The same playlist to fall asleep every night, news podcasts in the morning, loud music on Fridays: if you stream, you tell your provider more about yourself than you probably realize. Music streaming feels harmless - it's "just" music, after all. But listening behavior is one of the most intimate data signals there is: it reveals daily rhythms, moods, relationship phases and life changes. This post takes a concrete look at Spotify: what gets collected, what gets inferred from it, and where it flows.
What you hand over, according to the privacy policy
To Spotify's credit, its own privacy policy is remarkably forthcoming. Among the data collected are:
- Usage data: your complete streaming history, search queries, playlists - what you listen to, when, how often and for how long
- Location data: your approximate location (country, region, city), and your precise location with permission
- Voice data: audio recordings when you use voice features
- Payment and purchase data as well as technical data such as device IDs, IP addresses and cookies
The crucial part is tucked away in the details: Spotify explicitly draws "inferences (i.e. our understanding) of your interests and preferences" as well as your age, based on your usage. So it's not just recording what you do - it computes a profile that claims more about you than you ever stated.
A look at the privacy label
What this looks like in practice is shown by the privacy label on the App Store. Under "Data Used to Track You" - data that follows you across apps and websites owned by other companies - it lists contact info, identifiers and usage data. The list of "Data Linked to You" spans twelve categories, including location, search history, contacts, financial info and, remarkably, "Health & Fitness". The stated purposes include third-party advertising and product personalization.
Importantly, this applies to paying customers too. A Premium subscription removes the ad breaks, not the data collection.
Where the data flows
According to the policy, Spotify shares data with several categories of recipients: service providers, payment partners, advertising partners ("to show more relevant ads"), marketing partners for promotions and bundles, podcast hosting platforms, and courts and authorities upon request. That's not a data breach - it's the business model: for ad-supported accounts, these profiles determine the price of the ad inventory.
How precise the profiling has become is something Spotify demonstrates itself every year - with Wrapped, the friendliest form of self-surveillance. For the 2025 recap, Spotify generated roughly 1.4 billion personalized reports for 350 million users, including AI-generated listening "narratives" (InfoQ). What circulates through social media as a shareable story is, technically, the same profile that feeds the ad business.
When things go wrong: fines and a remarkable patent
That the transparency has limits was demonstrated by a case in Spotify's home country: in 2023, the Swedish data protection authority IMY imposed a fine of 58 million kronor (around 5 million euros) because Spotify did not fully answer data access requests under Article 15 GDPR - meaning users could not find out clearly enough, even when they asked, what was stored about them. The court of appeal upheld the full amount in June 2025.
And a patent granted to Spotify in January 2021 hints at where the technology could go: it describes recognizing a person's emotional state, gender, age or accent from voice recordings and background noise in order to recommend music. A coalition of civil rights organizations and nearly 200 musicians publicly called on Spotify to never deploy the technology. Spotify responded that it has never implemented it and has no plans to do so - which is not quite the same as a permanent commitment.
What you can do
If you stick with streaming, you can at least curb the data flow:
- Turn off personalized ads: account settings let you object to processing for "tailored ads".
- Use private sessions: prevents individual listening sessions from showing up in public profiles and recommendations.
- Review app permissions: a music player doesn't strictly need your location, microphone or contacts.
- Request your data: Article 15 GDPR gives you the right to know what's stored - exactly the point where Spotify had to improve in Sweden.
The alternative: music nobody reads along with
All of this mitigates the problem but doesn't solve it: the business model remains data-driven. The consistent alternative is music you own - purchased downloads or ripped CDs, stored locally on your device or your own NAS. Then no third-party recommendation algorithm has a say, and no listening profile accumulates at a corporation. I've described what that looks like on the iPhone without an account, ads or tracking on the page about CLAUDIO, my own privacy-focused player. CLAUDIO builds a taste profile for its recommendations too, but only on the device; you can inspect and reset it.
Sources
- Spotify: Privacy Policy - collected data categories, inferences about interests, recipient categories
- Apple App Store: Spotify - Music and Podcasts - privacy label with tracking and linked data categories
- IMY (Swedish data protection authority): Administrative fee against Spotify - 58 million kronor fine for incomplete responses to Article 15 GDPR access requests
- Digital Policy Alert: Court of appeal upholds the fine - ruling of June 2025
- Access Now: Coalition letter against the speech-recognition patent - demand by civil rights organizations and musicians
- Music Ally: Spotify responds to protests against speech-recognition patent - statement that the technology was never implemented
- InfoQ: Inside Spotify's 2025 Wrapped Archive - 1.4 billion personalized reports for 350 million users
Full disclosure: I develop CLAUDIO, the player linked at the end. The statements about Spotify above come from the linked sources and hold no matter which player you use.