Resonance plays music from a server you run. We do not have a copy of your library, your listening history, or your account.
We collect nothing about you unless you write to us. There is no analytics, no crash reporting, no advertising and no tracking of any kind in this app — not anonymised, not aggregated, none. The one exception is the feedback form, which sends only what you typed and what you can see listed on the screen before you press Send.
Everything the app sends goes either to a server you chose or to a service you can switch off. The rest of this page says exactly which, and what each one receives.
Resonance is made by David Monteiro, an independent developer in Portugal. For anything on this page — questions, requests, complaints — write to hello@resonancemusic.app.
Where the GDPR applies, we are the data controller for the small amount of processing described below. We are not the controller for your own music server, which is yours, nor for a third-party service you choose to connect to.
All of this stays on your phone. It is not uploaded, and we cannot see it.
Deleting the app, or clearing its storage in Android settings, removes all of it.
Resonance signs in to the Jellyfin or Subsonic server you configure and asks it for your music. That server necessarily sees your credentials and what you browse, search, play and download. It is your server, run by you or by whoever you trust to run it, and this policy does not govern it.
If you cast to a Chromecast, or play to a Home Assistant media player, Resonance hands that device the track's details and a link to the audio so it can fetch the music itself.
Worth knowing: that link contains the access credentials for your server, because that is how those servers authorise a stream — a Subsonic-type server signs the link with a value derived from your password, and Jellyfin appends an access token to it. Anything you cast to therefore receives credentials capable of reaching your library. Only send music to devices you trust.
When your own server has no lyrics for a track, Resonance can look them up at LRCLIB. The track's title, artist, album and length are sent; nothing identifying you is attached.
Turn it off in Settings → Music Discovery → Third-party lyrics, and nothing is sent — the app then shows only the lyrics your own server provides.
To suggest similar artists, Resonance can ask ListenBrainz about an artist, using the MusicBrainz identifier already present in your own music files. Only that identifier is sent. Artists whose files carry no identifier are skipped.
Turn it off in Settings → Music Discovery → Similar Artists.
If you enter a ListenBrainz token, Resonance submits each finished play: the track title, artist, album, and the time you listened. Nothing is sent until you provide a token, and removing the token stops it.
Scrobbled listens are public and permanent. ListenBrainz publishes listening histories openly and includes them in public data dumps released under a public-domain licence. Once a listen is published it cannot be recalled from copies others have already taken. Please decide with that in mind.
You choose where these go. The default is ListenBrainz, but the address is a setting, and it can point at any compatible service you run or trust — so we cannot name a single recipient here. Whoever receives them is a separate, independent controller of that data, with their own policy and their own obligations. We have no agreement with them on your behalf and cannot delete anything you have sent them. To have listens removed, contact that service.
Settings → Send feedback is the only place where we receive anything. Nothing is sent unless you fill it in and press Send.
The form shows you the complete contents before you send it. It carries:
About screenshots. A screenshot of the Settings screen shows your server address, so the app will not let you send one until you have opened it full size and looked at it. We also remove the hidden metadata a picture carries — the device and capture time, and the GPS coordinates a photograph can contain — before it leaves your phone.
Reports are stored on Cloudflare, who host them for us. They are not shared with anyone, sold, or used for anything except fixing the thing you told us about. Screenshots are deleted automatically after 90 days. To have a report removed sooner, email hello@resonancemusic.app — quote the reference the app showed you if you still have it.
To offer nearby servers and cast targets during setup, the app broadcasts a discovery request on your local network. This never leaves your network.
| Processing | Basis |
|---|---|
| Connecting to your server and playing your music | Performance of a contract — it is the function you bought |
| Lyrics and similar-artist lookups | Legitimate interests, narrow in scope, and switchable off at any time |
| Scrobbling to a service you configure | Consent, given by entering a token and withdrawn by removing it |
| Feedback you send us | Consent, given by pressing Send |
The GDPR gives you rights of access, correction, erasure, restriction, portability and objection. In practice these are unusually simple here, because unless you have sent us feedback we hold nothing about you at all: your data is on your device and on your server, both under your control. Uninstalling the app, or clearing its storage, erases everything it kept.
If you have sent feedback, write to us and we will send you a copy of it or delete it.
If you believe we have handled something badly, please write to us first — and you also have the right to complain to your national supervisory authority, which in Portugal is the CNPD.
Connections to your server, and to the services above, use HTTPS wherever the server supports it. Self-hosted servers sometimes do not offer HTTPS, and the app allows plain connections so that those still work — a plain connection can be read by others on the network path, so prefer HTTPS if your server offers it.
Your server credentials — and the Home Assistant and ListenBrainz tokens, if you set them — are encrypted at rest, with a key held in the Android Keystore and protected by your device's secure hardware where it has any. They are stored in the app's private storage, which Android also keeps separate from other apps.
One consequence is worth knowing before you meet it: a Keystore key never leaves the phone it was created on, and Resonance is excluded from Android's cloud backup and device-transfer. So your credentials cannot be carried to a new device, and you will sign in to your servers again after a transfer or a factory reset. Your music, playlists and favourites live on your server and are unaffected.
Resonance is not directed at children and collects nothing about anyone, of any age.
This site sets no cookies, includes no analytics, and loads no fonts, scripts or images from anyone else. Our host, Cloudflare, processes requests and keeps short-lived operational logs in order to serve the page.
If what the app does changes, this page changes with it, and the date at the top moves. When a change is significant — a new recipient, or something new leaving your device — we will say so in the app's release notes rather than relying on you to re-read this page.