Privacy Policy
This policy explains how NIRUNE accesses, uses, stores, and shares data. NIRUNE is currently an experimental, private-preview music application for Windows, with Android support in development.
1. Data NIRUNE accesses
Google account and YouTube data
When you choose to connect Google, NIRUNE requests the following OAuth permissions:
- basic Google profile information and email address;
- read-only YouTube access through
youtube.readonly.
The current preview uses the authorized Google session to establish the connected provider and to perform YouTube catalog searches only after the user explicitly submits a query. NIRUNE does not use this permission to create, modify, or delete YouTube data.
OAuth credentials
Google issues access and refresh credentials after consent. NIRUNE stores those credentials in platform-secure storage on your device. They are not displayed in the interface, written to application logs, or sent to a NIRUNE-operated server.
Local music and application data
When you select a local music folder, NIRUNE reads the audio files and metadata needed to display and play that library. It may store local preferences, library indexes, playlists, queue state, playback history, likes, and dislikes on the device. The public website does not receive this information.
2. How data is used
NIRUNE uses data only to provide user-facing application features, including:
- connecting and restoring a provider session;
- submitting searches that the user explicitly requests;
- showing provider-neutral catalog metadata and availability;
- maintaining the on-device music library and playback state;
- diagnosing failures through sanitized error categories that do not contain credentials or provider response bodies.
3. Sharing and disclosure
NIRUNE does not sell Google user data, local-library data, or listening activity. It does not use Google user data for advertising. User-initiated Google and YouTube requests are sent directly to Google's services and are governed by Google's own privacy practices. Data may be disclosed only when required by applicable law or necessary to protect users and the integrity of the application.
4. Data retention and deletion
Search results are used for the current application experience and are not uploaded to a NIRUNE server. Local library and preference data remain until you remove them through the application, clear the application's data, or uninstall it.
Selecting Disconnect for Google deletes the saved Google OAuth credential from NIRUNE's secure local storage. You can also revoke NIRUNE from your Google Account's connected-app settings. Because the current preview operates without a NIRUNE account server, NIRUNE does not retain a separate server-side copy of your Google user data.
5. Security
NIRUNE uses the system browser for Google authorization, a temporary
loopback callback on 127.0.0.1, HTTPS for Google API requests,
and platform-secure credential storage. No method of storage is perfectly
secure, but access is deliberately limited to the authentication adapter
that needs it.
6. Google API Services User Data Policy
NIRUNE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Children
NIRUNE is not directed to children under the minimum age required to manage their own Google Account in their country. Do not connect an account if you are not permitted to grant the requested access.
8. Changes to this policy
This policy will be updated before NIRUNE introduces materially different data collection, a managed synchronization service, new Google scopes, or new sharing practices. The effective date at the top will identify the latest revision.
9. Contact
Questions, privacy requests, and security reports can be sent to slcrmmbr@gmail.com.