MusicAssistantMate · Privacy

How your music data is handled.

Privacy information for MusicAssistantMate on iPhone, Mac, Apple TV and Apple Watch, and for enquiries to app support.

Last updated: 12 September 2026

1. At a glance

  • No advertising, analytics or tracking SDKs, and no app-operated crash-reporting service.
  • The app connects directly to the Music Assistant server you choose. The developer does not receive your library, searches or playback commands through an app backend.
  • Saved account details and access tokens stay in the Keychain of each device. The app does not synchronise them through iCloud.
  • Cover images and web sign-in can contact external providers.
  • Apple Watch receives playback information and room information from the iPhone, but no passwords or Music Assistant access tokens.

2. Controller and scope

Controller
Fabian Vocke
Am Autobahnzubringer 1
76709 Kronau
Germany

privacy@mate.build

This policy describes the app and support provided by the developer. Your Music Assistant server operator and any music or sign-in providers are responsible for processing they perform independently. They set their own access permissions, logging and retention. Visiting mate.build is covered by the separate website privacy policy.

3. Connecting to your server

The app processes the server address you enter, user and account identifiers, username, display name and a Music Assistant access token. Direct account sign-in sends your username and password to that server to obtain a session. The app does not permanently save the password.

To display and control your music, the app sends searches, media and player identifiers, playback commands, volume changes and group changes to your server. It receives albums, playlists, tracks, artists, service details, room names, availability and playback state. Your server also receives technical connection information, including your IP address.

Your account’s server permissions determine which services and players are visible. Adding another account does not automatically create a separate library. The developer has no automatic access to the server or its data.

Native API requests do not keep a persistent response or cookie cache. Public server addresses require HTTPS. HTTP is accepted for recognised local server addresses and is unencrypted, including for credentials. The encryption rule for server connections does not mean that every cover-image request is encrypted.

4. Web sign-in and music services

On iPhone and Mac, the server interface opens in an isolated, non-persistent web session. During use, it can process cookies, browser storage and other website data, and connect to Home Assistant or music providers. A validated Music Assistant session is transferred to the native app. When you manage services, the app can supply its session to the web interface of the selected server.

Apple TV uses Apple’s system authentication on a nearby iPhone or iPad. It validates the returned Music Assistant session and saves it on Apple TV. It does not copy the existing access token from the iPhone app. This system sign-in follows Apple’s and the selected sign-in provider’s browser and session behaviour; the non-persistent web-view statement above applies to iPhone and Mac.

Music services are connected through Music Assistant and their own authorisation flows. The native app does not import credentials from other installed music apps. Provider credentials are managed by your server and the provider. Their privacy policies apply to those connections.

5. Cover images and external recipients

Album and artist images can be loaded directly from public image URLs supplied by your server. The image host receives your IP address and the technical request, including the requested image address. The app does not add its Music Assistant authentication header to these requests.

Image URLs may use HTTPS or HTTP. HTTP images are transferred without encryption. Apple’s image-loading and cache mechanisms may retain images temporarily; the app does not provide its own fixed retention period for them.

Recipients depend on your server, configured services, sign-in flow and image URLs. External providers or their infrastructure may be outside the EU or EEA. Their privacy information explains applicable locations, retention and safeguards. The app does not promise exclusively EU-based processing.

6. Local storage and Apple Watch

Accounts and app state

Account identifiers, server address, username, display name and access token are stored in the device’s Keychain. iPhone and Apple TV use device-bound protection; Mac uses the local login Keychain. Keychain synchronisation is disabled for these entries. The selected account identifier is stored in local app settings.

Library responses, search results and playback state are held in memory. The app has no cloud-sync service of its own and does not use CloudKit. System caches and the companion context below are separate from this in-memory app state.

Apple Watch companion connection

The iPhone sends room identifiers and names, availability, selected room, track, artist, playback state, volume, timestamps, status messages and a temporary app-session identifier through WatchConnectivity. The Watch sends control commands back. No server address, passwords or Music Assistant access tokens are sent to the Watch.

Apple’s companion system can retain the last application context, which the Watch may show on its next launch. Commands are sent directly and are not queued for later execution. The Watch does not connect directly to your Music Assistant server.

7. Permissions and system services

Local network access is used to reach your server and is subject to the operating system’s permission controls. You can change permissions in system settings; disabling access can prevent a local connection.

The app does not request access to your microphone, camera, photo library, contacts or location. It includes no advertising or analytics integration. Apple’s App Store, authentication, companion and optional system-diagnostic services operate under Apple’s policies and your system settings.

8. Support enquiries and legal bases

If you email support, we process your email address, your message and any diagnostic details or attachments you choose to send to answer the enquiry. Our email service providers process the correspondence for delivery and storage. Do not send passwords, access tokens or sensitive content that is unnecessary for your enquiry.

Where we process personal data to provide a requested app service or contractual support, the basis is Article 6(1)(b) GDPR. Other support enquiries are handled under Article 6(1)(f) GDPR, based on our legitimate interest in answering them. Where consent is required, Article 6(1)(a) GDPR applies; consent can be withdrawn for the future. Statutory retention obligations are based on Article 6(1)(c) GDPR.

A server address and valid credentials are needed for a real server connection. Providing them is voluntary; without them you can use the simulated preview. Independent server and service operators determine the legal basis for their own processing.

9. Retention and deletion

Saved accounts remain in the Keychain until their entries are removed. On iPhone and Mac, use Profile → Saved accounts, select the trash button and confirm. This removes the selected local account and token from that device. It does not delete a server account, remove a music-service connection or revoke a server-issued session.

Disconnect and Apple TV’s Sign out clear the current selection and in-memory app state, but keep saved credentials. Apple TV currently offers no local account-removal button. A session or token can be revoked on the server to prevent its further use; this does not erase the local Keychain entry. Uninstalling alone does not guarantee removal of Keychain data.

Temporary images and companion data are subject to system cache management. Data retained on your server or by music, image and sign-in providers follows their own retention and deletion rules.

Support correspondence is retained while needed to resolve the enquiry and any related follow-up, and where required to comply with legal retention duties or establish, exercise or defend legal claims. It is then deleted when no further retention ground applies.

10. Your rights and updates

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction and data portability. You may object to processing based on legitimate interests on grounds relating to your situation, withdraw consent for the future and complain to a data protection supervisory authority. The app does not make automated decisions with legal or similarly significant effects.

Contact the controller using the address above. For data held only on your server or by a provider, also contact that operator. The developer cannot directly inspect or erase data held only on your devices or server; this does not affect your statutory rights.

This policy will be updated when app features or data processing change materially. General Data Protection Regulation.