SonicBrain is a personal, multi-cloud music player. It has no user accounts and no backend servers that receive your music, credentials, or library. The app connects directly to the storage you choose. We do not sell personal data, and the app contains no advertising or tracking SDKs. A few feature-specific exchanges with third parties exist and are described in section 5.
Who we are
The data controller is Z.ARS Ltd, registration No. LV 50003812481, Balasta dambis 68-2, Rīga, LV-1048, Latvia. Contact: jz.zars@gmail.com.
Summary
SonicBrain is a personal, multi-cloud music player. It has no user accounts and no backend servers that receive your music, credentials, or library. The app connects directly to the storage you choose. We do not sell personal data, and the app contains no advertising or tracking SDKs. A few feature-specific exchanges with third parties exist and are described in section 5.
Data overview
Crash reporting
In regular (non-beta) releases crash-report sending is off by default. You can turn it on in Settings. In beta and test builds we ask for your choice on first launch, and nothing is sent until you agree. You can change your choice at any time in Settings; turning sending off also deletes crash reports already stored locally.
Reports are sanitized automatically before they are stored or sent. They never contain song or artist names, file paths, server addresses, or credentials. When sending is on, only the sanitized error message and stack trace are sent, together with technical metadata (app version, operating system version, device model). Sentry's servers technically receive your IP address as part of the connection; we configure Sentry not to store it. Reports are kept for [30] days.
Third parties
Your own storage provider (Google Drive, a WebDAV server such as Nextcloud, or another service you connect): the app connects directly to it. We are not involved and do not receive your files or credentials. That provider's privacy policy applies.
Google Drive (Google user data): if you connect Google Drive, SonicBrain accesses only the files needed to list and play your music. Google user data is processed on your device, is not transferred to us or any third party, and is not used for advertising. SonicBrain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at myaccount.google.com/permissions.
Last.fm (Discover Mix): only the artist name is sent, never an identifier. Last.fm also receives your IP address as part of the connection. See the Last.fm privacy policy.
Google Play / Apple App Store (purchases): standard store billing. We do not see your payment details.
Sentry (crash reporting): only if you enabled it or you use a beta/test build and agreed. Only the sanitized report described in section 4 is sent. See the Sentry privacy policy.
Sentry processes data in [the EU / the United States]. Where data is transferred outside the European Economic Area, the transfer relies on Standard Contractual Clauses or an adequacy decision.
What we never do
We do not collect your name, email address, or any other identity. There is no user-account system.
We do not send audio data, search queries, or server addresses to our servers. We have none.
We do not sell or share data with advertisers and do not use advertising or tracking SDKs.
We do not store passwords in plain text.
Legal bases (GDPR)
Crash reports: your consent (Art. 6(1)(a)), which you can withdraw at any time.
Discover Mix: necessary to provide the feature you request (Art. 6(1)(b)).
Purchases: performance of the purchase contract (Art. 6(1)(b)), handled by the store.
Data that stays on your device is not processed by us.
Retention
Local data stays on your device until you delete it. Crash reports at Sentry are kept for [X] days. Data held by Last.fm, Google, Apple, and your own storage provider is governed by their policies.
Your rights and controls
Access / portability: Settings → Export my data.
Deletion: Settings → Delete all my data (immediate and irreversible; removes your local library, history, and stored credentials).
Withdraw consent: turn crash reporting off at any time in Settings.
Under the GDPR you also have the rights of access, rectification, erasure, restriction, and objection. Because we keep no server-side copy of your data, most requests are fulfilled by the controls above; for anything relating to crash reports, contact us. You may lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija, dvi.gov.lv) or your local supervisory authority.
Security
Credentials are kept only in the operating system's secure storage. Sensitive values are held in memory only for the duration of an operation and then cleared. No method of storage or transmission is completely secure.
Children
SonicBrain is not directed to children and does not knowingly collect data from anyone under 13.
Changes to this policy
Changes to how data is processed will be reflected in this document, with the date updated, and announced in the app if significant.