Privacy Policy

Last updated: 3 August 2026 · Applies to the dodast app and this website

The short version:

1. Who is responsible for dodast

dodast is developed and provided by Mohammad Khakpaki, an individual independent developer — not a company. For everything in this policy, I am the person responsible for your data, and the person you can write to:

Email: mohamad.khakpaki@gmail.com

2. Data that stays on your device

dodast is local-first. The following is stored in a private database and cache on your device, and nowhere else:

This data is excluded from Android's cloud backup, is never uploaded anywhere, and is deleted when you clear the app's storage or uninstall the app. dodast never deletes or moves your music or video files. The one write it can perform is the tag editor (a song's Details → Edit tags): when you save, your edits are written into that file's own tags — on Android 10 and newer only after the system's per-file consent dialog — and nothing is ever written without you asking. The one thing that does travel between devices — the currently playing track during a listening session — goes only to devices you invite, and is described in section 4.

3. Artwork lookups over the internet

When a file has no embedded artwork, dodast looks the artwork up online during and after library scans. Three services are contacted, and what is sent to them is metadata from your own files' tags — never the files themselves:

Like any internet request, these lookups necessarily expose your IP address and standard HTTP metadata (such as the app's user-agent string) to the service being contacted. dodast sends no identifier of you or your device beyond that — there is no account and no tracking ID in these requests. Results (including "nothing found") are cached on your device so lookups are not repeated unnecessarily; misses are retried on later scans.

Each of these services processes requests under its own privacy policy, available on its website.

4. Listening sessions on your local network

dodast can keep playback in sync across devices on the same network. When you host or join a session:

None of this traffic is routed through the internet or any server of mine — there is no such server. It stays on your local network, which also means it is only as private as that network: on a shared or public Wi-Fi, other people on the same network could observe session traffic (including the transferred audio). Leaving a session (or closing the app) stops all of it.

5. QR code scanning and in-app review (Google Play services)

Joining a session by QR code uses Google's code scanner, which runs inside Google Play services on your device — this is why dodast itself needs no camera permission. Scanning is processed on the device, and dodast receives only the decoded text of the code. Google Play services' own handling of data is governed by Google's Privacy Policy.

dodast may also occasionally invite you to rate it using Google Play's in-app review dialog. The dialog is shown and handled entirely by Google Play: dodast sends it no data about you, cannot see whether the dialog appeared, and never learns what (or whether) you answered — any rating you submit goes to Google Play under Google's Privacy Policy. dodast only keeps a local, on-device note of when it last asked, so it does not ask often.

6. Firebase services (Google)

dodast uses the following Firebase services, provided by Google LLC, starting from the first release that ships with them. If you are running an earlier build, none of this applies to it yet — and if a future release adds or removes a Firebase service, this policy will be updated at the same time.

This data is processed by Google on Google's infrastructure, which may be located outside your country. Details of what Firebase collects and for how long it is kept: Privacy and Security in Firebase and the Google Privacy Policy.

Diagnostics exist to make the app better, not to profile you. Analytics events are also used, in aggregate, to measure advertising campaigns for the app itself (for example, how many installs from a campaign go on to use a feature) — they are not used to target you with third-party advertising and are never sold. In the European Economic Area, the United Kingdom, and Switzerland, the consent dialog described in section 7 also governs analytics storage: declining all data processing switches analytics identifiers off, leaving only aggregate or modeled data. Crash reporting remains active in all cases — it exists to keep the app stable and secure, not to advertise.

7. Advertising (Google AdMob)

The free version of dodast shows ads, starting from the first release that ships them — if you are running an earlier build, it shows no ads yet. Ads are served by Google AdMob (Google LLC) and are what keep the app free. One boundary matters most here: advertisers never see your music, videos, playlists, or anything else about your library. What the ad system receives is the standard ad-serving data below:

Consent comes first where the law requires it. In the European Economic Area, the United Kingdom, and Switzerland, dodast shows a consent dialog (Google's User Messaging Platform) before any ad loads: you choose how your data may be used for advertising. If you decline personalization only, ads are non-personalized — they rely on context rather than a profile of you — and all features remain available. If you decline all advertising-related data processing, no ads can be served to you; in that case, multi-device listening sessions — which are funded by advertising — are available only if you subsequently grant consent or purchase the optional ad-free upgrade (section 8). All other features remain available free of charge regardless of your decision. You can review or change your consent decision at any time from the app's settings. On iOS, Apple's App Tracking Transparency prompt additionally controls the advertising identifier: decline it and ads are served without your IDFA.

