This Privacy Policy describes how the Music Widget mobile application ("the app", "we") handles your information.
The app is published on Google Play under the package id com.eyalar.cloudtunes (a legacy identifier from an earlier project name; it cannot be changed without unpublishing the listing and has no user-facing impact). It is a personal music-control widget for Android home screens that lets you play music from one of two supported backends: Audius or Radio Browser. No data leaves your device except the network requests required to talk to whichever backend you selected.
Nothing on our servers. We do not operate any backend. The app does not send analytics, crash reports, advertising identifiers, or any other telemetry to any server we own.
The only data the app handles at all is:
| Data | Where it lives | Why |
|---|---|---|
| Your Audius @handle (only if you connect Audius) | Stored locally in EncryptedSharedPreferences on your device (AES-256-GCM, key bound to the Android Keystore) |
So the favourites grid can fetch your liked tracks |
| Your saved favourites and last-played queue | Stored locally in plain SharedPreferences |
So the widget shows your favourites and resumes where you left off |
| Your settings (active music source, accent colour, transparency, volume step) | Stored locally in plain SharedPreferences |
So your customisations survive reboots |
None of the above is transmitted off-device by the app itself.
Audius and Radio Browser do not require an authenticated sign-in to play content — you only need a sign-in if you want your Audius library's favourites to sync.
When you use the app, it talks directly to the public servers of the music backend you've selected, in order to:
These requests are made directly from your device to the relevant operator's servers over HTTPS. That operator will see your IP address and account activity in the same way they would if you used their own app or website. Their privacy policies apply to those interactions, not ours:
The app does not relay any of your data through any intermediate server we control.
androidx.security for encrypted storage).The app requests these Android permissions:
INTERNET — to fetch metadata and stream audio.ACCESS_NETWORK_STATE — so playback adapts to losing connectivity.FOREGROUND_SERVICE + FOREGROUND_SERVICE_MEDIA_PLAYBACK — so audio keeps playing when you switch apps.POST_NOTIFICATIONS — so the now-playing notification appears (required by Android 13+).When you choose a music source, the app talks to that source's public API on your behalf. We do not control what those operators log, and they may apply their own data-collection practices independent of the app. Selecting a source is a deliberate, user-initiated action — the app does not contact any of these services until you pick one.
| Source | Authentication | What we send |
|---|---|---|
| Audius | Optional @handle | Anonymous search / stream requests identifying the app via app_name=music-widget |
| Radio Browser | None | Anonymous search / station-click requests identifying the app via User-Agent: MusicWidget/<version> |
The app is not directed at children under 13. We do not knowingly collect personal information from children.
All data the app handles lives only on your device. Uninstalling the app removes all of it instantly — there is nothing on any server we control to delete.
If you connected Audius through the app, disconnecting (in the app's Settings screen) removes your @handle from the device.
If this policy changes, the new version will replace this document at the same URL with an updated "Last updated" date.
Questions about this privacy policy can be sent to eyalar.cloudtunes@gmail.com.