Privacy Policy
Last updated: 3 August 2026 · Applies to the dodast app and this website
The short version:
- Your music and library are never uploaded — dodast has no server and no cloud. The app never deletes your files; the only change it can make is a tag edit you save yourself, confirmed per file with Android's own permission prompt.
- No accounts, and your data is never sold. The free app is supported by ads (Google AdMob); an optional premium removes ads and unlocks extra features. Both are described below, together with your consent choices. Advertisers never see your library or your files.
- The internet is used for a few bounded things: artwork lookups you can see, ads and purchase validation, and crash/usage diagnostics (Google Firebase) — each described below.
- Listening sessions sync directly between your devices on your local network — no server in the middle. That includes the music: the host device sends the current track straight to the devices that joined.
1. Who is responsible for dodast
dodast is developed and provided by Mohammad Khakpaki, an individual independent developer — not a company. For everything in this policy, I am the person responsible for your data, and the person you can write to:
Email: mohamad.khakpaki@gmail.com
2. Data that stays on your device
dodast is local-first. The following is stored in a private database and cache on your device, and nowhere else:
- Your library index — file locations and the tags read from your audio files (titles, artists, albums, durations, dates), plus file details for your videos (title, duration, resolution, size).
- Playlists you create, which can mix audio and video.
- Playback state — your queue, position, and settings, so the app can resume where you left off.
- Artwork and thumbnail cache — embedded art extracted from your audio files, video thumbnails generated locally from your video files, and images downloaded during artwork lookups.
This data is excluded from Android's cloud backup, is never uploaded anywhere, and is deleted when you clear the app's storage or uninstall the app. dodast never deletes or moves your music or video files. The one write it can perform is the tag editor (a song's Details → Edit tags): when you save, your edits are written into that file's own tags — on Android 10 and newer only after the system's per-file consent dialog — and nothing is ever written without you asking. The one thing that does travel between devices — the currently playing track during a listening session — goes only to devices you invite, and is described in section 4.
3. Artwork lookups over the internet
When a file has no embedded artwork, dodast looks the artwork up online during and after library scans. Three services are contacted, and what is sent to them is metadata from your own files' tags — never the files themselves:
- MusicBrainz — receives artist and album names (and related release details) to find standard music identifiers.
- Cover Art Archive (a joint project of MusicBrainz and the Internet Archive) — receives those identifiers and returns album covers.
- fanart.tv — receives MusicBrainz artist identifiers, together with the app's API key, and returns artist images.
Like any internet request, these lookups necessarily expose your IP address and standard HTTP metadata (such as the app's user-agent string) to the service being contacted. dodast sends no identifier of you or your device beyond that — there is no account and no tracking ID in these requests. Results (including "nothing found") are cached on your device so lookups are not repeated unnecessarily; misses are retried on later scans.
Each of these services processes requests under its own privacy policy, available on its website.
4. Listening sessions on your local network
dodast can keep playback in sync across devices on the same network. When you host or join a session:
- Your device advertises the session on your local network (via mDNS/Bonjour-style discovery) so other devices can find it. The advertisement includes a device/session name.
- If you show a QR code to let someone join, that code contains local connection details (such as your device's local network address). It is generated on your device.
- While in a session, devices exchange now-playing metadata (track titles, artists, timing) and playback commands directly with each other over your Wi-Fi.
- The audio itself travels device-to-device. To keep every device in perfect sync, the host sends the current track's audio directly to each joined device over your network. If the current item is a video, only its audio track is extracted and sent — the video image itself never leaves the host. The receiving device uses this only to play the session: the audio is prepared in memory for playback, is not added to that device's library, and no lasting copy is kept.
None of this traffic is routed through the internet or any server of mine — there is no such server. It stays on your local network, which also means it is only as private as that network: on a shared or public Wi-Fi, other people on the same network could observe session traffic (including the transferred audio). Leaving a session (or closing the app) stops all of it.
5. QR code scanning and in-app review (Google Play services)
Joining a session by QR code uses Google's code scanner, which runs inside Google Play services on your device — this is why dodast itself needs no camera permission. Scanning is processed on the device, and dodast receives only the decoded text of the code. Google Play services' own handling of data is governed by Google's Privacy Policy.
dodast may also occasionally invite you to rate it using Google Play's in-app review dialog. The dialog is shown and handled entirely by Google Play: dodast sends it no data about you, cannot see whether the dialog appeared, and never learns what (or whether) you answered — any rating you submit goes to Google Play under Google's Privacy Policy. dodast only keeps a local, on-device note of when it last asked, so it does not ask often.
