Privacy
What stays private.
Listening Record began as a private owner archive. Rated Series are published through a separate, withdrawable public projection; the rest of the diary stays private.
Selected for publication
The public Listening Record archive contains only a Series title, Show title, description, genre, artwork, source link, and Listening Record score. Current and future owner scores are public and can be withdrawn. Owner notes, reviews, dates, queues, tags, status, source payloads, and identity are not copied into it.
Private by default
Saves, queues, personal notes, listening and completion dates, statuses, tags, listening history, and profile or review drafts stay private. They are never inferred into a public profile, taste summary, or review.
Separate owner access
Listener accounts and owner access are separate. A listener account cannot open the private Library, correction tools, or owner history.
Withdrawal and control
Published judgments and profiles can be withdrawn. Reports, follows, and blocks stay private. Account settings can permanently remove a listener's Listening Record data without deleting shared catalog identity; removing the separate sign-in identity requires a separate operator step.
Recommendation requests
Recommendation text is sent to OpenAI to interpret and rank candidates from the public archive. Listening Record does not retain the raw request, model prompt, full model response, IP address, or user-agent string. It keeps only short-lived opaque recommendation runs and aggregate counts for accepted searches, outcomes, result totals, account state, and coarse latency.