Summary

Local playback, playlists, favorites and most settings are processed on your device. BlueMusic does not sell personal data and does not use third-party advertising or cross-app tracking.

Optional online features may process limited data needed to provide the feature: cloud storage and personal media server browsing, online radio, artwork, lyrics and metadata lookup, audio recognition, Firebase sign-in, library sync, shared playlists and subscription verification.

Local Music Library

Your audio files remain on your device unless you choose to access files from a cloud provider or your own media server. BlueMusic stores local app data such as playlists, favorites, hidden items, playback state and settings on your device.

BlueMusic does not upload your audio files to our servers, either for playback or for library sync.

Account and Library Sync

You do not need an account to use BlueMusic as a local music player. If you turn on library sync, BlueMusic uses Firebase Authentication so your data belongs only to your account.

You can sign in with an email and password or with Google, and with Apple on iOS. Depending on the method you choose, Firebase may process identifiers such as your Firebase user ID, email address, Google account identifier or Apple sign-in identifier. We use this only to authenticate you and protect your data.

Library sync stores your playlists and favorites in Firebase Firestore, under your own account, and keeps them up to date across your devices in real time. A playlist entry holds the title, artist, duration and identifiers needed to find the same song on your other devices. Your audio files are never uploaded, and neither are your settings, your edited lyrics or your custom cover images: those stay on the device where you created them.

Because your data is stored in your account, it comes back when you sign in on a new device. This is a live copy rather than a dated snapshot: a change or a deletion you make is applied on your other devices too. When you delete a playlist it is kept for 30 days so you can restore it, and is then deleted permanently. That recovery window covers deleted playlists, not individual favorites.

Sync uses Firebase Cloud Functions, Firebase App Check, authentication and server-side security rules, and is transmitted over encrypted connections.

Shared Playlists

If you share a playlist through a link, the people who open that link join it and can see and edit it together with you. From that moment the playlist name and the song entries it contains are visible to every member, and any change one member makes is visible to the rest.

A shared playlist is stored separately from your personal data and is readable only by its members. Sharing is your choice and applies only to the playlists you decide to share: the rest of your library stays private to your account. Anyone holding the link can join, so treat it as you would any private link.

Shared playlists carry the same song information as a normal playlist. They never carry your audio files, your account details beyond membership, or any credentials for your cloud providers or media servers.

If you delete your account, the shared playlists you created are deleted for everyone, and you are removed from the ones created by other people.

Subscriptions and Purchases

Library sync and shared playlists are paid features. Purchases are handled by Google Play Billing or Apple In-App Purchase. BlueMusic verifies subscription status with Google Play or Apple before enabling them. Opening a shared playlist someone sent you does not require a subscription.

For fraud prevention, restore and support, BlueMusic stores limited subscription records in Firebase, such as product ID, platform, subscription state, expiration time, verification time and hashed purchase or transaction identifiers. Raw purchase tokens are not stored as plain text by our backend.

Billing, cancellation, refund and tax data are handled by Google or Apple according to the store account you used for the purchase.

Cloud Storage and Media Providers

Google Drive, OneDrive, Dropbox, Box, pCloud, self-hosted media servers

If you connect a cloud storage account, BlueMusic uses the permissions you approve to browse and play your own audio files. Where supported, BlueMusic requests read-only access. It does not modify, delete or upload files to those storage providers for playback.

OAuth tokens and media server credentials are stored on your device using the platform's secure storage when available. Requests to browse or stream cloud files are sent to the provider you selected.

If you manually configure a self-hosted server over plain HTTP, traffic to that server may not be encrypted by TLS. Use HTTPS for remote servers whenever possible.

Google API Services - Limited Use

BlueMusic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The read-only access to your Google Drive is used for a single purpose: to let you browse and play your own audio files inside BlueMusic. This Google user data:

  • is used only to provide or improve the in-app music playback feature;
  • is not transferred to or sold to third parties, except as strictly necessary to provide the feature, comply with applicable law, or as part of a merger or acquisition;
  • is not used for advertising or unrelated profiling; and
  • is not read by humans unless you give explicit consent for support, it is necessary for security, or it is required by law.

Artwork, Lyrics and Metadata Lookup

When you ask BlueMusic to find artwork or complete song metadata, the app may send search terms, song title, artist, album, duration, ISRC or other music identifiers to the services below, so it can retrieve public artwork, track details and lyrics. Your audio files are not uploaded for these lookups, except for the audio recognition case described below.

Apple, the iTunes Search API and BlueMusic's Firebase backend

Song details are sent to Apple's public search service and to BlueMusic's own Firebase backend, which queries the Apple Music catalogue on the app's behalf, to obtain cover art and track information.

LRCLib

When a song has no lyrics stored inside the file, the app looks them up automatically at lrclib.net, sending the title, artist, album and duration needed to find a match. This is a free public service and needs no account.

ShazamKit

If you ask BlueMusic to identify a track it cannot name, the app creates an acoustic fingerprint of that audio file and sends it to Apple's ShazamKit service to obtain the title and artist. This only happens when you start it yourself, on the song you choose.

