MusicX is designed around your own music library. Most MusicX data stays on your devices. Features that use a connected service or another device may send the information needed for that feature.
This policy applies to MusicX for iPhone, iPad, Mac, and Android, related widgets and shortcuts, connected media-device features, and this website. Availability varies by platform and build.
Information MusicX stores on your device
MusicX stores the information it needs to organize, play, sync, and restore your music library. This can include library entries, file paths, security-scoped file bookmarks, source names, song titles, artists, albums, genres, playlists, favorites, queue state, resume position, lyrics, artwork references or cached artwork, equalizer settings, playback settings, app preferences, and diagnostics settings.
This information is used for app features such as playback, search, library repair, metadata editing, playlists, widgets, Siri or app shortcuts, nearby playback handoff, Direct Sync, iCloud or Google Drive sync, and restoring your selected sources after relaunch. MusicX does not use your local library information for advertising or cross-app tracking.
How MusicX gets information
MusicX gets information when you choose files, folders, libraries, discs, cloud folders, provider settings, or devices; when the app scans media that you have allowed it to access; when you edit metadata, playlists, or settings; when you connect another service; and when the operating system provides information needed for a permissioned feature.
On Android, MusicX may request media-library and storage permissions such as audio-library access, older external-storage access, or broad file-management access where the feature needs to scan or manage a user-selected music collection. MusicX can also use camera access on iPhone, iPad, or Android when you choose to scan a local Direct Sync pairing code. On Apple platforms, MusicX uses file pickers, security-scoped bookmarks, iCloud entitlements, local-network permissions, camera permission for pairing codes, Siri permission, and removable-volume access on Mac where applicable.
Optional permissions and connected features
These features are optional or depend on a user action. The data involved is used for the feature you choose.
- Local music files and folders: MusicX reads audio files and metadata from folders, app documents, removable volumes, Android media libraries, or other sources you add so it can build and play your library.
- Camera pairing codes: On iPhone, iPad, or Android, MusicX can use the camera when you choose to scan a local Direct Sync pairing code shown by your Mac, phone, tablet, or another MusicX device. The camera is used for that scan and is not used for advertising or developer analytics.
- Local network and Direct Sync: MusicX can discover, pair with, compare metadata with, and transfer selected music to another MusicX device on your local network. Pairing and transfer require your approval. MusicX may exchange device names, pairing identifiers, library metadata, file names, file sizes, file dates, sync status, and selected audio files needed for the transfer.
- iCloud: If you enable iCloud features, MusicX may store or sync MusicX documents, settings, library state, sync documents, or encrypted catalog evidence in your iCloud container so the data is available on your Apple devices. Apple processes that data under the Apple Privacy Policy, iCloud Terms, and Apple iCloud/CloudKit service rules.
- Google Drive: If you connect Google Drive, MusicX uses Google Sign-In and the permissions you grant. On iPhone, iPad, and Mac, MusicX uses read-only Drive access for selected music-library browsing and app-data access for MusicX sync data. On Android, MusicX uses Drive read-only access for music-library browsing, app-data access for MusicX sync data, and Drive file access when you choose a file or folder through the Drive picker. Google processes that data under the Google Privacy Policy, Google Terms of Service, Google Drive API rules, and Google Account controls.
- Android phones, MP3 players, DAPs, and USB/MTP media devices: When you connect one of these devices, MusicX may read device names, storage names, serial or topology identifiers where exposed by the device, folder paths, audio file names, file sizes, file dates, and song metadata so it can show available music and copy selected files. MusicX does not read unrelated app data and does not automatically upload a USB/MTP inventory to the developer.
- SMB and NAS sources: If you add a network share, MusicX stores the server address, share name, root path, display name, user name, domain, signing or encryption preference, and related settings. Passwords or API keys are stored in Keychain or encrypted Android storage where supported and are supplied to the provider only at runtime. On Apple devices, saved NAS connections and their login credentials can be shared through iCloud Keychain on devices using your Apple Account with iCloud Keychain enabled. These credentials are not included in ordinary library sync files.
