Privacy Policy
Your music, your business.
Kord is a local-first music player. Your library stays on your device. Optional services you enable, such as Last.fm scrobbling, can receive the limited metadata they need for their features. Kord does not use your data for advertising or sell it.
Effective date: August 9, 2026
What Kord does
Kord is a native music player for iPhone and Mac. It plays audio files stored on your device or imported from cloud storage you connect. There is no Kord account, no streaming service, and no server that stores your library.
Data we collect
Kord does not collect personal data for its own accounts, analytics, or advertising. Optional services you connect can receive the data needed for the features you enable, including Google Drive for connected imports and Last.fm for optional now-playing and scrobbling. Your music library, playback history, EQ settings, and lyrics stay on your device.
Google user data
Kord can optionally connect to your Google Drive so you can import audio files into your local library. Connecting Google Drive is entirely optional — Kord works fully without it. When you choose to connect, Kord requests the following Google data through Google's standard OAuth consent flow:
- Read-only access to your Google Drive (the drive.readonly scope). This scope permits Kord to view and download files in your accessible Drive. Kord uses folder metadata across that Drive to locate a source folder, then reads file metadata and FLAC bytes only from the folder you choose and its nested subfolders.
- Your account email address (the openid and email scopes), used only to show you which Google account is connected.
Your Google credentials are handled entirely by Google — Kord never sees or stores your Google password.
Why Kord requests read-only Drive access
Kord keeps drive.readonly because its Drive workflow lets you find a music folder anywhere in your accessible Drive, including nested locations and shared drives, then import FLAC files from that folder and its subfolders. Kord reads the file metadata and audio bytes needed for the library and playback inside the selected folder tree. It never creates, changes, or deletes anything in Drive, and it does not share Drive files or audio contents. A narrower per-file permission such as drive.file would require a different workflow based on individually selected files and would not support Kord's current folder browser and recursive import.
How Kord uses Google user data
Kord uses the Google data it accesses to let you add your own audio files from Google Drive to Kord's library and play them on your device. To let you find a source folder, Kord may read folder metadata across your accessible Drive, including shared drives and locations outside the folder you eventually choose. After you choose a folder, Kord reads the metadata and FLAC audio inside that folder and its nested subfolders, builds local library entries from the audio tags, and downloads or streams audio when you play it. Kord does not read audio contents outside the folder tree you choose. It also displays the connected account's email address so you know which account is signed in. Kord does not use Google user data for advertising or sell it. It does not send Google account credentials, Drive file contents or audio, Drive IDs, folder listings, or account email to third parties. If you enable Last.fm scrobbling, Kord's configured Last.fm proxy may receive the current track's title, artist, album, album artist, track number, and duration, plus a play timestamp for scrobbles, when those values are available. The proxy forwards the Last.fm request to Last.fm. These fields may come from a file imported from Google Drive. This transfer is optional, user-directed, and limited to that user-facing feature. Kord's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How Kord retains and deletes Google user data
Kord has no server that stores your Google Drive files, Drive account data, or library. Google data received by the app is kept on your device for the purposes described above, except for the optional Last.fm metadata transfer described above. The configured Last.fm proxy forwards that metadata to Last.fm and does not write request bodies to a Kord application database. Last.fm and hosting infrastructure may retain requests under their own policies. Local data remains until you remove it or it is evicted by Kord's cache rules. Deleting the app removes its local library and cache, but Keychain credentials may survive app deletion depending on the operating system. Apple Developer Technical Support documents this behavior in its Keychain guidance. Sign out of Google Drive before deleting Kord if you want the stored OAuth credentials removed immediately.
- OAuth tokens — the access and refresh tokens Google issues are stored in your device's Keychain so you stay signed in between sessions. Kord removes them when you sign out or disconnect Google Drive in Kord's settings. Revoking Kord's access from your Google Account prevents future API access; Kord removes the local tokens when it next discovers that the session has expired.
- Library entries — for each track you add from Drive, Kord saves the Drive file ID, the track's title, artist, album, and last-modified timestamp in its local library database, so the track keeps working across launches. These entries remain until you remove the tracks or erase Kord's local app data. Signing out removes the Google credentials and selected folder, but does not automatically delete library entries you already imported.
- Cached audio — to play a Drive track, Kord downloads it into a private cache folder on your device. The cache is capped (5 GB by default) and evicts the least recently played files automatically. You can erase it at any time with Clear Drive Cache in Kord's Google Drive settings.
- Nothing else — Kord does not keep browsing history, folder listings after the browsing session, or any other Google data. It holds no background connection to your Drive and does nothing when the app isn't running.
To remove Google user data from your device, sign out of Google Drive, tap Clear Drive Cache, and delete any Drive tracks you no longer want in your library. If you delete Kord without signing out first, the local Keychain credentials may remain and must be removed by reinstalling Kord and signing out. You can also revoke Kord's access at any time from your Google Account permissions page.
Third-party services
Kord may contact the following external services during normal use:
- MusicBrainz — to look up album and artist metadata (credits, release dates). These are anonymous API requests with no user-identifying information.
- Last.fm — if you choose to enable scrobbling and the build has a Last.fm service configured. Kord's proxy receives the track name, artist, album, album artist, track number, and duration when available, plus a play timestamp for scrobbles, then forwards the request to Last.fm. Drive-imported metadata can be included. Kord does not send Drive files, audio, file IDs, folder listings, or Google account email. Last.fm and hosting infrastructure may retain requests under their own policies.
- Google Drive — only if you connect it, as described above.
Analytics and tracking
Kord does not include any analytics SDKs, ad trackers, or telemetry. We don't know how many songs you play, which screens you visit, or how often you open the app.
Data stored on your device
Kord stores your library database, playback settings, EQ presets, and cached metadata locally using Apple's standard frameworks (SwiftData, the file system, and the Keychain for OAuth tokens). This data is included in your device backups and is protected by your device passcode and encryption.
Children's privacy
Kord is not directed at children under 13. We do not knowingly collect personal information from children, because we do not collect personal information from anyone.
Changes to this policy
If we change this policy, we'll update the effective date at the top and post the new version here. For material changes, we'll note it in the app's changelog.
Contact
Questions about this policy? Email support@kordsound.com.