New Spotify privacy policy says it can collect data on location, sensors, and photos from your phone
Location, Sensors, Voice, Photos?! Spotify Just Got Real Creepy With The Data It Collects On You — Spotify has updated its privacy policy, and users should be careful about what they agree to.
Context & Ripple Effects
Spotify's August 2015 privacy update quietly claimed rights to location, sensors, voice, and photos on subscribers' phones, and the reaction was immediate enough that within a day it posted an apology promising no collection without explicit permission — a retreat that only set up the real test of whether rewritten language could hold the expanded scope.
The episode fits a longer arc in the related coverage: two years later the company was still tightening data demands, requiring Premium Family members to hand over location data to prove they share an address, while its mood-listening data was already being pitched as advertiser gold. The 2015 fight is where that data appetite first collided with users in public.
First-order effects
- Users agreeing to the new terms are granting Spotify potential access to phone sensors, photos, and location — with the company's own follow-up clarifying that actual collection requires separate explicit permission.
Second-order effects
- Every player in the streaming stack reads the same signal: pre-save campaigns already give labels like Sony broad account access, so each consent layer added at the platform level compounds what downstream partners can reach.
Third-order effects
- If the pattern holds, consent language becomes the battleground rather than actual collection practices — platforms claim broad rights upfront, walk them back under pressure, then re-approach through narrower feature-specific asks like family-plan location checks.
The trend: Consumer apps are normalizing broad device-level data claims secured by consent checkboxes, with user backlash functioning as a speed bump rather than a reversal.