Skip to content
Fair Software logoFair Software logo

Spotify

Spotify has 640 million listeners and relies on collecting user behavior data for advertising and AI training. The app is closed-source, and there is no public record of a security audit.

About the assessment

Spotify's low privacy and security scores come from one main issue: Spotify USA Inc. controls all user data worldwide, so every user's records fall under U.S. law, no matter where they live. The privacy policy clearly states that both user and usage data are shared with advertising partners for targeted ads, and that training algorithms is an official use of this data. Features like AI DJ and AI playlists are examples of this. There is no specific way to opt out of either. The main app is fully closed source. While Spotify's GitHub hosts projects like Backstage, Luigi, and Pedalboard, none of these are the streaming client. There is also no public security audit. However, Spotify supports many platforms (including Linux), offers a JSON data export, and has operated for 18 years, which helps its score somewhat.

Strengths
  • Official Linux client, officially maintained
  • Available on 6 platforms plus Web
  • Free tier requires no credit card
  • JSON data export in open format
  • Regional pricing varies by country
  • No ownership change since 2018 NYSE listing
  • 17+ years of continuous operation
  • 761M monthly active users; active development
  • Net-zero 2030 target; Scope 1/2/3 data published
Weaknesses
  • Spotify USA Inc. controls data for all users
  • All user data under U.S. jurisdiction
  • Listening data shared with ad partners
  • AI training on user data; no opt-out
  • Free tier uses behavioral data for ads
  • Core app is entirely closed source
  • No public independent security audit
  • Security incidents in 2020 and 2025
  • No self-hosting option
  • Offline only for Premium with sync
  • Data export limited to 12 months by default
Fair Score
35Poor
We evaluated 1.2.94.583 (macOS) on Jul 2026
using Fair Score 1.0 | See disclaimer
By section
Privacy & Data
13.6%
Openness & Transparency
0%
Pricing Model
35.3%
Ownership & Portability
35%
Independence & Ethics
60%
Longevity & Community
100%
See detailed evaluation ↓
LicenseProprietary
PlatformsWeb, iOS, Android, Windows, MacOS, Linux
Launch2008
DeveloperSpotify AB(Sweden)
SpotifyGo to app

