Section 01
Introduction
MusicCloud ("the App") is a music player available as an Android application and as a web application ("the Web App"), developed and maintained by Aquila Innovations. We are committed to protecting your privacy and being fully transparent about how our services work.
This Privacy Policy describes our practices regarding data collection, how the App and Web App handle your information, and your rights as a user. By using MusicCloud on any platform, you agree to the terms outlined in this policy.
MusicCloud is, at its core, a fully offline, privacy-first music player. We also offer an entirely optional Ad Monetization & Earnings feature that lets you choose to listen to advertiser-supplied audio ads in exchange for earnings, which can be withdrawn to a bank account or UPI ID you provide. This feature is off by default, fully within your control, and described in detail in Section 05 below.
Wherever a section below describes a feature only available on one platform (for example, wireless transfer or notifications), the same privacy principles apply to that feature on whichever platform it runs.
Core principle: If you never enable the Ad Monetization & Earnings feature, MusicCloud collects no personal information from you whatsoever. Any additional data collection described in this policy only applies if you actively choose to opt in to that feature.
Section 02
Information We Collect (and Don't)
By default โ using MusicCloud in Guest Mode with monetization off โ we never collect:
- Personal identifiers โ name, email, phone number, date of birth
- Device identifiers โ IMEI, advertising ID, device fingerprints
- Location data โ GPS, IP-based location, or network location
- Usage analytics โ what songs you play, how long you listen, your listening habits
- Crash reports โ crash logs are not transmitted to our servers
- Music file content โ your audio files, metadata, or playlists (unless you actively use the optional Friends feature to share a specific track with a specific friend โ see Section 07)
- Contact information โ the App does not access your contacts
- Camera or microphone data โ the App does not access these sensors
Only if you opt in to the Ad Monetization & Earnings feature, we additionally collect:
- Ad engagement counters โ how many advertiser ads you've listened to, so your earnings can be calculated and your self-set daily ad limit enforced
- Earnings ledger โ a running balance of money earned, tied to your account
- Payout account details โ the bank account number, IFSC code, account holder name, and/or UPI ID you provide for monthly withdrawals
- Listening-time totals โ cumulative minutes of music and ad listening used solely to determine when the optional monetization feature unlocks for you (see Section 05)
Only if you create an account and use connected-device or notification features, we additionally collect:
- Device identifiers and names โ a generated identifier and the name you choose for each phone or browser you use, so the multi-device playback feature can work (e.g. "play here instead of on my other device?")
- Push-notification tokens โ a token issued by Google (Android) or your browser (Web Push) so we can send you the optional notifications you've allowed
- Referral & promo code records โ which referral code you redeemed and which code you own, so unlock-time rewards can be applied (see Section 10)
None of this is collected unless you deliberately create an account or enable the relevant feature. See the sections below for full detail.
Section 03
Permissions Used
MusicCloud requests the following Android permissions. Here is exactly why each one is needed:
| Permission |
Why It's Needed |
Data Leaves Device? |
READ_MEDIA_AUDIO (Android 13+) |
To scan and read your audio files stored on the device |
No โ never |
READ_EXTERNAL_STORAGE (Android โค 12) |
Same as above, for older Android versions |
No โ never |
FOREGROUND_SERVICE |
To keep music playing in the background when you switch apps |
No |
FOREGROUND_SERVICE_MEDIA_PLAYBACK |
Required by Android 14+ for media playback services |
No |
FOREGROUND_SERVICE_DATA_SYNC |
Used when uploading/downloading a shared track or transferring files between your devices |
Only the specific file you chose to share/transfer |
WAKE_LOCK |
Prevents the CPU from sleeping during playback |
No |
MODIFY_AUDIO_SETTINGS |
Required for the 5-band equalizer and bass boost features |
No |
POST_NOTIFICATIONS (Android 13+) |
To show playback controls, earnings updates, and other optional notifications |
No โ you can disable at any time |
CAMERA |
Optional โ used only to scan a QR code for the wireless-transfer pairing screen. Manual code entry also works, so the app runs fine without this permission. |
No โ the camera stream is processed on-device and never transmitted |
INTERNET |
Required only if you use the optional account login feature, the wireless-transfer feature, and/or if you opt in to the Ad Monetization & Earnings feature (to fetch ad audio/thumbnails and sync your earnings) |
Only login/token data if you create an account; ad engagement and earnings/payout data if monetization is enabled; only the files you choose to transfer |
The INTERNET permission is declared in the app but is only actively used if you choose to create an account, enable Ad Monetization & Earnings, or use wireless transfer (all optional). Guest mode with monetization off โ the default โ never uses an internet connection for playback.
Section 04
Optional Account Feature
MusicCloud offers an optional account system that allows you to log in using an email address and password. This feature is entirely optional. The app is fully functional without creating an account (Guest Mode).
