Privacy Policy
This policy explains how NIRUNE accesses, uses, stores, and shares data. NIRUNE is currently an experimental, private-preview music application for Windows, with Android support in development.
1. Data NIRUNE accesses
Provider sessions and catalog data
When you choose to connect YouTube, YouTube Music, or Yandex Music, NIRUNE opens the provider's first-party sign-in page inside a protected in-app web session. The provider may set ordinary session cookies and return account, subscription, catalog, library, playlist, and playback data available to that account and region. Online searches are submitted only after an explicit user action.
Session credentials
NIRUNE does not use Google OAuth or the YouTube Data API. Provider session
cookies are stored in platform-protected storage on your device. They are
not displayed in the interface, written to normal application logs, or sent
to a NIRUNE-operated cloud server. While NIRUNE is running, the minimum
session data needed for a request may be copied into authenticated local
helpers bound to 127.0.0.1; those copies remain in memory and
are cleared when the helpers stop or the provider is disconnected.
Local music and application data
When you select a local music folder, NIRUNE reads the audio files and metadata needed to display and play that library. It may store local preferences, library indexes, playlists, queue state, playback history, likes, and dislikes on the device. The public website does not receive this information.
2. How data is used
NIRUNE uses data only to provide user-facing application features, including:
- connecting and restoring a provider session;
- submitting searches that the user explicitly requests;
- showing provider-neutral catalog metadata and availability;
- maintaining the on-device music library and playback state;
- diagnosing failures through sanitized error categories that do not contain credentials or provider response bodies.
3. Sharing and disclosure
NIRUNE does not sell provider-session data, local-library data, or listening activity and does not use that data for advertising. User-initiated requests are sent to the selected provider through local NIRUNE adapters and are governed by that provider's privacy practices. Data may be disclosed only when required by applicable law or necessary to protect users and the integrity of the application.
4. Data retention and deletion
Search results are used for the current application experience and are not uploaded to a NIRUNE server. Local library and preference data remain until you remove them through the application, clear the application's data, or uninstall it.
Selecting Disconnect for a provider deletes its saved session from NIRUNE's protected local storage and clears the in-memory facade copy. You may also end the session through the provider's own account controls. Because the current preview operates without a NIRUNE account server, NIRUNE does not retain a separate cloud copy of provider data.
5. Security
NIRUNE uses protected in-app provider sessions, HTTPS for provider requests,
authenticated local services bound to 127.0.0.1, and
platform-protected credential storage. NIRUNE does not disable TLS checks or
expose its local facade to the network. No method of storage is perfectly
secure, but access is deliberately limited to the authentication adapter
that needs it.
6. Children
NIRUNE is not directed to children under the minimum age required to manage their own provider account in their country. Do not connect an account if you are not permitted to grant the requested access.
7. Changes to this policy
This policy will be updated before NIRUNE introduces materially different data collection, a managed synchronization service, new provider access, or new sharing practices. The effective date at the top will identify the latest revision.
8. Contact
Questions, privacy requests, and security reports can be sent to slcrmmbr@gmail.com.