Privacy Policy
Dubplate is a music player app for iPhone, Mac and Android that turns folders in your cloud storage, including folders shared with you, into a private streaming library. It works with Dropbox, Microsoft OneDrive and Nextcloud, the last of which is a server you or someone you trust runs. You choose which services to connect, and you can connect one, several, or all of them. The app also retains limited, unadvertised support for Google Drive, which the ordinary app does not offer and which is covered separately below. This policy explains what data the app touches, what it does with that data, and where the data lives. The short version: the Dubplate app has no backend, so your data goes between your device and the storage services you connected, and nowhere else.
The app never sends your account data or your files to us. There is no Dubplate server in the path between your device and the service you connected. Your sign-in, your file names, your folder structure, and your audio are handled on your device only.
What the app accesses
The app asks each service only for read-only permissions, on that service's own consent screens, and only when you choose to connect it. If you never connect a service, the app never asks it for anything.
Dropbox
- Basic account information (the
account_info.readscope) so the app can show which account is connected. - Read-only access to file and folder names
(
files.metadata.read) so the app can list the folders you choose and notice when tracks are added or replaced. - Read-only access to file contents
(
files.content.read) so the app can stream the audio, download albums you sync for offline listening, and read the tags and cover art embedded in your files. - Read-only access to sharing information
(
sharing.read) so the app can find folders that others have shared with you, and open a shared folder link you paste in.
Microsoft OneDrive
- Basic profile information (the
openid,profileandemailscopes) so the app can show which account is connected. The app reads your name and email address from the sign-in token Microsoft returns, and makes no separate request for your profile. - A refresh token (the
offline_accessscope) so your session survives closing and reopening the app, and you are not asked to sign in every time. - Read-only access to your files (the
Files.Read.Allscope) so the app can list the folders you choose, read file names and metadata, read the tags and cover art embedded in your audio files, stream them, download albums you sync for offline listening, and open a shared folder link you paste in.
Microsoft names that last permission Files.Read.All rather than
Files.Read because a folder someone else has shared with you does not
live inside your own OneDrive, and playing shared folders is the point of the app.
The suffix means "across the files you can reach", not "write". It grants no
ability to change anything, and Dubplate requests no write permission from
Microsoft or from any other service.
Nextcloud
Nextcloud works differently from the others, because there is no company in the middle: you connect a server, at an address you type in yourself, and that server may be one you run at home, one your studio or label runs, or one you rent from a hosting provider. Dubplate has nothing registered with anyone to make this work, and no relationship with the server you connect.
- Your sign-in happens on your own server. The app opens your server's login page in your device's browser. When you approve, the server issues Dubplate a device-specific app password, which appears on your server under Settings → Security → Devices & sessions with the name Dubplate. Your account password is never typed into the app and never reaches it.
- Your login name and display name, so the app can show which account is connected.
- Read-only use of your files: listing the folders you choose, including folders others have shared with you, reading file names and metadata, reading the tags and cover art embedded in your audio files, streaming them, downloading albums you sync for offline listening, and opening a folder link you paste in.
Nextcloud has no permission scopes to request: an app password simply carries the rights your own account already has. So read-only here is a property of the app rather than a limit the server imposes, and the app is built for it. Dubplate issues no request that would create, change, move, or delete anything on your server, with one deliberate exception: when you disconnect, it asks the server to delete the app password it was issued, so the session does not linger there after you have finished with it.
The server address you enter is treated as an exact address, and the app will only
ever talk to that one. It must be reachable over https; a plain
http address is refused rather than connected to insecurely.
Google Drive (limited access)
Google Drive is not offered in the ordinary app, and most people using Dubplate will never see it. The support is still built into the app for a small circle of existing users, reachable only by someone who has been told how to enable it. It is described here because it does still handle Google account data when it is used, and because Google's own consent screen links to this policy.
If you do connect Google Drive, the app tells you the same three things before the consent screen appears: Google has not reviewed Dubplate for Drive access, so Google will warn you that the app is unverified; only a limited number of people can connect, and you may need to ask to be added to the testers list first; and this access can stop working at any time, in which case your albums stay in your library and you can reconnect a different service. Nothing about how the data is handled changes: there is still no Dubplate server in the path.