If you choose to create an account, the following data is collected and stored on our secure server:
- Username โ chosen by you at registration
- Email address โ used for login and account recovery only
- Password โ stored as a secure bcrypt hash (cost factor 12). We never store plain-text passwords.
Creating an account also lets you use the optional connected-device features (wireless transfer, multi-device playback, and notifications). When you do, we record a generated identifier and a name you choose for each device, and a push-notification token if you allow notifications โ described in Sections 08, 09 and 11.
What is not collected even with an account:
- Your music library, playlists, or listening history
- Your device information or identifiers
- Your location
Account data is used solely for authentication purposes. We do not sell, rent, or share account information with any third party.
If you also choose to enable the Ad Monetization & Earnings feature, an account becomes required (so your earnings and payout details can be tied to a real, identifiable user). See Section 05 for details.
Section 05
Ad Monetization & Earnings Feature
MusicCloud offers an entirely optional feature that lets you earn money by listening to advertiser-supplied audio ads while you play music. This section explains exactly how it works and what data it involves.
How it works:
- The feature is off by default. You must actively opt in from Settings to enable it.
- Ads are audio clips with an accompanying thumbnail, supplied directly to us by the advertising businesses themselves. We do not use Google AdMob, Google Ad Manager, Meta Audience Network, or any third-party ad SDK or ad exchange. We do not use programmatic ad auctions, and no ad-tech company receives your data.
- You control how frequently ads play โ you set your own daily ad count/frequency in the app's settings.
- Each ad listened to in full credits a fixed, disclosed amount to your in-app earnings balance.
- You can disable the feature at any time. Disabling it stops future ad delivery and earnings accrual; it does not erase previously earned, unpaid balances (see below).
Minimum age for this feature: Because this feature involves real monetary payouts to a bank account or UPI ID, you must be 18 years or older to enable Ad Monetization & Earnings, even though the base music player has no such restriction. We do not knowingly enable this feature for accounts we know belong to a minor.
Payouts:
- Earnings are paid out monthly to the payout account you provide.
- We currently process payouts manually โ there is no automated third-party payment gateway integrated into the app at this time. Our team reviews and initiates each payout directly to the bank account or UPI ID you've registered.
- Because payouts are manual, please allow for standard processing time each month; any minimum payout threshold or delay will be clearly disclosed in-app.
- If we later integrate an automated payment gateway or processor, we will update this policy and notify you before your payout data is shared with that processor.
This is not a rewards, loyalty-points, gambling, or chance-based program. Every ad listened to earns a fixed, disclosed amount โ there is no randomness, wagering, or lottery mechanic involved.
Section 06
Payout & Financial Data
If you opt in to Ad Monetization & Earnings and choose to withdraw your balance, we collect:
- Bank account number and IFSC code
- Account holder name
- UPI ID (as an alternative or additional payout method)
This information is used solely to process your monthly payout. It is never sold, rented, shared with advertisers, or used for any marketing purpose. Because payouts are currently handled manually by our team, this data is accessed only by authorized personnel for the purpose of initiating your transfer.
We retain payout and earnings transaction records for as long as required under applicable tax and financial record-keeping laws, even after you disable monetization or delete your account, solely to satisfy those legal obligations.
Section 07
Friends & Track Sharing Feature
MusicCloud includes an optional Friends feature that lets you share specific tracks with specific friends who also use the app. This is entirely user-initiated โ no track is ever shared automatically or without your explicit action.
How it works:
- You choose which friend(s) on the app you want to share with โ sharing is never public or broadcast to anyone outside your chosen recipient(s).
- You choose which specific track(s) to send. No other files, playlists, or library contents are shared.
- If you never use this feature, no music file of yours is ever transmitted off your device.
- The recipient friend receives only the track(s) you selected, and can play them within the app.
- Sharing requires an account and an internet connection, since the track has to be transferred to the recipient through our servers.
We do not scan, analyze, or use the content of shared tracks for any purpose other than delivering them to the friend you selected. Files are only retained on our servers as long as needed to complete delivery, after which they follow our standard retention/deletion practices.
Section 08
Wireless Transfer Feature
MusicCloud includes an optional Wireless Transfer feature that moves a music file directly between two of your own devices โ for example, from the Web App on your desktop to the Android app on your phone โ without uploading the file to our servers.
How it works:
- You start a transfer on one device and pair it with the receiving device by scanning a QR code or entering a short session code.
- Devices connect to each other directly (peer-to-peer). The file flows straight between your two devices.
- Our servers only coordinate the brief connection handshake (matching the pairing code) and never receive or store the music file itself.
- Transfer sessions expire automatically after a short time (10 minutes) if not completed.
- The feature requires an account and an internet connection only for the pairing handshake โ the file itself never touches our servers.
