Primuse

Privacy Policy

Primuse is a local-first music player that connects to storage and media services chosen by the user. This policy explains what data the app accesses, why it is needed, where it goes, and how users can delete it.

Effective and last updated: September 3, 2026

1. Scope and core principles

This policy applies to the Primuse apps for Apple platforms, the Primuse website, and optional Primuse relay services. Core library browsing and playback are local-first and normally connect directly from the user's device to services the user chooses. Optional relay processing occurs only when the user enables or invokes the corresponding feature.

Primuse does not sell user data, use it for advertising, build advertising profiles, or use Google user data to train or improve generalized or personalized artificial-intelligence or machine-learning models.

2. Google Drive data we access

After a user explicitly connects Google Drive and grants OAuth consent, Primuse may access:

  • Drive file and folder metadata: identifiers, names, MIME types, sizes, timestamps, checksums, parent relationships, folder hierarchy, and change records needed to browse and incrementally update the music library.
  • File content: audio selected for playback or offline caching, plus artwork and LRC sidecar files needed for music-library features.
  • Write and trash operations: artwork or LRC sidecar files created at the user's request, and files the user explicitly asks Primuse to move to Google Drive trash.
  • Authorization data: OAuth access and refresh tokens, and a stable Google account identifier used only to keep the connected account linked and prevent duplicate mounts.
  • Locally derived data: an on-device index, playback metadata, artwork, lyrics, scan state, and cache entries derived from the connected library.

The Google Drive scope can technically permit actions beyond Primuse's features. Primuse does not change Drive sharing permissions, transfer file ownership, or permanently empty Google Drive trash.

3. How Google user data is used

Primuse uses Google Drive data only to provide user-facing music features:

  • browse user-selected folders and preserve their existing hierarchy;
  • scan and index existing audio files as a music library;
  • stream, play, or cache selected audio on the user's device;
  • detect Drive changes and refresh the local library index;
  • write artwork and LRC sidecar files beside existing music when the user enables or invokes write-back; and
  • move selected remote files to Google Drive trash only after a user-initiated delete action.

Primuse requests https://www.googleapis.com/auth/drive because it must browse and manage music already present throughout folders selected from the user's existing Drive. The narrower drive.file scope cannot discover or access an arbitrary existing library unless each file is individually opened with the app, while read-only scopes cannot support sidecar write-back or user-requested remote deletion.

4. Sharing, transfer, and disclosure

Primuse does not send Google OAuth tokens to Primuse relay services or unrelated third parties. Google Drive file content leaves the user's device only when needed for a feature the user explicitly requests, such as playing through Google or sharing a selected track.

  • Google: requests go directly to Google OAuth and Google Drive APIs to perform the operation the user requested.
  • Apple services controlled by the user: if the user enables iCloud synchronization or iCloud Keychain, source configuration, library metadata, app settings, and credentials may be encrypted and synchronized by Apple across devices signed in to the user's Apple Account.
  • User-selected metadata services: Primuse may send song search terms such as title, artist, and album to built-in or user-configured metadata providers. Google OAuth tokens and Drive file content are not sent to those providers.
  • AI providers and the optional Primuse AI relay: when the user invokes an AI feature, Primuse may send the feature input needed for that request, such as search text, selected candidate metadata, or lyric lines. Raw audio and Google OAuth credentials are not included. A provider selected by the user is also governed by that provider's terms and privacy policy.
  • Optional Primuse Share Relay: when the user explicitly shares a selected media file, Primuse uploads that file and the minimum manifest needed to deliver the share. The current relay requires client-side AES-GCM encryption; the decryption key stays in the URL fragment and is not sent to the relay. Access controls and expiration follow the user's selected share settings.
  • Legal and security obligations: information may be disclosed only when required by applicable law or necessary to protect users, the service, or others from fraud, abuse, or security threats.

Primuse does not sell, rent, or license Google user data to data brokers, advertisers, or unrelated third parties.

5. Storage and security

  • OAuth tokens and credentials are stored in Apple Keychain. iCloud Keychain synchronization is used only when enabled and available for the user's Apple Account.
  • Library indexes, metadata, artwork, lyrics, and audio caches are stored in the app sandbox. Eligible app data may synchronize through the user's private iCloud or CloudKit container when Primuse iCloud sync is enabled.
  • Connections to Google and optional relay services use HTTPS. Primuse avoids placing OAuth tokens in ordinary app data, relay requests, or analytics.
  • The Primuse AI relay does not intentionally persist feature payloads after a response. It retains operational identifiers, security state, and aggregate usage needed to enforce quotas, prevent replay, and operate the service; an upstream AI provider may process data under its own policy.
  • The Share Relay stores encrypted manifests and encrypted media chunks until the share expires or is revoked. Passwords are stored only as salted verifiers, not as plaintext.
  • The Primuse website does not currently load third-party advertising or analytics trackers.

6. Retention and deletion

  • While a source is active: Primuse retains the credentials, source configuration, and local library data needed to keep the Google Drive source connected and functional.
  • Recently deleted sources: after a user removes a source, its source configuration and OAuth credentials may be retained for up to 30 days so the user can restore it.
  • Permanent deletion: choosing permanent deletion, or expiration of the 30-day recovery period, removes the OAuth tokens and app credentials stored by Primuse for that source. Users can separately clear downloaded audio and other caches in the app.
  • Google account control: users can revoke Primuse access at any time in Google Account permissions. Revocation prevents further Drive API access. Users may also delete Primuse and its local data using Apple platform controls.
  • Remote files: disconnecting or permanently deleting a source does not delete files from Google Drive. A separate explicit remote-delete action moves selected items to Google Drive trash; subsequent trash retention or permanent deletion is controlled by Google and the user.
  • Relay data: AI request content is processed for the request and is not intentionally retained by the Primuse relay afterward. Encrypted media shares remain until their selected expiration or, for non-expiring shares, until the user revokes them. Operational and security records may be retained as reasonably necessary to prevent abuse and maintain the services.

7. Google API Services User Data Policy

Primuse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Children, policy changes, and support correspondence

Primuse is not directed to children under 13 and does not knowingly collect children's personal information. If a user contacts support, Primuse receives the information the user voluntarily includes and retains it only as reasonably necessary to respond, keep support records, and meet legal obligations.

Material changes to this policy will be posted on this page with an updated effective date.

9. Contact

Questions or deletion requests can be sent to support@welape.com.