TinyTunes · Privacy

Privacy Policy — TinyTunes

Effective date: 6 August 2026

Last updated: 14 August 2026

Language: English (authoritative for international disclosure). A German version is provided at privacy-policy.de.html.

1. Who we are (controller)

TinyTunes (“the App”) is a mobile audio player for Android (and planned for iOS).

Controller (responsible for personal data processed in connection with the App as described here):

Field Value
Legal name Mario Angerer
Contact email privacy@blumenlaube.at
App package (Android) at.blumenlaube.tinytunes

If you have questions about this policy or your personal data, contact us at the email above.

2. Scope

This policy explains how TinyTunes processes personal data when you install and use the App.

TinyTunes is designed as a local-first app: your music library index, play queue, settings, and (optional) cloud cache live on your device. The App does not operate its own backend server that receives your library or listening history.

Third parties you choose to connect (notably Google for Drive and Microsoft for personal OneDrive) process data under their own terms and privacy policies when you sign in or access cloud files. Section 6 summarizes those relationships.

3. What data we process

3.1 Data stored only on your device

Depending on how you use the App, the following may be stored in the App’s private storage on your device (for example via the local database and preferences):

Category Examples Purpose
Library / catalog Folder roots you add, file/display names, opaque locators (local content URIs, gdrive:<fileId>, or OneDrive drive/item locators), optional audio tags (title, artist, album) Index music and show it in the queue
Queue / playback state Ordered playlist entries, now-playing related state Play and navigate your queue
Settings Theme preference, cloud cache size limit, last update-check time, dismissed update tag Remember your choices
Session messages Short in-app status/error messages Show recent feedback in the message center
Cloud cache (optional) Downloaded audio files and cache index metadata (size, last access) Play cloud tracks offline-capable after download

The App may read audio metadata and embedded artwork from files you open (local or cached) to display titles and related information. That metadata stays on the device unless you separately share it outside the App.

3.2 Google account data (only if you sign in)

If you use Sign in with Google for Drive:

3.3 Microsoft account data (only if you sign in to OneDrive)

If you use Sign in with Microsoft for personal OneDrive:

3.4 Data we do not collect (current App)

As of the effective date, TinyTunes does not:

3.5 GitHub release check

On the official GitHub APK (release-signed), on launch (at most once per 24 hours) and when you tap Check for updates in About, the App requests the latest public release from GitHub (https://api.github.com/repos/Tyniann/tinytunes/releases/latest). GitHub receives your device IP address and a User-Agent identifying TinyTunes. The App does not send your music library, cloud accounts, or listening history. Forks and debug builds do not make this request. GitHub processes that request under GitHub’s Privacy Statement. Last-check time and a dismissed version tag may be stored on the device.

If that changes in a future version, this policy will be updated.

4. Purposes and legal bases (GDPR)

We process personal data only as needed to provide the App you choose to use:

Purpose Typical data Legal basis (GDPR)
Provide local playback, catalog, and queue On-device library and queue data Art. 6(1)(b) — performance of the contract / service you request by using the App
Remember settings (theme, cache budget, update-check) Preferences on device Art. 6(1)(b); where required locally, Art. 6(1)(f) legitimate interest in a functioning UI — overridden by your control of settings and uninstall
Check GitHub for a newer public release Device IP and User-Agent seen by GitHub; on-device last-check / dismissed-tag prefs Art. 6(1)(f) legitimate interest in telling you a newer APK exists — you can dismiss the dialog
Optional Google Drive library (sign-in, list, download-to-cache, play) Google email/name display, tokens, Drive file metadata and file bytes you trigger for playback Art. 6(1)(a) — consent, given when you sign in and grant Drive access (and withdrawable by signing out / revoking access in Google Account settings)
Optional personal OneDrive library (sign-in, list, download-to-cache, play) Microsoft email/name display, tokens, OneDrive file metadata and file bytes you trigger for playback Art. 6(1)(a) — consent, given when you sign in and grant Files.Read (and withdrawable by signing out / revoking access in your Microsoft account)
Answer privacy requests you send us Whatever you include in email Art. 6(1)(c) legal obligation and/or Art. 6(1)(f) / (b) as applicable

You can refuse Google and/or Microsoft sign-in and still use local folders. Each cloud provider’s features simply will not be available until you consent to that provider.