Because the transfer is peer-to-peer, your music file is never uploaded to or stored on our servers. The only data that passes through our servers is the short-lived pairing information used to connect your two devices.
Section 09
Multi-Device Playback & Device Takeover
With an account, MusicCloud can track which devices you are signed in on, so you can control playback across your own devices โ for instance, answering "play here instead of on my other device?" when you start listening somewhere new.
What we store:
- A generated device identifier and a name you choose for each device (e.g. "My Pixel", "Home PC")
- Which device is currently active for playback
- A push-notification token if you allow notifications, so the "continue on another device" prompt can reach you
This feature only ever links your own devices to your own account. It is never used to link or identify third parties. You can remove registered devices from your account at any time, which also stops those devices from receiving playback prompts.
Section 10
Referral & Promo Codes
MusicCloud offers optional referral codes and promo codes as a way to reward users and reduce time spent unlocking monetization. Using them is entirely voluntary.
- Referral codes: each account is assigned its own 6-digit referral code, which you may share with friends who are considering the app. When a friend enters your code, they may unlock monetization earlier and you receive an unlock-time reward.
- Promo codes: from time to time our team issues promo codes (for example, to followers or testers). Redeeming one grants the account a reward such as reduced unlock time.
- We record which code was redeemed and by whom, purely to apply the unlock-time reward and to prevent abuse (for example, each account may only redeem a referral code once, and cannot redeem its own code).
Referral and promo codes are optional, voluntary features. No code is redeemed and no reward is applied unless you actively enter a code yourself. We never share your code with third parties.
Section 11
Notifications & Messaging
MusicCloud can send notifications only if you allow them. Notifications are entirely optional and you can revoke permission at any time through your device or browser settings.
- Android push notifications: if you allow them, we use Google's Firebase Cloud Messaging to deliver notifications such as playback controls, earnings updates, and multi-device playback prompts. This requires a push token associated with your device.
- Web Push notifications: the Web App can send browser notifications for the same purposes, using your browser's built-in Web Push mechanism. You control this through your browser's site-permission settings.
- Media-session controls: playback notifications are a standard Android media feature controlled entirely by the operating system.
Notification permission is never required to use the app or the Web App. Playback controls appear in notifications only while music is actively playing.
Section 12
The Web App
MusicCloud is also available as a Web App at app.musiccloud.in/webapp. The Web App provides the same offline-first music player experience in your browser and works under the same privacy principles described in this policy.
How the Web App stores data:
- Playlists, favourites, settings, and the currently playing queue are stored in your browser (using the browser's IndexedDB storage) โ exactly like on Android, this data stays on your device.
- The Web App can read audio files only from folders you explicitly select using the browser's file-picker dialog โ it never has unrestricted access to your device's storage.
- If you sign in, your account and (if enabled) earnings data sync with our server over HTTPS, the same as the Android app.
- If you use the optional Wireless Transfer feature, files move peer-to-peer between your browser and your phone as described in Section 08.
The Web App requires no installation. Data stored in the browser is cleared when you clear your browser data or remove the site's storage.
Section 13
Local Data Storage
The following data is stored exclusively on your device โ in Android's SharedPreferences and local file storage, or in your browser's IndexedDB when using the Web App:
- Playlists you create within the app
- Your favourited songs (stored as a list of media IDs)
- Equalizer settings and presets
- Shuffle and repeat mode preferences
- Sort and filter preferences
- The last played song position (for resuming playback)
None of this data is ever transmitted off your device. Uninstalling the app (or clearing the site's data in your browser) will permanently delete all locally stored data.
Section 14
Third-Party Services
MusicCloud does not integrate with any third-party advertising networks, ad exchanges, or programmatic ad SDKs. The app does not include:
- Google AdMob, Google Ad Manager, or any Google advertising SDK
- Google Analytics, Firebase Analytics, or any usage tracking SDK
- Crashlytics or any crash reporting service
- Facebook Audience Network, Meta SDK, or any social media ad tracking
- Any third-party ad mediation or ad-tech SDK
Ads shown as part of the optional Ad Monetization & Earnings feature are supplied directly by the advertising businesses we partner with, delivered from our own servers as simple audio + thumbnail assets โ not through any ad exchange or ad network. User earnings payouts are currently processed manually by our team.
Limited third-party services used:
- Firebase Cloud Messaging (Google) โ used only to deliver push notifications to Android devices, and only if you have allowed notifications. No listening data or music content is sent through it.
- PhonePe Payment Gateway โ used only in the Business/Advertiser portal for businesses to top up their advertising wallet (see Section 16). Advertiser payment details are processed directly with PhonePe.
The libraries used in the app (ExoPlayer, Retrofit, Glide, CameraX, ML Kit QR scanning, etc.) are used solely for local device functionality and, aside from the optional account, monetization, notification, and transfer features described in this policy, do not transmit data to external servers.
