Privacy policy for Disconnected

Last updated: 7 October 2026

Disconnected is a music player for Android phones, tablets and Wear OS watches. I'm Robert DeBodt, an independent developer in British Columbia, Canada, and I make it on my own. If you have a question about this policy, email me at admin@debodt.ca.

The short version

What the app keeps on your device

The app's working data is kept in its private storage on Android. Files you choose to export or back up are written to the destination you select and can be read there by that destination or anyone you share them with.

What leaves your device, and where it goes

Your own music servers (Jellyfin, Navidrome or another Subsonic server, Plex, Emby, Ampache, WebDAV). The app sends your user name and password or token to the server you entered, asks it for your music, and tells it what you play, like and add to playlists so the server stays up to date. A server address that starts with http:// is not encrypted. Use https:// if your server supports it. Jellyfin, Emby and Plex also receive an app identifier made from the account (Disconnected-<number>), which they require.

Finding servers on your home network. When you search for servers, the app sends discovery messages on your local network (the broadcasts Jellyfin, Emby and Plex answer, multicast DNS, and a short check of the usual music-server ports on your own subnet). They stay on your network and nothing about them is sent anywhere else.

Plex. If you sign in to Plex, you approve the app on plex.tv with a PIN; Plex then gives the app a token for your servers. Plex's own privacy policy applies to your Plex account: https://www.plex.tv/about/privacy-legal/

DroppedNeedle, the music manager you connect (Add to Playlist). Only when you add a song or album you don't have, or choose Get it with DroppedNeedle for liked songs, the app sends its title, artist, album, length and MusicBrainz IDs to your DroppedNeedle, signed in with your own login. What you type when searching DroppedNeedle for an album goes there too. When you add a Jellyfin server by typing its password, the app looks for DroppedNeedle on that same server and at droppedneedle on the same web domain (for example droppedneedle.example.com beside media.example.com); if one answers, it signs in there once with the same Jellyfin username and password. The password is not stored; only DroppedNeedle's sign-in token is kept on your device. The app can read service keys you stored in your own DroppedNeedle, to use them on your behalf.

Streaming services you connect (YouTube, Apple Music, Spotify, TIDAL and Deezer when their supported connection is available). You sign in on the service's own page. The service gives the app a token. The app reads your playlists and saved songs. It only changes anything on that service when you ask it to, for example when you move a playlist there or save songs to your library there. To find a song on the service, it searches by title, artist and ISRC code.

ListenBrainz (and Last.fm where available). When you connect them, the app learns your user name. Discover then asks them for artists and songs similar to the music you play. If you enable Scrobble to ListenBrainz with a saved sending token, the app sends the title, artist, album, duration and available MusicBrainz recording ID of the music you play, plus when counted plays started, to your ListenBrainz account. It also sends playing-now updates. Counted plays are queued on your device while offline and retried when sending is enabled. Turning scrobbling off stops new sending; private sessions and Discover preview auditions do not create new scrobbles. Listens already sent stay at ListenBrainz until you remove them there.

Audius, on in Discover unless you switch it off. Discover asks Audius's public catalogue for songs that fit your taste (genre words and artist names from your library) and plays the ones it deals straight from Audius. No account details are sent. Audius's privacy policy applies: https://audius.co/legal/privacy-policy

Demo music. If you choose Try demo music, the app connects to Navidrome's public demo server (demo.navidrome.org) with its published shared login and plays from it. Everyone who tries the demo shares that account, so the app never saves your likes or playlists there; they stay on your device.

Listen together. When you start or join a party, the app uses SyncPlay on your own Jellyfin server: it tells your server what the party plays, pauses or skips, and your server tells everyone in the party. People in the party see your Jellyfin user name and the songs the party plays.

Public music databases used by Discover, when you enable them: ListenBrainz, MusicBrainz, Cover Art Archive, Discogs and Deezer (30-second previews; off unless you turn it on). The app sends song titles, artist names, genre tags or song IDs from your library to find similar music and covers. No account details are sent. Like any web request, these reach the service with your IP address.

Runs. A run you record on the watch is sent from the watch to your own phone, where you see it and can save it as a FIT, GPX or TCX file to use wherever you like.

Strava. Disconnected does not start a Strava sign-in or post runs through Strava's API, including with a sign-in saved by an older build. You can save a run as a FIT file and upload it to Strava yourself, or share it with any app you choose; what you upload is under that destination's privacy policy. Disconnecting an old Strava sign-in asks Strava to revoke its access and removes the saved sign-in, athlete name and activity links from this device. Activities already at Strava stay there until you delete them at Strava. Location and heart rate are read while you are preparing or recording a run you started, including the GPS warm-up before recording.

Each of these services handles your data under its own privacy policy. I don't control what they do with it.

Buying the app

If you obtain Disconnected through Google Play, Google handles the payment; I never see your card details. In Google's developer console I can see each order (order number, date, country and the email address on the Google account) so I can refund it or help you with it.

Google and YouTube

Disconnected uses YouTube API Services. If you connect YouTube, the app reads your name and Google account ID to show which account is connected, your YouTube playlists and the videos in them, and video titles and lengths. It writes to YouTube only when you ask: creating, renaming, refilling or deleting a playlist, or liking a video when you save songs to YouTube. It doesn't upload videos, read comments or manage your channel.

YouTube data the app stores on your device is read again each time the app syncs with YouTube, is deleted automatically if no sync has refreshed it for 30 days, and is deleted from the device within 7 days when you disconnect YouTube. Deleting it in the app doesn't change anything stored at YouTube; to delete data there, use YouTube itself. Google's Privacy Policy applies to your use of YouTube: http://www.google.com/policies/privacy

You can remove Disconnected's access to your Google account at any time at https://security.google.com/settings/security/permissions (or Disconnect in the app).

Disconnected's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy

Health and location data

Heart rate, steps per minute and location are used only to prepare and record a run you start on the watch, to show it on the watch and your phone and, if you choose, to save or share it as a file. Preparing a run starts GPS and heart-rate measurements before you tap Start, so the watch can show signal readiness. These measurements are never used for ads or sold. They are shared only with your paired phone and destinations you explicitly choose. Disconnected is not a medical device; ask a healthcare professional for medical advice.

Disconnecting and deleting

Children

Disconnected is meant for adults and isn't directed at children. The developer does not operate a service that collects children's information. Connected services receive the data described in this policy and have their own age requirements.

Security

Tokens and passwords are kept in the app's private storage and are never included in a backup file. A backup does include your server addresses, account labels, usernames and account IDs, along with settings, playlists and listening records; it is not encrypted by Disconnected. Keep exported backups private and choose a destination you trust. Inside the app, the screens talk to the app's engine over a connection that stays on your phone and is protected with a key that changes every time the app starts. Connections to streaming services, legacy Strava revocation and the public databases use HTTPS. Connections to your own server use whatever its address says, so prefer https://.

Changes

If this policy changes I'll update this page and the date at the top. Big changes will also be in the app's release notes.

Contact

Robert DeBodt British Columbia, Canada admin@debodt.ca