Skip to content
phonolite
Download Mission Goals Support

Phonolite Privacy Policy

How Telolith L.L.C. handles information for Phonolite's public website, official app distribution, support channels, and explains self-hosted server privacy.

Last updated: June 30, 2026

This Privacy Policy explains how Telolith L.L.C. ("Telolith," "Phonolite," "we," "us," or "our") handles information in connection with the Phonolite mobile and desktop app, the Phonolite self-hosted server, the public Phonolite website, official distribution channels, support channels, and any service that expressly identifies Telolith as its operator.

Phonolite is designed for self-hosted music playback. In the normal self-hosted setup, your app connects to a Phonolite server chosen or operated by you. Telolith's operation of the public Phonolite website, official downloads, app-store listings, or support channels does not mean Telolith hosts your music files, operates your server, or controls your server account, playback history, playlists, logs, library metadata, or server credentials. We do not provide music files, operate a public music library, or operate a central Phonolite account service unless we separately state that a Telolith-operated hosted service is being used.

Who Is Responsible for Data

Telolith is responsible for information we directly control, such as information submitted to the public Phonolite website, app-store listings, support channels, email, public repositories, or any service that we expressly operate.

Self-hosted Phonolite servers are controlled by their operators. If you run your own server, you control the information on that server. If you connect to a server operated by someone else, that server operator controls the server-side information, accounts, logs, playlists, library metadata, playback settings, and optional statistics stored on that server.

Accounts created on a self-hosted Phonolite server are server accounts, not Telolith accounts, unless Telolith expressly operates that server or hosted service.

Information the App Handles

When you use the Phonolite app, the app may handle:

  • Server connection information, such as the server URL you enter, your username, authentication tokens, and connection status.
  • Login credentials that you submit to your selected server. The app sends your username and password to that server to sign in. If you choose "remember me," the app stores the server URL, username, and authentication token on your device so it can restore your session.
  • Music library information received from your selected server, such as track titles, artists, albums, genres, durations, artwork, server track identifiers, and playlist data.
  • Playback and library activity, such as searches, likes, playlists, playback settings, download requests, and download status, when those actions are sent to your selected server.
  • Offline data stored on your device, including downloaded tracks, artwork, music metadata, download state, local playlist data, local likes, and a locally generated client identifier used for download coordination with your server.
  • Preferences stored on your device, such as volume, collection view mode, shuffle filters, and offline storage locations.
  • Playlist artwork that you choose from your photo library. Phonolite uses the selected image for playlist artwork and does not scan your full photo library.
  • Now playing information, such as track title, artist, album, playback position, and artwork, for operating system media controls, notifications, background audio, and supported vehicle interfaces.
  • App diagnostic information shown in the app's local log view. The current app does not send these logs to us automatically.

The current app does not request access to your precise location, contacts, microphone, or camera. The app does request network access, local network access where required by the operating system, background audio/media playback capabilities, notification/media-control capabilities, and photo library access for user-selected playlist artwork.

Information the Self-Hosted Server Handles

If you run or use a Phonolite server, that server may store and process:

  • User accounts, usernames, password hashes, roles, disabled status, authentication sessions, and session expiration times.
  • Admin-console login cookies and related session tokens used to keep administrators signed in to a self-hosted server.
  • Music library index data from configured music folders, including file paths relative to configured music roots, track metadata, album and artist metadata, genres, durations, artwork references, embedded artwork, and tag parsing errors.
  • Audio streams and downloadable media files served to authenticated apps.
  • Playlists, playlist track lists, playlist descriptions, playlist cover images, likes, playback settings, and download jobs.
  • Optional listening statistics, when enabled by the server administrator, including per-user aggregate listening time and track, artist, and genre playback summaries.
  • Server activity records and log files, including operational messages, errors, scan activity, request handling information, and, depending on configuration and log level, music metadata, relative file paths, track identifiers, and external metadata lookup results.
  • Configuration values, such as music folders, metadata folders, log folders, ports, session duration, external metadata settings, and API keys or user agents entered by the server administrator.

The server is controlled by its operator. If you connect to a server operated by someone else, that operator may be able to access server-side data, logs, account information, playlists, playback settings, library metadata, and optional statistics stored on that server.

External Metadata Services

Phonolite server administrators can enable optional external metadata lookups. When enabled, the server may send artist names, album names, configured API keys, and configured user-agent information to third-party metadata providers such as TheAudioDB or MusicBrainz. Those providers process requests under their own privacy policies and terms.

Website and Support

The public Phonolite website operated by Telolith does not include analytics scripts, advertising trackers, cookies, forms, localStorage, or sessionStorage in the current implementation. Website hosting infrastructure may still process standard server logs such as IP address, browser information, request path, and timestamp to provide and secure the website.

