Legal

Privacy Policy

Koda is built on a simple principle: your music is yours. We don't collect your data, and we never will.

Last updated: April 11, 2026

Short version: Koda does not collect, store, or share any personal information. No account is required. All your library data and settings live on your own device. The only time anything leaves your device is when you choose to enable optional third-party features (scrobbling, lyrics, Chromecast).

1. Who We Are

Koda is a music player app for Android developed by an independent developer. The app is available on Google Play and its website is joinkoda.eu.

For any privacy-related questions, contact us at post@joinkoda.app.

2. What We Do Not Collect

Koda collects absolutely none of the following:

Name or email address
Device identifiers
Location data
Advertising IDs or behavioural analytics
Contacts or calendar
Browsing history
Microphone or camera

3. Data Stored Locally on Your Device

Koda stores the following data exclusively on your own device. None of it is transmitted to Koda's servers (we don't have any).

Data Purpose Where
Server URL, username, password & auth token Connect to your Jellyfin, Plex, Navidrome, Subsonic, Emby, Kodi, or Audiobookshelf server Android Keystore (never in plaintext)
Music library (songs, albums, artists, playlists) Offline browsing and fast search On-device SQLite database
Audiobook library (books, chapters, progress, bookmarks) Audiobook playback, chapter navigation, and continue-listening On-device SQLite database
App settings (theme, sort order, EQ, accent colour) Remember your preferences On-device AsyncStorage
Play counts & listening history Listening stats and smart playlists On-device SQLite database

You can delete all locally stored data at any time by uninstalling the app. For a full overview of deletion options, including scrobbling accounts, see our Account Deletion page.

4. Optional Third-Party Services

The following integrations are entirely optional and disabled by default. They are only activated when you explicitly enable them and log in via Settings.

Scrobbling — Last.fm, ListenBrainz, Libre.fm

If you connect a scrobbling account, Koda will send data to the respective service in two situations:

After each track you play:

  • Song title
  • Artist name
  • Album name
  • Playback timestamp

When you mark a song as a favourite (Last.fm and Libre.fm only):

  • Song title
  • Artist name

This mirrors the Love feature on Last.fm and Libre.fm. Removing a favourite sends an Unlove action with the same data.

These services have their own privacy policies. You are responsible for reviewing them before enabling scrobbling:

Crash Reporting — Sentry

Koda uses Sentry to automatically capture unhandled errors and crashes in production builds. This helps us identify and fix bugs. The following information may be included in a crash report:

  • Stack trace and error message
  • Device operating system and version
  • App version

Crash reports contain no personal data — no user ID, no email address, no server URLs, and no music library content. Crash reporting is active only in production builds; it is disabled in development. Reports are stored on Sentry's EU infrastructure (Frankfurt).

Sentry's privacy policy: sentry.io/privacy.

Casting — Chromecast & UPnP/DLNA

If you cast to a Chromecast device, Koda uses the Google Cast SDK. The SDK may collect device identifiers and usage telemetry according to Google's Privacy Policy. Your audio stream travels directly from your media server to the Chromecast device on your local network — it does not pass through Koda's infrastructure.

UPnP/DLNA casting is handled entirely on your local network using open standards. No data is sent to any third-party service.

5. Automatic Requests to Third Parties

The following requests happen automatically when you use certain features in Koda. No account or login is required for any of these.

Service What is sent Why
Last.fm API Artist name or artist + album name Fetch artist biography, artist images, similar artists, top tracks, and album artwork when your own server has no image. This uses Last.fm's public read-only API — no account or scrobbling is involved. Requests are made when you open an artist or album page. Can be disabled under Settings → Playback → Last.fm artist data.
Libre.fm API Artist name Fetch similar artists and top tracks for the Radio Mix feature when Libre.fm scrobbling is enabled and Last.fm is not. Uses Libre.fm's public read-only API — no account is required for this specific request. Only triggered when Radio Mix is started.
LRClib.net Artist name, song title, album, duration Fetch synced lyrics. LRClib is a free, open, non-commercial service with no accounts. Can be disabled under Settings → Playback → Show lyrics.
iTunes Search API Artist name + album title Fetch album artwork when your media server has no cover image. No account required. Only triggered when an album is missing artwork.
TheAudioDB Artist name Fetch artist photos when your media server has no artist image. Free public API, no account required. Only triggered when an artist is missing an image.
Expo Updates (expo.dev) App version, platform Check for over-the-air bug fix updates at app startup. No personal data is included. Handled by the Expo Updates SDK.
Your own media server Requests depend on your server (Jellyfin, Emby, Plex, Navidrome, Subsonic, Kodi, Audiobookshelf, or local files) Stream audio, fetch artwork, and sync your library. For Audiobookshelf, this also includes audiobook chapters and listening progress. Traffic goes directly to your server — not through Koda.

Last.fm's privacy policy applies to requests made through their public API: last.fm/legal/privacy.

6. In-App Purchases & Subscriptions

Koda offers two types of in-app purchases, both processed entirely by Google Play Billing:

  • Annual subscription — unlocks the full app with all future updates.
  • One-time support purchases (Coffee, Pizza, Steak) — optional tips to support development.

Koda never receives or stores your payment information — that data stays between you and Google.

Google's handling of purchase data is governed by the Google Payments Privacy Notice .

7. Android Permissions Explained

Permission Why it is needed
INTERNET Stream music from your self-hosted server and send optional scrobbles.
NEARBY_WIFI_DEVICES Discover Chromecast and UPnP/DLNA devices on your local Wi-Fi network. Required on Android 13+. No data leaves your network.
CHANGE_WIFI_MULTICAST_STATE Enable mDNS/SSDP multicast needed for UPnP device discovery on your local network.
READ_EXTERNAL_STORAGE / MEDIA_* Access local audio files you choose to add to your library.
FOREGROUND_SERVICE Keep audio playback running when the screen is off, and run background downloads as a foreground service.
POST_NOTIFICATIONS Show a persistent notification while downloads are in progress (Android 13+). Koda requests this permission the first time you start a download.
RECEIVE_BOOT_COMPLETED Resume pending background downloads after a device restart.
MEDIA_CONTENT_CONTROL Expose your music library and playback controls to Android Auto.

8. Children's Privacy

Koda does not collect any personal information from anyone, including children. The app does not contain advertising and does not target any age group specifically.

9. Changes to This Policy

If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and, where appropriate, notify users through the app or the Google Play listing. Continued use of Koda after any changes constitutes acceptance of the updated policy.

Because Koda collects no personal data, most changes will be minor clarifications rather than substantive privacy changes.

10. Contact

Questions, concerns, or requests regarding this Privacy Policy? Reach out at post@joinkoda.app. We aim to respond within 5 business days.