Scope and developer
This policy applies specifically to the Icy Lyrics Android app. Icy Lyrics is developed and maintained by Jackscurrie.
Questions or privacy requests can be sent to jack@jackscurrie.com.
Notification and playback access
Android notification-listener access is broad at the operating-system level. After you enable it, Icy Lyrics filters notification callbacks and active media sessions to Spotify. It ignores unrelated notifications and does not store or transmit their contents.
For the active Spotify session, the app reads the track title, artist, album, Spotify identifiers, duration, playback position and state, available controls, and artwork. It uses this information to identify the song, synchronize lyrics, display the player, and let you seek or control Spotify. Some current-track fields may be sent to lyric providers as described below.
Spotify connection
Connecting Spotify is optional and is not needed for local TTML, the Icy Lyrics Database, or LRCLIB. It remains available for the optional Apple Music compatibility fallback and for resolving a track whose notification lacks a Spotify ID. Icy Lyrics requests only the user-read-currently-playing permission. Spotify sign-in happens in a browser tab, so the app does not receive your Spotify password.
The app communicates with Spotify Accounts and the Spotify Web API to complete authorization, refresh access, resolve the current track, and search for a matching track when necessary. It stores the resulting access and refresh credentials, expiry, scope, and temporary authorization state in encrypted app storage using AES-GCM with key material held in Android Keystore.
Disconnecting Spotify removes those locally stored credentials. You can also revoke Icy Lyrics from the apps section of your Spotify account. Icy Lyrics does not create a separate account of its own.
Spotify Privacy PolicyLyrics providers and network transfers
Saved TTML is checked locally before remote providers. Depending on the sources you enable, Icy Lyrics may make these HTTPS requests:
Icy Lyrics Database
Receives the complete Spotify track URI in an anonymous exact-match request after local TTML misses. It does not receive a Spotify access token. Successful results are cached on the device for 30 days, misses for one hour, and the app does not automatically repeat this request until the song changes or you reload lyrics.
LRCLIB
Receives the track title and artist, plus album and duration when available, to find a matching lyric document.
Apple Music compatibility fallback
When you enable Apple Music, approve token sharing, and connect Spotify, Spicy Lyrics receives the Spotify track ID, Icy Lyrics client version, and a short-lived Spotify access token to request an Apple Music-backed result. The automatic Spicy database source and direct Spotify lyric source are not used by Android 1.1.0. The app does not contact Apple directly.
Spotify
Receives authorization, token-refresh, currently-playing, and track-search requests when you connect Spotify.
As with ordinary internet connections, each recipient can receive network information such as your IP address. These services control their own server logs and retention. Icy Lyrics does not promise that a third party will delete information on the same schedule as the app.
Information kept on your device
The app keeps the following information in its private local storage so its features work:
- TTML files you explicitly choose, including their full contents, parsed lyrics, song metadata, source content URI, track matching keys, and timestamps. Imported TTML is not uploaded.
- Retrieved lyrics and provider responses in a cache, along with track matching keys and source information.
- App settings, source choices, layout preferences, global timing, track aliases, and Bluetooth timing records.
- For optional Bluetooth timing, the selected audio route's display name and type, a hashed form of its address or route identity, the timing offset, and the update time. This information is not sent to lyric providers.
- Diagnostics containing redacted errors, provider results, HTTP status, timestamps, and a short hash instead of the raw track key. Access tokens, authorization headers, cookies, and similar secrets are redacted.
Android cloud backup and device transfer are limited to ordinary app settings. TTML files, Spotify credentials, lyric cache, diagnostics, aliases, and Bluetooth timing records are excluded from the app's backup rules. Google may retain eligible backed-up settings according to your Android backup and Google account choices.
Retention and security
- Successful Icy Lyrics Database cache entries expire after 30 days; other successful remote lyric cache entries normally expire after three days. Unsuccessful lookup records expire after one hour. The cache is capped at 250 entries.
- Diagnostics are capped at 200 events and retained for no more than seven days. They leave the device only when you intentionally use Android's copy or share action.
- Imported TTML, aliases, preferences, and Bluetooth timing stay until you delete or change them, clear the app's storage, or uninstall the app. Spotify credentials stay until you disconnect Spotify, clear app storage, or uninstall.
- Off-device requests use HTTPS. Spotify credentials are encrypted at rest as described above. No system can guarantee absolute security, and third-party services apply their own safeguards and retention practices.
Your choices and deletion controls
You can control the app's data handling at any time:
- Leave notification access disabled or revoke it in Android settings. Without it, the app cannot follow Spotify playback.
- Decline or revoke Bluetooth permission and use only the global timing offset.
- Individually disable saved local TTML, the Icy Lyrics Database, LRCLIB, or Apple Music in the app's lyric-source settings. Disabling Apple Music also stops that fallback; you can separately disconnect Spotify.
- Disconnect Spotify in the app and separately revoke Icy Lyrics in your Spotify account settings.
- Delete individual imported TTML entries from the local library and clear diagnostics from the diagnostics screen.
- Clear Icy Lyrics storage in Android settings or uninstall the app to remove its remaining local database and credentials. Eligible settings already held in an Android backup may be restored unless you also manage that backup through your Google account.
Changes and contact
If the app's data practices change, this page will be updated and the effective date above will change. A material change may also be explained inside the app before it takes effect.
For questions, access or deletion requests, or concerns about this policy, email jack@jackscurrie.com. Requests concerning data retained by Spotify, Spicy Lyrics, LRCLIB, Google, or another third party must also be directed to that service.
Email privacy contactWebsite TTML database accounts and contributions
The optional TTML database at jackscurrie.com/icy-lyrics/db uses Supabase to provide email-and-password accounts. Supabase processes your email address, password authentication, session information, and related security records. Icy Lyrics does not receive your plain-text password.
When you contribute, the database stores your account identifier, song metadata, source filename, raw TTML content, reviewer notes, review status, and timestamps. Pending or rejected submissions are available to you and the administrator. Approved TTML content and its song metadata become publicly searchable and downloadable through the website and API.
You may request deletion of your database account or submissions by emailing the contact below. Approved contributions may remain available where needed to preserve the public lyric library or comply with legal obligations, subject to a valid removal request. Supabase may process ordinary connection information such as IP address under its own privacy terms.
Supabase privacy policy