隱私權政策
本政策包含以下內容
一、我們如何收集和使用您的資訊
(一)本地音樂庫資料 本地存儲
本產品以本地音樂庫為核心。導入目錄、歌曲資訊、歌單、最近播放記錄及設定,預設保存在當前設備本地,不會自動上傳至任何外部伺服器。
(二)媒體文件解析 本地讀取
我們的應用程式會讀取您音訊文件中的標籤(ID3/Vorbis 等)、歌詞(LRC/嵌入式)及封面圖片,用於在應用程式內展示和管理您的音樂庫。所有解析均在本地設備完成,不外傳。
(三)匿名使用遙測 匿名 · 可選 預設關閉
為改善應用程式品質,只有在您開啟「匿名使用資料」後,我們才會生成不含任何個人識別資訊的隨機設備 ID(UUID v4),並透過 PostHog 收集以下匿名事件:
| 收集項目 | 用途 | 是否含 PII |
|---|---|---|
| 功能使用事件(播放格式、使用引擎、功能開關) | 產品改進 | 否 |
| 應用程式生命週期(開啟 / 關閉) | 活躍度分析 | 否 |
| 音訊引擎錯誤類型 | 穩定性改進 | 否 |
| OS 版本、CPU 架構、記憶體分段(≤4GB / ≤8GB …) | 相容性最佳化 | 否 |
| 應用程式版本號 | 版本分佈 | 否 |
我們從不收集:歌曲標題、演出者名稱、文件路徑、歌詞內容、IP 位址(於伺服器端截斷丟棄)。
您可在「設定 → 隱私 → 使用分析」中隨時關閉此功能。
(四)崩潰與錯誤報告 匿名
如果目前發佈版本配置了 Sentry,應用程式可能會自動捕獲崩潰事件與未處理例外,以協助我們快速修復問題。Sentry 收集的資訊包含:匿名設備 ID(若匿名使用資料已開啟)、堆疊追蹤、錯誤類別、OS 版本與應用程式版本。不包含任何音樂庫內容、使用者姓名或聯絡資訊。
(五)本地診斷日誌 本地存儲
我們在本地保存 crash dump 文件與 lifecycle 診斷快照(保留最近 5 個 crash dump,lifecycle 快照超過 24 小時自動清理)。這些資料僅用於本地恢復,不主動傳送至外部。
(六)功能旗標遠端設定 匿名
在發佈版本明確配置 ConfigCat SDK 時,我們使用 ConfigCat 進行功能旗標管理(例如控制實驗性功能的開關)。ConfigCat 僅接收匿名設備 ID、平台類型(Windows 桌面)及應用程式名稱,不接收任何個人識別資訊;未配置時只使用本地預設值。
(七)用戶主動導出 本地生成
只有當您主動點擊「導出資料快照」功能時,我們才會生成包含您音樂庫資訊的 JSON 文件。導出路徑完全由您自行選擇。
(八)不收集的資訊
我們不收集:設備識別碼(IMEI/MAC 等)、位置資訊、通訊錄、相機 / 麥克風資料、廣告識別碼。本產品不含任何廣告 SDK,不進行任何形式的行為追蹤或個性化廣告投放。
二、第三方 SDK 與服務揭露
以下是本應用程式整合的第三方 SDK,及各自的資料處理說明:
| SDK / 服務 | 用途 | 傳送資料 | 隱私政策 |
|---|---|---|---|
| PostHog (透過 seek.music.blrra.com 反向代理) |
匿名使用分析 | 匿名設備 UUID、功能事件、OS/版本資訊 | posthog.com/privacy |
| Sentry | 崩潰報告 / 錯誤監控 | 匿名設備 UUID、堆疊追蹤、錯誤類別、OS/版本 | sentry.io/privacy |
| ConfigCat | 功能旗標 / 遠端設定 | 匿名設備 UUID、平台類型(windows_desktop) | configcat.com/privacy |
上述所有服務均不接收歌曲名稱、演出者、文件路徑、歌詞、IP 位址或任何個人識別資訊。PostHog 的遙測可在「設定 → 隱私 → 使用分析」中完全停用。
三、應用程式能力(Capabilities)聲明
本應用程式在 Windows 應用程式套件(MSIX)中聲明了以下能力,以下說明各能力的實際用途:
| 能力名稱 | 使用原因(最低範圍原則) |
|---|---|
| musicLibrary | 存取 Windows 音樂媒體庫資料夾,以掃描並導入您的本地音樂集合。 |
| removableStorage | 支援從隨身碟、行動硬碟等可移除媒體讀取音樂文件。 |
| internetClient | 必要:連接 Sentry(崩潰報告)、PostHog(使用分析)、ConfigCat(功能旗標),以及用戶主動配置的 Subsonic / Jellyfin 伺服器、Last.fm 封面 / 元數據、歌詞來源。 |
| privateNetworkClientServer | 必要:在家庭 / 辦公室私人網路中探索並連接 Subsonic、Jellyfin 伺服器及 DLNA 渲染器。 |
我們嚴格遵循「最低權限」原則,僅請求應用程式功能運作所必需的能力,不申請相機、麥克風、聯絡人、位置或帳戶存取等無關能力。
四、Cookie 及同類技術
本產品為 Windows 桌面應用程式,不使用瀏覽器 Cookie。我們僅使用操作系統本地存儲(SQLite 資料庫及文件系統)保存您的設定和音樂庫資料。只有在您開啟使用分析或發佈版本明確配置遠端旗標時,才會建立匿名設備 UUID(存放於 %AppData%/MusicX/analytics/device_id)。
五、資訊的共享、轉讓與公開披露
我們不向任何第三方出售、出租或公開披露您的個人資訊。只有在您開啟使用分析,或目前發佈版本明確配置遠端旗標/崩潰報告時,相關匿名資料才會傳送至上述第三方 SDK。
