ByTune is a free, open-source desktop music player for Windows. This policy explains what information ByTune and its infrastructure handle, what never leaves your device, and what rights you have. Use of the account feature is also governed by our Terms of Use.
Summary
- No ads. No analytics. No tracking. No cookies. The app and the website contain none.
- Without an account, ByTune sends nothing about you anywhere. Your library, settings, history and statistics stay on your PC.
- With an account, we store what is needed to sync your library between your own devices: your username, an account ID, and your library, settings, recent searches and listening signals, private to your account.
- When you stream or look up lyrics, the music and lyrics providers you request content from necessarily learn the title/artist you are asking about and your IP address. This is inherent to streaming and is described in Third parties we rely on.
- Downloads, local file paths, local music metadata, and your authentication tokens never leave your device.
What we collect (account feature)
ByTune works fully without an account. If you create one (a username account, or sign-in with Google), the following is stored so your data can sync between your own devices:
| Data | Purpose | Stored |
|---|---|---|
| Username | Your account identity; shown publicly only in that it must be unique (others can check whether a name is taken) | Supabase (cloud database & authentication) |
| Account ID (random UUID) | Links your data to your account | Supabase |
| Password | Sign-in: stored only as a server-side hash by our authentication provider; never readable by us | Supabase Auth |
| Google account (if you sign in with Google) | Sign-in. We receive your account ID and use your display name only to suggest a username | Supabase Auth |
| Library (liked songs, playlists, followed artists), settings, recent searches, listening signals | Syncing across your devices | Supabase, private to your account |
What we do not collect
Your email (username accounts use a non-functional placeholder address; Google emails stay inside the authentication provider and are not used by us), your real name, address, phone number, payment data, age, location, device fingerprints, browsing history outside ByTune, or any analytics or telemetry.
What never leaves your device
Downloaded audio files and their registry, your local music library’s file paths and metadata, your listening statistics (the Replay feature), your authentication tokens, and backups you export.
Why we process account data
To provide the service you asked for: storing your library so it syncs. For security and abuse prevention: rate limits and integrity checks by our infrastructure providers. Where consent would be required, we would ask first; today there is nothing that needs consent, because ByTune has no analytics and no marketing.
Data retention and deletion
Account data is kept while your account exists. In the app today you can clear your listening history, recent searches and statistics, and reset all local app data.
Honest limitation, stated plainly: ByTune does not yet offer self-service account deletion. Resetting app data on your device does not delete the copy stored in the cloud. Account and cloud-data deletion is currently available only by requesting it through our support contact support email: owner to provide, and self-service deletion is in development.
Third parties we rely on
| Provider | What they receive | Why |
|---|---|---|
| Supabase (database & authentication) | Account credentials and your synced library data | Cloud sync |
| YouTube / Google | Your search queries and the titles/artists of music you stream (with your IP address), via an anonymous session; you are not signed in to YouTube | The music catalogue |
| Lyrics providers (LRCLIB, KuGou, and community mirrors; Apple Music search) | Track title and artist | Synced lyrics |
| Tidal (public endpoints) and a community video index | Track title and artist | Album “canvas” video art |
| Piped community mirrors (stream fallback only) | The video ID, only when direct streaming fails | Backup stream relays |
| GitHub | Standard download requests when you download the installer | Distribution |
These providers process requests under their own privacy terms; ByTune sends them no account information. Your IP address is necessarily visible to these providers (and to the hosting provider that serves this website) as standard network mechanics.
The website itself is static: it has no forms, no cookies and no analytics. It loads album artwork from Apple’s iTunes Search CDN (no cookies, no tracking).
Security
Passwords are hashed by the authentication provider. Session tokens are stored encrypted with your operating system’s credential vault (DPAPI on Windows, Keychain on macOS). Data in transit uses TLS. Cloud data is protected by row-level security so accounts cannot read each other’s data. No system is perfectly secure; if you find a vulnerability, please report it responsibly to security contact: owner to provide.
Your rights
Subject to your local law, you may have rights to access, correct, export and delete your personal data, and to object to or restrict processing. Exports: the app’s backup feature. Access and correction: in the app. Deletion: see Data retention and deletion above.
Because ByTune is used worldwide, jurisdiction-specific sections (for example for the EU/UK, California or India) are being finalized as part of our ongoing legal review and will be added here.
Children
ByTune is a general-audience application, not directed to children under 13 (or under the digital-consent age in your country). We do not knowingly collect personal information from children. If you believe a child has created an account, contact support email: owner to provide and we will delete it.
International users
Your account data may be processed in the countries where our providers operate, including the United States and the region of the Supabase project Supabase project region: owner to confirm. Where required, transfers rely on our providers’ safeguards, such as the EU Standard Contractual Clauses.
Changes to this policy
We will post changes on this page with a new effective date. owner decision: whether material changes are also announced in-app
Contact
ByTune is maintained as an independent open-source project publisher / legal identity: owner to provide. The source code is public on GitHub.
Privacy questions, data and deletion requests: support email: owner to provide
Postal address: not required today. postal address: add here only if legally required later