Music Widget — Privacy Policy

Last updated: June 24, 2026

This Privacy Policy describes how the Music Widget mobile application ("the app", "we") handles your information.

The app is published on Google Play under the package id com.eyalar.cloudtunes (a legacy identifier from an earlier project name; it cannot be changed without unpublishing the listing and has no user-facing impact). It is a personal music-control widget for Android home screens that lets you play music from one of two supported backends: Audius or Radio Browser. No data leaves your device except the network requests required to talk to whichever backend you selected.

What we collect

Nothing on our servers. We do not operate any backend. The app does not send analytics, crash reports, advertising identifiers, or any other telemetry to any server we own.

The only data the app handles at all is:

DataWhere it livesWhy
Your Audius @handle (only if you connect Audius) Stored locally in EncryptedSharedPreferences on your device (AES-256-GCM, key bound to the Android Keystore) So the favourites grid can fetch your liked tracks
Your saved favourites and last-played queue Stored locally in plain SharedPreferences So the widget shows your favourites and resumes where you left off
Your settings (active music source, accent colour, transparency, volume step) Stored locally in plain SharedPreferences So your customisations survive reboots

None of the above is transmitted off-device by the app itself.

Audius and Radio Browser do not require an authenticated sign-in to play content — you only need a sign-in if you want your Audius library's favourites to sync.

Network requests the app makes

When you use the app, it talks directly to the public servers of the music backend you've selected, in order to:

These requests are made directly from your device to the relevant operator's servers over HTTPS. That operator will see your IP address and account activity in the same way they would if you used their own app or website. Their privacy policies apply to those interactions, not ours:

The app does not relay any of your data through any intermediate server we control.

What we don't collect

Permissions

The app requests these Android permissions:

Third-party services

When you choose a music source, the app talks to that source's public API on your behalf. We do not control what those operators log, and they may apply their own data-collection practices independent of the app. Selecting a source is a deliberate, user-initiated action — the app does not contact any of these services until you pick one.

SourceAuthenticationWhat we send
AudiusOptional @handleAnonymous search / stream requests identifying the app via app_name=music-widget
Radio BrowserNoneAnonymous search / station-click requests identifying the app via User-Agent: MusicWidget/<version>

Children

The app is not directed at children under 13. We do not knowingly collect personal information from children.

Data retention and deletion

All data the app handles lives only on your device. Uninstalling the app removes all of it instantly — there is nothing on any server we control to delete.

If you connected Audius through the app, disconnecting (in the app's Settings screen) removes your @handle from the device.

Changes to this policy

If this policy changes, the new version will replace this document at the same URL with an updated "Last updated" date.

Contact

Questions about this privacy policy can be sent to eyalar.cloudtunes@gmail.com.