Hollowpoint Collective
Addit — Privacy Policy
Effective 12 August 2026
Addit has no servers. Your music, your account details and your listening all stay on your device or inside your own cloud storage. We have no infrastructure that could receive them, and no analytics or advertising code in the app.
Addit is an iOS music player that plays audio you already keep in Google Drive, Microsoft OneDrive, or on your iPhone. This policy explains what the app touches, where it stays, and the one narrow case where something reaches us.
What stays on your device
All of the following is written only to Addit's own storage on your iPhone. None of it is transmitted to Hollowpoint Collective.
- Sign-in tokens. OAuth access and refresh tokens for the cloud accounts you connect, held in the iOS Keychain.
- Account details. The email address, display name and profile-photo URL of each connected account, so the app can show you an account switcher.
- Your library. Album and track records — names, artists, file identifiers, track ordering, artwork references.
- Cached audio and artwork. Tracks you play or mark for offline use are downloaded and cached, in a separate directory per account.
- Preferences. Accent colours, appearance mode, library layout.
Deleting the app removes all of it. Removing a single account from the in-app account switcher deletes that account's tokens and cached audio.
Your cloud storage
When you connect a Google or Microsoft account, Addit talks to that provider directly from your device. Nothing is proxied through us.
Google Drive
Addit requests the full drive scope. It needs that breadth
because albums are ordinary Drive folders that you or your collaborators own —
including folders shared with you by other people, which a narrower scope
cannot reach. The app uses this access to list folders and audio files, read and
write the small .addit-data file that stores each album's track
order, upload album artwork and audio you add, and manage sharing permissions
when you ask it to.
Addit's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the features described above. It is never sold, never transferred to third parties except as required to provide those features, never used for advertising, and never read by a human — including us — except where you have explicitly asked us to help with a problem, or where required by law.
Microsoft OneDrive
Addit uses Microsoft Graph with the permissions needed to read and write files in your OneDrive, for the same purposes described above. The same restrictions apply: no selling, no advertising, no transfer beyond what the feature itself requires.
Album chat
Addit's per-album chat is built on Google Drive's comments feature. Messages you send are stored by Google on the album's folder and are visible to anyone you have shared that folder with. They do not pass through us, and we cannot read them.
Photo library
If you choose an album cover from your photo library, Addit reads only the image you select and copies it into the album. It does not browse, index or upload anything else, and it does not request access until you ask it to pick a photo.
Bug reports — the one thing that reaches us
"Pls report bugs" in the app composes an email to us. Because Addit has no server, it hands the message to your own mail app rather than sending anything itself: you see the complete message and press send yourself, from your own email account. Nothing leaves your device unless you do that.
The message contains whatever you type, plus a single automatically appended
line with the app version and build number, your iOS version, and your device
model (for example iPhone17,1). That line is visible to you in the
composer before you send, and you can delete it.
Because you send it by email, we necessarily receive the email address you send from. Reports are used only to diagnose and fix problems, and are not added to any mailing list.
What Addit does not do
- No analytics, telemetry or crash-reporting services.
- No advertising, and no tracking across apps or websites.
- No selling or sharing of personal information.
- No accounts of our own — there is nothing to register for, and no password we could hold.
Addit uses Google's official sign-in library to authenticate with Google.
That library is governed by Google's privacy
policy. Microsoft sign-in is handled by Apple's own
ASWebAuthenticationSession talking to Microsoft, covered by Microsoft's
privacy statement.
Children
Addit is not directed at children under 13, and we do not knowingly collect information from them.
Your control
- Disconnect an account from the account switcher inside the app.
- Revoke Addit's access entirely at Google account permissions or Microsoft app permissions.
- Delete everything by deleting the app.
Changes
If this policy changes materially, the effective date above will change and the revision will be posted at this address.
Contact
Questions about this policy, or requests concerning your information: waterloo.sunset.fine@gmail.com