6. Firebase services (Google)
dodast uses the following Firebase services, provided by Google LLC, starting from the first release that ships with them. If you are running an earlier build, none of this applies to it yet — and if a future release adds or removes a Firebase service, this policy will be updated at the same time.
- Crashlytics — when the app crashes, a report is sent containing the stack trace, device model and OS version, app version, state at the time of the crash, and a Crashlytics-generated installation identifier. Purpose: finding and fixing bugs.
- Google Analytics for Firebase — anonymous-by-design usage events (screens viewed, features used), an app-instance identifier, device and app metadata, and an approximate location derived from IP address. Purpose: understanding which features matter so development time goes to the right places.
- Firebase Performance Monitoring — automatic performance traces such as app start-up time, screen rendering, and network-request timing (including the addresses dodast requests, their response sizes, and whether they succeed), together with your device model, OS version, app version, an approximate location derived from IP address, and a Firebase installation identifier. Purpose: finding slow screens, dropped frames, and failing network calls so they can be fixed.
- Firebase Cloud Messaging — a push registration token for the app installation, used only to deliver notifications to the app.
- Firebase Remote Config — fetches configuration values (for example, feature flags) using the app's Firebase installation identifier.
This data is processed by Google on Google's infrastructure, which may be located outside your country. Details of what Firebase collects and for how long it is kept: Privacy and Security in Firebase and the Google Privacy Policy.
Diagnostics exist to make the app better, not to profile you. Analytics events are also used, in aggregate, to measure advertising campaigns for the app itself (for example, how many installs from a campaign go on to use a feature) — they are not used to target you with third-party advertising and are never sold. In the European Economic Area, the United Kingdom, and Switzerland, the consent dialog described in section 7 also governs analytics storage: declining all data processing switches analytics identifiers off, leaving only aggregate or modeled data. Crash reporting remains active in all cases — it exists to keep the app stable and secure, not to advertise.
7. Advertising (Google AdMob)
The free version of dodast shows ads, starting from the first release that ships them — if you are running an earlier build, it shows no ads yet. Ads are served by Google AdMob (Google LLC) and are what keep the app free. One boundary matters most here: advertisers never see your music, videos, playlists, or anything else about your library. What the ad system receives is the standard ad-serving data below:
- Advertising identifier — your device's resettable advertising ID (on Android the Google advertising ID; on iOS the IDFA, and only if you allow tracking in Apple's App Tracking Transparency prompt).
- IP address and device metadata — device model, OS version, screen size, app identifier and version, and an approximate location derived from the IP address.
- Ad interaction data — which ads were served, viewed, and tapped. Used for ad delivery, measurement, frequency capping, and fraud prevention; with your consent, also for ad personalization.
Consent comes first where the law requires it. In the European Economic Area, the United Kingdom, and Switzerland, dodast shows a consent dialog (Google's User Messaging Platform) before any ad loads: you choose how your data may be used for advertising. If you decline personalization only, ads are non-personalized — they rely on context rather than a profile of you — and all features remain available. If you decline all advertising-related data processing, no ads can be served to you; in that case, multi-device listening sessions — which are funded by advertising — are available only if you subsequently grant consent or purchase the optional ad-free upgrade (section 8). All other features remain available free of charge regardless of your decision. You can review or change your consent decision at any time from the app's settings. On iOS, Apple's App Tracking Transparency prompt additionally controls the advertising identifier: decline it and ads are served without your IDFA.
You can also reset or delete your advertising ID whenever you like in your device's settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking).
Install and campaign measurement. When dodast itself is advertised (for example through Google Ads or Apple Search Ads), attribution is used to understand which campaigns lead to installs and in-app activity: on Android, Google Analytics for Firebase attributes installs using the Google Play install referrer and may share conversion events with Google Ads; on iOS, attribution uses Apple's privacy-preserving SKAdNetwork (aggregate reports, no user-level identifiers) and Apple Search Ads attribution data processed by Adapty (section 8). These signals honor the consent choices described above — where consent is declined, they are disabled or limited to aggregate, non-identifying data.
Google processes this data on its own infrastructure, which may be outside your country, under the Google Privacy Policy; how Google uses data from apps that use its advertising services is described at policies.google.com/technologies/partner-sites. Buying premium (section 8) removes ads: while your purchase is active, dodast shows no ads.
8. In-app purchases (Adapty)
dodast is free to use. It offers optional in-app purchases — a premium (a weekly or yearly subscription, or a one-time lifetime unlock) that removes ads and unlocks extra features. Buying anything is always your choice. Purchases work like this:
- Payment is handled entirely by the store you installed from. On Android your payment method (card, balance, and so on) is processed by Google Play under the Google Privacy Policy; on iOS, by Apple's App Store under Apple's Privacy Policy. dodast and Adapty never see or store your card or payment details.
