Privacy Policy
Last updated: June 10, 2026
Karadrome is a client for your own Navidrome or Subsonic-compatible music server. We do not operate a central music service or host your library.
Summary
- Server credentials stay on your device (encrypted) and are sent only to your server.
- Optional cloud sync uses Google Firebase for preferences and listening metadata — not passwords.
- Premium purchases and trial anchoring use Google Play Billing and Firebase.
- No analytics or advertising SDKs are included.
Data stored on your device
- Server URL, username, and password (Android EncryptedSharedPreferences)
- Saved multi-server profiles
- Offline downloads and download-queue metadata
- App preferences, pins, favorites cache, and cached media
- Premium and trial state
Data sent to your music server
- Credentials via the Subsonic API token scheme (HTTPS when your server uses HTTPS).
- Library, search, playlist, playback, scrobble, and favorite requests.
Optional services
Google Firebase (cloud sync)
When sync is enabled, Karadrome uses anonymous Firebase Auth and Firestore to store a JSON snapshot of preferences, pinned playlists, and listening history keyed to your Navidrome identity. Passwords are never synced. Firebase also stores trial-start timestamps to limit trial abuse.
Google Play Billing
Premium purchases and restores are handled by Google Play on your device.
Last.fm, LRCLIB, octofiesta
Only used when you enable those features. Last.fm receives artist names for similar-artist lookups; LRCLIB receives song metadata for lyrics; an octofiesta proxy you configure receives search/playback requests for online results.
Data we do not collect
- No analytics or advertising SDKs
- No Karadrome-hosted music library
- We do not sell personal data
Your choices
- Turn off cloud sync, external lyrics, online search, and artist mixes in Settings
- Disconnect your server and uninstall the app
Contact
Changes
We may update this policy in app release notes. Continued use after changes constitutes acceptance.