Primuse

Privacy Policy

Primuse is a local-first music player that connects directly to storage and media services chosen by the user. This policy explains what data the app accesses, why it is needed, where it goes, and how users can delete it.

Effective and last updated: August 16, 2026

1. Scope and core principles

This policy applies to the Primuse apps for Apple platforms and the Primuse website. Primuse does not operate a developer-owned cloud service for uploading or analyzing a user's music library. The app communicates directly from the user's device to the services the user connects.

Primuse does not sell user data, use it for advertising, build advertising profiles, or use Google user data to train or improve generalized or personalized artificial intelligence or machine-learning models.

2. Google Drive data we access

After a user explicitly connects Google Drive and grants OAuth consent, Primuse may access:

  • Drive file and folder metadata: identifiers, names, MIME types, sizes, timestamps, checksums, parent relationships, folder hierarchy, and change records needed to browse and incrementally update the music library.
  • File content: audio files selected for playback or offline caching, plus artwork and LRC sidecar files needed for music-library features.
  • Write and trash operations: artwork or LRC sidecar files created at the user's request, and files the user explicitly asks Primuse to move to Google Drive trash.
  • Authorization data: OAuth access and refresh tokens, and a stable Google account identifier used only to keep the connected account linked and prevent duplicate mounts.
  • Locally derived data: an on-device index, playback metadata, artwork, lyrics, scan state, and cache entries derived from the connected library.

The Google Drive scope can technically permit actions beyond Primuse's features. Primuse does not change Drive sharing permissions, transfer file ownership, or permanently empty Google Drive trash.

3. How Google user data is used

Primuse uses Google Drive data only to provide user-facing music features:

  • browse user-selected folders and preserve their existing hierarchy;
  • scan and index existing audio files as a music library;
  • stream, play, or cache selected audio on the user's device;
  • detect Drive changes and refresh the local library index;
  • write cover-art and LRC sidecar files beside existing music when the user enables or invokes write-back; and
  • move selected remote files to Google Drive trash only after a user-initiated delete action.

Primuse requests https://www.googleapis.com/auth/drive because it must browse and manage music already present throughout folders selected from the user's existing Drive. The narrower drive.file scope cannot discover or access an arbitrary existing library unless each file is individually opened with the app, while read-only scopes cannot support sidecar write-back or user-requested remote deletion.

4. Sharing, transfer, and disclosure

Primuse does not send Google OAuth tokens or Google Drive file content to the developer's servers. Google user data is disclosed only in the following limited circumstances:

  • Google: requests go directly to Google OAuth and Google Drive APIs to perform the operation the user requested.
  • Apple services controlled by the user: if the user enables iCloud synchronization or iCloud Keychain, source configuration, library metadata, app settings, and credentials may be encrypted and synchronized by Apple across devices signed in to the user's own Apple Account.
  • User-selected metadata services: Primuse may send song search terms such as title, artist, and album to built-in or user-configured metadata providers. Google OAuth tokens and Drive file content are not sent to those providers.
  • Legal and security obligations: information may be disclosed only when required by applicable law or necessary to protect users, the service, or others from fraud, abuse, or security threats.

Primuse does not sell, rent, license, or otherwise disclose Google user data to data brokers, advertisers, or unrelated third parties.

5. Storage and security

  • OAuth tokens and credentials are stored in Apple Keychain, with iCloud Keychain synchronization used only when enabled and available for the user's Apple Account.
  • Library indexes, metadata, artwork, lyrics, and audio caches are stored in the app sandbox on the user's device. Eligible app data may synchronize through the user's private iCloud/CloudKit container when the user enables Primuse iCloud sync.
  • Connections to Google use HTTPS and bearer-token authorization. Primuse avoids placing Google OAuth tokens in ordinary app data or analytics.
  • The website does not currently load third-party advertising or analytics trackers.

6. Retention and deletion

  • While a source is active: Primuse retains the credentials, source configuration, and local library data needed to keep the Google Drive source connected and functional.
  • Recently deleted sources: after a user removes a source, its source configuration and OAuth credentials may be retained for up to 30 days so the user can restore the source.
  • Permanent deletion: choosing permanent deletion, or expiration of the 30-day recovery period, removes the stored OAuth tokens and app credentials for that source from Primuse storage. Users can separately clear downloaded audio and other caches in the app.
  • Google account control: users can revoke Primuse access at any time in their Google Account permissions. Revocation prevents further Drive API access. Users may also delete Primuse and remove its local data using Apple platform controls.
  • Remote files: disconnecting or permanently deleting a Primuse source does not delete the user's files from Google Drive. A separate, explicit remote-delete action moves selected items to Google Drive trash; subsequent trash retention or permanent deletion is controlled by Google and the user.

7. Google API Services User Data Policy

Primuse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Children, policy changes, and support correspondence

Primuse is not directed to children under 13 and does not knowingly collect children's personal information. If a user contacts support, Primuse receives the information the user voluntarily includes and retains it only as reasonably necessary to respond, keep support records, and meet legal obligations.

Material changes to this policy will be posted on this page with an updated effective date.

9. Contact

Questions or deletion requests can be sent to [email protected].


简体中文

Primuse 隐私政策摘要

Primuse 是一款以本地处理为主的音乐播放器,会从用户设备直接连接用户选择的存储和媒体服务,不会把用户的音乐库上传到开发者自有服务器进行分析。

访问的 Google Drive 数据

用户主动连接并授权 Google Drive 后,Primuse 会读取文件和文件夹标识、名称、类型、大小、时间、校验值、层级与变更记录;按播放、缓存和音乐库功能需要读取音频、封面与歌词内容;保存 OAuth 令牌和稳定账号标识;在用户启用或执行回写时创建封面、LRC sidecar 文件;在用户明确执行远程删除时把所选文件移入 Google Drive 回收站。

完整权限的用途

Primuse 需要浏览用户现有 Drive 中所选文件夹下的整座音乐库并保持目录结构。drive.file 无法访问未逐个由应用打开的既有文件,只读权限又无法完成 sidecar 回写和用户主动发起的远程删除,因此使用完整 Drive scope。Primuse 不修改共享权限、不转移所有权,也不会永久清空 Google Drive 回收站。

共享、传输与披露

Google OAuth 令牌和 Drive 文件内容不会发送到开发者服务器,也不会出售、用于广告画像或用于训练 AI/机器学习模型。数据仅会直接发送给 Google API 以执行用户请求;用户启用 iCloud 或 iCloud 钥匙串后,配置、资料库元数据、设置和凭据可能由 Apple 在用户自己的 Apple 账号设备之间加密同步;歌曲标题、艺术家、专辑等搜索词可能发送给内置或用户自行配置的元数据服务,但 Google OAuth 令牌和 Drive 文件内容不会发送给这些服务。只有法律要求或安全保护所必需时才会进行其他披露。

保留与删除

Google Drive 来源启用期间,Primuse 会保留连接所需凭据、来源配置和本地资料库数据。移除来源后,相关配置和 OAuth 凭据最多保留 30 天以供恢复;用户选择永久删除或恢复期届满后,会删除该来源在 Primuse 中保存的 OAuth 令牌和应用凭据。用户也可以在 Google 账号权限页面随时撤销 Primuse。删除 Primuse 来源不会删除 Drive 原文件;单独的远程删除操作只会把用户选中的项目移入 Google Drive 回收站,之后的保留和永久删除由 Google 与用户控制。

Google Limited Use

Primuse 对从 Google API 获得的信息的使用和传输遵守 Google API Services User Data Policy,包括 Limited Use 要求。

联系

隐私或删除请求请联系 [email protected]