Self-hosted Phonolite server admin consoles use a session cookie to keep administrators signed in. That cookie is set and controlled by the server operator's deployment, not by the public Phonolite website.

The public Phonolite website does not track visitors over time across third-party websites for targeted advertising and does not change behavior in response to browser Do Not Track signals because it does not perform that tracking.

If you contact us through email, GitHub, Discord, app stores, or another support channel, we may receive the information you choose to provide, such as your name or handle, email address, issue description, logs, screenshots, device information, server configuration details, and any other information included in your message. GitHub, Discord, app stores, and other third-party support channels process your information under their own privacy policies.

If you post in public repositories, issue trackers, community spaces, or app-store reviews, the information you post may be publicly visible and may remain available according to the policies of the platform where it was posted.

How We Use Information

We use information to:

  • Provide authentication and connect the app to your selected server.
  • Browse, search, stream, download, and manage your music library.
  • Sync playlists, likes, playback settings, downloads, and library metadata between the app and server.
  • Display now playing information in system media controls, notifications, background audio, and supported vehicle interfaces.
  • Store offline music and preferences on your device.
  • Operate, secure, debug, and improve the self-hosted server and website.
  • Respond to support requests and investigate issues you report.

Sharing

We do not sell personal information or share personal information for targeted advertising, and the current app and public website do not include third-party advertising, tracking, or analytics SDKs.

Information may be shared or made available in these situations:

  • With the Phonolite server you choose to connect to, including its operator or administrator.
  • With third-party metadata providers if the server administrator enables external metadata lookups.
  • With operating system media controls, notifications, background audio services, and supported vehicle interfaces so they can display and control current playback.
  • With third-party support platforms or app stores if you contact us through those services.
  • When required to comply with law, protect rights and safety, investigate abuse, or enforce applicable terms.

Retention and Deletion

App data remains on your device until you remove it through app controls, sign out and clear saved credentials, delete downloads or local data, or uninstall the app. Some files stored in user-selected custom directories may remain until you delete them.

Server data remains on the server until the server operator deletes it, resets the server, removes users, clears logs or activity records, deletes playlists or media, disables or clears optional statistics, or removes the underlying database and files. Log files are stored locally on the server and are size-limited by the server implementation, but the server operator controls the server environment and any backups.

Support messages remain in the support channel used to send them and in our records while the request is active and for as long as reasonably needed to maintain support history, maintain security, resolve disputes, and comply with legal obligations. When support records are no longer needed, we delete or de-identify them unless continued retention is required or permitted by law.

To request deletion of information we control directly, contact us at [email protected]. For information stored on a self-hosted server, contact the operator of that server or remove the data from your own server environment.

Your Choices and Rights

You can stop using the app, disconnect from a server, sign out, clear saved credentials, delete local downloads or local data where app controls allow it, and uninstall the app. Server-side account deletion, playlist deletion, log deletion, statistics deletion, and library metadata deletion must be handled by the operator of the server where that information is stored.

Depending on where you live, you may have rights to request access, correction, deletion, export, restriction, or objection for personal information we control. These rights may also include the right to know what categories of personal information we process, withdraw consent where processing is based on consent, appeal a decision where applicable, or complain to a privacy regulator. To exercise rights for information controlled by Telolith, contact us at [email protected]. We may need to verify your request and may retain information where required or permitted by law.

Where law requires a legal basis for processing, we process information to provide requested services, operate and secure Phonolite, respond to support requests, comply with legal obligations, protect legitimate interests, or with your consent where required.

We do not use personal information for automated decisions that produce legal or similarly significant effects about you.

Security

Phonolite uses authentication tokens and server-side sessions to control access to protected server features. Because Phonolite is self-hosted, the security of your deployment depends on how your server, network, device, backups, and remote access are configured. Use trusted networks, strong passwords, current software, and HTTPS or another secure transport when exposing a server beyond a local network.

No method of storage or transmission is completely secure. We cannot guarantee that information will be secure in all circumstances.

Children

Phonolite is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us at [email protected].

International Transfers

Your information may be stored and processed where your device, your selected server, your website host, support providers, app stores, or optional metadata providers operate. Those locations may be outside your state, province, or country.

Changes

We may update this Privacy Policy from time to time. The updated version will be posted with a new "Last updated" date. If changes materially affect how we handle information we directly control, we will provide additional notice where required by law.

Contact

[email protected]

Copyright © 2026 Telolith L.L.C.

License AGPL-3.0-or-later.

Privacy Terms Support GitHub