1. Scope and core principles
This policy applies to the Primuse apps for Apple platforms, the Primuse website, and optional Primuse relay services. Core library browsing and playback are local-first and normally connect directly from the user's device to services the user chooses. Optional relay processing occurs only when the user enables or invokes the corresponding feature.
Primuse does not sell user data, use it for advertising, build advertising profiles, or use Google user data to train or improve generalized or personalized artificial-intelligence or machine-learning models.
2. Google Drive data we access
After a user explicitly connects Google Drive and grants OAuth consent, Primuse may access:
- Drive file and folder metadata: identifiers, names, MIME types, sizes, timestamps, checksums, parent relationships, folder hierarchy, and change records needed to browse and incrementally update the music library.
- File content: audio selected for playback or offline caching, plus artwork and LRC sidecar files needed for music-library features.
- Write and trash operations: artwork or LRC sidecar files created at the user's request, and files the user explicitly asks Primuse to move to Google Drive trash.
- Authorization data: OAuth access and refresh tokens, and a stable Google account identifier used only to keep the connected account linked and prevent duplicate mounts.
- Locally derived data: an on-device index, playback metadata, artwork, lyrics, scan state, and cache entries derived from the connected library.
The Google Drive scope can technically permit actions beyond Primuse's features. Primuse does not change Drive sharing permissions, transfer file ownership, or permanently empty Google Drive trash.
3. How Google user data is used
Primuse uses Google Drive data only to provide user-facing music features:
- browse user-selected folders and preserve their existing hierarchy;
- scan and index existing audio files as a music library;
- stream, play, or cache selected audio on the user's device;
- detect Drive changes and refresh the local library index;
- write artwork and LRC sidecar files beside existing music when the user enables or invokes write-back; and
- move selected remote files to Google Drive trash only after a user-initiated delete action.
Primuse requests https://www.googleapis.com/auth/drive because it must browse and manage music already present throughout folders selected from the user's existing Drive. The narrower drive.file scope cannot discover or access an arbitrary existing library unless each file is individually opened with the app, while read-only scopes cannot support sidecar write-back or user-requested remote deletion.
5. Storage and security
- OAuth tokens and credentials are stored in Apple Keychain. iCloud Keychain synchronization is used only when enabled and available for the user's Apple Account.
- Library indexes, metadata, artwork, lyrics, and audio caches are stored in the app sandbox. Eligible app data may synchronize through the user's private iCloud or CloudKit container when Primuse iCloud sync is enabled.
- Connections to Google and optional relay services use HTTPS. Primuse avoids placing OAuth tokens in ordinary app data, relay requests, or analytics.
- The Primuse AI relay processes feature request content to provide the requested response and does not intentionally retain that content afterward. It does retain installation IDs and, when an account is linked, an internal account ID and the Apple app transaction ID; App/build versions and client or system information available in requests or verification data; and call records such as feature, time, result, usage, latency, and error information. Security events may also contain IP addresses and User-Agent headers. These records can be linked to an installation or account. They support authentication, quotas, fraud prevention, troubleshooting, service reliability, and usage analysis. Primuse does not use them for advertising or tracking across other companies' apps or websites. Upstream AI providers process data under their own policies.
- The Share Relay stores encrypted manifests and encrypted media chunks until the share expires or is revoked. Passwords are stored only as salted verifiers, not as plaintext.
- The Primuse website does not currently load third-party advertising or analytics trackers.
6. Retention and deletion
- While a source is active: Primuse retains the credentials, source configuration, and local library data needed to keep the Google Drive source connected and functional.
- Recently deleted sources: after a user removes a source, its source configuration and OAuth credentials may be retained for up to 30 days so the user can restore it.
- Permanent deletion: choosing permanent deletion, or expiration of the 30-day recovery period, removes the OAuth tokens and app credentials stored by Primuse for that source. Users can separately clear downloaded audio and other caches in the app.
- Google account control: users can revoke Primuse access at any time in Google Account permissions. Revocation prevents further Drive API access. Users may also delete Primuse and its local data using Apple platform controls.
- Remote files: disconnecting or permanently deleting a source does not delete files from Google Drive. A separate explicit remote-delete action moves selected items to Google Drive trash; subsequent trash retention or permanent deletion is controlled by Google and the user.
- Relay data: Under the current retention policy, individual AI call records are retained for 400 days, daily usage summaries for 35 days, hourly usage summaries for 800 days, and security incident records for 90 days. Scheduled cleanup removes records after these periods. Installation/account identifiers and authentication or security state are retained as needed to provide the service and prevent abuse; they do not share the call-record deletion deadline. AI request content is not intentionally retained by the Primuse relay after processing. Encrypted media shares remain until expiration or revocation, including non-expiring shares until revoked. Uninstalling the app or removing a media source does not automatically delete relay records. Contact support to request deletion of server records. Upstream providers apply their own retention policies.
7. Google API Services User Data Policy
Primuse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Children, policy changes, and support correspondence
Primuse is not directed to children under 13 and does not knowingly collect children's personal information. If a user contacts support, Primuse receives the information the user voluntarily includes and retains it only as reasonably necessary to respond, keep support records, and meet legal obligations.
Material changes to this policy will be posted on this page with an updated effective date.
9. Contact
Questions or deletion requests can be sent to [email protected].