Last updated September 28, 2026
Berwel is an archive of Libyan song. You can search it, read lyrics and listen without an account. This page says what we collect when you listen and when you sign in, what we keep and for how long, which cookies we set, who else handles it, and how to delete it.
Berwel is run by [operator's legal name and address: needs Berwel]. Questions about this policy or about your data go to [contact email: needs Berwel], or through the report form.
There are no passwords. You sign in with a Google account or with a six-digit code sent to your email address.
With Google, we receive the name, email address and profile picture on your Google account, and whether Google has verified that address. We also keep the sign-in tokens Google issues for the link between the two accounts, and use them for nothing else. We never see your Google password or your contacts.
With email, we receive the address you type. The code is delivered by Resend, the email service we use, and expires after five minutes.
Either way, the account that results holds an email address, the display name you choose and a picture: the one Google gave us, one of Berwel's preset pictures, or an image you upload. You can change the name and the picture in Settings. If you change your email address, a code goes to the new address and a notice to the old one.
Signing in keeps you signed in for seven days, renewed while you keep using the site. For as long as that session exists, the server keeps the IP address and browser it was opened from. Signing out, or deleting your account, removes it. To slow down abuse, the server also counts recent sign-in attempts per IP address, and forgets those counts within a day.
Everything you do while signed in is stored against your account so it is there next time: the songs and albums you like, the mixtapes you make and the mixtapes you like, the artists and people you follow, whether your account is private, your language (so emails reach you in it) and whether you want notification emails.
Your contributions are stored too: every submission you send (lyrics, translations, transliterations, annotations, corrections, artist and album details, links to recordings, images), its review outcome, the annotations you upvote, the points you earn and the stamps you are awarded. We also keep a trust score worked out from how many of your contributions were approved and rejected, which staff use to decide who becomes a trusted contributor.
Once you have listened to a recording for at least thirty seconds, we record a play event: the song and recording, the time, the kind of page you started it from, a random id for that visit, a random id this browser keeps, and whether you listened to the end. Signed in, the play is also stored against your account, counts towards listening stamps and fills the Continue listening row on any device you sign in on. Signed out, only the browser's random id is kept with it, which names no one. Because the same browser id goes with plays before and after you sign in, plays made on this browser before you signed in can be linked to your account.
Nobody sees your individual plays. They are counted into totals: the most-played lists on the site, and the listening figures Berwel staff use to run it.
When someone follows you, a contribution of yours is approved or rejected, or you are awarded a stamp, you get a notification on the site and an email, unless you turn email notifications off in Settings. Emails are delivered by Resend.
The report form sends its topic, your message, the song it is about and, if you give one, a reply email address to Berwel's inbox as an email. It is not stored in the database. Signed in, your name and email address go with it. Signed out, the form first runs a Cloudflare Turnstile check to keep out bots, which loads a script from Cloudflare.
Some things are kept only in this browser's own storage and never sent to the server: the current queue and where you were in it, the songs you played recently, your recent searches, your theme, how you like lyrics shown and whether the sidebar is collapsed. Clearing the browser's site data clears them. The random browser id used for play events is kept here too, and is sent with each play; clearing site data replaces it with a new one.
Berwel's own cookies are the ones the site needs to work: one that keeps you signed in (seven days, renewed while you use the site, with a thirty-second copy that saves the server a lookup), a short-lived one used while you sign in with Google, one that remembers your language until you close the browser, and one that remembers whether names are shown in Arabic or Latin letters (one year). None of them is used for tracking or advertising.
When Google Analytics is switched on, Google's script sets its own cookies, named _ga and _ga_ followed by an id, which last up to two years. They are described under Analytics below. Blocking them in your browser does not stop Berwel from working.
When Google Analytics is switched on, Google's script runs on every page and receives the page views, including the words you search for (they are part of the search page's address), and the device information Google collects. Separately, the server tells Google Analytics about the plays we record (the song and its artist, the recording, the kind of page it was started from, whether you were signed in and whether you listened to the end) and about each new account (only whether it was made with Google or with email). These carry Google's own id for your browser, or for plays where Google's script did not load, the random browser id described above. They never carry your name, email address or account. When Google Analytics is switched off, none of this is sent. We do not use analytics to profile individual accounts, and Berwel shows no ads.
Your display name and picture appear on your public profile and beside your approved contributions. A private account hides its profile's contents and its contributions from other people; the name, picture, the date it joined and its follower and following counts stay visible. Likes are yours alone, and so are mixtapes unless you make one public.
Reviewers see who sent each submission. Actions by Berwel staff are written to an audit log with the staff member's name and email. Deleting your own account is written there too, with the name and email the account had, so there is a record that you asked for it.
Recordings are not hosted by Berwel. They stream from SoundCloud, or from YouTube where a recording links there. When you press play, your browser connects to that platform, which sees your IP address and applies its own privacy policy.
Berwel runs on Railway, which hosts the site, its database and its search index. Artwork, stamp images and uploaded pictures are stored on Cloudflare R2. Google handles the sign-in handshake when you use Google, and a profile picture that came from Google is loaded from Google. Resend delivers emails. Cloudflare Turnstile checks the report form for bots.
Open Settings, go to the bottom, choose Delete account and confirm. You are signed out everywhere at once, and the link to your Google account is removed at the same moment.
Your account, library, mixtapes, follows, points, stamps, notifications and play events are then removed from the database, and a picture you uploaded is deleted from storage. They wait thirty days before a daily sweep removes them for good. Contributions you already sent, approved or still waiting for review, stay in the archive without your name, and the audit log keeps its record of the deletion. [how long database backups are kept: needs Berwel]
Your email address is free to sign up again the moment you delete.
When this page changes, the date at the top changes with it.