5. How long we keep data

Data Retention
On-device catalog, queue, settings, messages, cloud cache Until you delete it in the App (for example Forget folder, Clear cloud cache, Sign out for that provider’s cache wipe) or uninstall the App / clear App storage
Google tokens / session Until you sign out in the App or revoke access in your Google Account; Sign out also wipes that provider’s local cloud cache
Microsoft tokens / session Until you sign out in the App or revoke access in your Microsoft account; Sign out also wipes that provider’s local cloud cache
Emails you send to our contact email Only as long as needed to handle your request and meet legal record-keeping duties

We do not run a TinyTunes server-side archive of your library.

6. Recipients and processors (Google / Microsoft / GitHub)

6.1 No TinyTunes cloud recipients

We do not transmit your library or listening history to a TinyTunes-operated server.

6.2 Google

If you enable Google Drive features, Google Ireland Limited and/or other Google entities process your Google Account and Drive data as described in Google’s documentation and policies, including:

TinyTunes uses Google Sign-In and the Google Drive API solely to:

  1. Authenticate you
  2. List Drive folders/files (audio and folders relevant to browsing)
  3. Download selected audio into the App’s local cache for playback

TinyTunes does not use Drive data for advertising and does not grant the App write access to your Drive.

Google may process data in locations outside the EEA under Google’s own transfer mechanisms (for example Standard Contractual Clauses). See Google’s privacy documentation for details.

6.3 Microsoft

If you enable personal OneDrive features, Microsoft entities process your Microsoft account and OneDrive data as described in Microsoft’s documentation and policies, including:

TinyTunes uses Microsoft sign-in (MSAL) and Microsoft Graph solely to:

  1. Authenticate you with a personal Microsoft account
  2. List folders/files in your own OneDrive (audio and folders relevant to browsing)
  3. Download selected audio into the App’s local cache for playback

TinyTunes does not use OneDrive data for advertising and does not grant the App write access to your OneDrive.

Microsoft may process data in locations outside the EEA under Microsoft’s own transfer mechanisms. See Microsoft’s privacy documentation for details.

6.4 GitHub

The App contacts GitHub (api.github.com) to read the latest public TinyTunes release. That request is processed by GitHub under GitHub’s Privacy Statement. TinyTunes does not send your library or account data in that request.

6.5 Device / OS vendors

Your device manufacturer and OS (for example Google Android / Play Services) may process data under their own policies when you install the App, use system folder pickers, or use platform sign-in components.

7. International transfers

On-device data stays on your device unless you choose a feature that contacts Google (Sign-In / Drive), Microsoft (sign-in / Graph / OneDrive), or GitHub (latest-release check). Those transfers are governed by Google’s, Microsoft’s, or GitHub’s terms and transfer tools. We do not operate additional TinyTunes international transfers of your library.

8. Security

We aim to limit data exposure by design:

No method of electronic storage is perfectly secure. Protect your device with a screen lock and keep the OS updated. Anyone with unlock access to your device may access App data stored on it.

9. Your rights (EEA / UK and similar)

Where the GDPR (or UK GDPR) applies, you have the right to:

Practical exercise in the App:

For requests that need our help (for example confirmation what we hold as controller), email privacy@blumenlaube.at. We will respond within the statutory period (generally one month).

You also have the right to lodge a complaint with a supervisory authority, in particular in your EU/EEA member state of residence. In Austria, for example, that is the Österreichische Datenschutzbehörde (dsb.gv.at).

10. Children

The App is not directed at children. We do not knowingly offer Google Drive or OneDrive sign-in aimed at users under the digital consent age applicable in their country (often 16 in the EU, sometimes lower). If you believe a child provided personal data via the App contrary to this policy, contact us and we will help delete on-device guidance and revoke access as appropriate.

11. No automated decision-making

TinyTunes does not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects (GDPR Art. 22).

12. Changes to this policy

We may update this policy when the App’s features or legal requirements change. The “Last updated” date at the top will change accordingly. Material changes affecting cloud OAuth use should be reflected before you rely on a new scope or new sharing of data.