Privacy Policy
Sealed — 16 September MMXXVI
The Pact, in Brief
What the Engine knows of the listener stays with the listener. There are no accounts, no telemetry, no analytics, no advertisements, no third-party SDKs, no advertising identifiers, no fingerprinting of the listener or their device. The Engine runs upon the listener's device and reports to nothing beyond it — save for five listener-invoked rites, described below in full. Each conveys only what the listener has commanded, and only to the service or server the listener has named; none renders to Vox Machina any record of who the listener is.
The Engine does keep a record of the listener's listening — the dates, the durations, the returns — for the sake of the Auguries, the shelves it composes from the listener's own habit. That record is the listener's alone, and it does not depart the device.
What the Engine Reads
The Engine reads the audio files within the listener's reliquary, drawn from the directories the listener has granted it access to. It conducts its census across what it finds — titles, artists, albums, durations, formats, sample rates, bit depths — and inscribes the truth of measure and the truth of identity into a library kept locally upon the device. None of it travels onward.
- The library: kept locally; never transmitted.
- The listening spine: kept locally; the arithmetic that composes the Auguries is drawn from it. Never transmitted.
- DAC communion: handled by Android's USB subsystem. Vendor and product identifiers, sample rates, and similar descriptor fields are recorded only on the listener's device, and travel onward only through the listener-invoked Witnessing rite described below.
What the Engine Writes
The Engine never alters the audio itself — it does not re-encode, does not touch the samples, does not delete files. Absent the listener's explicit command, it writes nothing at all. Should the listener enable the Rite of Enrichment described below, the Engine may write corrected metadata and cover art back into the listener's own files — those fields alone, and only then. Beyond that single, invited exception, the reliquary remains the listener's jurisdiction entire, in all of its choices and its accidents.
The Witnessing
If, by their own hand, the listener invokes the Witnessing rite from a connected DAC's diagnostics surface, the application transmits to the Forge — and to nothing else — the following, and no more:
- the USB descriptor's model string (e.g. Snowsky Tiny A);
- the USB Vendor and Product identifiers;
- a one-time ceremonial UUID identifying the act of witnessing — no listener, no device, is named;
- the alt-setting descriptors the DAC itself publishes: interface, sample format, sample rates, bit depth, channel count, USB Audio Class version, and the like.
The Forge does not record the listener's IP address, does not record the listener's User-Agent, and mints no identifier that could bind multiple witnesses to a single listener. Two listeners offering the same DAC produce indistinguishable transmissions. The witnessed descriptor enters, anonymously, the public Concordance at voxmachina.audio/dossiers/.
The rite is silent by default; only a deliberate tap invokes it.
The Outward Cadence
The listener may, by their own hand, dispatch the cadence of their listening to Last.fm or to ListenBrainz, configured under Settings → Scrobbling with credentials the listener supplies. The Engine dispatches only because the listener has so commanded. The fields conveyed are:
- track title and artist;
- album, album artist, and track number — when present in the track's tags;
- duration;
- the timestamp at which playback began;
- the MusicBrainz recording identifier — when present in the track's tags;
- the listener's own credentials for the configured service, used to associate the listen with that listener's own account.
Vox Machina receives none of this. All data handling by Last.fm and ListenBrainz is governed by their respective privacy policies. The Outward Cadence is silent by default. The listener may revoke it at any moment from the same surface; once revoked, no further dispatch occurs.
The Rite of Enrichment
Should the listener, by their own hand, enable Metadata & Artwork Enrichment, the Engine computes an acoustic fingerprint of a recording's audio — a compact hash of the sound itself, never the audio file, and never the listener — and offers it outward to name the recording and to gather what metadata and cover art the archives hold. The fingerprint names a song, not a person; it carries no identifier of the listener or their device. Conveyed, and only these:
- a Chromaprint acoustic fingerprint and the track's duration, borne to the AcoustID lookup service to name the recording;
- a MusicBrainz recording identifier, once resolved, borne to MusicBrainz for release and artist metadata;
- a MusicBrainz release identifier, once resolved, borne to the Cover Art Archive for album artwork.
The rite is sealed twice before it speaks: one consent to compute the fingerprint upon the device, a second and separate consent to permit the lookups. Both are dark by default. What the archives return — corrected tags and cover art — the Engine may write back into the listener's own files, and into no others. Neither transmission bears any identifier binding it to the listener. AcoustID, MusicBrainz, and the Cover Art Archive (served by the Internet Archive) each govern their own handling under their own terms. Vox Machina receives none of it.
A further leg of the same rite may draw upon Discogs: where the archives above are questioned by the fingerprint of the sound, this one is questioned by the name of the release. Should the listener enable it — a consent of its own, dark by default and apart from the fingerprint lookups — the Engine bears a recording's artist and album, drawn from its own tags, to the Discogs database to match a release and gather its metadata and cover art. It is text about the music — never the fingerprint, and never the listener. The query rides the Forge's own Discogs application key, not the listener's; what returns, the Engine may write back into the listener's own files as above. Discogs governs its own handling under its own terms. Vox Machina receives none of it.
