1. Controller and scope
This policy covers the CoYoMu app and the official product website hosted on West IT's own server. The controller for processing carried out by West IT is identified below. Providers you connect to through the app may also process data under their own responsibilities.
West IT
Proprietor: 
83104 Hohenthann
Germany
Phone: +49 8065 246 9824
Email: info@west-it.de
CoYoMu plays audio locally on your device and connects directly to your chosen servers and public audio services. It does not require a CoYoMu account or route your library through a CoYoMu cloud.
2. Website hosting and cookies
The website is a static product site. Its own pages contain no advertising pixels, analytics scripts, newsletter or contact forms, external web fonts, tracking cookies or browser-storage features. Images, fonts supplied by your system and page scripts do not require third-party media embeds.
West IT operates the official CoYoMu website on its own server. To deliver the pages, maintain reliable operation, protect against misuse and diagnose errors, technical connection data may be processed. This can include your IP address, the date and time of a request, the requested resource, referrer information where transmitted, browser/device information and the response status. These data are used for website operation and security, not to analyse your listening behaviour.
The website does not receive your app profiles, server passwords or listening history. Questions about website data processing can be addressed to West IT using the contact details in the imprint.
3. Advertising, analytics and diagnostics
CoYoMu does not operate advertising, behavioural profiling or its own analytics or telemetry service. The active app does not integrate Firebase Analytics, Google Analytics, Sentry, Crashlytics or similar analytics/crash-reporting SDKs. Apple and Google may process store, crash or diagnostic information under their own platform settings and privacy terms.
4. Data stored on your device
Depending on how you use the app, local data includes:
- Profiles, profile names and appearance, the selected profile and preferences.
- Configured server addresses, accounts, authentication tokens and connection settings.
- Favourites, listening history, podcast subscriptions, feed references, media identifiers, chapters and saved listening positions.
- The current queue, playback session, media descriptions, cover cache and temporary service responses.
- Downloaded audio, private download manifests, storage settings and pending listening-progress updates.
- Trial and purchase status needed to determine access to Pro features.
Credentials are kept in iOS Keychain or Android keystore-backed secure storage. Authentication headers stay in private request/playback data and are not included in system-visible media extras. Local profiles personalise the app; they are not separate cloud accounts or an operating-system security boundary. West IT has no routine access to data held only on your device or your configured servers.
5. Your own servers and authentication
When you configure Navidrome/Subsonic/OpenSubsonic, Audiobookshelf, Plex or Jellyfin, CoYoMu connects to the service you choose. Requests can include authentication data, search terms, library/media identifiers, playback decisions, favourites and metadata needed for the selected feature. Your server also receives connection information such as your IP address. Audio, artwork and metadata may be retrieved directly from that server or from hosts it identifies.
Subsonic uses salted token authentication. Audiobookshelf and Plex secrets are sent as request headers rather than placed in system-visible media extras. Jellyfin uses its login and access-token mechanism. Use HTTPS for public servers. Cleartext HTTP is intended only for permitted private-network or loopback self-hosting destinations and does not protect traffic against others with network access.
If you sign in to Plex through the app, account authorisation and server discovery involve Plex services, including plex.tv. Plex processes those requests under its own privacy policy. Other self-hosted server operators are responsible for their own processing.
6. Listening progress and offline sync
Music, audiobook and podcast listening positions are stored locally per profile. Audiobookshelf also receives listening-session and progress updates during online playback; Plex receives playback timeline/progress updates where supported. Jellyfin and Subsonic resume positions are maintained locally through the app's progress store.
For Audiobookshelf and Plex, progress recorded while offline can be kept in a persistent, device-local outbox and sent directly to the configured server when a connection becomes available. These records contain the media and position information necessary for the update, plus a private connection/account binding. Conflicting server progress can require your choice before an overwrite. Downloading an audiobook does not itself open an Audiobookshelf listening session.
7. Podcasts and public feeds
Podcast search sends your search term directly to Podcast Index. Discovery retrieves regional charts and public feed information from Apple Podcasts services. Opening a show retrieves its public RSS/Atom feed; artwork and playback or download requests go to the respective content hosts. These providers receive your IP address and request metadata and may use their own delivery and measurement systems.
CoYoMu does not attach your self-hosted account credentials or local profile data to public podcast search requests. Subscriptions and listening progress are stored on your device. Podcast Index and Apple have their own Podcast Index privacy information and Apple privacy information.
8. Internet radio
Discovering stations sends selected search/filter parameters to Radio Browser servers. Selecting a station can also send its station identifier to Radio Browser to register the selection and obtain station information. The app connects to the selected broadcaster or stream host for audio and available station metadata. Radio Browser and broadcasters receive technical connection data and may apply their own logging and statistics. Live radio requires a network connection and is not treated as an offline download.
9. Downloads and storage
If you use offline listening, supported audio files and a private manifest are saved in the app's device storage. The original content host receives the download request. The manifest keeps the source and resume information needed to play and synchronise that content later; it is not exposed as system media extras.
Downloads are excluded from app backup. Storage limits and inactivity rules can remove eligible downloads; individually protected files and files in the current queue are protected from routine eviction. You can manage or delete downloads in the app. Deleting cached audio does not automatically remove pending progress updates.