- Artwork, lyrics, metadata, and identification providers: MusicX can contact Apple ShazamKit, lyrics services such as LRCLIB, artwork sources, or user-installed manifest providers to improve metadata, artwork, lyrics, or identification results. Depending on the feature, requests may include song title, artist, album, duration, catalog identifiers, provider identifiers, file metadata, or an audio fingerprint or signature created from a selected local file.
- Custom provider manifests and add-ons: If you import a provider manifest or add a credential, MusicX stores the provider metadata and credentials needed to use that provider. Provider manifests can define their own HTTPS endpoints and privacy notes. You should review those notes before enabling a custom provider.
- Diagnostics and support: MusicX can generate or keep diagnostic information on your device, including app events, settings state, library counts, source names, file paths, song metadata, device-transfer status, local-network status, iCloud or Google Drive status, and error details. MusicX does not send diagnostic logs to the developer automatically. If you choose to share logs for support, review them first.
Provider content and song-file write-back
Artwork, lyrics, metadata, and identification results can be copyrighted or limited by provider terms. MusicX may display provider results, store them in the MusicX app library, cache them for app use, or keep provider references so the feature works for your personal listening and library-management experience. MusicX does not claim ownership of provider content.
ShazamKit recognition results, LRCLIB lyrics, provider artwork, and custom-provider results are app-library data inside MusicX. They may be visible in MusicX screens, search, playlists, library repair, sync state, widgets, or now-playing surfaces, but they do not mean your audio files have been retagged or now contain that provider data.
MusicX must not embed provider-supplied artwork, lyrics, or other third-party content into audio files, export it as reusable files, or transfer it into another song file unless you supplied that content yourself or the provider or license clearly permits that use. User-entered lyrics, user-selected artwork, and metadata already embedded in files are separate from provider-supplied content.
When MusicX creates a new audio file, it may write descriptive track metadata needed for the rip or chosen by you. Artwork and lyrics are written into audio files only when the content is user-entered, user-selected, already embedded in a user-owned file, or otherwise licensed for that use. Provider artwork and provider lyrics stay limited to MusicX display, cache, and app-library state unless a provider grants broader rights.
Google API data and Limited Use
When you connect Google Drive, Google may provide MusicX with an account name, email address, account identifier, OAuth access token, granted scopes, and Drive file or folder metadata needed for the feature you selected. MusicX may create or update its own library-state and playback-state sync documents in the Google Drive app-data folder. Depending on the platform and feature, the Google consent screen may show permissions such as https://www.googleapis.com/auth/drive.readonly, https://www.googleapis.com/auth/drive.appdata, or, on Android file-picker flows, https://www.googleapis.com/auth/drive.file. These sync documents can contain MusicX library state, favorites, playlists, lyrics state, resume state, provider choices, equalizer settings, source identities, and related sync metadata.
MusicX uses Google user data only to provide and maintain the Google Drive features you choose, keep the selected account connected, verify the account and scopes, read selected Drive music metadata, and sync MusicX state. MusicX does not sell Google user data, use it for advertising, use it for credit or eligibility decisions, or use it to train generalized AI models.
MusicX does not transfer Google user data except as needed to provide the Google Drive feature, when you direct the app to move or sync data, when required by law, or with a service provider that is bound to protect the data. MusicX's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Learn more from Google's Drive files and folders overview, Drive app data folder documentation, OAuth policy compliance guide, and Google Account linked-app access controls.
Provider documentation and privacy links
The following external services may apply their own terms, privacy notices, or developer rules when you choose a connected feature. These links are provided so you can review the provider documents directly:
- Apple Privacy Policy, iCloud Terms, and Apple CloudKit documentation for iCloud-backed MusicX data.
- Apple ShazamKit documentation and Shazam & Privacy for music-recognition features.
- Google Privacy Policy, Google Terms of Service, the Google API Services User Data Policy, Google Drive OAuth scope documentation, Google Drive files and folders overview, Google Drive app data folder documentation, Google OAuth policy compliance guide, and Google Account linked-app controls for Google Sign-In and Google Drive features.
