Wookie-Radio - Privacy Policy

Effective date: 30 September 2026

Wookie-Radio ("the app") plays internet radio and podcasts on iPhone, iPad (Apple) and Android. It is made by Łukasz Dec, trading as AlmostCyb.org, Poland ("we"). We are the controller for the little personal data this policy describes. Contact: use the form at almostcyb.org/support/wookie-radio.

The short version

What is stored on your device

Your station list and favourites, play counters, followed podcasts, queue, played and liked marks, listening positions, downloaded podcast episodes, scheduled shows, the calendar address you may enter, your settings, and the date you first installed the app. If you turn on Restricted Mode, a PIN hash is stored (it is a filter for children, not a security feature). All of this lives inside the app's own storage on your device. We cannot see it. Deleting the app deletes it from the device (see iCloud and backup below).

iCloud (iPhone and iPad)

If you turn on iCloud sync, the app stores your favourites, followed shows, positions, played marks, own stations and settings in Apple's iCloud key-value storage, tied to your Apple Account. It is your private iCloud data, governed by Apple's terms and privacy policy. We cannot read it. Turning sync off stops this device from taking part; it does not erase what is already in iCloud (manage that in Settings > your name > iCloud). The install date is also kept in iCloud so that it survives deleting and reinstalling the app; this needs no sync switch.

Android backup (Android)

Android can back up the app's data to your Google account (Google's automatic backup, if you have it turned on). That copy belongs to you and is handled by Google under its own policy. We do not receive it. The app has no live sync between devices.

Who the app contacts

The app connects to these third parties only when you use the related feature. They receive your device's IP address and the request itself; their own privacy policies apply. We receive nothing.

ServiceWhenWhat is sent
Radio stations and their stream hostswhen you play a stationa request for the stream (your IP address; the app's name)
radio-browser.info (public station directory, servers de1 and at1)when you search for stations to addyour search words, genre or country filters
Apple iTunes Search (itunes.apple.com)when you search podcasts or browse top showsyour search words or the show id
Podcast publishers' servers (feeds, audio files, transcripts, chapters)when you follow, open or download a showa request for the feed or file
Artwork and station logo servers (a publisher's or station's own address)when a cover or logo is showna request for the image; downloaded logos are kept in a cache on your device
The website you enter as a calendar (.ics) addressat launch and about every five minutes if you set onea request for that file
ShazamKit (Apple's song-recognition service, on both iPhone and Android)only when you tap "What song is this?"a short audio signature (a digital fingerprint, not a recording) made from the audio the app is playing, not from the microphone

Some stations and feeds use plain http, which is not encrypted; the app allows this because many radio stations only offer it. Nothing you type into the app is sent to us.

Song identification

The button listens to the sound the app itself is playing for about eight seconds, turns it into a fingerprint on the device and sends that to Apple's Shazam service (ShazamKit) to find the title and artist - on both iPhone and Android. The microphone is never used and the app asks for no microphone permission. On iPhone, a match is added to your Shazam library, under Apple's privacy policy; on Android the result is shown in the app only.

Notifications

If you schedule a show, the app can send local notifications (an optional reminder before it starts, off by default) on both iPhone and Android. They are made on your device; no push service or server is involved. On Android the app also asks for notification permission to show the playback controls. You can refuse; playback still works.

Calendar

The app does not access your calendar. If you paste a public or private .ics link, the app downloads that file from the address you gave and uses the show names in it. No calendar permission is requested.

If you contact us

The app itself sends us nothing. If you write to us through the website, the data is handled as follows.

Purchases

If the app offers paid features, they are sold by Apple (App Store) or Google (Google Play), who process the payment. We never see your payment details.

What we do not do

We do not sell or share personal data, build profiles, show ads, use advertising identifiers, read your contacts, photos or location, or track you across other apps or websites.

Legal basis, retention, transfers

Through the app we process no personal data, so there is nothing to retain or to transfer. The device-side processing above is carried out at your request to provide the app's features (Art. 6(1)(b) GDPR). If you contact us, we process the details you send to answer you (Art. 6(1)(f) GDPR, our interest in replying to requests), and we keep the ticket for up to 12 months after the request is closed, then delete it. Cloudflare and GitHub act on our behalf to deliver and store it, and may process it outside the EU under their own safeguards. Apple, Google and the third parties in the table are independent controllers for their own processing, and may process data outside the EU under their own safeguards.

Your rights (GDPR)

If you are in the EU or UK you have the right to access, correct, erase, restrict, object to and move personal data about you, and to withdraw consent. Because the app gives us none, the practical answer to a request is usually that we hold nothing about you, unless you wrote to us; you can still ask through the support form and we reply within 30 days. To remove your data yourself: delete the app, turn off and clear iCloud data for it (iPhone) or delete the backup in your Google account settings (Android). You may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, uodo.gov.pl), or to the authority in your country.

Children

The app is not directed to children and we do not knowingly collect data from anyone, children included. Radio and podcasts are third-party content and may contain adult material; Restricted Mode (Podcasts settings) greys out explicit-marked shows and asks for a PIN to follow them. It is an in-app filter, not parental control. Use your device's own parental controls for stronger protection.

Station names, logos and artwork

Station names and logos belong to their owners; the app is not affiliated with or endorsed by them. Podcast artwork comes from each show's own feed. Station owners can ask for removal at almostcyb.org/takedown.

Changes

If this policy changes we post the new version here with a new effective date; a material change is also announced in the app's release notes.

Contact

Łukasz Dec, trading as AlmostCyb.org. Contact form: almostcyb.org/support/wookie-radio.