Privacy Policy

Effective July 18, 2026 · Last updated August 19, 2026

This policy explains what verses.lol collects, why, where it is stored, and the choices you have. verses.lol is a home base for underground artists. If anything here is unclear, email us at support@verses.lol.

1Information we collect

We collect only what the platform needs to work:

  • Account data — the email address and password you register with. Passwords are handled by our authentication provider and are never stored by us in plain text.
  • Profile content — everything you add to your profile and listings: display name, bio, links, ratings, and any media you upload such as images and audio.
  • Messages — the content of conversations you send through our real-time messaging so we can deliver and display them.
  • Usage analytics — aggregate page and performance data collected through privacy-friendly analytics to understand how the site is used and to keep it fast.
  • Payment data — if you subscribe to Premium, billing is processed by a PCI-compliant payment processor that handles your card details directly. We never see or store your card numbers. We keep a record of your subscription status so we know which features to unlock.
  • Integration data — if you connect Discord or Spotify, we store the account identifiers and public details needed to show presence, verification status, or listener counts on your profile.

2How we use your information

We use your information to run your account, display your profile and listings, deliver messages, process subscription payments, operate Discord and Spotify features you opt into, keep the platform secure, and respond to support requests. We do not use your content to build advertising profiles.

3Where your data is stored

verses.lol relies on a small set of infrastructure providers:

  • Managed database hosting — accounts, profiles, listings, messages, ratings, and application data.
  • Cloud media storage and CDN — media you upload, such as profile images and audio.
  • A PCI-compliant payment processor — payments and subscription processing. Card details never touch our servers.
  • Cloud hosting with usage analytics — infrastructure hosting and aggregate site analytics.

Each provider processes data on our behalf under its own security and privacy commitments.

4Cookies

We use cookies for authentication and session management — to keep you signed in and to protect your account. We do not use third-party advertising or cross-site tracking cookies. If you block essential cookies, signing in and staying signed in may not work.

5The browser extension

We publish a Chrome extension, verses.lol Sonar. It adds YouTube search to Sonar and shows your unread message count on the toolbar icon. It is optional, and verses.lol works without it.

The extension has no access to the pages you visit. It puts no script into any page you open, and it holds no permission to read tabs, cookies, browsing history or network requests — so it cannot see what you are looking at, or the address of any tab you have open. Opening a tab needs no permission; reading one does, and it never does. The only permissions it asks for are the three its features need: right-click menu items, a timer, and local storage.

This is everything it touches:

  • The two sites it can reach — www.youtube.com and verses.lol, and nothing else. YouTube, so the searches you run in Sonar leave from your own browser instead of from our servers. verses.lol, for exactly one request: the unread count behind the toolbar badge.
  • YouTube searches, made logged out— the extension sends your search terms to YouTube with no cookies attached. It never touches your YouTube account and sends nothing that identifies you. It receives YouTube's raw response and hands it back to the Sonar page to read.
  • The right-click and address-bar shortcuts — the two menu items appear on YouTube pages only, and they read only the address of the video or channel you right-clicked, handed over by Chrome as part of the click itself. They never read the address of a tab. Typing vl in the address bar turns what you type into a Sonar link in your browser; nothing is sent anywhere until you press Enter and land on verses.lol.
  • The badge token — to show your unread count, the extension has to identify you to us, and it has no session of its own. So verses.lol creates a small signed token while you are signed in on the site and hands it to the extension. The extension has no way to ask for one and never reads a cookie, so it cannot get a token for anyone who did not sign in themselves. The token carries your user id and an expiry and nothing else — no password, no email, no session. Its only use is as the credential on one request, which answers with two numbers: unread messages and pending message requests. It expires after 30 days, and the site re-issues it about once a week while you are signed in. Disconnect, in the extension's popup, deletes the copy stored in your browser, stops the checks and clears the badge.
  • What it stores— in the browser's own extension storage, on your device: the badge token, those two counts, when it last checked, and how many checks in a row came back empty. That is the complete list. Removing the extension removes all of it.
  • How often it calls us — every 15 minutes while something is waiting for you, backing off to hourly when nothing is. An install that has never been handed a token never calls us at all.

Your Sonar data stays on your device.That is stored by the website rather than by the extension, and it does not leave your browser: your stash, your passed and maybe piles, your per-producer settings, and the taste model computed from them all live in your browser's own storage. None of it is uploaded, so we cannot see it — which also means it does not follow you to another device, and clearing your browser's data for verses.lol deletes it.

The extension has no analytics of its own, shows no ads, and contacts no servers other than YouTube's and ours.

6How we share information

We do not sell your personal data. We share it only with the infrastructure providers listed above so they can perform their function, and where required by law or to protect the rights and safety of our users. Content you choose to make public — your profile, listings, and ratings — is visible to others by design.

7Your rights and choices

You can view and edit most of your information directly in your account settings. To request access to, correction of, or deletion of your data, email support@verses.lol. Deleting your account removes your profile and associated content, though some records may be retained where required for legal, security, or accounting reasons.

8Age requirement

verses.lol is not directed to children. You must be at least 13 years old to create an account. If we learn that we have collected data from someone under 13, we will delete it.

9Changes to this policy

We may update this policy as the platform evolves. When we do, we will revise the “last updated” date above. Material changes will be communicated through the platform.

10Contact

Questions about this policy or your data? Email support@verses.lol. See also our Terms of Service and Copyright & DMCA Policy.

This page is provided for transparency and does not constitute legal advice.