用戶主動配置的第三方服務連接
若您主動在設定中配置以下服務,相關資料處理以各服務商隱私政策為準:
- Subsonic / Jellyfin 家庭媒體伺服器(需您提供伺服器地址和憑據)
- DLNA / AirPlay 無線串流(本地網路內)
- Last.fm / Spotify 元數據抓取(需您授權)
- WebDAV 雲端磁碟(需您提供伺服器地址和憑據)
除您開啟的分析/崩潰報告及發佈版本明確配置的遠端旗標外,其他上述連接均由您主動發起;核心播放與本地曲庫管理不需要網路。
六、我們如何保護您的資料
- 所有本地資料(音樂庫、設定、診斷日誌)存儲於設備的應用程式資料目錄,受 Windows 存取控制保護。
- 雲端服務憑據(如 Jellyfin / WebDAV 密碼)使用 Windows Credential Manager 加密存儲,不以明文保存。
- 不建立任何未經您授權的外部網路連接。
- 診斷日誌文件定期自動清理,避免資料積累。
- 傳送至 PostHog 的流量通過我們自建的反向代理(seek.music.blrra.com),IP 位址在進入 PostHog 前已截斷丟棄。
七、您的權利
(一)查閱與刪除
您可以隨時在應用程式內查看、管理您的音樂庫資料、播放記錄和設定。如需完整刪除所有本地資料,可在「設定 → 關於 → 清除所有資料」中操作,或直接解除安裝應用程式。
(二)關閉使用分析
前往「設定 → 隱私 → 使用分析」,可隨時停用 PostHog 遙測。停用後,應用程式將不再向外部傳送任何使用事件。
(三)導出
您可以隨時透過「導出資料快照」功能將您的資料以 JSON 格式導出,以便遷移或備份。
(四)停止使用
您可以隨時解除安裝本產品以停止使用。解除安裝後,應用程式在設備上存儲的所有資料將根據作業系統行為被清除。
八、兒童個人資訊的處理
本產品為面向一般成人的桌面音樂播放器,不針對兒童設計也不主動收集兒童個人資訊。如您為未成年人的監護人,請依您的判斷決定是否允許使用本應用程式。
九、本政策如何更新
如本隱私權政策發生重大變更(例如新增資料收集類型、改變資料用途),我們將在本頁面更新內容並修改頂部的更新日期。對於重大變更,我們還會在應用程式內透過彈出視窗或通知提示您。
十、如何聯繫我們
開發者:BLRRA LTD
電子郵件:blr931@proton.me
我們將在收到您的請求後 15 個工作日內予以回覆。
隐私政策
本政策包含以下内容
- 我们如何收集和使用您的信息
- 第三方 SDK 与服务披露
- 应用程序能力(Capabilities)声明
- Cookie 及同类技术
- 信息的共享、转让与公开披露
- 我们如何保护您的数据
- 您的权利
- 儿童个人信息的处理
- 本政策如何更新
- 如何联系我们
一、我们如何收集和使用您的信息
(一)本地音乐库数据 本地存储
本产品以本地音乐库为核心。导入目录、歌曲信息、歌单、最近播放记录及设置,默认保存在当前设备本地,不会自动上传至任何外部服务器。
(二)媒体文件解析 本地读取
我们的应用程序会读取您音频文件中的标签(ID3/Vorbis 等)、歌词(LRC/嵌入式)及封面图片,用于在应用内展示和管理您的音乐库。所有解析均在本地设备完成,不外传。
(三)匿名使用遥测 匿名 · 可选 默认关闭
为改善应用程序质量,只有在您开启「匿名使用数据」后,我们才会生成不含任何个人识别信息的随机设备 ID(UUID v4),并通过 PostHog 收集以下匿名事件:
| 收集项目 | 用途 | 是否含 PII |
|---|---|---|
| 功能使用事件(播放格式、使用引擎、功能开关) | 产品改进 | 否 |
| 应用程序生命周期(开启 / 关闭) | 活跃度分析 | 否 |
| 音频引擎错误类型 | 稳定性改进 | 否 |
| OS 版本、CPU 架构、内存分段(≤4GB / ≤8GB …) | 兼容性优化 | 否 |
| 应用程序版本号 | 版本分布 | 否 |
我们从不收集:歌曲标题、演出者名称、文件路径、歌词内容、IP 地址(于服务器端截断丢弃)。
您可在「设置 → 隐私 → 使用分析」中随时关闭此功能。
(四)崩溃与错误报告 匿名
如果当前发布版本配置了 Sentry,应用程序可能会自动捕获崩溃事件与未处理异常,以协助我们快速修复问题。Sentry 收集的信息包含:匿名设备 ID(仅在匿名使用数据已开启时)、堆栈追踪、错误类别、OS 版本与应用程序版本。不包含任何音乐库内容、用户姓名或联系信息。
(五)本地诊断日志 本地存储
我们在本地保存 crash dump 文件与 lifecycle 诊断快照(保留最近 5 个 crash dump,lifecycle 快照超过 24 小时自动清理)。这些数据仅用于本地恢复,不主动传送至外部。
(六)功能标志远程配置 匿名
在发布版本明确配置 ConfigCat SDK 时,我们使用 ConfigCat 进行功能标志管理(例如控制实验性功能的开关)。ConfigCat 仅接收匿名设备 ID、平台类型(Windows 桌面)及应用程序名称,不接收任何个人识别信息;未配置时只使用本地默认值。
(七)用户主动导出 本地生成
只有当您主动点击「导出资料快照」功能时,我们才会生成包含您音乐库信息的 JSON 文件。导出路径完全由您自行选择。
(八)不收集的信息
我们不收集:设备识别码(IMEI/MAC 等)、位置信息、通讯录、相机 / 麦克风数据、广告标识符。本产品不含任何广告 SDK,不进行任何形式的行为追踪或个性化广告投放。
二、第三方 SDK 与服务披露