Radio Browser

When you start a radio station, the app notifies the public Radio Browser directory so the station's play count is recorded. The notification identifies the station, not you.

These lookups are used to provide the requested in-app feature and are not used for advertising.

Online Radio

The station list is bundled with the app, so browsing it needs no account and no network request. When you play a station, your device connects directly to that broadcaster's stream, and the broadcaster receives the connection data any internet request carries, such as your IP address. BlueMusic does not control what a broadcaster logs.

Diagnostics and Support

BlueMusic does not include advertising trackers and does not use analytics products. Platform providers, such as Google Play, Apple, Firebase, Google or Apple sign-in, may provide crash, integrity, billing or security information needed to operate their services.

The app sends crash and error reports to Firebase Crashlytics so we can fix what breaks: unexpected crashes, and some errors the app detects without closing, as explained in the next paragraph. It also sends a small set of anonymous counters about the first use of an install, each one at most once in the lifetime of that install: whether you granted, denied or skipped the music permission, that the first library scan finished and how many songs it found, that the first playback happened, and that feedback was sent. These counters carry no identifier and are added to a daily total per platform, so there is no record of an individual device.

An error that does not close the app is reported only when it leaves you without something, and at most once per error in each session: for example, a purchase or restore that does not complete, a download that fails, a playlist or favorite that does not sync, or a song that cannot be played or deleted. The report says what the app was doing, with which provider (such as Google Drive or Jellyfin) and sometimes on which screen, the type and code of the error, and where in the app's code it happened. It may also carry short notes about what had just happened, like a local, radio or cloud song starting, without saying which one. It never includes your music, your playlists or your email address, nor song titles, file or folder names, web or server addresses, passwords or tokens. As with any Crashlytics report, it also carries technical details about the device (model, operating system and app version, free memory and storage) and a random installation identifier generated by Firebase. Crashlytics also records when each session of use starts, though not what you do in it, to work out how many sessions end without a crash. None of this is linked to your BlueMusic account or to an advertising identifier, and Crashlytics deletes it after 90 days. We process this data on the basis of our legitimate interest in keeping the app working and secure. You can stop sending crash and error reports at any time by turning off Send error reports in Settings → About.

If you send us feedback from inside the app, the message travels with the app version and build number, your operating system version, your device model and manufacturer, and the language you chose in the app. We use it only to reproduce and fix the problem you are reporting.

If you email us for support, we will receive your email address and anything you choose to include in your message. We use that information only to respond, investigate bugs, protect the service or comply with legal obligations.

Account, Retention and Deletion

You can delete your BlueMusic account and its synced data in the app or by request. See our dedicated Delete Your Account page for step-by-step instructions.

Local data can be removed by deleting the app or clearing its app data on your device. On Android, if you have Google backup turned on, Google also keeps a copy of BlueMusic's settings and other local data, such as your playlists and favorites, in your own Google account, and we have no access to it. That copy never includes your audio files, your downloads, your library, the access tokens for your cloud providers or the passwords for your servers. On iPhone and iPad, if you have iCloud Backup turned on, BlueMusic's data goes into your device's iCloud backup like any other app's, including your settings, your playlists, your favorites and the songs you imported into BlueMusic. The songs downloaded from your cloud providers are left out. Apple keeps that backup in your own iCloud account, and we have no access to it either. Cloud provider access can be revoked from the provider's account settings.

To request deletion of your BlueMusic account or its synced data, email laskyfeedback@gmail.com from the email address associated with your BlueMusic account and write "BlueMusic account deletion" in the subject.

After we verify ownership, we delete the Firebase Authentication account, your synced playlists and favorites, the shared playlists you created, and the subscription entitlement records associated with that account, unless we must retain limited records for security, fraud prevention, legal compliance, dispute handling or tax/accounting obligations.

You can also request deletion of only your synced data without deleting your account. We aim to complete verified deletion requests within 30 days, unless a longer period is required by law or by an active dispute, security investigation or fraud-prevention hold.

Children

BlueMusic is not directed to children under the age required by applicable law to consent to online services. Do not enable online account or payment features if you are not allowed to do so.

Who Is Responsible for Your Data

The controller of the personal data described in this policy, for the purposes of the EU General Data Protection Regulation (GDPR), is Pedro Antonio Flores Casquet, who publishes his apps as Lasky.

Your Rights

You are in control of your personal data. Under the GDPR and equivalent laws, you can:

  • Access the personal data we hold about you.
  • Correct any inaccurate or incomplete information.
  • Obtain a copy of your synced playlists and favorites (portability).
  • Request the deletion of your account and its synced data.
  • Object to processing based on our legitimate interest, such as crash and error reports.
  • Ask for the processing of your data to be restricted.
  • Lodge a complaint with your data protection authority (in Spain, the AEPD).

For any privacy question, or to exercise your rights over your data, write to laskyfeedback@gmail.com.

Changes and Contact

We may update this Privacy Policy from time to time. Updates will be reflected on this page with a new date.

Technical Support: laskyfeedback@gmail.com