This Privacy Policy explains how Ymusic Player ("Ymusic", "the app", "we", "us") collects, uses, stores, shares, and protects your information. Ymusic is a personal audio player that runs in your web browser at https://ymusic.dalim.dev. It is an independent project operated by an individual developer, not a company.
This policy also serves as Ymusic's disclosure of how it accesses and uses information from Google APIs, in compliance with the Google API Services User Data Policy, including its Limited Use requirements (see section 10).
Contact / data controller: the developer of Ymusic, reachable at dalimchyjony@gmail.com for any question, access request, or deletion request.
1. Summary of the data Ymusic collects
If you do not sign in and do not donate, Ymusic collects no personal data on its server beyond ordinary web-server request logs. Everything else stays in your browser on your device. The table below summarises every category of data the app can handle:
- Google profile data (name, email address, profile picture, Google account ID) — collected only if you choose to sign in with Google. Source: Google Identity Services. Used to identify your account and separate your library from other users. Stored: in your browser, and (for sync) referenced by account ID on our server. Not shared with anyone.
- Google Drive file access (the specific audio files you pick, plus one app-created settings file) — collected only if you use the "Add from Google Drive" feature. Source: Google Drive API,
drive.file scope. Used to stream those files for playback and to sync your Drive track list across devices. Stored: file references in your browser and in the app-created file in your own Drive; audio is never stored on our server. Not shared with anyone. - Your audio files and library (audio data, track metadata, playlists, liked songs, playback settings) — collected when you add files. Source: files you choose from your device or Drive. Used to build and play your library. Stored: in your browser; audio files additionally on our storage server if you are signed in and sync is active. Not shared with anyone.
- Donation data (amount, currency, one-off vs monthly, your optional name and message, the email Stripe collects for your receipt, Stripe payment/customer/subscription IDs) — collected only if you make a donation. Source: you and Stripe Checkout. Used to process the payment and show a supporters list (name and message only). Stored: on our server and by Stripe. Shared with: Stripe (payment processor).
- Technical logs (IP address, browser/user-agent, request time and path) — collected automatically for every visitor. Source: the web server. Used for security and troubleshooting. Stored: in server logs for a short period. Not shared except where required by law.
Ymusic does not use cookies for tracking, does not run analytics or advertising, and does not sell or rent your data. See section 8.
2. How the app is put together
Playback happens entirely in your browser. Audio files you add from your device are stored locally in your browser and played from there. Ymusic also has a small backend service (at https://ymusic.dalim.dev/api) used only for three optional things:
- verifying your Google sign-in;
- optional cross-device library sync for signed-in users;
- processing donations, if you choose to make one.
3. Signing in with Google
Signing in with Google is optional. Local playback works fully without an account. If you do sign in, Ymusic uses Google Identity Services and receives, from Google's sign-in response, your:
- name and profile picture — shown in the app so you can see who is logged in;
- email address — used to identify your account, to match the app's admin account, and (if you donate) for your payment receipt;
- Google account ID — a stable identifier used to keep your library, playlists, and synced files separate from anyone else's.
When you use a feature that needs the backend (library sync), your browser sends Google's signed ID token to our backend, which verifies it with Google to confirm the request is really from you. We never receive or store your Google password. We do not request access to your contacts, calendar, Gmail, photos, or any Google data other than what is described here.
4. Google Drive access
Playing audio from your own Google Drive is an optional feature you turn on by using "Add from Google Drive". If you never use it, no Drive permission is requested.
Ymusic requests only the https://www.googleapis.com/auth/drive.file scope — the most limited Drive scope available. It grants access only to:
- the specific files you select yourself through Google's own file-picker dialog; and
- one small file the app itself creates in your Drive, named ymusic-library.json, which holds a list of the Drive tracks you have added so the same list appears when you sign in on another device. It contains file references and basic track metadata (title, artist) — never audio.
Ymusic cannot see the rest of your Drive — not your other files, folders, or file list. When you play a Drive track, the audio is streamed on demand from Google directly to your browser for playback; it is not routed through, copied to, or stored on our server. The OAuth access token for these requests is held only in your browser and is discarded when it expires or when you sign out.
We use Drive data solely to provide the playback and sync features above. We do not transfer it to third parties, do not use it for advertising, and do not use it to train any AI/ML models.
5. Cross-device library sync (signed-in only)
If you are signed in, Ymusic can keep your library available across your devices. This is the only situation in which files or records leave your browser for our server:
- Local audio files you add are uploaded in the background to our object storage (a self-hosted MinIO server) so they can be downloaded automatically on your other devices where you are signed into the same Google account. Every stored object's key is prefixed with your Google account ID and is not accessible to other users. Deleting a track in the app deletes it from our server too.
