Tomes Karaoke

Privacy policy

Back to karaoke

Tomes Karaoke is a small, private, non-commercial karaoke web application. This page explains the limited information it uses to run a karaoke session.

Effective date: 13 August 2026

Information Tomes Karaoke accesses, collects and stores

Information people provide

Guests provide a display name, song-search words, and a selected YouTube video ID when requesting a song. A host provides a password to sign in and may provide queue or party settings. The host password is used to verify access; Tomes Karaoke stores only its password hash, not the password itself.

Information created through use of the app

Tomes Karaoke creates party-scoped IDs and records the guest display name, the one-way hash of a random guest-browser token, song-request and queue activity, request and playback timestamps, session state, and host queue preferences. These let the app run the queue, recognise a returning guest browser, and show live statistics.

The random guest token itself stays in an HTTP-only browser cookie; only its one-way hash is stored in the database. A separate HTTP-only cookie records that this policy was acknowledged. A host session is held in a signed HTTP-only cookie containing session information needed to authorise the host console.

YouTube API Data

The YouTube Data API provides the video ID, video title, channel name and ID, thumbnail URL, duration, and embeddability or availability information for karaoke videos. Tomes Karaoke uses these fields to show search results, create requests, and check that a selected video can be embedded.

Tomes Karaoke does not ask users to sign in with Google or YouTube, does not use Google or YouTube OAuth, and does not access private YouTube account information, subscriptions, playlists, watch history, or other private YouTube user data.

The application does not ask for an email address, phone number, postal address, payment information, government ID, precise location, or a real name. Its code does not store IP addresses, browser user-agent strings, advertising IDs, or a device fingerprint. The guest-browser token is an anonymous browser identifier, not a hardware-device identifier.

How this information is used

Tomes Karaoke uses this information to find karaoke videos, display search results, create and manage song requests, operate the party queue and host console, recognise a guest browser, and calculate the live queue display and statistics. It also uses video IDs and metadata to recheck whether videos remain available and embeddable, and uses host-session and failed-login information to protect host access and reduce password guessing.

YouTube API Services

Tomes Karaoke uses YouTube API Services: the YouTube Data API and the standard YouTube embedded player. The guest's search words may be sent from the Tomes Karaoke server to the YouTube Data API to find karaoke videos. A selected video ID is also sent to the YouTube Data API to revalidate its metadata and embeddability before a request is created. Tomes Karaoke does not send guest names, guest tokens, or host passwords to YouTube.

When a host plays a song, the host's browser loads YouTube's embedded-player code and the selected video ID from YouTube. YouTube may process that browser's player activity and related information under its own terms and privacy policies. Tomes Karaoke does not download, copy, modify, host, or redistribute YouTube video content.

Use of YouTube-backed search or playback functionality involves YouTube API Services and Google's processing of information under its own policies, including the Google Privacy Policy and YouTube Terms of Service.

How information is processed and shared

Supabase

Supabase stores and processes the party, guest-browser hash and display name, queue requests, YouTube metadata attached to requests, queue and playback status and timestamps, party-session records, host password hash and session version, and failed host-login counters. Browser clients also connect to Supabase Realtime with the public project key to receive live queue updates.

Vercel

Vercel hosts the application and processes ordinary web requests needed to deliver it. This can include request URLs, headers, cookies, and network information such as IP address as part of Vercel's infrastructure. Tomes Karaoke's application code does not separately write IP addresses or user-agent strings to its database.

Other party participants

The active live queue is publicly viewable for the default party. Other participants, and anyone able to view that public party page, can see display names, requested song and video information, current or queued status, and derived queue position or estimated time. The public live-stats page can show completed-session display names and aggregate singing statistics, including the longest completed song and most-requested artist.

Tomes Karaoke does not sell or rent personal information, use it for advertising or behavioural profiling, or share it with unrelated third parties for their own marketing purposes.

Browser storage, retention and deletion

We use HTTP-only, same-site cookies rather than browser-readable local storage. A guest cookie contains a random anonymous token and lasts for up to one year; its server-side hash links a guest to their own requests. A host cookie contains a signed host session and lasts for up to 12 hours. A privacy-acknowledgement cookie lasts for up to one year and records that this policy was accepted. YouTube may also use its own cookies or similar technologies in its embedded player under Google's policies.

You can remove these local identifiers in your browser's cookie or site-data settings for karaoke.tomes.me. Doing so does not itself delete karaoke records already held by Tomes Karaoke.

Fallback YouTube search queries and their results are held only in server memory for up to five minutes. A selected video is rechecked with YouTube before entering the queue. YouTube metadata attached to a queue request is removed within 30 days of the request; the non-YouTube operational request history may remain.

To ask about or request deletion of data Tomes Karaoke holds about you, email paul@tomes.me with the party and display name you used. Deletion requests are handled manually; the app does not provide an automated deletion tool. This does not delete anything held by YouTube, Google, Supabase, or Vercel under their own records or policies.

Contact

For privacy questions, complaints, or deletion requests, contact Paul Tomes at paul@tomes.me.