- Basic profile information (your name, email address, and profile picture) so the app can show which account is connected.
- Read-only access to Google Drive
(the
drive.readonlyscope) so the app can list the folders you choose, read file names and metadata, and stream or download the audio files in them. This includes folders that others have shared with you.
Read-only means exactly that. The app cannot and does not modify, rename, move, upload, or delete anything in any storage you connect, and it never asks a service for permission to. No write permission is requested from any service, so even a bug in the app could not change your files.
What OneDrive support requires of you
Two things about OneDrive are worth knowing before you connect it, because they are properties of Microsoft's service rather than choices the app makes:
- Shared folders need a shortcut, or a link. OneDrive gives apps no usable way to list the folders other people have shared with you. To play one, open OneDrive in a browser, find the folder under Shared, and choose Add shortcut to My files; it then appears when the app browses your OneDrive. If all you have is a link to the folder, you can paste that into the app instead.
- Work and school accounts are not supported the same way. Dubplate is built for personal Microsoft accounts. You can try to sign in with a work or school account, but many organisations require an administrator to approve an outside app before it may read files, and that approval is out of our hands. If your organisation has not granted it, the app will tell you so and nothing will have been shared with anyone.
Personal OneDrive and work or school storage on SharePoint are separate systems at Microsoft, and a link belonging to one cannot be opened by an account of the other. The app detects this and explains it rather than failing silently.
How the app uses this data
Data from a connected service is used solely to provide the app's user-facing features to you:
- Browsing your folders, and folders shared with you, to find music.
- Building your library: reading file names, tags, and cover art from the audio files so albums display with correct titles and artwork.
- Streaming audio from your cloud storage to your device.
- Offline sync: downloading albums you select to your device so they play without a connection.
Nothing else. The app does not use data from any service you connect, including your Google user data, your Dropbox data, your Microsoft data and the contents of a Nextcloud server you connect, for advertising, does not sell it, does not let humans read it, and does not use it to train machine learning or artificial intelligence models.
Where your data is stored
- Sign-in tokens are stored in your device's secure storage (iOS Keychain, Android Keystore) and are used only to talk to the connected service's API from your device.
- Your library (album and track metadata, artwork, your local edits and playlists) is stored in a database on your device.
- Downloaded audio for offline playback is stored in the app's private storage on your device.
None of this is stored on, or transmitted through, any server operated by us. All data from your connected services is processed and stored on your device only.
How your data is protected
Because the contents of your cloud storage are sensitive data, the app protects them with the following measures:
- Encryption in transit. All communication between the app and
the services you connect, covering sign-in, folder listings, metadata, and
audio, travels over encrypted HTTPS/TLS connections. The app makes no
unencrypted network requests for your data. The app will only contact a fixed
list of addresses belonging to the services it supports, plus the exact address
of a Nextcloud server you have entered yourself, and nothing else. A Nextcloud
address is accepted only over
https, and only as you typed it: the app will not follow a redirect or a link onto some other server with your credentials. On OneDrive, audio is delivered from Microsoft's own content servers rather than from the main Microsoft Graph address, which is normal for that service and still goes directly from Microsoft to your device. - Encryption at rest. Everything the app keeps on your device, meaning the library database, artwork, downloaded audio, and the stored sign-in session, is written to the app's private storage area, which the operating system encrypts at rest as standard (Data Protection on iOS, file-based or full-disk encryption on Android). The app keeps no unencrypted copy anywhere else, and no copy at all off the device.
