.
- Developer-account, API-access and API-key management data is retained while your developer account is active and as long as required to provide the requested service or meet legal obligations.
- You can delete your developer account in the Developer Portal. Account, authentication, API-access request, client and key records associated with the account are deleted. Audit events are retained only after their direct link to your deleted account has been removed, where necessary for security and integrity of the service.
- Analytics data is used only in aggregated, non-profiled form and is retained only as long as needed to evaluate and improve the service.
5. Your rights
Subject to the applicable legal requirements, you have the right to request access to your personal data, rectification, erasure, restriction of processing, data portability and to object to processing based on Art. 6(1)(f) GDPR.
You can request a copy of your Developer Portal account data from the Developer Portal. You may also contact us at privacy@musiccloud.io to exercise your rights or ask questions about this Privacy Policy.
You have the right to lodge a complaint with the Austrian Data Protection Authority.
6. Changes to this Privacy Policy
We may update this Privacy Policy when the service or the applicable legal requirements change. The current version is published on musiccloud.io and linked from the Developer Portal.