Privacy Policy
Koda is built on a simple principle: your music is yours. We don't collect your data, and we never will.
Last updated: April 11, 2026
Short version: Koda does not collect, store, or share any personal information. No account is required. All your library data and settings live on your own device. The only time anything leaves your device is when you choose to enable optional third-party features (scrobbling, lyrics, Chromecast).
1. Who We Are
Koda is a music player app for Android developed by an independent developer. The app is available on Google Play and its website is joinkoda.eu.
For any privacy-related questions, contact us at post@joinkoda.app.
2. What We Do Not Collect
Koda collects absolutely none of the following:
3. Data Stored Locally on Your Device
Koda stores the following data exclusively on your own device. None of it is transmitted to Koda's servers (we don't have any).
| Data | Purpose | Where |
|---|---|---|
| Server URL, username, password & auth token | Connect to your Jellyfin, Plex, Navidrome, Subsonic, Emby, Kodi, or Audiobookshelf server | Android Keystore (never in plaintext) |
| Music library (songs, albums, artists, playlists) | Offline browsing and fast search | On-device SQLite database |
| Audiobook library (books, chapters, progress, bookmarks) | Audiobook playback, chapter navigation, and continue-listening | On-device SQLite database |
| App settings (theme, sort order, EQ, accent colour) | Remember your preferences | On-device AsyncStorage |
| Play counts & listening history | Listening stats and smart playlists | On-device SQLite database |
You can delete all locally stored data at any time by uninstalling the app. For a full overview of deletion options, including scrobbling accounts, see our Account Deletion page.
4. Optional Third-Party Services
The following integrations are entirely optional and disabled by default. They are only activated when you explicitly enable them and log in via Settings.
Scrobbling — Last.fm, ListenBrainz, Libre.fm
If you connect a scrobbling account, Koda will send data to the respective service in two situations:
After each track you play:
- Song title
- Artist name
- Album name
- Playback timestamp
When you mark a song as a favourite (Last.fm and Libre.fm only):
- Song title
- Artist name
This mirrors the Love feature on Last.fm and Libre.fm. Removing a favourite sends an Unlove action with the same data.
These services have their own privacy policies. You are responsible for reviewing them before enabling scrobbling:
Crash Reporting — Sentry
Koda uses Sentry to automatically capture unhandled errors and crashes in production builds. This helps us identify and fix bugs. The following information may be included in a crash report:
- Stack trace and error message
- Device operating system and version
- App version
Crash reports contain no personal data — no user ID, no email address, no server URLs, and no music library content. Crash reporting is active only in production builds; it is disabled in development. Reports are stored on Sentry's EU infrastructure (Frankfurt).
Sentry's privacy policy: sentry.io/privacy.
Casting — Chromecast & UPnP/DLNA
If you cast to a Chromecast device, Koda uses the Google Cast SDK. The SDK may collect device identifiers and usage telemetry according to Google's Privacy Policy. Your audio stream travels directly from your media server to the Chromecast device on your local network — it does not pass through Koda's infrastructure.
UPnP/DLNA casting is handled entirely on your local network using open standards. No data is sent to any third-party service.
5. Automatic Requests to Third Parties
The following requests happen automatically when you use certain features in Koda. No account or login is required for any of these.
| Service | What is sent | Why |
|---|---|---|
| Last.fm API | Artist name or artist + album name | Fetch artist biography, artist images, similar artists, top tracks, and album artwork when your own server has no image. This uses Last.fm's public read-only API — no account or scrobbling is involved. Requests are made when you open an artist or album page. Can be disabled under Settings → Playback → Last.fm artist data. |
| Libre.fm API | Artist name | Fetch similar artists and top tracks for the Radio Mix feature when Libre.fm scrobbling is enabled and Last.fm is not. Uses Libre.fm's public read-only API — no account is required for this specific request. Only triggered when Radio Mix is started. |
| LRClib.net | Artist name, song title, album, duration | Fetch synced lyrics. LRClib is a free, open, non-commercial service with no accounts. Can be disabled under Settings → Playback → Show lyrics. |
| iTunes Search API | Artist name + album title | Fetch album artwork when your media server has no cover image. No account required. Only triggered when an album is missing artwork. |
| TheAudioDB | Artist name | Fetch artist photos when your media server has no artist image. Free public API, no account required. Only triggered when an artist is missing an image. |
| Expo Updates (expo.dev) | App version, platform | Check for over-the-air bug fix updates at app startup. No personal data is included. Handled by the Expo Updates SDK. |
| Your own media server | Requests depend on your server (Jellyfin, Emby, Plex, Navidrome, Subsonic, Kodi, Audiobookshelf, or local files) | Stream audio, fetch artwork, and sync your library. For Audiobookshelf, this also includes audiobook chapters and listening progress. Traffic goes directly to your server — not through Koda. |
Last.fm's privacy policy applies to requests made through their public API: last.fm/legal/privacy.
6. In-App Purchases & Subscriptions
Koda offers two types of in-app purchases, both processed entirely by Google Play Billing:
- Annual subscription — unlocks the full app with all future updates.
- One-time support purchases (Coffee, Pizza, Steak) — optional tips to support development.
Koda never receives or stores your payment information — that data stays between you and Google.
Google's handling of purchase data is governed by the Google Payments Privacy Notice .
7. Android Permissions Explained
| Permission | Why it is needed |
|---|---|
INTERNET |
Stream music from your self-hosted server and send optional scrobbles. |
NEARBY_WIFI_DEVICES |
Discover Chromecast and UPnP/DLNA devices on your local Wi-Fi network. Required on Android 13+. No data leaves your network. |
CHANGE_WIFI_MULTICAST_STATE |
Enable mDNS/SSDP multicast needed for UPnP device discovery on your local network. |
READ_EXTERNAL_STORAGE / MEDIA_* |
Access local audio files you choose to add to your library. |
FOREGROUND_SERVICE |
Keep audio playback running when the screen is off, and run background downloads as a foreground service. |
POST_NOTIFICATIONS |
Show a persistent notification while downloads are in progress (Android 13+). Koda requests this permission the first time you start a download. |
RECEIVE_BOOT_COMPLETED |
Resume pending background downloads after a device restart. |
MEDIA_CONTENT_CONTROL |
Expose your music library and playback controls to Android Auto. |
8. Children's Privacy
Koda does not collect any personal information from anyone, including children. The app does not contain advertising and does not target any age group specifically.
9. Changes to This Policy
If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and, where appropriate, notify users through the app or the Google Play listing. Continued use of Koda after any changes constitutes acceptance of the updated policy.
Because Koda collects no personal data, most changes will be minor clarifications rather than substantive privacy changes.
10. Contact
Questions, concerns, or requests regarding this Privacy Policy? Reach out at post@joinkoda.app. We aim to respond within 5 business days.