Section 15
Business & Advertiser Portal
MusicCloud offers a separate portal for businesses and advertisers who wish to run audio ads in front of listeners who have opted in to the Ad Monetization & Earnings feature.
What we collect from advertisers (via the portal registration form):
- Company name and contact person name
- Email address โ used as the login and for account correspondence
- Phone number
- GST number โ collected for billing and compliance with Indian tax regulations
- Password โ stored as a secure bcrypt hash
Advertisers can upload ad audio files and thumbnails through their portal dashboard, and track the impressions, delivery, and spend of their campaigns. Ad content you upload is stored on our servers and served to opted-in listeners on the platforms you select (Android and/or Web App).
Advertiser account information is used solely to run and bill advertising campaigns. We do not sell or share advertiser contact details with third parties, other than as needed to process payments (see Section 16).
Section 16
Advertising Wallet & Payment Processing
Advertisers fund their campaigns through a wallet balance in the Business Portal. Topping up the wallet is processed by PhonePe Payment Gateway (PhonePe Private Limited, an Indian UPI/payments provider).
- When you top up, we create a pending order record containing your advertiser account ID, the amount, and a unique order reference, and send you to PhonePe to complete the payment.
- PhonePe handles the actual payment and confirms the transaction to us. Your bank/UPI credentials are entered only on PhonePe's own secure pages โ we never see or store them.
- Once confirmed, the amount is credited to your advertising wallet and deducted as ads are delivered.
Payment transaction details are retained as required by applicable financial and tax regulations (see Section 18).
Section 17
Data Security
We take the security of any data we hold seriously:
- All API communication uses HTTPS/TLS encryption
- Passwords are hashed with bcrypt (cost factor 12) โ irreversible
- Authentication tokens use JWT (HS256) with a 30-day expiry
- Logged-out tokens are blacklisted server-side immediately
- Database queries use prepared statements to prevent SQL injection
- Bank account, IFSC, and UPI details are encrypted at rest and only accessible to a limited number of authorized personnel who process payouts
- Access to earnings and payout records is logged and restricted on a need-to-know basis
- Music files are only ever uploaded to our servers when you actively choose to share a track via the Friends feature โ never automatically or in the background
Section 18
Data Retention
We keep your data only as long as necessary:
- Account credentials โ kept until you delete your account
- Ad engagement counters & earnings balance โ kept while monetization is enabled and until any owed balance is fully paid out
- Payout/financial records โ retained for the period required by applicable tax and financial regulations, even after account deletion, solely to meet those legal obligations
- Device records โ kept until you remove the device from your account
- Referral/promo redemption records โ kept to apply unlock-time rewards and prevent abuse; removed with your account
- Transfer session handshakes โ deleted automatically within a short time (10 minutes) if not completed
- Advertiser accounts, campaign content, and wallet records โ kept while the advertiser account is active and for the period required by applicable tax and financial regulations after closure
- Local playlists, favourites, and settings โ retained only on your device until you clear app data, clear the site's browser data, or uninstall
Section 19
Children's Privacy & Age Requirements
MusicCloud does not knowingly collect any personal information from children under the age of 13 for the base music player. The app does not have features designed to appeal to children in ways that would prompt data collection.
The Ad Monetization & Earnings feature is restricted to users 18 years of age or older, because it involves real monetary payouts to a bank account or UPI ID. We do not knowingly permit anyone under 18 to enable this feature. If you believe a minor has accessed this feature or provided personal or financial information, please contact us immediately at apps@aquilainnovations.in and we will promptly disable the feature and delete the relevant information.
Section 20
Your Rights
If you have created an optional account, you have the following rights:
- Access โ request a copy of your account, ad engagement, and earnings data
- Correction โ update your username or payout details via the app's profile screen
- Deletion โ request permanent deletion of your account and all associated server-side data by emailing us, subject to the financial record-keeping retention described in Section 18
- Portability โ request your data in a machine-readable format
- Opt-out โ disable Ad Monetization & Earnings at any time from Settings, with no need to delete your account
- Device management โ remove any registered device from your account at any time
- Notification control โ revoke notification permission at any time from your device or browser settings
Advertisers on the Business Portal have the same rights over their advertiser account data and can request access, correction, deletion, or portability by emailing us.
Guest mode users with monetization disabled have no server-side data. All data is local and can be cleared by uninstalling the app or clearing the site's browser data.
Section 21
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes โ particularly to what data we collect or how we use it โ we will update the "Last Updated" date at the top of this document and notify users via an in-app notice, the Web App, or update release notes on Google Play.
Continued use of the app or Web App after any changes constitutes acceptance of the revised policy.
Section 22
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please get in touch: