Many Library Minus — Privacy Policy
Effective date: 18 September 2026
Who we are: Many Library Minus is made by Jack Davidson, an independent developer ("I", "me").
Contact: jack.davidson38@gmail.com
This policy covers the Many Library Minus app on Android, iOS, macOS, Windows and Linux, and its
command-line tool.
The short version
- The app works on your DJ library on your own device and your own USB drive. Your library is
not uploaded anywhere as part of normal use.
- There are no analytics, no advertising, no tracking, and no crash reporting that sends itself.
The app has no install id, device id or advertising id.
- There is no Many Library Minus account today. One is planned, for purchases and subscriptions
only — see Accounts, purchases and proof of ownership.
- Data leaves your device in exactly two situations, both started by you:
- you connect SoundCloud, or
- you press Send report to send me a bug report.
- I do not sell your data and I do not share it with anyone for their own purposes. The only other
companies that touch it are the infrastructure providers listed under
Service providers, who carry it on my behalf.
Bug reports
This is the one place the app can send me a meaningful amount of your data, so it is described in
full.
Nothing is sent automatically
A bug report is sent only when you press Bug report (which packs a report file on your device)
and then press Send report. If the app hits an error it may save a small interaction trace on
your device so that a later report is more useful; that file stays on your device unless you send a
report yourself.
What a bug report contains
A report is a single compressed file of at most 15 MB. It can contain:
- Your library data: the DJ library databases on the drive (Engine DJ, Serato, rekordbox and the
app's own database), as many as fit. These hold track titles, artists, albums, genres, comments
and tags, playlist and crate names, cue points, loops, beatgrids, and the file paths of your
tracks.
- Logs and sync state from the drive: the commands that were run, errors, conflicts and the
record of what a sync changed. These include file paths and "Artist - Title" labels.
- The beginning of an audio file, only when that file caused an error: up to the first 2 MB,
which includes the file's embedded tags and artwork. Whole tracks are never included.
- File and folder paths, which on a computer often include your operating-system user name.
- Device and app information: app version, operating system, browser engine (user agent),
screen size, time zone offset, CPU and battery-temperature readings, the drive's name and an
app-generated drive id, and on Android the app's own system log.
- A trace of recent activity in the app: which screens and buttons were used, including short
snippets of the text on a pressed button or row (which can be a track title).
- Your SoundCloud username, if SoundCloud is connected.
- Your email address and a note, if you choose to type them into the Send report form. The email
is used only to reply to you.
A report never contains your SoundCloud access or refresh tokens, or any password. The app
redacts URLs and credentials from its own activity trace before it is packed.
How I use bug reports
- To find and fix the problem you reported.
- To write automated tests so the same problem does not come back. When I do this I build a
synthetic test case that reproduces the shape of the problem — for example "a track whose tag is
laid out this way". Your track names, playlists, file paths, audio, username and email are not
copied into the app's source code, its test files, or anything that is published or shipped.
- To reply to you, if you gave an email address.
I do not use bug reports for marketing, profiling, advertising, or training machine-learning models.
Who sees a bug report
Only me. Reports are not sold, published, or passed to any other person or company for their own
use. To reach me, a report travels through the two service providers described below.
How long bug reports are kept
Reports are delivered to my email inbox and are deleted within 12 months of receipt. You can
ask me to delete a report you sent at any time — see Your choices and rights.
The copy of the report on your own drive and device stays there until you delete it.
SoundCloud
Connecting SoundCloud is optional.
- You sign in on SoundCloud's own page in your browser. The app never sees your SoundCloud password.
- The app reads your SoundCloud username and account id, and, for tracks you work with, the
track's address and its audio stream. It does not read your email, likes, followers or playlists.
- Your SoundCloud sign-in tokens are stored only on your device, in the app's private storage.
They are never written to your USB drive and never sent to me.
- Streamed audio is analysed and played in memory and is not saved to disk. The track's SoundCloud
address and the analysis results (key, tempo, waveform and similar) are saved in your library.
- To complete sign-in, the app sends the one-time sign-in code (and later, the refresh token) to a
small sign-in service I run, which forwards it to SoundCloud and returns the result. That
service does not store or log the code or the tokens.
- SoundCloud receives your requests directly (including your IP address and which tracks you
stream) under SoundCloud's privacy policy.
