Your music stays on your phone.
Tempo keeps your listening history in an encrypted database on your phone. No server copy. No account. The only thing that ever leaves is anonymous app-health data, described in section 5, which you can turn off.
What Tempo reads
Title, artist and app name from the media notification. Music only. Messages, mail, podcasts and audiobooks are skipped.
What stays put
History, stats and login tokens stay encrypted on your phone. There is no server copy to leak or sell.
The one thing it sends
Anonymous crash and feature counts to Aptabase in the EU. No song names. No device IDs. Off in one tap.
Your controls
Export, import or wipe your data any time. Encrypted Drive backup stays off until you turn it on.
01 Introduction
Tempo (“we”, “our”, or “the App”) is a local-first music journal. It runs with no central server, no user accounts and no advertising.
One exception: anonymous app-health statistics in section 5. That is the only data Tempo sends about itself, and it never includes what you played.
02 Data collection & permissions
Tempo needs these Android permissions to track plays:
BIND_NOTIFICATION_LISTENER_SERVICEDetects a playing song from the media notification: title, artist, app name. Filters for music apps and ignores everything else.
FOREGROUND_SERVICEKeeps tracking alive in the background so Android does not stop it.
INTERNETFetches album art and artist info, and sends the app-health stats in section 5. Your listening history never uploads.
MEDIA_CONTENT_CONTROLReads the active media session for playing or paused state and track position.
03 Data storage
- History and stats sit in an encrypted SQLite (Room) database in internal storage. Login tokens sit in encrypted preferences.
- No server copy exists. Lose the phone without a backup and the data goes with it. We cannot recover what we never had.
- Backups are yours to make: export to a file any time, or switch on encrypted backup to your own Google Drive. Drive backup is off by default.
04 External services & data sharing
To add artwork and artist info, Tempo queries public services. Each query sends the artist and title being looked up, and nothing from your history.
Spotify
Cover art, audio traits and genres. Sends artist and song title. A linked account token stays on your phone and only signs these calls.
iTunes / Apple Music
Backup source for artwork and artist photos, including public artist pages when the API has no image. Sends artist and album title.
MusicBrainz & Cover Art Archive
Metadata and tags. Sends artist and song title.
ReccoBeats
Mood and energy when Spotify has no data. Sends artist and song title, and at most the public 30-second preview URL. Never your audio files.
Last.fm & Deezer
Bios, tags and extra art. Sends the search text only.
Nothing else
No advertisers. No sale or profiling of what you play. The only analytics is the anonymous reporting in section 5.
05 Anonymous app-health stats
Tempo sends anonymous counts about the app itself so crashes and broken features get fixed. A few hundred bytes per event, about 16 KB on a busy day. The exact event list is published in the app at Settings → Your Data → Data & diagnostics and in docs/ANALYTICS.md.
What is sent
Crash signature (obfuscated class and line, never the message), failure counts by category, screens reached, onboarding completion, and whether background detection is alive. Counts go out as ranges, not exact figures.
What is never sent
Track, artist, album or playlist names. Search text. Notification content. File paths. Listening timestamps. Account details. Device IDs of any kind: no ad ID, no ANDROID_ID. Crash messages are left out on purpose, because a parse error can echo the song text Tempo just read.
How you stay anonymous
No user ID. The only identifier is a random session value kept in memory, renewed on every launch and after an hour idle, and never written to disk. No cookies. Data goes to Aptabase in the EU, which hashes IP and user agent with a salt that rotates every 24 hours and purges old salts, so events cannot link across days. One caveat stated plainly: that IP also yields a coarse country or region stored with the event. Not precise, and not linked to anything else about you.
When it runs, and how to stop it
Over any connection, including mobile data. Nothing is collected until the in-app notice has been shown, and the notice stays up until you acknowledge it or turn reporting off. To turn it off, open Settings → Your Data → Anonymous app-health stats. That stops collection at once and deletes anything buffered but unsent. Builds compiled from source send nothing: the reporting key is not in the repository.
06 Network communication
Requests go straight from your phone to the services above. No Tempo server or proxy sits in between.
07 Desktop companion
The Chrome and Firefox companion is optional and open source. It sends browser plays to your phone over local Wi-Fi, with no cloud in the middle. If the phone is away, plays wait in the browser and send when both are on the same network again.
How the extension works · Read the code
08 Your controls
Save the full database to a file any time.
Restore from a file, Last.fm, Google Takeout or YouTube Music. Duplicates are skipped.
Wipe everything in Settings in one tap.
09 Children’s privacy
Tempo is a general utility app, not directed at children under 13. We do not knowingly collect personal information from children.
10 Changes to this policy
This page changes when the app does. There is no email list, so check the date at the top or About in the app.
11 Contact
Questions on privacy or how this works in code? The source is open. Read each claim above in the repository.
Developer of Tempo · hi@avinash.im · github.com/avinaxhroy/Tempo
Your music. Your device. Your memory.
One journal for everything you play. Read the code that keeps it that way.