| SDK / 服务 | 用途 | 传送数据 | 隐私政策 |
|---|---|---|---|
| PostHog (通过 seek.music.blrra.com 反向代理) |
匿名使用分析 | 匿名设备 UUID、功能事件、OS/版本信息 | posthog.com/privacy |
| Sentry | 崩溃报告 / 错误监控 | 匿名设备 UUID、堆栈追踪、错误类别、OS/版本 | sentry.io/privacy |
| ConfigCat | 功能标志 / 远程配置 | 匿名设备 UUID、平台类型(windows_desktop) | configcat.com/privacy |
上述所有服务均不接收歌曲名称、演出者、文件路径、歌词、IP 地址或任何个人识别信息。PostHog 遥测可在「设置 → 隐私 → 使用分析」中完全停用。
三、应用程序能力(Capabilities)声明
| 能力名称 | 使用原因(最低范围原则) |
|---|---|
| musicLibrary | 访问 Windows 音乐媒体库文件夹,以扫描并导入您的本地音乐集合。 |
| removableStorage | 支持从 U 盘、移动硬盘等可移除媒体读取音乐文件。 |
| internetClient | 必要:连接 Sentry(崩溃报告)、PostHog(使用分析)、ConfigCat(功能标志),以及用户主动配置的 Subsonic / Jellyfin 服务器、Last.fm 封面 / 元数据、歌词来源。 |
| privateNetworkClientServer | 必要:在家庭 / 办公室私有网络中发现并连接 Subsonic、Jellyfin 服务器及 DLNA 渲染器。 |
我们严格遵循「最低权限」原则,仅申请应用功能运作所必需的能力。
四、Cookie 及同类技术
本产品为 Windows 桌面应用程序,不使用浏览器 Cookie。我们仅使用操作系统本地存储(SQLite 数据库及文件系统)保存您的设置和音乐库数据。只有在您开启使用分析或发布版本明确配置远程标志时,才会建立匿名设备 UUID(存放于 %AppData%/MusicX/analytics/device_id)。
五、信息的共享、转让与公开披露
我们不向任何第三方出售、出租或公开披露您的个人信息。匿名遥测数据仅传送至上述第三方 SDK 以改善产品质量。
用户主动配置的第三方服务连接
- Subsonic / Jellyfin 家庭媒体服务器(需您提供服务器地址和凭据)
- DLNA / AirPlay 无线串流(本地网络内)
- Last.fm / Spotify 元数据抓取(需您授权)
- WebDAV 云盘(需您提供服务器地址和凭据)
除您开启的分析/崩溃报告及发布版本明确配置的远程标志外,其他上述连接均由您主动发起;核心播放与本地曲库管理不需要网络。
六、我们如何保护您的数据
- 所有本地数据存储于设备的应用数据目录,受 Windows 访问控制保护。
- 云端服务凭据(如 Jellyfin / WebDAV 密码)使用 Windows Credential Manager 加密存储,不以明文保存。
- 不建立任何未经您授权的外部网络连接。
- 诊断日志文件定期自动清理,避免数据积累。
- 传送至 PostHog 的流量通过自建反向代理(seek.music.blrra.com),IP 地址在进入 PostHog 前已截断丢弃。
七、您的权利
(一)查阅与删除
您可以随时在应用内查看、管理您的音乐库数据、播放记录和设置。如需完整删除所有本地数据,可在「设置 → 关于 → 清除所有数据」中操作,或直接卸载应用。
(二)关闭使用分析
前往「设置 → 隐私 → 使用分析」,可随时停用 PostHog 遥测。停用后,应用将不再向外部传送任何使用事件。
(三)导出
您可以随时通过「导出资料快照」功能将您的数据以 JSON 格式导出,以便迁移或备份。
(四)停止使用
您可以随时卸载本产品以停止使用。卸载后,应用在设备上存储的所有数据将根据操作系统行为被清除。
八、儿童个人信息的处理
本产品为面向一般成人的桌面音乐播放器,不针对儿童设计也不主动收集儿童个人信息。
九、本政策如何更新
如本隐私政策发生重大变更,我们将在本页面更新内容并修改顶部的更新日期,同时在应用内通过弹窗或通知提示您。
十、如何联系我们
开发者:BLRRA LTD
电子邮件:blr931@proton.me
我们将在收到您的请求后 15 个工作日内予以回复。
Privacy Policy
This policy covers
- How we collect and use your information
- Third-party SDK and service disclosures
- App capability declarations
- Cookies and similar technologies
- Sharing, transfer and disclosure of information
- How we protect your data
- Your rights
- Children's personal information
- How this policy is updated
- How to contact us
1. How We Collect and Use Your Information
1.1 Local music library data Stored locally
