FTP Music Privacy Policy

FTP Music is an Android client for private music libraries hosted on Navidrome or Subsonic-compatible servers selected and controlled by the user. FTP Music does not provide, host, or sell access to a public music catalog.

FTP Music Privacy Policy

FTP Music is an Android client for private music libraries hosted on Navidrome or Subsonic-compatible servers selected and controlled by the user. FTP Music does not provide, host, or sell access to a public music catalog.

Developer

FTP Music is developed and maintained by **Lucas de Souza Santos**.

For privacy questions, contact:

**[email protected]**

Project website:

https://github.com/lucasdss/ftpmusic

Information processed by FTP Music

FTP Music processes information required to connect to and use the music server selected by the user. This may include:

  • server URL;
  • server username and password;
  • library metadata, including artist, album, track, genre, and playlist information;
  • favorites, ratings, and playback history;
  • search queries sent to the selected server;
  • cached and explicitly downloaded audio;
  • application, playback, cache, and download settings.

FTP Music does not operate a developer-hosted account system. Users cannot create an FTP Music account. Server accounts and credentials are created and managed by the operator of the selected Navidrome or Subsonic-compatible server.

Developer data collection

FTP Music contains no advertising, analytics, attribution, tracking, or crash-reporting SDK.

The developer does not operate an FTP Music data-collection server and does not receive, sell, rent, or use personal information for advertising or profiling.

The app must transmit information off the device to provide its requested functionality. These transmissions are described below.

User-selected music server

FTP Music connects to the Navidrome or Subsonic-compatible server configured by the user. The app may send the following information to that server:

  • server username and password;
  • authentication requests;
  • library browsing and search requests;
  • playlist changes;
  • favorites and ratings;
  • playback and scrobbling information;
  • requests for music streams and artwork.

Data stored or logged by that server is controlled by the server operator and is subject to the server operator’s privacy and retention practices.

Users should connect only to servers they own or are authorized to access.

External metadata and artwork services

When artwork or public metadata is unavailable from the selected server, FTP Music may send artist, album, or track names to:

  • Apple iTunes Search API;
  • MusicBrainz;
  • Cover Art Archive.

These services may receive standard network information such as the user’s IP address. Their handling of information is governed by their respective privacy policies.

FTP Music 1.0.0 does not send requests to Last.fm because this release does not include a Last.fm API key.

Google Cast and Google Play services

When the user selects a Google Cast device, FTP Music may send stream URLs and media metadata to the selected Cast receiver. This transfer occurs only to support user-requested playback.

FTP Music may also use Google Play services to discover Cast devices and retrieve downloadable application fonts. Google’s handling of information is governed by the Google Privacy Policy:

https://policies.google.com/privacy

Local storage

FTP Music stores information in private application storage, including:

  • server configuration;
  • encrypted server credentials;
  • music-library metadata;
  • playlists, favorites, ratings, and playback history;
  • cached artwork and audio;
  • explicitly downloaded music;
  • application settings.

Server credentials are encrypted at rest using Android Keystore-backed encrypted storage. Cached and downloaded audio is stored in the app’s private storage.

Network security

HTTPS is supported and recommended for all server connections.

FTP Music also permits HTTP connections to private or local-network servers. HTTP does not encrypt credentials, metadata, or music traffic in transit. The app displays a warning when HTTP is used and rejects cleartext connections to public internet hosts.

Users are responsible for securing their selected server and network.

Android backup

If Android backup is enabled, Android may back up application settings and local database metadata to the user’s Google account.

Encrypted server credentials and cached or downloaded audio are excluded from Android backup.

Android backup is controlled by the user’s device and Google account settings.

Data retention and deletion

Local FTP Music data remains on the device until the user:

  • clears the app’s storage;
  • removes cached or downloaded content through the app;
  • or uninstalls FTP Music.

Uninstalling FTP Music removes its local application data from the device. Android backups may remain according to Google’s backup-retention practices.

Uninstalling FTP Music does not delete information stored on the user-selected music server. Users must manage that information through the server or contact its operator.

FTP Music does not provide developer-hosted accounts, so there is no FTP Music account requiring a separate account-deletion request.

Permissions

FTP Music may request or use:

  • **Internet access:** connect to the selected server, metadata services, and Cast devices;
  • **Foreground service and media playback:** continue user-started music playback while the app is backgrounded or the screen is off;
  • **Notifications:** display optional playback controls;
  • **Wake lock:** prevent user-started playback from being interrupted while the screen is off.

FTP Music does not request access to contacts, location, camera, microphone, phone calls, SMS messages, or advertising identifiers.

Children’s privacy

FTP Music is not designed for children under 13. Its intended audience is users aged 13 and older.

The app does not knowingly collect information from children through a developer-operated service.

Security

Reasonable technical safeguards are used to protect locally stored information. However, no device, network, or internet transmission can be guaranteed completely secure.

Users should:

  • prefer HTTPS;
  • use strong server credentials;
  • keep their server software updated;
  • avoid exposing insecure servers directly to the public internet;
  • connect only to trusted servers and networks.

Changes to this policy

This policy may be updated when FTP Music’s functionality or data practices change. Updates will be published at this same URL with a revised “Last updated” date.

Contact

Questions about this policy may be sent to:

**[email protected]**

Project repository:

https://github.com/lucasdss/ftpmusic