- To verify purchases and unlock or restore what you have bought across your devices, dodast uses Adapty (Adapty Tech Inc.). Adapty receives your purchase history (which products you bought and their purchase, renewal, or expiry state), the store purchase token/receipt used to check the purchase, an Adapty profile identifier generated for the installation (not your name or email), and standard device and app metadata (including an approximate location derived from IP address). Purpose: validating purchases, unlocking and restoring your entitlements, managing any subscriptions, and preventing fraud.
- Adapty processes this data on its own infrastructure, which may be outside your country, under the Adapty Privacy Policy. It is used to run purchases — not to serve you ads — and is never sold. There is still no dodast account: the identifier ties to your purchases, not to your identity.
9. App permissions and why
| Permission (Android) | Why dodast asks for it |
|---|---|
| Music & audio (on Android 12 and older: read storage; on Android 9 and older, tag edits also use write storage) |
Scanning and playing the music files on your device. The app never deletes files; the only write is a tag edit you save, and on Android 10 and newer each file's edit goes through the system's own consent dialog. |
| Photos & videos (READ_MEDIA_VIDEO on Android 13+; read storage on older versions) |
Scanning and playing the video files on your device, and generating thumbnails locally. Requested separately from the music permission and only when you open the Videos tab. The app never deletes your videos. |
| Notifications | Showing the playback notification with play/pause/skip controls. |
| Internet, network & Wi-Fi state | Artwork lookups, ads (Google AdMob), purchase validation, Firebase diagnostics, and device-to-device session sync on your local network. |
| Advertising ID (AD_ID on Android 13+) |
Lets Google AdMob serve and measure the ads described in section 7. The ID is resettable and deletable by you at any time in your device's privacy settings. |
| Foreground service (media playback), wake lock | Keeping music playing reliably with the screen off or the app in the background. Granted automatically; listed for transparency. |
dodast requests no location, no contacts, no microphone, and no camera permission (QR scanning happens inside Google Play services' own scanner, as described above).
10. What dodast never does
- Never uploads your music, videos, or your library index to the internet — the only thing that ever leaves your device during a listening session is audio, sent directly to devices you invite, on your own network.
- Never deletes your files, and never touches them behind your back — the only write dodast can perform is a tag edit you explicitly save, one file at a time.
- Never gives advertisers your library, playlists, files, or listening history — ads live in their own box (section 7) and receive only the ad-serving data described there.
- Never sells your data. Beyond the ad serving described in section 7, nothing is shared for advertising or marketing.
- Never requires an account or collects your name, email, or contacts.
11. Data retention and deletion
- On-device data (library, playlists, playback state, artwork cache) exists only on your device. Clear the app's storage or uninstall the app and it is gone.
- Firebase data is retained by Google according to the schedules described in Firebase's privacy documentation (crash reports and analytics events are kept for limited periods, then deleted or aggregated).
- Advertising data is retained by Google under Google's advertising data policies. The advertising ID it keys on is yours: reset or delete it at any time in your device's privacy settings.
- Purchase data (once in-app purchases ship) is kept by the store (Google Play or the App Store) and by Adapty for as long as needed to provide, restore, and account for your purchases, and for as long as tax, accounting, and consumer-protection law require.
- If you would like the diagnostics, advertising, or purchase data associated with your device deleted, email me and I will handle the request against the Firebase, AdMob, and Adapty tools available to me.
12. This website
This site is a set of static pages hosted on GitHub Pages (GitHub, Inc.). It sets no cookies and runs no analytics or trackers of mine. As with any web host, GitHub may log standard technical data such as your IP address when serving the pages — see the GitHub Privacy Statement.
13. Children
dodast is not directed at children under 13 (or the equivalent minimum age in your country), and I do not knowingly collect personal data from children. The ads dodast shows are likewise not directed at children, and its ad requests are not flagged for child-directed treatment. If you believe a child has provided personal data through the app, contact me and I will delete it.
14. Your rights
Depending on where you live (for example under the GDPR or UK GDPR), you may have rights to access, correct, delete, or object to the processing of personal data concerning you, and to lodge a complaint with your local data-protection authority. Since dodast keeps almost everything on your device, most of these rights are literally in your hands — but for anything involving the services above, or any question at all, email me and I will help: mohamad.khakpaki@gmail.com.
15. Changes to this policy
When the app gains or loses a feature, library, or service that touches your data, this policy is updated to match, with a new "Last updated" date at the top. Material changes will also be called out in the app's release notes.
16. Contact
Mohammad Khakpaki · mohamad.khakpaki@gmail.com