Privacy Policy
Last updated September 12, 2026
Playlistr is an offline concert playlist app. You put the audio files from a show in the order they were played, and the app gives you an offline recreation with a built-in player.
This policy explains what the app keeps on your device, the small amount it sends to its server, and what happens to it. It is written to be read, not to be survived — if anything here is unclear, use the Contact form in Settings and ask.
The short version
- Your music never leaves your device. Audio files, playlists, artwork and play positions are stored locally. They are not uploaded, backed up, streamed or scanned.
- The app does not have accounts. There is no sign-up, no password, and no email address required to use it.
- There are no advertisements, and no third-party analytics or tracking SDKs. Nothing about you is sold, rented or shared for advertising.
- The app does report each launch — what kind of device it is, and how many playlists and songs are on it. Settings has a switch that turns this off.
- Nothing you have typed is ever sent - not a playlist's name, not a track's. This is described in full below.
- The app never asks for your location, contacts, photos, microphone or camera, because it never uses them.
Who is responsible
Playlistr is published by Keith Rochkind, an individual developer based in California, United States. For the purposes of the GDPR, that is the "data controller" for the information described here.
The way to reach the developer about anything in this policy — including a request to see or delete your data — is the Contact form in the app, under Settings. It sends your message directly to the developer.
What stays on your device
The following is stored only on your phone or tablet, and is never transmitted:
| What | Where it lives | | ----------------------------------------------------- | ----------------------------------------------- | | Audio files you import or download | The app's private storage | | Playlists, track order, and artwork | The app's private storage | | Play position, if you enable "Save playlist position" | Stored with the playlist | | Your app preferences | The app's private storage | | Your device code | The device keychain (iOS) or keystore (Android) |
Deleting the app removes this. On iOS the device code is kept in the Keychain and survives deletion, so reinstalling reconnects you to the same records; on Android an uninstall removes it, which is why the app shows you the code in Settings and suggests writing it down.
Your device code
The first time you open Playlistr, it generates a random code — something like
K7RPQ29M. It is not tied to your name, your email address, your phone number,
or any identifier assigned by Apple, Google or your carrier. It is a random
string this app made up.
That code is how the server tells one library's records apart from another's. It is a persistent identifier: it does not rotate, it does not expire, and it is included in the reports described below.
It is not a password and it is not proof of who you are. It exists so that your records stay yours, and so that a support message can be matched to the library it is about.
What the app sends, and when
1. Launch reports
On each cold launch — and on returning to the app after it has been in the background a while — the app sends one report. It contains:
| Category | Fields | | ------------ | -------------------------------------------------------------------------------------- | | Identifier | Your device code | | Device | Platform, operating system and version, model, manufacturer, whether it is a simulator | | App | App name, version, build number, bundle identifier | | Display | Screen width, height, pixel ratio | | System | Language code and tag, time zone, web view version | | Storage | Memory in use, the app's own storage quota and usage | | Network | Connection type — "wifi", "cellular", "none" or "unknown" | | Library size | Number of playlists, number of songs, total size in bytes |
Connection type is the kind of connection, not the network, the carrier or any address. No permission is requested for any of this, because none of it needs one.
These reports tell the developer how many people use the app, on which devices, and whether a release has broken something on a particular OS version.
2. Playlist sizes
When your library changes, the app sends a summary of your playlists: for each one, its randomly generated identifier, how many songs it has, how much space it takes up, and how long it runs.
No playlist name, track title, artist name or file name is ever sent, and neither is the audio. A playlist reaches the server as an identifier and three numbers. The name you gave it stays on your device, so the server has no way to know what any of your playlists is of.
3. Messages you send through the Contact form
If you write to the developer through the app, the app sends what you typed: your name (optional), your email address, the subject, and the message. It also sends your device code, and — the same three fields a launch report includes — your platform, OS version and the app's build number.
The message is stored and is also emailed to the developer, so that a reply can reach you. The device code is included so that a message about a playlist can be matched to the records for that library. The platform, OS version and build number are included so that a bug report is one that can actually be reproduced — the same reason a launch report includes them. Any of these that cannot be read is simply left out, the way a name is when none is given.
4. Downloads
If you download a track from cloud storage, the app sends the address you pasted to the server, which fetches the file and passes it back to your device.
Where the app offers downloading from a link, the server — not your device — fetches the audio from that site, converts it, holds it briefly in temporary storage, and deletes it once your device has it. Your own IP address is never exposed to the site being downloaded from, because your device never contacts it.
You are responsible for having the right to download whatever you point the app at. See the Terms of Service.
5. Written documents
When you open this policy, the Terms, the EULA or the FAQ, the app requests the current text from the server. Nothing about you is sent with that request beyond the ordinary technical details described next.
6. When something goes wrong
If the app hits an error it did not expect, it sends a report so the fault can be fixed: what went wrong, where in the code it happened, which screen you were on, the app version, and your device code.
The description is stripped before it is sent. File paths, web addresses and anything quoted are removed on your device, because an error about a file is an error that would otherwise name it — and the name of a playlist or a track is yours. No audio, no playlist name and no track title is ever in one of these.
These stop with the same switch as everything else: Settings → Send usage data off means no error reports either.
There is no crash-reporting service in the app — no Firebase, no Crashlytics, no third party of any kind. These go to the same server as everything else.
