Privacy Policy
What Coda Media Group holds about you, what we do with it, and who else it reaches. The agreement covering your use of Coda is a separate document — the Terms of Service.
Last updated 1 September 2026
1What this policy covers
Coda is a real-time jam-session tool operated by Coda Media Group (“Coda”, “we”, “us”), who is the controller of the personal data described here. This policy covers the mobile app, the web app and the audience screen, and it applies whether you hold an account or joined a session as a guest.
Questions about anything below, and any request to exercise the rights in section 5, go to legal@codajam.com.
2What we hold
- Account data: your email address, and the name and profile picture your sign-in provider gives us.
- Profile data: the instruments you select.
- Session data: sessions you host or join, session codes, tempo and status, and your membership of them.
- Library data: your playlists, setlists and the songs in them, plus any Guitar Pro files you upload.
- Integration data: where you connect Spotify, the access and refresh tokens for that connection, your Spotify display name and account identifier, and the playlists you chose to mirror.
- Operational data: server logs and the cookie-free analytics described in section 4.10.
3What we do with it
We use it to run Coda — to sign you in, keep a session in sync, show your library, and fix things when they break. We do not sell your data, we do not use it for advertising, and we do not use it to train AI models.
Uploaded files and the content you add are handled under the licence you grant in the Terms of Service, which is limited to operating Coda for you and the people you share a session with.
4Third-party services and attributions
Coda is built on the services below. Each entry says what it does, what data reaches it, and what the provider requires of us and of you.
4.1Spotify
Cover art, track metadata, playlist importContent displayed in Coda is provided by Spotify. Coda queries the Spotify Web API for album artwork, track titles, artist names and track durations, and displays that content alongside the Spotify mark wherever it appears. Cover art is loaded directly from Spotify’s own servers; we do not copy, crop, recolour, overlay or otherwise alter it, and we do not place our branding on it.
If you connect your Spotify account, Coda additionally reads the playlists you authorise so they can be mirrored into your Coda library and used as a session queue. The mirror is read-only inside Coda: we never modify, reorder or delete anything in your Spotify account, and changes you make in Spotify flow one way into Coda on the next sync.
Spotify content in Coda always links back to Spotify, so you can open the artist, album or playlist in the Spotify app or on the web. Coda does not play Spotify audio; playback happens in Spotify’s own client, and a Spotify account subject to Spotify’s terms is required to use it.
What we will not do with Spotify content
- We do not use Spotify content or the Spotify Platform to train machine-learning or AI models.
- We do not offer Spotify metadata, cover art or preview clips as a standalone product or service, and we do not sell them.
- We do not derive analytics, rankings or user profiles from Spotify content, and we do not manipulate play counts or engagement.
- We do not modify Spotify content or its metadata, and we do not mix it with, or place it beside, a competing music service in a way that treats Spotify unfairly.
Disconnecting, and what happens to your data
You can disconnect your Spotify account from Coda at any time from your profile page. Disconnecting revokes and deletes the access and refresh tokens we hold for you, stops all further syncing, and removes the mirrored playlists from your Coda library. You can also revoke Coda’s access from within Spotify at spotify.com/account/apps. To have any remaining Spotify-derived data deleted, email legal@codajam.com.
Access tokens are stored encrypted at rest, are readable only by our server — never by the app or the browser — and are never shared with anyone else.
Trademarks and endorsement
Spotify is a trademark of Spotify AB. The Spotify mark is used here solely to attribute content as required by Spotify’s Developer Policy. Coda is an independent product; it is not affiliated with, endorsed by, sponsored by or certified by Spotify AB, and Spotify is not responsible for Coda.
Spotify Developer Terms · Spotify Developer Policy · Spotify End User Agreement · Spotify Privacy Policy
Apple
Cover art fallback, Sign in with AppleWhere Spotify has no match, Coda falls back to the iTunes Search API for album artwork and track duration. Artwork is loaded from Apple’s servers unmodified. Coda also offers Sign in with Apple; if you use it, Apple handles your credentials and may relay a private email address to us. Apple, the Apple logo and iTunes are trademarks of Apple Inc.
Genius
Song search and lyricsSongs not already in Coda’s library are looked up through the Genius API, which supplies titles, artists and artwork, and lyrics where no synced source is available. Lyrics belong to their writers and publishers and are shown for reference only.
LRCLIB
Time-synced lyricsLine-by-line timed lyrics come from LRCLIB, a free community lyrics database. Timings are contributed by its users and may be imperfect or missing.
Chordify
Chord chartsChord information may be looked up from Chordify where Coda has no chart of its own. Chords are machine-derived approximations, not authoritative transcriptions.
Signing in with Google shares your name, email address and profile picture with Coda, and nothing else. Coda requests no access to any other Google service.
Supabase
Database, authentication, file storageYour account, sessions, playlists and uploaded files are stored in Supabase, which also issues the tokens that sign you in. Row-level security keeps each account’s rows readable only by that account.
Upstash
CacheLive session state and recent search results are cached in Upstash Redis, with a short expiry, so that a server restart does not drop a session. The cache holds no durable record — it is discarded and rebuilt from the database.
Railway
Real-time server hostingThe WebSocket server that carries clock sync and session events runs on Railway.
Vercel
Web hosting, analyticsThe web app is hosted on Vercel. We use Vercel Web Analytics and Speed Insights to count page views and measure load performance. These are cookie-free, collect no cross-site identifiers, and do not build a profile of you.
Open-source components
Licences and noticesCoda includes open-source software, used under these licences:
- alphaTab — Guitar Pro and score rendering, under the Mozilla Public License 2.0. Source for the unmodified library is available from its project page.
- Lucide icons — ISC licence.
- Next.js, React and Tailwind CSS — MIT licence.
- Syne, Inter and Google Sans Code typefaces — SIL Open Font License 1.1, self-hosted with the app rather than requested from Google at page load.
5Your rights
You can access, correct, export or delete your data, object to or restrict our processing of it, and withdraw consent for anything you have consented to. Deleting your account removes your profile, playlists, uploads and integration tokens. Session records that other people also took part in may be retained in anonymised form. To exercise any of this, email legal@codajam.com.
6How to contact us
Coda Media Group answers both of these addresses. Neither is a form or an automated mailbox — write to whichever fits, in plain email.
- Privacy, data rights and copyright notices: legal@codajam.com
- Anything else, including help with the app: support@codajam.com
See also the Terms of Service.
© 2026 Coda Media Group. All rights reserved. Spotify is a trademark of Spotify AB. Apple, iTunes and Sign in with Apple are trademarks of Apple Inc. Google is a trademark of Google LLC. All other trademarks are the property of their respective owners, and their use here is for identification and attribution only.
Back to Coda