You can disconnect SoundCloud in the app at any time, which deletes the tokens from your device, and
you can revoke the app's access in your SoundCloud account settings.
Data stored only on your device
The following never leaves your device unless you include it in a bug report: your library and any
offline copies of a drive you make in the app, app settings, SoundCloud tokens, logs, backups, and
performance timings. Removing the app (and deleting the .many-library-minus folder on a drive)
removes them.
Backups on your USB drive
Before the app changes a library on your drive it writes a backup of the affected library files to
the .many-library-minus folder on that same drive, so a change can be undone. Backups hold the
same library data as the originals. They stay on your drive, are never uploaded, and are yours to
delete. Anyone you hand the drive to can read them, exactly as they can read the library itself.
Storage permission
On Android the app asks for access to files on external storage. It uses this only to read and
write the DJ library and music files on the USB drive or folder you choose.
Server logs and IP addresses
When the app contacts my sign-in and bug-report service, the service:
- logs the request path, status, duration, app version and size — never your email, note, report
contents or tokens;
- uses your IP address (for IPv6, its /64 prefix) to limit abuse, and keeps counters keyed on it
for up to 48 hours, after which they expire automatically.
Service providers
These companies process data on my behalf, solely to run the service:
| Provider |
What it does |
What it handles |
| Cloudflare |
Hosts the sign-in and bug-report service |
Requests in transit, IP address, short-lived rate-limit counters, request logs |
| Google (Gmail) |
Delivers and stores bug reports in my inbox |
Bug report files, your note, your email address if given |
All connections are encrypted in transit (HTTPS/TLS). Reports are not end-to-end encrypted; they are
stored in my mailbox under Google's standard protections.
Accounts, purchases and proof of ownership
This section describes features that are planned but not yet available. It will be revised, with a
new effective date, before they are switched on.
Many Library Minus account. Paid features and subscriptions will use a Many Library Minus
account. The account will hold your email address (or the account identifier supplied by Google,
Apple or another sign-in provider you choose, and your email where that provider shares it), and
your purchase and subscription status. The account exists to prove that you own the app and to
restore your purchase on another device. Your library, your bug reports and your SoundCloud
connection are not stored in it.
Payments. Payments are handled by the store or payment processor you buy through — Google Play,
Apple App Store, PayPal or Stripe. I never receive or store your card or bank details. Each
processor handles your payment under its own privacy policy, and each will be added to the
Service providers table when it goes live.
Purchase records. To confirm that you own the app, I receive and store a minimal purchase
record: a purchase or order identifier or licence code, the product, the purchase date and status,
and the store it came from. I use this only to verify and restore your purchase, to provide
support, and to meet tax and accounting obligations. I keep it for as long as your account or
licence is active and afterwards only as long as the law requires. You will be able to ask for your
account to be deleted.
Children
The app is not directed at children under 13 (or the equivalent minimum age where you live), and I
do not knowingly collect their data.
Your choices and rights
- You never have to send a bug report or connect SoundCloud; everything else works without them.
- You can ask me for a copy of, a correction to, or the deletion of any bug report or purchase
record connected to you, by emailing jack.davidson38@gmail.com. I will respond within 30 days.
- I must be able to confirm a report is yours before I act on it. Write from the email address
you entered when you sent the report. If you sent a report without an email address, I usually
cannot tell whose it is: I will not send a copy of such a report to anyone, because I cannot rule
out handing one person's library to another. I can still delete it if you give me details only
the sender would know — the date and time it was sent and the report's file name (shown in the
app when the report was packed). Deleting the wrong report harms nobody; disclosing one could.
- If you are in the EEA, the UK or a similar jurisdiction: I process bug reports on the basis of
your consent (you choose to send them) and my legitimate interest in fixing the app, and purchase
records on the basis of our contract and legal obligations. You have the right to access, correct,
erase, restrict or object to processing, to data portability, and to complain to your data
protection authority.
- If you are in California: I do not sell or share personal information as those terms are defined
in the CCPA/CPRA.
Because my providers operate globally, your data may be processed outside your country.
Changes to this policy
If this policy changes, the new version will be posted at this address with a new effective date.
Material changes — in particular anything that adds a new kind of data collection — will also be
noted in the app's release notes.