Privacy Policy
We take the protection of your personal data very seriously. Personal data is only collected when necessary.
Server Log Files
The hosting provider automatically collects and stores information transmitted by your browser.
Cookies & Browser Storage
For SoundCloud login, we use one strictly necessary, short-lived HttpOnly cookie to bind the login attempt to your browser. It expires after ten minutes or is deleted when the callback is processed. This website also uses localStorage to store the following data locally in your browser:
- likedDJs: Your favorited DJs or sets
- savedArtists: The identifiers of artists you save to Bunny Brain
- bunny_token: A pseudonymous identifier derived from your SoundCloud account when you sign in. It is the same on ShallowBunny.com and Sisyduck.com, which is what lets your likes and saved artists be shared between the two apps.
- festival: The currently selected festival
- following: The SoundCloud accounts you follow (if logged in)
- lastLikesUpdate and lastFollowingUpdate: Last-refresh timestamps used to avoid unnecessary API requests
- now-hide-non-music: Your preference for showing non-music entries in the current view
- likesSyncEnabled and likesSyncDeviceId and likesSyncRevision and likesSyncOperations and likesSyncInitialized and likesSyncToken and savedArtistsSyncDeviceId and savedArtistsSyncRevision and savedArtistsSyncOperations and savedArtistsSyncInitialized and savedArtistsSyncToken: Your opt-in preference, random device identifier, sync revision, and pending offline like and saved-artist operations
- shallowbunny_stats_id: A random anonymous identifier used for aggregate usage statistics. It rotates after 30 days and is sent to our API together with the device category (desktop, mobile web, or installed app). It is not linked to your SoundCloud account or bunny_token.
- bunnyBrainTracks: The last Bunny Brain track recommendations, used only as a fallback when refreshing them fails
We also use sessionStorage for temporary navigation and display data, such as the selected room, your current search query, and scroll positions. This data is removed when the browser session ends.
Optional SoundCloud Connection
If you connect SoundCloud, our backend temporarily stores a random OAuth state and PKCE verifier for up to ten minutes and deletes them when the login callback is processed. It then stores your SoundCloud user ID, profile URL, and client-specific OAuth access and refresh tokens so the connection can be maintained. Duck and Bunny credentials are stored separately. Followed-account data may be cached to highlight artists and reduce SoundCloud API requests. Disconnecting SoundCloud from this app deletes its stored access and refresh tokens.
Optional Like Synchronization
If enabled while signed in with SoundCloud, liked festival sets, saved artist identifiers, and deletion tombstones are stored pseudonymously on our backend. Because you sign in with the same SoundCloud account on both apps, this data is shared across ShallowBunny.com and Sisyduck.com: a like or saved artist appears in both, and removing one removes it from both. The data is used only to synchronize your devices and is not public. Turning sync off stops future synchronization. You may request deletion of server data using the contact details below.
Contact
If you contact us via email, your data will be stored to process your request and handle follow-up questions. We do not share this data without your consent. For privacy-related inquiries, please use the contact details in the Impressum.
Access, Deletion, Blocking
You have the right at any time to request free information about your stored personal data, its origin and recipient, and the purpose of data processing. You also have the right to correct, block, or delete this data.
Last updated: July 2026