Our app revolves around a local music library. Imported directories, song info, playlists, play history and settings are stored locally on your device by default and are never uploaded to external servers.
1.2 Media file parsing Local only
We read tags (ID3/Vorbis etc.), lyrics (LRC/embedded), and cover artwork from your audio files to build and display your local library. All parsing happens on your device and is never sent externally.
1.3 Anonymous usage telemetry Anonymous · Optional Off by default
To improve the app, we generate a randomly assigned, non-personally-identifiable device ID (UUID v4) and use PostHog to collect the following anonymous events only after you enable Anonymous Usage Analytics:
| Data collected | Purpose | Contains PII? |
|---|---|---|
| Feature usage events (format played, engine used, feature toggles) | Product improvement | No |
| App lifecycle events (app_open, app_close) | Engagement analytics | No |
| Audio engine error type | Stability improvement | No |
| OS version, CPU architecture, RAM tier (≤4GB / ≤8GB …) | Compatibility optimisation | No |
| App version number | Version distribution | No |
We never collect: song titles, artist names, file paths, lyrics, IP addresses (stripped server-side before reaching PostHog).
You can disable this at any time via Settings → Privacy → Usage Analytics.
1.4 Crash and error reporting Anonymous
If this release is configured with Sentry, the app may automatically capture crashes and unhandled exceptions so we can fix them quickly. Sentry receives: the anonymous device ID (only when analytics is enabled), stack traces, error category, OS version, and app version. It never intentionally receives music library content, your name, or contact information.
1.5 Local diagnostic logs Stored locally
We store crash dump files and lifecycle diagnostic snapshots locally (up to 5 crash dumps are kept; lifecycle snapshots older than 24 hours are auto-deleted). These are used for on-device recovery only and are never transmitted externally.
1.6 Remote feature flags Anonymous
When a release explicitly configures the ConfigCat SDK, we use ConfigCat to manage feature flags (e.g. enabling experimental features). ConfigCat only receives the anonymous device ID, platform type (windows_desktop), and app name — no personally identifiable information. Without that configuration, the app uses local defaults.
