Legal
Privacy Policy
Last updated: July 17, 2026
At a glance
- Choral has no listening-data cloud and no Choral account. We do not collect, sell, or use your listening activity for analytics or advertising.
- Your listening activity is processed on your Mac. The browser extension talks only to the Choral app on the same computer.
- Choral contacts the internet only for specific features: artwork, lyrics, updates, Pro licensing, and accounts you choose to connect (Last.fm and Spotify).
- No analytics, tracking, or ads in the app or extension. The website uses optional Google Analytics only after you consent.
1. Overview
Choral is a floating music control for macOS, made by FANG.works. This policy explains what information the Choral app, the Choral Connector browser extension, and this website handle, and where that information goes. The short version: almost everything stays on your Mac.
2. What Choral reads on your Mac
To show and control what's playing, Choral reads now-playing information — track title, artist, album, artwork, playback position, and playback state — from the music sources you use:
- Apple Music and Spotify (desktop apps): read locally through macOS automation (Apple Events). macOS will ask for your permission the first time.
- Online music services: supported sites include YouTube Music, YouTube, Spotify Web Player, Apple Music Web, Amazon Music, SoundCloud, TIDAL, Deezer, Bandcamp, Pandora, NetEase Cloud Music, and QQ Music. Choral Connector reads the authorized player tab and relays its state to the app over an authenticated local connection (127.0.0.1) that never leaves your computer. You may also explicitly enable additional web players.
This information is used solely to render the player, drive playback controls, and power the optional features described below. It is not transmitted to Choral's licensing service or used for analytics.
3. Network requests the app makes
Choral makes a small number of outbound requests, each for a specific feature:
- Album artwork — when a music source doesn't provide artwork, Choral queries Apple's public iTunes Search API (itunes.apple.com) with the track, artist, and album name to find a cover image. This request is subject to Apple's privacy policy.
- Lyrics — Choral fetches lyrics from LRCLIB (lrclib.net), an open lyrics database, by sending the track title, artist, album, and duration. No account or identifier is included.
- Update check — the direct-download version of Choral periodically fetches a small version file from choralapp.com to see whether a newer release exists. The request carries no identifiers and no listening data, and automatic checking can be turned off in Settings. The App Store version updates through the App Store and never performs this check.
- Pro license activation — if you buy Choral Pro, activating your license sends the license key and an anonymized device identifier (a one-way hash of your Mac's hardware UUID — it lets us count your devices without identifying them) to our license service at license.choralapp.com. Purchases themselves are processed by Stripe; Choral never sees your payment details.
Artwork, lyrics, Last.fm, and Spotify requests may contain the track or account data described above. License requests contain the license key and anonymized device identifier described above, but no listening data. As with any internet request, the receiving service can see your IP address.
4. Optional account connections
Choral works fully without any account. Two integrations are opt-in:
- Last.fm — if you connect Last.fm, Choral sends now-playing updates and scrobbles (track title, artist, album, and a timestamp) to Last.fm on your behalf. You choose which music sources scrobble in Settings, advertisements are never scrobbled, and you can disconnect at any time. Data submitted to your Last.fm account is governed by Last.fm's privacy policy.
- Spotify liking (advanced) — the like button for Spotify requires you to supply the Client ID of your own Spotify developer app. Authorization uses Spotify's standard OAuth flow in your browser; Choral requests only library read/write scopes, and your tokens are stored on your Mac. Choral never sees your Spotify password. You can remove the connection in Settings and revoke access from your Spotify account page at any time.
5. The browser extension
Choral Connector requests access only to music sites you select during setup or explicitly enable later. Access is granted per site through Chrome; the extension does not receive permission for every website simply by being installed. On authorized sites it reads the current track and playback state and relays control actions (such as play, pause, skip, seek, and like) back to that player. The generic-player feature can be enabled for an additional site only after you choose that site and approve Chrome's permission prompt.
The extension communicates with the authenticated Choral app on the same computer via 127.0.0.1. It has no remote backend, does not read your general browsing history, and contains no analytics or advertising. Disabling site access or uninstalling the extension stops that access immediately.
6. Where your data is stored
Your preferences and offline scrobble queue are stored locally inside the app's sandboxed container. Spotify and Last.fm authorization tokens and your Pro license are stored in macOS Keychain. Disconnecting an account removes its token from Keychain; you can also revoke access from that service's own settings page.
7. What we never do
- No analytics, telemetry, or crash reporting in the Choral app or browser extension.
- No advertising and no ad identifiers.
- No selling, renting, or sharing of listening data.
- No Choral account: there is nothing to sign up for and nothing for us to store.
8. This website
choralapp.com is a static website. With your consent, it uses Google Analytics to help us understand aggregate website traffic and Choral download clicks. This may process the page you visit, referral source, browser and device information, approximate location derived from your IP address, and interactions such as clicking a DMG download link. It never includes your listening activity, music accounts, license key, or payment details.
Google Analytics is not loaded until you select “Allow analytics.” After consent, Google Analytics may set first-party analytics cookies. Your choice is stored in your browser's local storage so the site can remember it. We disable Google Signals and advertising personalization. You can withdraw your choice by clearing site data for choralapp.com. Google's handling of analytics data is described in Google's privacy policy.
The website also loads the Outfit typeface from Google Fonts, which means your browser makes a request to Google's servers subject to Google's privacy policy.
9. Children
Choral is not directed at children under 13, and we do not knowingly collect children's personal information. The app and extension do not collect listening activity from any user; optional website analytics are limited to the data described above.
10. Changes to this policy
If Choral's data practices change — for example, if a future feature requires a new kind of network request — we will update this page and its "Last updated" date. Material changes will be called out in the release notes of the version that introduces them.
11. Contact
Questions about privacy? Reach us on X at @choral_app.