The Offered Signature
Should the listener go further and enable AcoustID Contribution — a rite apart from the lookup above, and consented apart — the Engine offers fingerprints back to the AcoustID archive, under the listener's own AcoustID key, never the Forge's. Borne outward, and only these:
- the Chromaprint fingerprint and duration of each song the listener elects — the same computed for the lookup above;
- the song's title, artist, and album, when present in its tags;
- the listener's own AcoustID API key, entered by their hand and kept only upon the device, by which AcoustID attributes the offering to their account.
This is a permanent and public act, and the listener should weigh it as one. What is offered enters AcoustID's open-data releases under a Creative Commons Attribution-ShareAlike license — attributed to the listener's account, and free for any to reuse, including other software. Once given, it cannot be recalled. AcoustID weighs each offering on its own terms, and the Engine cannot promise that what is offered will be kept, or matched to any particular recording. The rite is dark by default and demands its own deliberate consent, distinct from the lookup above — for offering a fingerprint back is a materially different act than reading one. Vox Machina receives none of it.
Communion with a Named Server
The listener may, by their own hand, connect the Engine to a media server of their own choosing — a Plex, Jellyfin, or Subsonic server — configured under Settings → Servers, that the reliquary held upon that server may be browsed and played. Vox Machina operates none of these servers; each belongs to the listener, or to a party the listener trusts. The Engine communes with them as a client alone, and is not affiliated with, endorsed by, nor sponsored by Plex, Inc. or any server's makers. Unlike the anonymous rites above, this one carries the listener's own credentials to the server they have named — that it may know them as its own.
When a server is connected, the following passes between the device and that server — and, for Plex, the plex.tv account service, which Plex requires to authorize the link:
- The credentials the listener provides: a Subsonic or Jellyfin username and password, or a Plex account link and token. These are held upon the device in encrypted storage (AES-256-GCM) and borne only to the server the listener named — and, for Plex, to plex.tv — to authenticate. The Forge keeps no copy anywhere but the listener's own device.
- A connection identifier: an identifier the Engine mints for this installation — not a hardware identifier, not an advertising identifier — borne to the server, and to plex.tv, that the connection may be recognized across sessions. It names the installation, never the listener.
- The cadence of what is played from that server: what is drawn from a connected server, and when, may be reported back to that same server as its own now-playing and history, that the server's account stays current. This reaches only the listener's server — never Vox Machina.
Of the safety of the passage. The Engine prefers a secured (HTTPS) connection wherever the server offers one, and its communion with plex.tv is always secured. A listener who enrolls a server by a plain http:// address — common upon a home network — conveys these credentials in the clear across that network, by their own explicit choice; the Engine marks such a connection plainly as Plain HTTP at the moment of enrollment, that the choice is never hidden.
To sever the communion. Removing a server under Settings → Servers deletes the Engine's stored copy of that server's credentials, its connection key, and its connection record from the device in a single act. Vox Machina cannot reach into the server itself, nor into plex.tv, to unmake what those keep of the listener; that remains between the listener and the party that holds it.
What the Engine Asks of Android
- Storage / Media access: to read the reliquary.
- USB device access: to commune directly with the connected DAC.
- Bluetooth: to read the identity and negotiated codec of a connected Bluetooth audio device, that the link's fidelity may be shown. Nothing is paired, dialed, or transmitted.
- Foreground service: to keep the rite of playback active in the background, and to carry the fetches of a connected server alongside it.
- Internet: employed only for the listener-invoked rites — the Witnessing, the Outward Cadence, the Rite of Enrichment, the Offered Signature, and communion with a media server — or when the listener taps an outbound link to the Forge or to its channels.
- Local network discovery: to find media servers upon the listener's own network, the Engine casts discovery queries across the local network — the UPnP/SSDP multicast, Plex's GDM beacon, Jellyfin's broadcast probe — and gathers the replies. It does so only while the listener is upon the Servers surface, and never beyond the local network. Subsonic servers do not announce themselves, and are entered by address.
Of the Bluetooth Link
When the listener routes playback to a Bluetooth device, the Engine reads that device's identity and its negotiated codec, that the fidelity of the link may be shown to the listener. This is used to witness the connection and nothing more — it pairs nothing, dials nothing, and reads nothing of the device beyond the audio link. No Bluetooth data departs the device, and the Forge keeps none.
Of Children
The Engine is not directed to children under 13. It does not knowingly collect information from any listener — child or otherwise — because it does not collect information at all.
Of Revision
Should this pact be amended, the effective date above shall change. Material revisions are also named in the Engine's release notes upon the Play Store.
To Reach the Forge
For questions concerning this pact, address the Forge: privacy@voxmachina.audio.