Privacy
Last updated 1 August 2026. Setlists.io is run by Grant Larcom, who is responsible for the data described here. This page describes what the app actually does. If you find a difference between the two, the difference is a bug and we want to hear about it at help@setlists.io.
The short version
Your setlists are yours. We do not sell them, we do not mine them, and there is no analytics service, no advertising network and no tracking pixel anywhere in this app.
Signed out, the setlist itself stays in your browser. One thing does leave it: to fill in a song’s key, tempo and length we send the title and artist you typed to our server, which asks the music services. That happens whether or not you have an account.
What we collect
If you are signed out:the setlist stays in your own browser’s local storage. Your notes, your band, the venue, the date and the running order never reach us, and clearing your browser data deletes them.
What does reach us is each song title and artist you look up, so the server can find the recording. Those are kept in a lookup cache for 30 days, so the same song is not fetched twice. The cache holds a title and an artist and nothing that says who asked.
If you sign in: your name and email address, handled by our authentication provider. Your setlists are copied to your account so they follow you between devices, and that copy is the whole of them: song titles, artists, keys, tempos, your own notes, band member names and roles, venue names and gig dates.
If you subscribe: your payment is handled entirely by Stripe. We never see your card number.
Who receives it
This is the complete list. Nothing else receives anything about you.
Clerk
Receives: Your email, name, session cookies and subscription state. Clerk loads on every page, including this one, so it sees the IP address of visitors who never sign up.
Why: Signing in, and knowing whether you subscribe.
Stripe (through Clerk)
Receives: Your payment details, directly. They do not pass through us.
Why: Taking subscription payments.
Neon
Receives: Your full setlists, once you are signed in. Also, for anyone signed out who looks a song up, the IP address that lookup came from.
Why: The database that keeps your setlists on your account. The address is how the hourly lookup limit tells one visitor from another, and those rows are swept after a day.
Vercel
Receives: Ordinary web server logs: IP address, page requested, time.
Why: Hosting the site.
Apple Music, MusicBrainz and GetSongBPM
Receives: The song title and artist you typed (nothing else, and nothing identifying you). These lookups run on our server, so these services see our address and never yours.
Why: Finding the recording, key, tempo and length for each song.
Every one of these is a company in the United States, so using Setlists.io means your data is stored and processed there.
Keeping it safe
The site is served over HTTPS everywhere. We never see your card number and we never store your password: Clerk handles signing in, Stripe handles paying, and neither passes through us. Your setlists sit in a database only this application can reach.
No system is proof against everything. If something does go wrong with your data, we will tell you what happened rather than wait to be asked.
Cookies
Only the ones needed to keep you signed in, set by Clerk. No analytics cookies, no advertising cookies, nothing that follows you to other sites. There is nothing here to consent to, which is why this site has no cookie banner.
How long it is kept
Your setlists stay on your account until you delete them or delete your account.
Deleting one takes it out of the app straight away: it stops being listed, stops being readable and stops syncing. The row itself is held back for up to 30 days so a deletion made by mistake can be undone, and is then erased. Deleting your account erases the setlists on it.
One limit worth saying out loud: the job that erases those held-back rows is not yet on a schedule, so a setlist you deleted may sit in the database, unreadable by the app, until we run it. If you want yours gone now rather than eventually, email help@setlists.io and we will do it by hand.
Database backups are retained for six hours, so a copy of recently deleted data may persist in a backup for up to that long before it ages out.
Getting your data, and getting rid of it
Any setlist you have open can be exported from the Print & Export dialog, as a CSV or as plain text, without asking anyone. You can delete your account from your account page, which erases the setlists stored on it.
For a copy of everything on your account in one file, ask us and we will send it. A button for that is coming; until it exists, asking is the way.
If you would rather we did it, or you want to know exactly what is held about you, email help@setlists.io. Depending on where you live you may have a legal right to access, correct, export or erase your data; we will do those things for anybody who asks, wherever they live.
One thing worth knowing about shared computers
Setlists you have worked on are saved in the browser as well as on your account, and signing out does not currently clear them. On a shared or borrowed computer, the next person to open Setlists.io in that browser may see them. Until that changes, clear your browser data when you are finished on a machine that is not yours.
Children
Setlists.io is not intended for children under 13, and we do not knowingly collect anything from them.
Changes
If this page changes in a way that affects what happens to your data, the date at the top changes with it. See also the terms of service.