Data and privacy
Privacy Policy
Translations are provided for convenience. If a translated version differs from the English version, the English version controls.
This policy describes how the Chrome extension processes data to provide Yandex Music controls, Last.fm features, local exports and diagnostics.
Data processed
The extension may process:
- Yandex Music track metadata, including artist, title, album, artwork URL, duration, playback position, playback state and like/dislike state;
- listening timestamps, local scrobble queue items, retry state and delivery results;
- Last.fm username, profile information, listening statistics, session key and Last.fm responses when a Last.fm account is connected;
- extension settings, selected theme, control preferences and local export preferences;
- a locally generated signing key, derived installation identifier, request timestamp, nonce and body hash used to authenticate requests to the YM Bridge service.
Yandex Music controls
Playback information is read from the open Yandex Music page to display the current track and operate controls requested by the user. It is stored locally only where needed for current state, queueing, diagnostics or user-selected exports.
Last.fm direct mode
When Last.fm is connected and direct delivery is available, track metadata, the Last.fm session key and API requests are sent directly to Last.fm. Last.fm profile and listening statistics displayed by the extension are also requested directly from Last.fm. The session key and cached extension state are stored in Chrome extension storage.
YM Bridge service and optional Cloud relay
The extension contacts ym-bridge.mytunnel.us.com to obtain the extension's Last.fm application configuration and to authenticate supported extension builds. Requests include a derived installation identifier, public signing key, timestamp, nonce, body hash and signature. The service uses this technical data for request authentication, replay protection and abuse limits.
When the user presses Connect Last.fm, direct browser authentication is attempted first. If the direct Last.fm authentication API is unavailable, the service may transiently request an authentication token or exchange the user-approved token for a Last.fm session key and return it to the extension. This authentication fallback does not change the user's Cloud relay preference. The Worker does not intentionally persist the token or session key.
If the user chooses the alternative username-or-email and password sign-in, those credentials are sent over HTTPS to the YM Bridge relay and forwarded once to Last.fm solely to obtain a Last.fm session key. The password is not stored in Chrome extension storage, is cleared from the form after the attempt, and is not intentionally stored or logged by the relay. The returned session key and Last.fm username are stored locally in Chrome extension storage. Cloudflare processes the request as the relay infrastructure provider.
Cloud relay for scrobbles is selected by default as a fallback, starts only after a one-time in-extension data-use review, and can be disabled in extension settings. The extension attempts direct Last.fm delivery first. Only when direct delivery is unavailable are completed track metadata and the Last.fm session key sent over HTTPS to the developer-operated Cloudflare Worker and forwarded to Last.fm. Batches are normally sent after 10 tracks or 30 minutes, while the extension periodically checks direct Last.fm availability.
The relay does not intentionally persist listening history, Last.fm session keys or request bodies. Cloudflare, as the infrastructure provider, may process IP addresses and technical request metadata under its own policies and platform retention practices.
Local storage and retention
Settings, Last.fm session data, signing keys, cached profile/statistics data, scrobble queue items and delivery state are stored in the Chrome profile. Queue entries are removed according to normal delivery and queue-management behavior. Users can clear the Last.fm session, disable exports, clear failed queue items or remove the extension to delete extension storage.
Now Playing file export
Optional Now Playing export writes track text, JSON data and a cover image to a folder only after the user explicitly grants folder access. Files remain on the user's device and can be disabled or deleted by the user.
Clipboard
Clipboard write permission is used only after a direct user action on a Copy command. It can write current track text, a cover URL or a cover image. The extension does not read clipboard contents and does not write automatically.
Optional desktop companion
The optional desktop companion communicates on localhost or 127.0.0.1 only to display track popups. The extension remains responsible for Last.fm delivery.
Sharing and sale of data
User data is not sold. It is disclosed only as needed for the selected feature:
- to Last.fm for authentication, profile/statistics requests, now-playing updates and scrobbling;
- to Cloudflare infrastructure for YM Bridge service requests and optional relay delivery;
- to the local desktop companion when desktop track popups are explicitly enabled;
- to local files or the clipboard after an explicit user action.
Analytics and advertising
The extension contains no advertising SDK, behavioral tracking or product analytics. Data is not used for advertising, creditworthiness or unrelated profiling. Chrome Web Store may provide the publisher with aggregated analytics for the Store listing; this does not add analytics code to the extension.
Security
Remote requests use HTTPS. Protected YM Bridge endpoints require signed requests and apply timestamp, nonce, extension-ID and rate-limit checks. No security control can guarantee absolute protection, but these controls limit unauthorized and replayed requests.
Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's disclosed, user-facing features.
Changes and contact
This page will be updated before material data-handling changes are released. For support or privacy questions, use the contact information on the Chrome Web Store listing or the support page.