The short version
- Your music library never leaves your device. HypeMuzik scans and plays your files locally. We do not upload them, copy them, or index them on a server.
- We do not run accounts. There is no HypeMuzik sign-up, no password, and no profile.
- Cloud access is opt-in and stays between you and your provider. If you connect Google Drive or Dropbox, your files stream directly from that provider to your device. They do not pass through any HypeMuzik server.
- We do not sell your data, show you ads, or train AI models on it. Ever.
- You can disconnect at any time, from inside the app and from your Google or Dropbox account settings.
Who this covers
This policy applies to the HypeMuzik desktop application (macOS, Windows and Linux), the HypeMuzik mobile application (Android and iOS), and this website, hypemuzik.com.
HypeMuzik, operated as a sole proprietorship by an individual developer based in the Republic of Uganda, is the party responsible for the data described here. You can reach us at brunolabs256@gmail.com.
What stays on your device
Most of what HypeMuzik knows about you never reaches us, because it never leaves the machine you installed it on. That includes:
| What | Why it exists | Where it lives |
|---|---|---|
| Your music library index | Titles, artists, albums and artwork, so search and browsing are instant | A local database on your device |
| Equalizer and DSP settings | So your presets, curves and effect chain survive a restart | Local app settings |
| Play history and counts | To build your daily mixes and recently-played lists | The same local database |
| Connected-account labels | To show which Google or Dropbox account a library belongs to | Local app settings |
| Cloud access tokens | So you do not have to reconnect every time you open the app | Your operating system's secure credential store |
None of the above is transmitted to us. If you uninstall HypeMuzik, it goes with it.
The same is true of Phone Link, the feature that streams audio from your phone to your desktop. That connection is made directly between your own two devices over your own network. The audio is not relayed through a HypeMuzik server, and we never see what you are streaming.
Connecting Google Drive
Connecting Google Drive is entirely optional. HypeMuzik is fully usable without it, and it is never switched on by default — nothing happens until you tap or click Connect yourself.
What we ask for, and why
When you connect, HypeMuzik asks Google for a single permission:
https://www.googleapis.com/auth/drive.readonly— read-only access to the files in your Google Drive.
We request it so HypeMuzik can list the audio files you keep in Drive and stream them back to you through its own equalizer and DSP chain. That is the whole purpose. HypeMuzik is a player, so it only ever reads; it cannot create, modify, or delete anything in your Drive.
Google does not offer a "music files only" permission, so this grant is broader than what HypeMuzik uses. HypeMuzik reads only audio files and the folder names needed to show them to you.
What actually happens to your files
- Your audio streams directly from Google to your device. It is not proxied, cached, or stored on any server we operate — we do not operate one for this.
- HypeMuzik keeps a local list of the tracks it found — names, durations and folder names — so your cloud library loads instantly next time. That list stays on your device.
- The email address of the connected Google account is stored locally, and only so the app can show you which account is connected.
- Access and refresh tokens are held in your operating system's secure credential store — Keychain on macOS, Credential Manager on Windows, the system keyring on Linux, and the Keystore or Keychain on mobile.
Google's Limited Use requirements
HypeMuzik's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means we do not transfer your Google data to anyone, do not use it for advertising, do not allow humans to read it, and do not use it to train any machine-learning or AI model. You can read the policy we are bound by here: Google API Services User Data Policy.
Taking it back
Disconnect the account inside HypeMuzik — this deletes the stored tokens and the cached file list from your device immediately. You can also revoke HypeMuzik's access from Google directly, at any time, at your Google Account permissions page. Revoking there takes effect at once, whether or not the app is running.
Connecting Dropbox
Dropbox works the same way and is equally optional. HypeMuzik requests read access so it can list and stream the audio files in your Dropbox, streams them directly from Dropbox to your device, and stores the resulting tokens in your system's secure credential store.
You can disconnect inside the app, or revoke access from your Dropbox connected-apps page.
Diagnostics and analytics
The mobile app uses two Google Firebase services:
- Firebase Crashlytics — when the app crashes, it sends a crash report so the bug can be fixed. A report contains the technical state of the crash: the stack trace, the device model, the operating system version, and an anonymous installation identifier. It does not contain your music, your file names, or your cloud account details.
