Data and privacy

Privacy Policy

Yandex Music to Last.fm Bridge (Scrobbler). Last updated: July 21, 2026.

This policy describes how the Chrome extension processes data to provide Yandex Music controls, Last.fm features, local exports and diagnostics.

Data processed

The extension may process:

Yandex Music controls

Playback information is read from the open Yandex Music page to display the current track and operate controls requested by the user. It is stored locally only where needed for current state, queueing, diagnostics or user-selected exports.

Last.fm direct mode

When Last.fm is connected and direct delivery is available, track metadata, the Last.fm session key and API requests are sent directly to Last.fm. Last.fm profile and listening statistics displayed by the extension are also requested directly from Last.fm. The session key and cached extension state are stored in Chrome extension storage.

YM Bridge service and optional Cloud relay

The extension contacts ym-bridge.mytunnel.us.com to obtain the extension's Last.fm application configuration and to authenticate supported extension builds. Requests include a derived installation identifier, public signing key, timestamp, nonce, body hash and signature. The service uses this technical data for request authentication, replay protection and abuse limits.

When the user presses Connect Last.fm, direct browser authentication is attempted first. If the direct Last.fm authentication API is unavailable, the service may transiently request an authentication token or exchange the user-approved token for a Last.fm session key and return it to the extension. This authentication fallback does not change the user's Cloud relay preference. The Worker does not intentionally persist the token or session key.

If the user chooses the alternative username-or-email and password sign-in, those credentials are sent over HTTPS to the YM Bridge relay and forwarded once to Last.fm solely to obtain a Last.fm session key. The password is not stored in Chrome extension storage, is cleared from the form after the attempt, and is not intentionally stored or logged by the relay. The returned session key and Last.fm username are stored locally in Chrome extension storage. Cloudflare processes the request as the relay infrastructure provider.

Cloud relay for scrobbles is selected by default as a fallback, starts only after a one-time in-extension data-use review, and can be disabled in extension settings. The extension attempts direct Last.fm delivery first. Only when direct delivery is unavailable are completed track metadata and the Last.fm session key sent over HTTPS to the developer-operated Cloudflare Worker and forwarded to Last.fm. Batches are normally sent after 10 tracks or 30 minutes, while the extension periodically checks direct Last.fm availability.

The relay does not intentionally persist listening history, Last.fm session keys or request bodies. Cloudflare, as the infrastructure provider, may process IP addresses and technical request metadata under its own policies and platform retention practices.

Local storage and retention

Settings, Last.fm session data, signing keys, cached profile/statistics data, scrobble queue items and delivery state are stored in the Chrome profile. Queue entries are removed according to normal delivery and queue-management behavior. Users can clear the Last.fm session, disable exports, clear failed queue items or remove the extension to delete extension storage.

Now Playing file export

Optional Now Playing export writes track text, JSON data and a cover image to a folder only after the user explicitly grants folder access. Files remain on the user's device and can be disabled or deleted by the user.

Clipboard

Clipboard write permission is used only after a direct user action on a Copy command. It can write current track text, a cover URL or a cover image. The extension does not read clipboard contents and does not write automatically.

Optional desktop companion

The optional desktop companion communicates on localhost or 127.0.0.1 only to display track popups. The extension remains responsible for Last.fm delivery.

Sharing and sale of data

User data is not sold. It is disclosed only as needed for the selected feature:

Analytics and advertising

The extension contains no advertising SDK, behavioral tracking or product analytics. Data is not used for advertising, creditworthiness or unrelated profiling. Chrome Web Store may provide the publisher with aggregated analytics for the Store listing; this does not add analytics code to the extension.

Security

Remote requests use HTTPS. Protected YM Bridge endpoints require signed requests and apply timestamp, nonce, extension-ID and rate-limit checks. No security control can guarantee absolute protection, but these controls limit unauthorized and replayed requests.

Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's disclosed, user-facing features.

Changes and contact

This page will be updated before material data-handling changes are released. For support or privacy questions, use the contact information on the Chrome Web Store listing or the support page.