7. Ordinary technical details
Like any app that talks to a server, requests carry your device's IP address, and are recorded in the server's diagnostic logs alongside error traces used to diagnose faults. IP addresses are not stored in the records described above, and are not used to build a profile of you.
What the app never collects
- Precise or approximate location. The app requests no location permission and holds no location data.
- Contacts, photos, calendar, health, microphone or camera.
- Advertising identifiers. There is no advertising in Playlistr, and no advertising SDK.
- Third-party analytics. There is no Google Analytics, Firebase, Meta SDK or comparable tracker in the app.
- Your music. No audio file, its metadata, or its artwork is ever uploaded.
- Payment information. The app takes no payments.
The permissions the app declares are only these: internet access, and — on Android — the ability to keep playing audio while the screen is off.
Why this information is used
| Purpose | What is used | | ------------------------------------------------------ | --------------------------------- | | Making the app work | Device code, download addresses | | Understanding how many people use the app, and on what | Launch reports | | Finding and fixing faults | Launch reports, diagnostic logs | | Knowing what a support message is about | Contact messages, playlist sizes | | Answering you | Your email address |
Under the GDPR, the lawful basis for the launch reports, playlist sizes and diagnostic logs is legitimate interest — understanding and improving an app the developer maintains alone. The lawful basis for handling a message you send is that you chose to send it.
Your information is not used to build advertising profiles, is not sold, and is not shared for cross-context behavioural advertising.
Who else sees it
Microsoft Azure hosts the server, stores the records, and delivers the email that a contact message becomes. Microsoft acts as a service provider and processes this information on the developer's instructions. Data is stored in the United States.
Sites you choose to download from. When you paste a link, the server requests that file from the site in question. That site sees a request from the server, not from you.
Information may also be disclosed if required by law, or to protect the rights and safety of users or the developer. Beyond that, nothing is shared with anyone.
International transfers
The servers are in the United States. If you use Playlistr from outside the United States — including from the United Kingdom or the European Economic Area — the information described here is transferred there. Where the GDPR or UK GDPR applies, that transfer relies on the European Commission's Standard Contractual Clauses as implemented in Microsoft's data protection terms.
How long it is kept
There is no fixed schedule. Records are kept for as long as Playlistr is operated — they are what the developer uses to know the app is being used, and that remains true for as long as there is an app to maintain. A playlist summary is replaced whenever the playlist changes, and removed when the playlist is.
If Playlistr is retired, the records are deleted with it.
You do not have to wait for that: ask through the Contact form and the records held under your device code will be deleted. See "Your choices and rights".
Anything on your own device is kept until you delete it, or delete the app.
Security
Traffic between the app and the server is encrypted in transit with HTTPS. Stored records are encrypted at rest by Azure. Your device code is held in the platform's secure store — the Keychain on iOS, the Keystore on Android — rather than in ordinary app storage. Access to the stored records is restricted to the developer through an identity-based sign-in rather than a shared key.
No system is perfectly secure, and no promise is made that one is. What can be said honestly is that the app holds very little worth taking: no passwords, no payment details, no contact list, and none of your music.
Your choices and rights
Everyone. Settings has a Send usage data switch. Turning it off stops the launch reports, the error reports and the playlist summaries immediately — not at the next launch — and nothing further is sent from that device unless you turn it back on. It does not need to be asked for and it is not recorded anywhere.
You can delete everything the app holds on your device by deleting the app. You can ask, through the Contact form, what records are held under your device code, and ask for them to be deleted.
Write in from the app. The Contact form attaches your device code, and that code is the only thing that identifies your records. There is no name, email address or account attached to them, so a request without the code cannot be matched to anything — the developer is not able to find your records from your email address, because that is not how they are stored.
If you are in California, the CCPA as amended by the CPRA gives you the right to know what personal information is collected and why; to obtain a copy of it; to have it corrected; and to have it deleted. You also have the right not to be discriminated against for exercising any of these rights — and nothing in Playlistr behaves differently for people who do.
Playlistr does not sell your personal information, and does not share it for cross-context behavioural advertising. There is therefore no "Do Not Sell or Share My Personal Information" mechanism, because there is nothing for it to switch off. Playlistr collects no sensitive personal information as the CPRA defines it.
If you are in the United Kingdom or the European Economic Area, the GDPR gives you the rights of access, rectification, erasure, restriction, portability and objection — including the right to object to processing carried out on the basis of legitimate interest, which covers the launch reports and playlist summaries. The Send usage data switch in Settings is that objection, and needs no request: turning it off is the whole of it. You also have the right to complain to your national supervisory authority.
To exercise any of these, use the Contact form. A request will be answered within 30 days. No fee is charged.
Children
Playlistr is not directed to children under 13, and is not intended for their use. The app's store content rating reflects the fact that it contains nothing objectionable, but the app is offered for use by people aged 13 and over.
No information is knowingly collected from a child under 13. If you believe a child under 13 has used the app and information has been collected, use the Contact form and it will be deleted.
Changes to this policy
This policy is delivered to the app from the server, so a change appears without needing an app update. Where a change materially affects what is collected or what it is used for, the effective date at the top will be updated and the change noted in the app.
Contact
Questions, requests and complaints about this policy all go to the same place: Settings → Contact in the app. Include your device code if your question is about your own records.