Privacy Policy
Effective Date: 2026-09-11
Thank you for using Share Music! This Privacy Policy explains how we collect, use, and protect your information when you use our iOS application and its related extensions (iMessage, Share Extension). Share Music includes social features such as user profiles, a friends system, direct messaging, and tools to help you find friends who are already using the app. This policy reflects all current features of the app.
1. Information We Collect
a) Account and Profile Information
When you create an account, you choose a unique handle (username) and a display name. These are stored in our database and are visible to other Share Music users within the app, including through search by handle or display name (used to help you find and add friends). Your handle and display name are not required to be your real name. You may also optionally configure your public profile to display your preferred streaming platform, most shared song, most shared album, and most shared artist, all of which you control individually through your profile settings.
If you choose to sign in with Apple, we receive and store the stable identifier and (if you share it) name associated with your Apple ID, used solely to link your Apple ID to your Share Music account for sign-in and account recovery.
If you choose to sign in with Google, we receive and store the stable identifier, and (if you share it) name and email address, associated with your Google account, used solely to link your Google account to your Share Music account for sign-in and account recovery.
b) Finding Friends: Contacts and Phone Number
To help you find friends who are already on Share Music, and let friends find you, you can optionally enable the following. Both are off until you take an explicit action to turn them on, and both can be reversed at any time.
- Contacts Matching: If you choose to sync your contacts, Share Music reads the phone numbers and email addresses in your device's Contacts app and converts each one into a one-way cryptographic hash (SHA-256) directly on your device. Only these hashes, never your actual contacts, names, or any other contact details, are sent to our servers, to check for a match against other Share Music users who have also registered a hashed phone number or email. We do not store, retain, or have access to your raw contact list at any point; hashes that don't produce a match are not linked to any contact information and cannot be reversed back into a phone number or email by us. Matched contacts are shown to you as friend suggestions; you choose whether to add them.
- Phone Number: If you choose to add your phone number, we verify it via a one-time SMS code (through Firebase Authentication) and store a one-way cryptographic hash of your verified number, associated with your account, to allow friends who have synced your number in their contacts to find you. We do not store your phone number in plain text, and it is never shown to other users or made searchable directly. Only the hash-matching process described above uses it.
You can review or reset your Contacts permission at any time in your device's Settings app (Settings > Share Music > Contacts). There is currently no in-app way to remove an already-registered phone number hash short of deleting your account (see Section 5); contact us at the email below if you'd like this removed sooner.
c) Social and Messaging Data
Share Music includes a social layer that enables the following, each of which involves storing associated data:
- Friend Connections: When you send or accept a friend request, a record of that mutual friendship (including both users' IDs and handles) is stored in our database.
- Direct Messages: When you send a song to a friend via Direct Messages, the message content — including the song metadata, an optional caption you write, and the timestamp — is stored in our database. Messages are visible only to the participants of that conversation.
- Message Reactions: Emoji reactions you place on received messages are stored and visible to both participants in a conversation.
- Read State: We store a timestamp indicating when you last read each conversation. This is used to display unread indicators and syncs across your devices and reinstalls.
d) Automatically Collected Information
- Device Country Code: We collect your device's two-letter country code (e.g., "US", "DE") based on your device's locale settings. This is used to fetch market-specific streaming links for shared songs.
- User ID: A unique identifier is generated for your account when you first sign up. This ID ties together your profile, sharing history, friends, and messages.
- Preferred Streaming Service: We store your selected preferred music streaming service to enhance your experience when opening music links.
- Sharing History: To provide the "Shared By You" and "Shared With You" features, we store a record of songs you share and receive, linked to your user ID.
- Song Metadata: When you share a song, we collect and store its title, artist, artwork URL, and public platform links for various streaming services.
e) Information Collected by Third-Party Services
We use third-party services to help us operate and improve the app. These services may collect data automatically.
- Firebase (Google): We use Firebase for our backend database (Firestore), authentication, and analytics (Google Analytics for Firebase). Google Analytics helps us understand how users engage with our app by collecting aggregated, anonymized data such as device information, OS version, and in-app activity.
- Meta (Facebook): We use the Facebook SDK for analytics purposes to understand user engagement and the effectiveness of our marketing efforts.
For more details on their data practices, please review the privacy policies for Google and Meta.
f) Information for Analytics and Advertising
With your explicit consent via the App Tracking Transparency (ATT) prompt, we may collect your device's Identifier for Advertisers (IDFA) and share it with our analytics partners (Google and Meta). If you decline, we will not collect or share your IDFA. Your choice does not affect any app feature and can be changed at any time in Settings > Privacy & Security > Tracking.
2. How We Use Your Information
- To Provide Core Functionality: To create universal song links, display your sharing history, and open links in your preferred music app.
- To Power Social Features: To display your profile to other users, enable friend connections, and deliver direct messages between friends.
- To Personalize Your Experience: To remember your preferred streaming service and profile visibility preferences.
- To Improve Our Service: To analyze usage trends, identify bugs, and enhance the user experience.
- To Maintain Security: To protect our services and our users, including detecting and preventing abuse.
- To Measure and Provide Advertising: With your consent, to measure the effectiveness of our advertising campaigns. Advertising may be presented to users on the free tier.
3. How We Share Your Information
We do not sell, rent, or trade your information with any third parties for marketing purposes.
- With Other Users: Your handle, display name, and any profile fields you choose to make public (preferred platform, most shared song/album/artist, share count) are visible to other Share Music users within the app. Direct messages are visible only to the participants of that conversation. Now Playing presence is shared only with your accepted friends, and only when you opt in.
- With Service Providers: We share data with Google (Firebase) and MusicFetch.io as necessary to operate the app. MusicFetch.io processes song metadata to generate universal links.
- For Legal Reasons: We may disclose information if required by law or in response to valid requests by public authorities.
4. Data Retention
Your profile, sharing history, friend connections, and direct messages are retained as long as your account exists. Now Playing presence data is ephemeral and not retained after your listening session ends. You may delete your account at any time to permanently remove all stored data.
5. Your Data Rights and Deletion
You have the right to access, update, and delete your personal data at any time.
How to Delete Your Data
- Open the Share Music app on your iOS device
- Tap the Settings icon in the top navigation bar
- Scroll down to the "Account" section
- Tap "Delete Account"
- Confirm your decision when prompted
What Gets Deleted
When you delete your account, the following is permanently removed from our systems:
- Your user ID, handle, and display name
- Your public profile data (platform preference, top song/album/artist, share count)
- All songs you have shared ("Shared By You" history)
- All songs you have received ("Shared With You" history)
- All direct message conversations and their contents
- All friend connections and pending friend requests
- Message reactions and read state data
- Now Playing presence data
- Your hashed phone number and any contact-matching registration data
- All app preferences and settings
Important: This action is permanent and cannot be undone.
Contact Us for Data Requests
If you need assistance or have questions about your data rights, please contact us at: support@sharemusic.link
6. Children's Privacy
Our service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information promptly.
7. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any significant changes by posting the new Privacy Policy within the app or on our App Store page. You are advised to review this Privacy Policy periodically for any changes.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at: support@sharemusic.link