1.7 User-initiated data export Local only
A shareable JSON file is generated only when you explicitly trigger the Export Data Snapshot feature. You choose the destination; we play no further role.
1.8 What we do NOT collect
We do not collect: device identifiers (IMEI/MAC etc.), location data, contacts, camera/microphone data, or advertising identifiers. This product contains no ad SDKs and performs no behavioural tracking or personalised advertising.
2. Third-Party SDK and Service Disclosures
| SDK / Service | Purpose | Data sent | Privacy policy |
|---|---|---|---|
| PostHog (via seek.music.blrra.com reverse proxy) |
Anonymous usage analytics | Anonymous device UUID, feature events, OS/version | posthog.com/privacy |
| Sentry | Crash reporting / error monitoring | Anonymous device UUID, stack traces, error category, OS/version | sentry.io/privacy |
| ConfigCat | Feature flags / remote config | Anonymous device UUID, platform type (windows_desktop) | configcat.com/privacy |
None of the above services receive song names, artist names, file paths, lyrics, IP addresses, or any personally identifiable information. PostHog telemetry can be fully disabled via Settings → Privacy → Usage Analytics.
3. App Capability Declarations
This app declares the following capabilities in its Windows app package (MSIX). Each capability is used only for the stated purpose (least-privilege principle):
| Capability | Why it is required |
|---|---|
| musicLibrary | Access the Windows Music library folder to scan and import your local music collection. |
| removableStorage | Read music files from USB drives, portable hard drives, and other removable media. |
| internetClient | Required to reach Sentry (crash reporting), PostHog (usage analytics), ConfigCat (feature flags), and user-configured services such as Subsonic/Jellyfin servers, Last.fm artwork/metadata, and lyrics providers. |
| privateNetworkClientServer | Required to discover and connect to Subsonic/Jellyfin servers and DLNA renderers on a home or office private network. |
We do not request camera, microphone, contacts, location, or account access capabilities.
4. Cookies and Similar Technologies
This product is a Windows desktop application and does not use browser cookies. We use only OS-level local storage (SQLite database and file system) for your settings and library data. An anonymous device UUID is created only when you enable usage analytics or when a release is explicitly configured for remote feature flags, and is stored at %AppData%/MusicX/analytics/device_id.
5. Sharing, Transfer and Disclosure
We do not sell, rent, or publicly disclose your personal information to any third party. Anonymous data is sent to the listed SDKs only when usage analytics is enabled or the release is explicitly configured for remote feature flags or crash reporting.
User-configured third-party service connections
If you voluntarily configure the following services in Settings, data handling is governed by each provider's privacy policy:
- Subsonic / Jellyfin home media servers (requires your server address and credentials)
- DLNA / AirPlay wireless streaming (local network only)
- Last.fm / Spotify metadata fetching (requires your authorisation)
- WebDAV cloud drives (requires your server address and credentials)
All connections above are initiated explicitly by you. We establish no external connections without your deliberate action.
6. How We Protect Your Data
- All local data is stored in your device's app data directory, protected by Windows access controls.
- Cloud service credentials (e.g. Jellyfin / WebDAV passwords) are encrypted via Windows Credential Manager and never stored in plain text.
- No unauthorised external network connections are established.
- Diagnostic log files are automatically cleaned up on a schedule to prevent data accumulation.
- Traffic to PostHog passes through our own reverse proxy (seek.music.blrra.com) where IP addresses are stripped before forwarding.
7. Your Rights
7.1 Access and deletion
You can view and manage your library data, play history, and settings at any time within the app. To delete all local data, use Settings → About → Clear All Data, or simply uninstall the app.
7.2 Opt out of analytics
Navigate to Settings → Privacy → Usage Analytics to disable PostHog telemetry at any time. Once disabled, no usage events will be sent externally.
7.3 Data export
Export your data as a JSON snapshot at any time via the Export Data Snapshot feature for migration or backup purposes.
7.4 Stop using the app
You can stop using this product at any time by uninstalling it. All data stored by the app will be cleared according to OS behaviour upon uninstallation.
8. Children's Personal Information
This product is a desktop music player intended for general adult audiences. We do not design features for children and do not knowingly collect personal information from children. If you are a parent or guardian, please use your own judgement in deciding whether to permit use of this app.
9. How This Policy Is Updated
If this Privacy Policy changes materially (e.g. new data types collected, changed purposes), we will update this page, revise the date at the top, and notify you via an in-app prompt for significant changes.
10. How to Contact Us
Developer: BLRRA LTD
Email: blr931@proton.me
We will respond to your request within 15 business days.