← Back to Flaurral

Privacy Policy

Flaurral is designed around the server you control. Your library and credentials do not pass through a Flaurral account or a Flaurral music service.

Last updated: August 28, 2026

This Privacy Policy explains how Flaurral (the “App”) handles information when you use it. The App is a client for an Aurral server that you choose and configure.

1. Aurral connection and credentials

Flaurral connects directly to the Aurral server address you provide. Depending on your setup, the App may use an API key, an Aurral OpenID Connect session, or temporary web authentication for a protected reverse proxy.

The server address, API key, and applicable server-scoped cookies are stored in the iOS Keychain. Credentials are sent only to the relevant server or authentication endpoint to perform requests. They are not placed in request URLs or included in Flaurral diagnostic reports. Disconnecting removes the stored connection from the App.

2. Music, library, and account data

Library data, artwork, recommendations, playlists, Flows, activity, playback URLs, and account settings are requested from and sent to your Aurral server. Your server and any music or scrobbling providers configured through Aurral are operated by you or third parties and are governed by their own privacy practices.

Flaurral does not operate a proxy for your Aurral traffic and does not receive your Aurral credentials, library, or listening history.

3. Data stored on your device

Flaurral stores app preferences, connection status, playback state, notification history, and caches for artwork, API responses, and validated played music on your device. Storage controls in the App let you review and clear supported caches. Push notification history is limited to the 100 most recent items and can be cleared item by item.

4. Flaurral+ purchases

Optional Flaurral+ purchases are processed by Apple through the App Store. Flaurral uses RevenueCat to load offers, validate purchase entitlement, and restore purchases. RevenueCat receives a pseudonymous App User ID and the purchase and entitlement information required for those functions. Flaurral declares Device ID and User ID data for app functionality and does not use them for tracking.

Apple and RevenueCat process information under their own privacy policies. Flaurral does not receive your payment card details.

5. Optional push notifications

If a Flaurral+ user enables push notifications, the App sends an Apple Push Notification service device token, a pseudonymous RevenueCat App User ID, and a per-installation secret to Flaurral's notification relay over HTTPS. The relay verifies the active entitlement and provides a signed webhook URL that the App adds to the connected Aurral server.

Your Aurral server sends only the supported event payloads you enable. The relay uses those payloads to deliver notifications through Apple Push Notification service. Registration data remains necessary while the feature is enabled. Disabling the feature asks both Aurral and the relay to remove the installation registration when they are reachable.

6. Music recognition and microphone

Flaurral requests microphone permission only when you choose Recognize Music. Microphone input is used temporarily by Apple's ShazamKit to create a match request. Flaurral does not save the recording. Match details and optional artwork may be returned by Apple services and displayed or cached on your device.

7. Diagnostics, analytics, and advertising

Flaurral contains no advertising SDK and does not track you across apps or websites. The current App configuration does not enable behavioral analytics. Apple may provide developers with aggregate App Store, sales, and opt-in diagnostic information through App Store Connect; Flaurral does not link those aggregate reports to your Aurral activity.

8. Sharing and selling data

We do not sell personal information. Information is shared only with the services needed for a feature you choose: your configured Aurral and authentication endpoints, Apple and RevenueCat for purchases, the notification relay and Apple for push notifications, and Apple ShazamKit for music recognition.

9. Data choices

You can disconnect your Aurral server, clear supported caches and notification history, disable push notifications, revoke microphone or notification permission in iOS Settings, and manage or cancel Flaurral+ through your Apple Account. You may also stop using and delete the App.

10. Children

Flaurral is not directed to children and does not knowingly collect personal information from children.

11. Changes to this policy

We may update this policy when Flaurral or its services change. The revision date at the top of this page will be updated when changes are published.

12. Contact

For questions or privacy requests, contact contact@nohit.dev.