Privacy
Effective 2026-08-09Summary
dither has no account and no server of its own. Nothing you do in the app is sent to us — there is nowhere for it to go. Your library, your listening history and your credentials stay on your device and on the servers you configured.
There is one exception, and it is why this page is longer than it used to be: with Online lookups on, the app asks a handful of open music databases about what you are playing. That setting is on by default. It is described in full below, and you can turn it off in Settings.
What we collect
- Nothing. There are no analytics, no crash reporting, no advertising SDKs and no trackers of any kind, and no dither-operated server for data to reach. We do not generate or read any advertising, device or install identifier.
Online lookups — what leaves your device
One setting, Settings → Online lookups, controls all of the following. It is on by default. Turning it off stops every request on this list; the app keeps working from your own library alone.
- Lyrics — artist name, track title and track length are sent to lrclib.net. This happens for tracks you play, so it does reveal what you are listening to.
- Artist information — the artist name goes to MusicBrainz, and identifiers derived from the reply go to Wikidata, Wikipedia, Wikimedia Commons and the Cover Art Archive, to fetch a biography, a portrait, and cover art for albums you do not own.
- Similar-track radio — artist name and track title go to ListenBrainz.
These are open, non-commercial services run by the MetaBrainz
Foundation, the Wikimedia Foundation and the lrclib project. No
account, device identifier or advertising identifier is attached. The
only header we add is a fixed User-Agent — dither/1.0 —
which carries no version and nothing that narrows you down. As with
any web request, the service sees your IP address, and the app cannot
prevent that.
These requests are made by your device, not by us. We do not receive them, proxy them or have any access to them. In the same way that a browser vendor is not part of the sites you visit, we are not part of these lookups.
Cloud sources you connect yourself
- Dropbox — a token and your account email are stored in your device's secure storage; requests go to Dropbox's API.
- Google Drive — sign-in is handled by Google's own SDK and requests go to Google's API. Your account email is stored; no refresh token is kept.
What is stored on your device
- Server addresses and credentials — in the device's secure storage (iOS Keychain / Android Keystore).
- Your library — artists, albums, tracks, playlists, album art, the streaming cache and downloads, in an unencrypted database and cache directory inside the app's private storage.
- Listening history — each play (track, artist, when) builds play counts and the Recap screen. It never leaves the device, and you can erase it from Settings.
- Audio analysis — a numeric fingerprint of each track's sound, for the on-device radio. Never uploaded.
- Local file paths, if you add music from the device.
- App settings, the last playback queue, up to twelve recent search terms, and per-output equaliser presets.
How long it is kept
There is no automatic expiry. Everything above is kept until you delete it or remove the app. Recent searches are capped at twelve by count, not by age. The lyrics, artist and similar-track caches stop being used after thirty days, but the files themselves are not deleted until the app is removed. There is no cache-clearing control in the app.
Deleting your data
- Removing a source deletes that source's library rows, its downloads, its analysis data and its credentials.
- Settings → Erase listening history removes every recorded play, and resets play counts with it.
- Removing the app deletes everything it stored.
Deletion is an SQL delete, a file unlink, or removal of a secure-storage item — we do not claim any form of secure overwrite. Note that playlists, and the caches above, survive removing a source.
Backups
On Android, none of the app's data is included in cloud backup or device-to-device transfer. On iOS, downloaded audio is excluded from your iCloud backup — it can be fetched again from your own server — while the library catalogue is included, so restoring a phone does not mean re-syncing everything. Caches are in a directory iOS excludes automatically.
Casting
When you cast, dither serves the audio from your phone to the speaker or TV over your local network, and sends the track title, artist, album and cover art to that device. What the receiving device does with that is outside dither's control. Speaker discovery uses your local network only.
Automatic processing, and how to refuse it
The app uses no cookies and contains no embedded browser; external links open in your system browser, where that browser's own settings apply.
- Device music scan — refuse by revoking the media permission in your OS settings.
- Online lookups (lyrics, artist info, radio) — one switch in Settings.
- Scrobbling to your own server — a switch in Settings.
- Listening history, queue saving, audio analysis of on-device files, and periodic server reachability checks — these have no off switch today. The history can be erased afterwards; the rest never leaves your device.
Payment
dither Pro is a one-time purchase handled entirely by the App Store or Google Play. No payment details reach the app or us, and the app stores no receipt or transaction identifier — only whether Pro is unlocked.
Children
dither is not directed at children. We do not collect anyone's age, and we collect no data with which to identify anyone.
Changes
If what the app sends changes, this page changes with it, and the date at the top moves.
Who operates dither
Egress (이그레스) — sole proprietor, Republic of Korea.
Representative and data protection officer: Jinho Jeong
Business registration number: 448-64-00825
B1 23-17, 6 Dogok-ro 84-gil, Gangnam-gu, Seoul 06282, Republic of Korea
+82 10 4484 0400 ·
support@dither.one
Contact
For any question about this policy, or about the data on your device, write to support@dither.one. Support is answered by email. The telephone number above is the operator's business contact, listed here so that it matches the details shown on our App Store and Google Play listings; calls are taken in Korean during Korean business hours.
If you are in the Republic of Korea, you may also raise a dispute with the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr) or the Privacy Infringement Report Centre (118, privacy.kisa.or.kr).