- Protected credentials. The app never sees or stores the password of any account you connect. You always sign in through that service's own screens, never on a password screen belonging to Dubplate. Google: sign-in is handled by Google's official SDK for each platform, which keeps the credentials in the operating system's protected storage, and the app itself holds only a short-lived access token, in memory, while it is running. Dropbox and Microsoft: you sign in on that service's own page in your device's system browser, never in an embedded web view inside the app, and the exchange uses PKCE so no shared secret is embedded in the app. The app then stores a single refresh token in the device's encrypted secure storage (iOS Keychain, Android Keystore), which is what keeps you signed in; the short-lived access token it exchanges that for is held in memory only. Nextcloud: you sign in on your own server's login page in your device's system browser, and the server hands the app a device-specific app password, which is stored in the same encrypted secure storage. That password is particular to this installation, it is listed on your server as a session named Dubplate, and you can revoke it there at any moment without changing your account password or disturbing your other devices.
- On-device isolation. Your library metadata, artwork, and downloaded audio are kept in the app's private, operating-system-sandboxed storage, which other apps cannot read. No data from your connected services is placed on any server, so it is never exposed to a server-side breach, to third parties, or to anyone at Buene AS.
- Access control. The only way into your files is your own account with the service that holds them, on your own device, after you grant consent through that service's screens. The app has no accounts, no logins, no administrative interface, and no support tool that could reach your data, because there is no server holding it. Nobody at Buene AS, and no third party, can be granted access to it. Revoking the app's access in that service's own account settings ends its access at once.
- Least privilege. The app requests read-only permissions and no write permission from any service, so a compromise could never modify, delete, or add files in your storage. It accesses only the folders you choose to open.
- Deletion under your control. All data lives only on your device, so removing it is entirely in your hands. Disconnect in the app clears the stored session and, with the option left enabled, this account's library and downloaded audio. Uninstalling removes everything the app has stored. Revoking access in your account with the storage service ends the app's access to your files; to also clear what is already on the device, disconnect or uninstall. Nothing survives on our side, because we hold nothing.
How long it is kept
We receive no data from your connected services, so there is nothing for us to retain, for any period. On your device, you decide how long it stays:
- Albums you sync for offline use are kept until you unsync them, disconnect, clear downloads in Settings, or uninstall the app. They are never removed automatically.
- Audio cached incidentally while streaming is removed automatically, least-recently-played first, to stay within the storage cap you set in Settings.
- Library metadata and artwork are kept while the album is in your library, and removed with it.
- Your sign-in session lasts until you disconnect in the app or revoke the app's access in your account with that service.
Sharing
We do not share, transfer, or disclose your data with anyone. The app transmits it to no one: the only network traffic involving your data is the app talking directly to the connected service's own API from your device.
Limited Use disclosure
Dubplate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Purchases
The one-time unlock is sold through Apple's App Store and Google Play. Payment is handled entirely by Apple or Google; we never see your payment details. The purchase record lives with your store account and on your device.
Diagnostics
The app currently sends no analytics and no crash reports. If a future version adds anonymous crash reporting or usage statistics, it will be designed so that it can never include data from your connected services: no file names, no folder names, no account details, no audio.
Deleting your data and revoking access
- Disconnect in the app (Settings → Disconnect) to remove the stored sign-in tokens and your library from the device. Each connected service disconnects separately.
- Revoke the app's access at Dropbox at any time from dropbox.com/account/connected_apps.
- Revoke the app's access at Google at any time from myaccount.google.com/permissions.
- Revoke the app's access at Microsoft at any time from account.live.com/consent/Manage. Microsoft gives an app no way to withdraw its own permission, so disconnecting in Dubplate clears the session from your device but leaves the permission listed in your Microsoft account until you remove it there.
- Revoke the app's access on a Nextcloud server under Settings → Security → Devices & sessions on that server, where the app appears as Dubplate. Disconnecting in the app asks the server to remove that session for you, so in the ordinary case there is nothing left to clean up.
- Uninstall the app to delete everything it stored on the device, including downloaded audio.
Because we hold no copy of your data, there is nothing for you to request deletion of on our side; removing it from your device removes it entirely.
Children
Dubplate is not directed at children and does not knowingly collect data from anyone. It collects no data on our side from any user of any age.
Changes to this policy
If this policy changes, the new version will be posted at this address with an updated effective date. A change that expanded the permissions the app uses would also require your renewed consent through the service's own screens.
Contact
Dubplate is made by Buene AS, Norway. Questions about this policy: erik@buene.com.