10. Optional external lyrics
No external lyrics provider is preconfigured. If you enter a compatible provider address and enable external lyrics, the app may send the current title, artist, available album and duration directly to that provider when you open the lyrics view. It also receives connection data such as your IP address. The feature requires your explicit choice and can be disabled in settings. Lyrics supplied by your own Subsonic server are retrieved from that server. CoYoMu does not operate a lyrics service.
11. CarPlay, Android Auto and permissions
CoYoMu shares the relevant catalogue, media identifiers, title/artist information, artwork, chapters, playback state and actions with CarPlay, Android Auto and operating-system media controls. This enables browsing and playback through your connected vehicle, lock screen and media notifications. Siri media search involves Apple's voice-assistant processing under your Apple settings and Apple's privacy terms.
The app uses network access, local-network permission where required, background audio, notifications/media integration and secure device storage to provide the features you select. The website does not use your microphone, location or vehicle connection. CoYoMu does not collect a vehicle route or GPS history for its own service.
12. Trials, purchases and tips
Public podcasts and Radio Browser are free to stream on phones/tablets. Own-server playback, downloads, offline playback, CarPlay and Android Auto require Pro or an active trial. You explicitly start the 30-day trial; it does not trigger an automatic payment. Pro is a permanent, one-time purchase. Voluntary tips do not unlock functionality.
Apple StoreKit and Google Play handle purchases and store accounts. The app processes product identifiers, verified transaction/purchase information, purchase dates and status, and local entitlement state to deliver and restore access. Payment-card details are handled by the store and are not entered into CoYoMu. Purchases do not transfer between Apple and Google stores.
To manage the trial and access to Pro features, CoYoMu processes the necessary activation and licence information. Depending on the platform, this includes verified store transactions and licence status held in secure local storage. Licence status is not included in profile exports or portable backups.
13. Backups and device deletion
The active CoYoMu app has no app-managed CloudKit profile backup or user-facing Dropbox sync feature. Automatic cross-device profile synchronisation is not part of the active app described here. Your operating system's general backup behaviour is controlled by that platform and your settings.
Some credentials for user-configured self-hosted services can synchronise separately through iCloud Keychain on Apple devices where supported and enabled. Purchase/trial caches remain in their separate device-bound storage. Downloads are excluded from backup. Profile/export data is filtered to omit credentials and private or temporary data where required by the respective models.
14. Contact and support
If you contact West IT, we process your contact details, message and any diagnostic information you choose to send in order to answer your request. Please do not send server passwords, tokens or private stream URLs. Information supplied voluntarily for support is not an automatic transfer of your app library.
15. Recipients
Recipients depend on the features you select: your server operators, Plex authorisation services, Podcast Index, Apple podcast services, Radio Browser, feed/artwork/audio hosts, an optional lyrics provider, and Apple and Google store/platform services. Support communications may also be processed by the communication providers used to deliver them. West IT does not sell personal data.
16. Legal bases
For processing for which West IT is responsible, the relevant bases under Article 6(1) GDPR are:
- Contract or requested pre-contractual steps — Article 6(1)(b): delivering requested app functions, purchases and support.
- Legitimate interests — Article 6(1)(f): reliable website operation, security, fault diagnosis and preventing misuse, subject to your interests and rights.
- Consent — Article 6(1)(a): optional processing where consent is requested, including your chosen external-lyrics feature.
- Legal obligations — Article 6(1)(c): processing required by applicable law.
Independent services may use different bases, as described in their own notices. Providing information necessary for a function is optional, but without it that function may not work. West IT does not use your app data for automated decisions producing legal or similarly significant effects.
17. Retention and deletion
Local profile data is retained until you remove it in the app, clear app data or uninstall, subject to operating-system storage behaviour. Some secure Keychain records can survive an ordinary iOS reinstall. Caches and eligible downloads may be removed automatically. Unconfirmed or conflicting progress updates remain pending until resolved; deleting a profile removes that profile's local progress records.
Server data, store purchase records and provider logs follow the respective provider's rules and your account settings. Where website server logs are kept, West IT retains them only for as long as necessary for reliable operation, security and error diagnosis, or to meet applicable legal obligations. They are deleted when those purposes and obligations end. This website maintains no separate visitor-history database. Support correspondence is retained as long as needed to resolve the request and, where applicable, meet legal retention duties or establish, exercise or defend claims. Data is deleted or restricted when that purpose and any applicable duties end.
18. Your rights and contact
Where the statutory requirements are met, you may request access, rectification, erasure, restriction or portability of your personal data. You may object to processing based on legitimate interests, including for reasons relating to your particular situation. You may withdraw consent at any time for the future without affecting processing already carried out lawfully.
You have the right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR if you consider that the processing of your personal data infringes the GDPR. You may contact a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the alleged infringement. The supervisory authority for private-sector controllers based in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA). Its online complaint service and contact details are available on its website. Contacting West IT first is not a condition for exercising this right; other administrative or judicial remedies remain available.
For requests concerning West IT's processing, use the contact details in the imprint. Data held only on your device or by a service you choose normally needs to be managed through the device or that provider; we will explain where we lack access.
19. Children, store disclosures and changes
CoYoMu is not specifically directed at children under 16. Content comes from sources you select and may carry its own age restrictions. App-store privacy and Data Safety information must reflect the released app. This policy will be updated when functions, providers, hosting or legal requirements change. The update date is shown at the top of this page.
