1. Scope and core principles
This policy applies to the Primuse apps for Apple platforms, the Primuse website, and optional Primuse relay services. Core library browsing and playback are local-first and normally connect directly from the user's device to services the user chooses. Optional relay processing occurs only when the user enables or invokes the corresponding feature.
Primuse does not sell user data, use it for advertising, build advertising profiles, or use Google user data to train or improve generalized or personalized artificial-intelligence or machine-learning models.
2. Google Drive data we access
After a user explicitly connects Google Drive and grants OAuth consent, Primuse may access:
- Drive file and folder metadata: identifiers, names, MIME types, sizes, timestamps, checksums, parent relationships, folder hierarchy, and change records needed to browse and incrementally update the music library.
- File content: audio selected for playback or offline caching, plus artwork and LRC sidecar files needed for music-library features.
- Write and trash operations: artwork or LRC sidecar files created at the user's request, and files the user explicitly asks Primuse to move to Google Drive trash.
- Authorization data: OAuth access and refresh tokens, and a stable Google account identifier used only to keep the connected account linked and prevent duplicate mounts.
- Locally derived data: an on-device index, playback metadata, artwork, lyrics, scan state, and cache entries derived from the connected library.
The Google Drive scope can technically permit actions beyond Primuse's features. Primuse does not change Drive sharing permissions, transfer file ownership, or permanently empty Google Drive trash.
3. How Google user data is used
Primuse uses Google Drive data only to provide user-facing music features:
- browse user-selected folders and preserve their existing hierarchy;
- scan and index existing audio files as a music library;
- stream, play, or cache selected audio on the user's device;
- detect Drive changes and refresh the local library index;
- write artwork and LRC sidecar files beside existing music when the user enables or invokes write-back; and
- move selected remote files to Google Drive trash only after a user-initiated delete action.
Primuse requests https://www.googleapis.com/auth/drive because it must browse and manage music already present throughout folders selected from the user's existing Drive. The narrower drive.file scope cannot discover or access an arbitrary existing library unless each file is individually opened with the app, while read-only scopes cannot support sidecar write-back or user-requested remote deletion.
5. Storage and security
- OAuth tokens and credentials are stored in Apple Keychain. iCloud Keychain synchronization is used only when enabled and available for the user's Apple Account.
- Library indexes, metadata, artwork, lyrics, and audio caches are stored in the app sandbox. Eligible app data may synchronize through the user's private iCloud or CloudKit container when Primuse iCloud sync is enabled.
- Connections to Google and optional relay services use HTTPS. Primuse avoids placing OAuth tokens in ordinary app data, relay requests, or analytics.
- The Primuse AI relay does not intentionally persist feature payloads after a response. It retains operational identifiers, security state, and aggregate usage needed to enforce quotas, prevent replay, and operate the service; an upstream AI provider may process data under its own policy.
- The Share Relay stores encrypted manifests and encrypted media chunks until the share expires or is revoked. Passwords are stored only as salted verifiers, not as plaintext.
- The Primuse website does not currently load third-party advertising or analytics trackers.
6. Retention and deletion
- While a source is active: Primuse retains the credentials, source configuration, and local library data needed to keep the Google Drive source connected and functional.
- Recently deleted sources: after a user removes a source, its source configuration and OAuth credentials may be retained for up to 30 days so the user can restore it.
- Permanent deletion: choosing permanent deletion, or expiration of the 30-day recovery period, removes the OAuth tokens and app credentials stored by Primuse for that source. Users can separately clear downloaded audio and other caches in the app.
- Google account control: users can revoke Primuse access at any time in Google Account permissions. Revocation prevents further Drive API access. Users may also delete Primuse and its local data using Apple platform controls.
- Remote files: disconnecting or permanently deleting a source does not delete files from Google Drive. A separate explicit remote-delete action moves selected items to Google Drive trash; subsequent trash retention or permanent deletion is controlled by Google and the user.
- Relay data: AI request content is processed for the request and is not intentionally retained by the Primuse relay afterward. Encrypted media shares remain until their selected expiration or, for non-expiring shares, until the user revokes them. Operational and security records may be retained as reasonably necessary to prevent abuse and maintain the services.
7. Google API Services User Data Policy
Primuse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Children, policy changes, and support correspondence
Primuse is not directed to children under 13 and does not knowingly collect children's personal information. If a user contacts support, Primuse receives the information the user voluntarily includes and retains it only as reasonably necessary to respond, keep support records, and meet legal obligations.
Material changes to this policy will be posted on this page with an updated effective date.
9. Contact
Questions or deletion requests can be sent to support@welape.com.