Privacy Policy — Sweett's MusicAPP
What the app stores on your device, and what it never collects.
Last updated: 2026-10-05
This policy explains what Sweett's MusicAPP stores when you connect a streaming service. The app runs entirely on your own Android device; there is no company server that collects your data.
Data stored on your device only
- Service credentials. OAuth access and refresh tokens for the services you
connect are saved in Android's
EncryptedSharedPreferences, backed by the Android Keystore. They are never written to plain files, logs or backups. - Your library index. Song titles, artists, albums, durations and file paths read from your device stay in a local Room database on the phone.
- Cached artwork. Album art is stored in the app's private files directory so lists do not re-download covers. It never leaves the device except as described below.
- Settings and scrobble queue. Playback preferences and any pending Last.fm scrobbles are stored locally.
Google Drive
- The app requests the
https://www.googleapis.com/auth/drive.readonlyscope. It can list folders you select and read audio files inside them. It cannot write, delete or share anything in your Drive. - File names, sizes and metadata from the folders you select are cached locally so your library lists load offline.
- Audio is streamed directly from Google to your device through a local proxy bound to
127.0.0.1. It is not routed through any third-party server. - Revoking access in your Google account settings immediately stops the app from signing in again. You can also disconnect the account inside the app, which deletes the stored tokens.
Cover art CDN
The app can publish a small 256×256 thumbnail of your album art to
musiccdn.devsweett.com so that Discord Rich Presence can display the cover of the
track you are playing. Thumbnails are uploaded content-addressed (named after the SHA-256 of the
image), contain no account information, and are readable by anyone who knows the hash. You can
turn this off; when disabled, no artwork is uploaded.
What is never collected
- No analytics, telemetry, crash reporting or usage tracking.
- No advertising identifiers and no third-party tracking SDKs.
- No selling or sharing of personal data. There is no such pathway in the app.
Children
The app is not directed at children and collects no personal information from anyone.
Changes
If this policy changes, the updated date at the top of this page changes with it.
Contact
Questions about this policy can be sent to the maintainer through the project's repository.