Wookie-Radio - Privacy Policy
Effective date: 30 September 2026
Wookie-Radio ("the app") plays internet radio and podcasts on iPhone, iPad (Apple) and Android. It is made by Łukasz Dec, trading as AlmostCyb.org, Poland ("we"). We are the controller for the little personal data this policy describes. Contact: use the form at almostcyb.org/support/wookie-radio.
The short version
- No account, no sign-up; the app collects no e-mail address. (If you contact us through the website, see "If you contact us".)
- No advertising, no analytics, no tracking, no third-party SDKs that collect data.
- We run no server for the app. The app does not send us your favourites, your listening, your searches or your location.
- Your data stays on your device, and, if you choose, in your own iCloud (iPhone) or your own Android backup.
- The app talks directly to the radio stations, podcast publishers and directories you use. Those services see what any player or browser would show them (see "Who the app contacts").
What is stored on your device
Your station list and favourites, play counters, followed podcasts, queue, played and liked marks, listening positions, downloaded podcast episodes, scheduled shows, the calendar address you may enter, your settings, and the date you first installed the app. If you turn on Restricted Mode, a PIN hash is stored (it is a filter for children, not a security feature). All of this lives inside the app's own storage on your device. We cannot see it. Deleting the app deletes it from the device (see iCloud and backup below).
iCloud (iPhone and iPad)
If you turn on iCloud sync, the app stores your favourites, followed shows, positions, played marks, own stations and settings in Apple's iCloud key-value storage, tied to your Apple Account. It is your private iCloud data, governed by Apple's terms and privacy policy. We cannot read it. Turning sync off stops this device from taking part; it does not erase what is already in iCloud (manage that in Settings > your name > iCloud). The install date is also kept in iCloud so that it survives deleting and reinstalling the app; this needs no sync switch.
Android backup (Android)
Android can back up the app's data to your Google account (Google's automatic backup, if you have it turned on). That copy belongs to you and is handled by Google under its own policy. We do not receive it. The app has no live sync between devices.
Who the app contacts
The app connects to these third parties only when you use the related feature. They receive your device's IP address and the request itself; their own privacy policies apply. We receive nothing.
| Service | When | What is sent |
|---|---|---|
| Radio stations and their stream hosts | when you play a station | a request for the stream (your IP address; the app's name) |
| radio-browser.info (public station directory, servers de1 and at1) | when you search for stations to add | your search words, genre or country filters |
| Apple iTunes Search (itunes.apple.com) | when you search podcasts or browse top shows | your search words or the show id |
| Podcast publishers' servers (feeds, audio files, transcripts, chapters) | when you follow, open or download a show | a request for the feed or file |
| Artwork and station logo servers (a publisher's or station's own address) | when a cover or logo is shown | a request for the image; downloaded logos are kept in a cache on your device |
| The website you enter as a calendar (.ics) address | at launch and about every five minutes if you set one | a request for that file |
| ShazamKit (Apple's song-recognition service, on both iPhone and Android) | only when you tap "What song is this?" | a short audio signature (a digital fingerprint, not a recording) made from the audio the app is playing, not from the microphone |
Some stations and feeds use plain http, which is not encrypted; the app allows this because many radio stations only offer it. Nothing you type into the app is sent to us.
Song identification
The button listens to the sound the app itself is playing for about eight seconds, turns it into a fingerprint on the device and sends that to Apple's Shazam service (ShazamKit) to find the title and artist - on both iPhone and Android. The microphone is never used and the app asks for no microphone permission. On iPhone, a match is added to your Shazam library, under Apple's privacy policy; on Android the result is shown in the app only.
Notifications
If you schedule a show, the app can send local notifications (an optional reminder before it starts, off by default) on both iPhone and Android. They are made on your device; no push service or server is involved. On Android the app also asks for notification permission to show the playback controls. You can refuse; playback still works.
Calendar
The app does not access your calendar. If you paste a public or private .ics link, the app downloads that file from the address you gave and uses the show names in it. No calendar permission is requested.
If you contact us
The app itself sends us nothing. If you write to us through the website, the data is handled as follows.
- Contact form (support questions, takedown requests, general messages): we receive the name, e-mail address and message you type. Cloudflare Turnstile checks that the sender is not a robot, and a Cloudflare Worker passes the message on. It is stored as a ticket in a private GitHub repository that only we can read. We use it only to answer you and to keep a record of the request. We do not share it, and we do not use it for marketing.
- Bug reports and improvement suggestions on GitHub: these are public. Anything you write there, and your GitHub username, can be seen by anyone. Do not put private details in them; use the contact form for anything private. GitHub's own privacy policy applies to your GitHub account.
- You can ask us to delete your ticket at any time through the support form.
Purchases
If the app offers paid features, they are sold by Apple (App Store) or Google (Google Play), who process the payment. We never see your payment details.
What we do not do
We do not sell or share personal data, build profiles, show ads, use advertising identifiers, read your contacts, photos or location, or track you across other apps or websites.
Legal basis, retention, transfers
Through the app we process no personal data, so there is nothing to retain or to transfer. The device-side processing above is carried out at your request to provide the app's features (Art. 6(1)(b) GDPR). If you contact us, we process the details you send to answer you (Art. 6(1)(f) GDPR, our interest in replying to requests), and we keep the ticket for up to 12 months after the request is closed, then delete it. Cloudflare and GitHub act on our behalf to deliver and store it, and may process it outside the EU under their own safeguards. Apple, Google and the third parties in the table are independent controllers for their own processing, and may process data outside the EU under their own safeguards.
Your rights (GDPR)
If you are in the EU or UK you have the right to access, correct, erase, restrict, object to and move personal data about you, and to withdraw consent. Because the app gives us none, the practical answer to a request is usually that we hold nothing about you, unless you wrote to us; you can still ask through the support form and we reply within 30 days. To remove your data yourself: delete the app, turn off and clear iCloud data for it (iPhone) or delete the backup in your Google account settings (Android). You may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, uodo.gov.pl), or to the authority in your country.
Children
The app is not directed to children and we do not knowingly collect data from anyone, children included. Radio and podcasts are third-party content and may contain adult material; Restricted Mode (Podcasts settings) greys out explicit-marked shows and asks for a PIN to follow them. It is an in-app filter, not parental control. Use your device's own parental controls for stronger protection.
Station names, logos and artwork
Station names and logos belong to their owners; the app is not affiliated with or endorsed by them. Podcast artwork comes from each show's own feed. Station owners can ask for removal at almostcyb.org/takedown.
Changes
If this policy changes we post the new version here with a new effective date; a material change is also announced in the app's release notes.
Contact
Łukasz Dec, trading as AlmostCyb.org. Contact form: almostcyb.org/support/wookie-radio.