- LRCLIB API documentation for LRCLIB lyrics lookup. LRCLIB is treated as a lyrics provider; MusicX does not treat LRCLIB responses as permission to embed lyrics into song files.
- Cloudflare Privacy Policy for delivery and security logs generated when this website is visited.
Sharing and third-party processing
MusicX does not sell personal information and does not share personal information for targeted advertising or cross-context behavioral advertising. MusicX does not include a developer-run advertising network or third-party tracking SDK in the current app.
MusicX shares or transmits data only when needed for a feature you choose, for example to Apple iCloud or ShazamKit services, Google Drive and Google Sign-In, a local MusicX device, an SMB/NAS server you add, a USB/MTP device you connect, or an artwork, lyrics, metadata, identification, or custom provider you enable. Those third parties process data under their own privacy terms and must protect user data consistently with their obligations and the feature's purpose.
The App Store, TestFlight, Google Play, the Microsoft Store if MusicX is distributed there, Apple, Google, and Microsoft may process account, purchase, device, crash, review, download, and store-listing information under their own policies. MusicX does not receive payment-card details from those stores.
Privacy-policy website hosting
This website is hosted on Cloudflare Workers Static Assets. The page does not include MusicX analytics scripts, advertising scripts, cookies, external fonts, or client-side tracking code. Cloudflare may process basic request information such as IP address, user agent, requested URL, time, and security signals to deliver and protect the page. That website request data is separate from your MusicX library data.
Retention and deletion
Local MusicX data stays on your device until you delete it, remove the related source, clear downloaded or cached data, reset MusicX data, or uninstall the app. iCloud and Google Drive sync data stays in those services until you delete it from MusicX or from the provider's storage controls. MusicX may keep local diagnostics until you delete them or reset the app.
If you disconnect Google Drive, iCloud, SMB/NAS, Direct Sync, a custom provider, or a USB/MTP device, MusicX stops using that connection. Disconnecting a provider may not automatically delete copies already stored by that provider or by another device; use the provider's own controls when you want to remove remote data.
Security
MusicX uses platform security features where supported, including sandboxed app storage, security-scoped file access on Apple platforms, Keychain storage for secrets on Apple platforms, encrypted Android storage for provider credentials where supported, Google and Apple sign-in/token handling, HTTPS for remote provider requests, and local-network pairing controls for Direct Sync. No app or network service can guarantee perfect security, so only connect services and providers you trust.
Children's privacy
MusicX is a general-audience music library app and is not directed to children under 13. MusicX does not knowingly collect personal information from children through a developer-run account service. If you believe a child has provided personal information to MusicX support, contact the developer support channel listed for MusicX so it can be reviewed and deleted where appropriate.
Your choices and privacy rights
You can control MusicX data by deleting libraries, sources, downloads, playlists, cached artwork, diagnostics, provider credentials, or app data; revoking file, camera, local-network, media-library, storage, Siri, iCloud, or notification permissions in system settings; disconnecting Google Drive or revoking MusicX access in your Google Account; unplugging USB/MTP devices; declining Direct Sync pairing or transfer requests; and using iCloud, Google Drive, SMB/NAS, or device-storage controls to delete remote copies.
MusicX currently has no developer-run account database. The developer normally cannot look up, export, correct, or delete the library data that stays on your device, in your iCloud container, in your Google Drive, on an SMB/NAS share, on a USB/MTP device, or in another store account. Privacy requests to the developer can cover information the developer actually receives, such as a support message, crash report, screenshot, diagnostic log, store-review message, or other information you choose to send. If the developer has no such information, there may be nothing developer-held to access, correct, or delete. MusicX does not sell personal information or use targeted advertising.
Changes to this policy
This policy may be updated when MusicX features, connected services, store disclosures, or legal requirements change. If MusicX changes how it uses Google user data or adds a materially different data use, the published policy and any required in-app notice or consent should be updated before that new use begins.
Contact
For privacy questions or requests about information you choose to send to the developer, email Support@getmusicx.com. See MusicX support for what to include and how to protect sensitive information.