data report card

Data Report Card · Spotify

Spotify Data Report Card

Music & podcast streaming
Data
Practices
2Access2Portability1Friction2Deletion1Sells1Trains AI
=
B
9/12
Agent
Readiness
2Access 2Portability 2API access
=
A
6/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026 · policies are checked weekly for changes  ·  stated — every cell is read from Spotify's published policy; none has been tested (run by us) yet.
2Accessstated
Self-serve Download your data tool on the Account Privacy page delivers a ZIP of account data plus extended streaming history for the life of the account; no fee.
Spotify — Data rights and privacy settings · accessed Jun 2026 ↗
2Portabilitystated
Export is structured machine-readable JSON (e.g. StreamingHistory.json, Userdata.json, Playlist.json).
Spotify — GDPR Article 15 information · accessed Jun 2026 ↗
1Frictionstated
Self-serve request but Spotify states it may take up to 30 days to prepare the data (the account-data package is usually faster than extended history).
Spotify — Data rights and privacy settings · accessed Jun 2026 ↗
2Deletionstated
Free users can self-serve close their account online with a 7-day reactivation window before deletion begins; Premium users must contact support first.
Spotify — Closing your account and deleting your data · accessed Jun 2026 ↗
1Sells / sharesstated
Spotify does tailored/targeted advertising and shares usage data with ad partners, but states it honors recognized opt-out signals including Global Privacy Control (GPC).
Spotify — Privacy Policy · accessed Jun 2026 ↗
1Trains AIstated
Spotify develops and trains algorithmic and machine-learning models on user data; ad/personalization controls exist but no explicit dedicated AI-training opt-out is documented (scored conservatively).
Spotify — Privacy Policy · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
Spotify's Web API uses OAuth 2.0 with refresh tokens, letting you authorize an app to read your own recently-played tracks, top items, saved library and playlists; complete lifetime streaming history is available only through a separate "Download your data" request.
Spotify for Developers — Web API · accessed Jun 2026 ↗
Spotify offers a strong self-serve JSON export and self-serve deletion for free accounts, but the up-to-30-day SLA, ad-sharing, and ML-training on user data (no dedicated opt-out) keep it mid-pack; Premium deletion requires contacting support. Source-verified Jun 2026; all cells stated (read from published policy/support docs), none yet tested via live export.

How to request your data from Spotify

  1. Go to https://www.spotify.com/us/account/privacy/ — Spotify's data-request entry point.
  2. Account → Privacy settings → Download your data.
  3. Expected wait: up to 30 days (often sooner) — Spotify's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact Spotify — Privacy / DPO Team: mailto:privacy@spotify.com.

These steps reflect Spotify's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.