Privacy Policy
1. What the app reads on your device
- Your Apple Music library, after you allow the standard "Media & Apple Music" permission. For each song: title, artist, album, genre, duration, play count, last-played date, date added, release date, ISRC, artwork URL, explicit flag. The app uses these to compute your listening statistics (DNA, Records, Recently played) on the device.
- Playback state for diagnostics: what is playing, position, rate, interruptions and audio route changes (headphones, speaker). This is kept in a small in-memory log of the most recent events and is discarded when the app quits.
- Device details written into that log: device model, the device name you set in Settings, iOS version, app build number, and whether the app is running on a Mac.
- Settings stored inside the app: theme, saved Mix Lab sets, Muse conversation state, dismissed hints, preview volume, and a cached copy of your library snapshot. All of it lives in the app's own storage and is removed when you delete the app.
- Push notification token. At first launch the app asks for notification permission and stores the Apple push token on the device. It is not uploaded automatically; a copy-token action exists so the developer can register his own devices by hand.
The app never reads your contacts, photos, location, microphone, camera, or clipboard.
2. What goes to Apple
- Playing full songs, catalog search, charts, radio stations, lyrics, creating playlists, and reading your library all go through MusicKit and the Apple Music API. Apple receives those requests under Apple's own privacy policy. The app identifies itself to Apple with a developer token, which identifies the app, not you.
- When you use lyrics or save a playlist, a MusicKit user token that Apple issues for your Apple Music account is attached to requests sent to Apple only. It is never sent to the developer.
- Artwork and 30-second previews are loaded from Apple's servers.
- Full songs need an Apple Music subscription. Previews, charts, radio metadata, search and all statistics work without one.
3. What goes to the developer's server, and only when you are signed in or it is reachable
The developer's server is a Mac in New York. On launch the app looks for it on the local network (this is why iOS shows the Local Network prompt), over a private VPN (Tailscale), and, since 2026-09-03, over the internet at musicintel.maxmoran.org through Cloudflare. Invited testers sign in with a username (their name) and a shared password; sessions last 180 days on a device and can be ended with Sign out. A tester who taps Continue offline, or whose device cannot reach the server, uses the offline copy inside the app and sends nothing to the developer. Cloudflare sees the connection metadata (IP address, timing) that any web request carries, under Cloudflare's privacy policy. When you are signed in:
- The diagnostics log described above is uploaded so device test runs can be graded. It is stored on that Mac as one file per device.
- Your library snapshot (the song fields listed in section 1) is uploaded so your statistics can be computed server-side as well. It is stored on that Mac as one file per device.
- Questions you type into Muse, the AI assistant, are sent from that Mac to Anthropic's API to generate the answer. Muse is hidden entirely when the Mac is not reachable.
- Tapping "+ Feed" on a search result adds that song's artist, title and Apple catalog id to the shared discovery catalog.
The identifiers used are your username (the name you were invited with) and Apple's per-app vendor identifier, which resets when you delete and reinstall the app. The server stores a salted hash of the shared password and a hashed session token, never the password itself. No email address, Apple ID, or location is collected; the email you use for TestFlight is handled by Apple, not by this app.
4. Retention
Files on the developer's Mac are kept until deleted by hand; there is no automatic expiry. Email the address above from any account and your device's files will be deleted within seven days. Data stored inside the app on your device is removed when you delete the app.
5. Third parties
- Apple: MusicKit, Apple Music API, iTunes previews and artwork, TestFlight, push notifications.
- Anthropic: only the text of Muse questions, only via the developer's private Mac, only when it is reachable.
No advertising networks, no analytics SDKs, no data brokers. Data is never sold or shared for marketing.
6. Children
Music Intel is not directed at children under 13. The Apple Music catalog it browses contains songs Apple marks explicit; the app shows Apple's explicit marker and does not filter it.
7. Your choices
- Revoke the Media & Apple Music permission in Settings › Privacy & Security › Media & Apple Music. The app keeps working with previews only.
- Turn off notifications in Settings › Notifications › Music Intel.
- Delete the app to remove everything stored on the device.
- Email to have server-side files deleted.
8. Changes
Changes are listed here with the date. Material changes are also noted in the App Store "What's New" text for the build that introduces them.
- 2026-09-03 — sign-in for invited testers; the developer's server is reachable over the internet at musicintel.maxmoran.org.
- 2026-09-02 — first version.