Fair Score

Click on the headers to expand/collapse
1
Privacy & Data
Where user data lives, how it is protected, and whether it is used to train AI models.
13.6%
1.1
Where is user data stored?
User's own device by default; data synchronization is optional and controlled by the user
6
EU/EEA, Switzerland, Iceland, Norway
5
Other democratic countries with strong data protection laws
4
USA, China, countries with weak/uncertain data protection, or unknown location
0
//
1.2
Is end-to-end encryption available for user content?
Yes, full end-to-end encryption for user content by default or as an option
6
Encryption at rest and in transit only (no E2EE)
3
No meaningful encryption
0
//
1.3
Does the company sell or share user data with third parties?
No, never (except for strictly necessary processors under data-processing agreements)
6
Only anonymized or aggregated data for analytics or research
3
Yes, personal or behavioral data is shared or sold for advertising, profiling, or similar purposes
0
//
1.4
Does the product train AI models directly on user data (including prompts, files, metadata)?
No, never; or only with explicit, granular opt-in, off by default, and clearly explained
4
Yes, but there is a clear, easy opt-out that does not degrade the core service
2
Yes, by default, with no meaningful opt-out (or only buried/obscure settings)
0
//
Section score: 3/22
2
Openness & Transparency
License, auditability, open governance, and independent security assurance.
0%
2.1
What is the source code licence?
OSI-approved open-source license for the core product
10
Open core (core open source, key features proprietary)
8
Source-available (can be inspected, but the license is not truly open)
4
Closed source (no public access to source)
0
//
2.2
Has the software been independently security-audited or certified?
Yes, a recent independent audit or relevant certification (within the last 3 years) with at least a public summary
5
Yes, but the most recent audit or certification is older than 3 years
2
No known independent audits or certifications
0
//
2.3
For open-source projects, is the governance model documented and open to community participation?
Yes, governance is documented (e.g., maintainers and decision process), with contribution guidelines and a code of conduct
1
No, or not applicable (closed-source or no documented governance)
0
//
Section score: 0/16
3
Pricing Model
How users pay for the product, whether pricing relies on exploiting user data, and how fair and transparent prices are across regions.
35.3%
3.1
What is the primary pricing structure?
Free forever: no purchase, subscription, or data monetization of any kind
6
Lifetime license / one-time purchase (no forced ongoing subscription for core use)
5
Annual subscription (fair, predictable)
4
Monthly subscription
2
"Free" but monetizes user data (ads, profiling, data sales)
0
//
3.2
Is there a genuinely functional free tier (without monetising user data)?
Yes, a fully functional free tier that does not monetize user data
4
Yes, but a limited free tier
2
No meaningful free tier
0
//
3.3
Is pricing transparent with no dark patterns?
Fully transparent pricing, clear plans, no manipulation
4
Minor issues or slightly confusing elements, but no clear manipulation
2
Dark patterns present (e.g., tricking users into higher tiers, hidden charges)
0
//
3.4
Does the product use fair regional pricing that reflects local purchasing power without exploiting any region?
Clear, documented regional pricing based on local purchasing power
3
Some regional adjustments, but not clearly documented
2
Flat or opaque pricing with no fair regional adjustments
0
//
Section score: 6/17
4
Ownership & Portability
User control over data and vendor lock-in, including export, self-hosting, offline use, cross-platform availability, and accessibility.
35%
4.1
Can users export ALL their data in an open format?
Yes, full export in open formats (JSON/CSV/XML, standard open formats)
6
Yes, but only in a proprietary format (requires the vendor's tools)
4
Partial export only (not all data, or heavily limited)
2
No meaningful export
0
//
4.2
Is self-hosting available?
Fully local: runs entirely on the user's device, no server or hosting required
6
Yes, a full self-hosting option for the entire product (or a feature-complete edition)
5
Partial self-hosting (some features require the vendor's cloud)
4
No self-hosting option
0
//
4.3
Does the software work offline?
Yes, fully offline for core features
3
Yes, with sync (works offline and syncs when online)
1
Requires an internet connection for core functionality
0
//
4.4
Is the app available on multiple operating systems, including at least one non-proprietary/open platform?
Available on multiple platforms, including at least one open or non-proprietary platform (e.g., Linux, *BSD, F-Droid)
3
Available on more than one platform, but only within closed ecosystems or with significantly reduced functionality outside the main platform
1
Available on a single proprietary platform only, with no public plans or APIs enabling broader access
0
//
4.5
Does the product demonstrate basic accessibility support (screen readers, keyboard navigation, contrast, captions, etc.)?
Clear, documented accessibility support (policy or page) and evidence of basic WCAG-style features
2
Some accessibility features are present but undocumented or clearly incomplete
1
No visible accessibility features and no public commitment
0
//
Section score: 7/20
5
Independence & Ethics
Ownership, independence from Big Tech, stability over time, and whether the company shows responsible behavior in ethics, advertising, and environmental impact.
60%
5.1
What is the company / project structure?
Non-profit, cooperative, or bootstrapped indie project (no external investors)
6
Small private company (no Big Tech parent, no large VC control)
4
VC-funded company
2
Owned or controlled by Big Tech (a large tech conglomerate with a surveillance-capitalism model)
0
//
5.2
Has ownership changed significantly in the last 3 years?
No ownership change
4
Minor change (e.g. small investor, internal restructuring)
3
Acquired by private company (non-Big-Tech)
1
Acquired by Big Tech
0
//
5.3
Does the company publish clear, public policies on responsible use, advertising, and AI?
Clear, public ethical policies covering harmful uses, ads, and data/AI
3
Some relevant ethical policies, but partial or limited
1
No clear public ethical policies beyond the legal minimum, or existing policies are contradicted by the company's actual practices
0
//
5.4
Does the company provide public information or commitments regarding the environmental impact of its infrastructure?
No vendor-operated infrastructure at all: zero environmental impact from operations
2
Clear public information or commitments (e.g., green hosting providers, use of renewable energy, sustainability report)
2
Some indications (blog posts, partial mentions), but no coherent or up-to-date policy
1
No public information or commitments regarding environmental impact
0
//
Section score: 9/15
6
Longevity & Community
How long the project has been actively maintained and how healthy and engaged its user and contributor community is.
100%
6.1
How long has the project been actively maintained?
5+ years of continuous maintenance and releases
5
2–5 years of maintenance
3
Less than 2 years
1
//
6.2
How active and engaged is the project's community and contributor base?
Active community (forums/chats/issues), regular releases, visible roadmap
5
Maintained but quiet (few public contributors, infrequent releases)
3
Low activity, long gaps between releases, "abandoned" feel
0
//
Section score: 10/10