- Firebase Analytics — aggregate, anonymous usage counts, used to understand which features are actually used and on which devices. It is not tied to your identity and is not used for advertising.
Both are governed by Google's Firebase privacy documentation. You can opt out of analytics collection in your device's system settings, and on Android by disabling ad personalisation.
The desktop app does not include Crashlytics or Analytics.
Device permissions, and what each one is for
Mobile operating systems ask you to approve permissions individually. Here is what each one HypeMuzik requests is genuinely used for. Every one of them can be declined; declining only disables the feature it belongs to.
- Music and audio files — to find and play the music already on your device. Nothing is uploaded.
- Microphone — used only by the on-screen audio visualiser, which reacts to what is currently playing. The audio is analysed in real time to draw the bars and is never recorded, stored, or transmitted. Turn the visualiser off and the microphone is not used at all.
- Camera — used only to scan the pairing QR code when you link your phone to the desktop app. No photos are taken or saved.
- Notifications — to show the playback controls in your notification shade and on your lock screen.
- Bluetooth — to detect and route audio to your headphones and speakers.
- Local network and Wi-Fi state — to discover your desktop on the same network for Phone Link and casting.
- Storage — to save tracks you explicitly choose to download for offline listening, into your device's music folder.
- Run in the background / ignore battery optimisation — so playback does not stop when your screen turns off.
This website
This site is a static marketing page. It sets no advertising cookies and runs no third-party tracking scripts.
If page analytics are enabled for a given build, the site stores a randomly generated identifier in your browser's local storage and records which pages were viewed, so we can count unique visitors. That identifier is not linked to your name, your email, or anything you do inside the apps, and it never leaves this purpose. Clearing your browser's site data removes it.
Downloads are served from GitHub, and the app-store buttons link to Apple and Google. Following those links takes you to services with their own privacy policies, which we do not control.
What we never do
- We never sell, rent, or trade your personal information.
- We never use your data — or your Google data — for advertising.
- We never use your content to train AI or machine-learning models.
- We never upload your music library to our servers.
- We never read your files. Cloud content moves between you and your provider; we are not in the middle of it.
Keeping and deleting your data
Because almost everything is stored locally, you control retention directly:
- Disconnect an account in the app to erase its tokens and cached file list from your device.
- Uninstall the app to remove the local library index, your presets and your play history.
- Revoke access at Google or Dropbox to cut off the connection at the source.
- Crash and analytics records held by Firebase are retained according to Google's published Firebase retention periods.
Depending on where you live you may have additional rights over personal data — to access it, correct it, export it, or have it deleted. Because we hold so little, these requests are usually answered in a sentence, but we will always answer. Write to brunolabs256@gmail.com and we will respond within 30 days.
Security
Cloud credentials are stored using the secure credential store your operating system provides, rather than in plain files. All traffic to Google, Dropbox and this website runs over encrypted HTTPS connections. Sign-in happens in your real browser or your system's secure authentication view using OAuth — HypeMuzik never sees, asks for, or stores your Google or Dropbox password.
No system is perfectly secure, and we cannot guarantee absolute security. If we ever become aware of a breach affecting your information, we will tell you and the relevant authorities as promptly as the law requires.
Children's privacy
HypeMuzik is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
Where your data goes
HypeMuzik operates from the Republic of Uganda. The limited data described above — crash reports and analytics — is processed by Google on infrastructure that may be located in other countries, including the United States. Google Drive and Dropbox content stays within those providers' own infrastructure and is governed by their policies. By using the apps you understand that this processing may occur outside your country of residence.
Changes to this policy
If this policy changes, the new version is published on this page with a new effective date. Where a change materially affects how your data is handled, we will make it obvious in the app rather than relying on you to re-read this page. Continuing to use HypeMuzik after a change means you accept the updated policy.
Contact
Questions about this policy, requests about your data, or anything that looks wrong to you — write to brunolabs256@gmail.com and a real person will read it.
See also our Terms & Conditions.