You can also reset or delete your advertising ID whenever you like in your device's settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking).

Install and campaign measurement. When dodast itself is advertised (for example through Google Ads or Apple Search Ads), attribution is used to understand which campaigns lead to installs and in-app activity: on Android, Google Analytics for Firebase attributes installs using the Google Play install referrer and may share conversion events with Google Ads; on iOS, attribution uses Apple's privacy-preserving SKAdNetwork (aggregate reports, no user-level identifiers) and Apple Search Ads attribution data processed by Adapty (section 8). These signals honor the consent choices described above — where consent is declined, they are disabled or limited to aggregate, non-identifying data.

Google processes this data on its own infrastructure, which may be outside your country, under the Google Privacy Policy; how Google uses data from apps that use its advertising services is described at policies.google.com/technologies/partner-sites. Buying premium (section 8) removes ads: while your purchase is active, dodast shows no ads.

8. In-app purchases (Adapty)

dodast is free to use. It offers optional in-app purchases — a premium (a weekly or yearly subscription, or a one-time lifetime unlock) that removes ads and unlocks extra features. Buying anything is always your choice. Purchases work like this:

9. App permissions and why

Permission (Android)Why dodast asks for it
Music & audio
(on Android 12 and older: read storage; on Android 9 and older, tag edits also use write storage)
Scanning and playing the music files on your device. The app never deletes files; the only write is a tag edit you save, and on Android 10 and newer each file's edit goes through the system's own consent dialog.
Photos & videos
(READ_MEDIA_VIDEO on Android 13+; read storage on older versions)
Scanning and playing the video files on your device, and generating thumbnails locally. Requested separately from the music permission and only when you open the Videos tab. The app never deletes your videos.
Notifications Showing the playback notification with play/pause/skip controls.
Internet, network & Wi-Fi state Artwork lookups, ads (Google AdMob), purchase validation, Firebase diagnostics, and device-to-device session sync on your local network.
Advertising ID
(AD_ID on Android 13+)
Lets Google AdMob serve and measure the ads described in section 7. The ID is resettable and deletable by you at any time in your device's privacy settings.
Foreground service (media playback), wake lock Keeping music playing reliably with the screen off or the app in the background. Granted automatically; listed for transparency.

dodast requests no location, no contacts, no microphone, and no camera permission (QR scanning happens inside Google Play services' own scanner, as described above).

10. What dodast never does

11. Data retention and deletion

12. This website

This site is a set of static pages hosted on GitHub Pages (GitHub, Inc.). It sets no cookies and runs no analytics or trackers of mine. As with any web host, GitHub may log standard technical data such as your IP address when serving the pages — see the GitHub Privacy Statement.

13. Children

dodast is not directed at children under 13 (or the equivalent minimum age in your country), and I do not knowingly collect personal data from children. The ads dodast shows are likewise not directed at children, and its ad requests are not flagged for child-directed treatment. If you believe a child has provided personal data through the app, contact me and I will delete it.

14. Your rights

Depending on where you live (for example under the GDPR or UK GDPR), you may have rights to access, correct, delete, or object to the processing of personal data concerning you, and to lodge a complaint with your local data-protection authority. Since dodast keeps almost everything on your device, most of these rights are literally in your hands — but for anything involving the services above, or any question at all, email me and I will help: mohamad.khakpaki@gmail.com.

15. Changes to this policy

When the app gains or loses a feature, library, or service that touches your data, this policy is updated to match, with a new "Last updated" date at the top. Material changes will also be called out in the app's release notes.

16. Contact

Mohammad Khakpaki · mohamad.khakpaki@gmail.com