- A sync record for each synced track — its metadata (title, artist, etc.) and storage key, not the audio itself — is kept in a small database on our server, keyed to your Google account ID.
- Google Drive tracks are not uploaded to us — only their references sync, via the ymusic-library.json file in your own Drive (section 4).
Playlists, liked songs, and per-track settings are deliberately not sent to our server; they stay in your browser on each device.
6. Donations
Donating via the "Support Ymusic" page is optional. Payments are processed by Stripe. Your card details are entered on Stripe's own hosted checkout page and are never seen by or sent to Ymusic.
For a donation, our server stores:
- the amount and currency, and whether it is one-off or a monthly recurring donation;
- the name and message you optionally enter — the name and message (never your email) may be shown on a public "supporters" list in the app;
- the email address Stripe collects for your receipt — stored on our server, not shown publicly;
- Stripe's payment, customer, and (for monthly donations) subscription identifiers, so renewals and any refund can be reconciled.
A monthly donation creates a Stripe subscription that you can cancel at any time from the link in the receipt emails Stripe sends you. Stripe's handling of your data is governed by Stripe's Privacy Policy.
7. What is stored locally in your browser
Using IndexedDB and localStorage on your device, the app stores: the audio data and metadata of local files you add (so they stay playable across visits); your playlists, liked songs, and per-track repeat settings; app preferences (volume, shuffle/repeat, playback speed); your sign-in session (name, email, picture, account ID) so you stay logged in; for Drive tracks, the file references and the short-lived OAuth access token; and, if you are the site's admin, local app configuration and a short-lived in-memory diagnostic log. This local data never leaves your device except as described in sections 5 and 6.
8. What Ymusic does NOT do
- No analytics, usage tracking, fingerprinting, or tracking cookies.
- No advertising and no ad-tracking of any kind.
- No selling or renting of your personal data.
- No sharing of your data with third parties except the service providers needed to run the features above (Google for sign-in/Drive, Stripe for donation payments, and the app's own hosting/storage), or where required by law.
- No use of Google user data, or any of your data, to train generalized AI/ML models.
9. Data retention and deletion
- Local data stays in your browser until you clear it — via the app's "Clear all local data" control (admin), or through your browser's site-data settings.
- Synced audio files and sync records on our server are deleted when you delete the track in the app, or on request by emailing dalimchyjony@gmail.com from your account's email address. We aim to action deletion requests within 30 days.
- The ymusic-library.json file lives in your own Drive; you can delete it yourself at any time.
- Donation records are retained as long as needed for accounting and tax purposes.
- Server logs are retained for a short period (typically a few weeks) and then rotated out.
- You can revoke Ymusic's access to your Google Account and Drive at any time at myaccount.google.com/permissions. Doing so signs you out; local data already on your device is unaffected.
10. Google API Services User Data Policy — Limited Use
Ymusic's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we only access the Google user data needed to provide the features described in this policy;
- we only use that data to provide or improve those user-facing features;
- we do not transfer that data to others except as necessary to provide those features, for security or legal compliance, or as part of a merger or acquisition (with prior notice to you);
- we do not use that data for serving advertisements;
- we do not allow humans to read that data unless we have your consent, it is necessary for security or to comply with the law, or the data has been aggregated and anonymised;
- we do not use that data to develop, improve, or train generalized/non-personalized AI and/or ML models.
11. Third-party services
- Google Identity Services, Google Drive API, and Google Picker API — for sign-in and optional Drive playback. Governed by Google's Privacy Policy.
- Stripe — for donation payments. Governed by Stripe's Privacy Policy.
- The app's hosting and object storage — used to serve the app and, for signed-in users, to store synced audio.
12. International users and legal bases
Ymusic is operated from the United Kingdom, and data may be processed there and in other countries where our service providers operate. Where the UK GDPR / EU GDPR applies, our legal bases are: your consent (for Google sign-in and Drive access, which you can withdraw at any time), performance of a contract (providing sync and processing a donation you requested), and our legitimate interests (keeping the service secure and working).
13. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, to withdraw consent, and to object to or restrict certain processing. To exercise any of these, email dalimchyjony@gmail.com. You also have the right to complain to your local data-protection authority (in the UK, the Information Commissioner's Office).
14. Children's privacy
Ymusic is not directed at children under 13 (or the equivalent minimum age in your country), and the developer does not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and it will be deleted.
15. Changes to this policy
This policy may be updated as the app changes. The "Last updated" date above reflects the most recent change, and material changes will be noted in the app where practical.
16. Contact
Questions or requests about this policy: dalimchyjony@gmail.com.