Codec

Privacy Policy

Updated September 22, 2026

Codec is a music player that connects to a Codec server you choose. This policy covers the Codec app, its web player, the project website at codec.codie.sh, and demonstration or review servers operated by the Codec developer.

Your server and who can access it

When you connect to your own server, music and synchronization information are sent to that server. The Codec developer does not automatically receive a copy. The operator of your chosen server controls its storage, access and backups.

If you use a developer-operated demonstration or review server, the developer operates that server and can access the information it receives. A server can be shared: other authorized clients and participants in an Aux session can see shared library and playback information. Codec does not make a separate private library for each device connected to the same server.

Information used to run Codec

This information is used for app functionality, access control and troubleshooting. Codec does not include advertising or third-party analytics SDKs, sell personal information, or track you across other companies’ apps and websites.

The project website

The website at codec.codie.sh provides screenshots, documentation and download links. It does not connect to your music server or ask for your server token. It has no analytics scripts or advertising. Its hosting provider receives the connection information needed to serve pages, including IP addresses, and may retain operational logs. Following a download or source link takes you to GitHub.

Information stored on your device

Codec saves connection credentials, preferences, its device identifier, library and artwork caches, and playback state in app or browser storage. The app also stores songs you choose to download so they can play offline. Browser storage includes local storage, IndexedDB and application caches.

Local network permission lets the app reach a server on your network. The system photo picker lets you select a playlist cover; it does not give Codec unrestricted access to your photo library. The visualizer analyzes the music being played and does not record your microphone.

Transport and sharing

HTTPS encrypts the connection to a server that supports it. Codec also supports plain HTTP connections, including local network servers; HTTP does not encrypt credentials or music in transit. Use HTTPS for a server reached over the internet.

Using Aux shares playback controls with participants in that session. A server operator may use hosting, storage or network providers to deliver the service. Opening an external support or source link is subject to that website’s privacy policy.

Retention and deletion

Library content and saved playback information remain on the connected server until they are changed or removed by the server operator or an authorized client. A device disappearing from the active-player list does not erase its saved device information or previous playback commands. There is no single automatic deletion period covering all Codec servers. Log and backup retention depends on the operator and hosting configuration.

In the app, Settings → Disconnect removes the saved server connection and cached library. Downloaded files and other local preferences may remain. Use a song’s Remove Download action to remove its offline copy; deleting the app removes its local app data. For the web interface, your browser’s site-data controls remove locally saved credentials and caches.

Disconnecting, clearing browser storage or removing the app does not delete server data. Deleting a playlist removes that playlist, not the underlying music. Contact the operator of your server about removing server-side content or backups.

Questions and privacy requests

For Codec support or a request relating to a developer-operated demonstration or review server, use the Codec support tracker. GitHub issues are public: do not include authentication tokens, private server addresses, personal music files or other sensitive information. You can request a private follow-up before providing details.

Changes to this policy will be published here with an updated date.