Privacy

The Digr app remains local-first. The website uses optional analytics and a waitlist you can choose to join. Where a network request happens, it is named below.

The application

There is no account. No sign-in, no licence key, no user record. Digr does not know who you are and has no mechanism to find out.

Nothing about your music is uploaded. Scanning reads your files and writes nothing back to them. The index it produces is a SQLite database in Digr's own application-support folder (digr-index.db), and extracted artwork is cached beside it. Both stay on your machine; deleting them just forces a rescan.

There is no analytics or telemetry in the desktop app. No usage reporting, no crash reporting service, no identifiers. The diagnostics log records playback, scan and cast failures so a bug report can be specific. It is held in memory and on your disk, and goes nowhere unless you press Export Diagnostics in Settings and choose where to save it.

The two times Digr uses the network

Being precise about this is more useful than a blanket claim, so here are both, and what each one exposes.

1. Casting, on your own network. When you cast, Digr runs a small HTTP server on your machine and gives the Cast device a URL pointing at it. The device fetches your original file directly, over your LAN. Nothing is uploaded to a service and nothing is transcoded. File paths never appear in a URL. Each track is addressed by an unguessable token, and discovery uses mDNS, which is local broadcast traffic. Your Cast device is a Google product and behaves according to Google's own policies; that part is outside Digr.

2. Checking for an update, when you ask. Digr does not check for updates on launch or on a timer. The check happens when you press the button in Settings, and it requests a small manifest file from Digr's public releases repository on GitHub. Like any HTTP request, that tells GitHub your IP address, and GitHub logs it under their terms. That is unavoidable for any download and worth stating plainly.

Outside those two, Digr makes no outbound requests. There is no metadata lookup, no artwork fetching service, no licence check and no "phone home" on launch.

This website

The site is statically generated and its fonts are served from the same domain. It uses Google Analytics 4 to understand page views and basic interactions, but the Google Analytics script is not loaded until you explicitly choose Allow analytics in the consent banner.

Before you make a choice, analytics storage is denied. If you choose No thanks, the Google Analytics script is not loaded and Digr sends no analytics data to Google. If you allow analytics, Google Analytics may set its own analytics cookies and receive information such as pages viewed, interactions, device/browser information and network information needed to deliver the service. Digr does not enable Google advertising storage, ad personalisation or ad-user-data consent.

Your analytics choice is stored locally in your browser so the site can remember it. You can reopen the choice at any time using Cookie settings in the footer. Changing from allowed to denied removes the Google Analytics cookies the site can identify and reloads the page with analytics disabled.

The Digr waitlist is handled by Brevo. If you choose to submit the waitlist form, the email address you enter is sent to Brevo and added to the Digr Waitlist contact list. It is used to send launch access and meaningful Digr release updates. Joining the waitlist is optional, and every marketing email will provide a way to unsubscribe. The current waitlist does not send an automatic confirmation email.

The web host will also keep ordinary server logs needed to serve and protect the site. Following a link to GitHub, including the support issue tracker or a future download, hands the request to GitHub under GitHub's own privacy terms.

What this page does not claim

It does not claim your data is encrypted at rest, because Digr does not encrypt its local index. Your operating system's disk encryption is what protects it. And it does not claim anonymity, because ordinary web requests and downloads necessarily expose network information to the service receiving them.

Data protection — the formal part

The section above is the substance. This one restates it in the terms UK GDPR and the EU GDPR use, because Digr Pro is priced and a paid product sold into the UK and the EU owes its customers this in writing. Everything here describes the position today.

Who is responsible

Digr is an independent project, operated by its developer. It is not yet an incorporated entity, and there is no registered company name, registered address, data protection officer or EU representative to publish, so none is invented here. Those details, and a named contact route for data-protection requests, will be published on this page before Digr takes a single payment from anyone in the UK or the EU. Until then the contact route is the public issue tracker linked from support.

What personal data is processed

By the desktop application: none. Digr has no account system, collects no identifiers, sends no telemetry and transmits nothing about your library. Your music, your tags and the index derived from them are files on your own machine, and Digr never has a copy.

By this website: ordinary hosting logs are processed by the web host. If you consent to analytics, Google Analytics also processes analytics data generated by your use of the site. If you decline analytics, the Google Analytics script is not loaded. The site's record of your analytics consent choice stays in your own browser's local storage. If you join the Digr waitlist, Brevo processes the email address you submit and stores it as a waitlist contact.

Purpose, legal basis and retention

  • Serving the pages and the download. Purpose: delivering the content you asked for, and keeping the service secure. Legal basis: legitimate interests (Article 6(1)(f)). Retention: whatever the host and GitHub keep under their own policies.
  • Website analytics. Purpose: understanding site usage and improving Digr's website. Legal basis: consent (Article 6(1)(a)). Analytics is disabled until consent is granted. Google controls its own processing and retention under the configured Google Analytics property and Google's terms. You can withdraw consent at any time through Cookie settings.
  • Digr waitlist and release email. Purpose: telling you when Digr is available and sending meaningful release updates you requested. Legal basis: consent (Article 6(1)(a)). Brevo stores the submitted email address until you unsubscribe, ask for deletion, or the waitlist is no longer needed, subject to records Brevo must retain for its own legal or abuse-prevention obligations.
  • The update check. Purpose: telling you a newer version exists, when you press the button. Legal basis: legitimate interests, and it happens only on your instruction. Retention: none here. The request is to GitHub and nothing is stored by Digr.
  • A bug report you choose to file. Purpose: fixing the bug. Legal basis: legitimate interests, on information you decided to send. Retention: for as long as the issue and its history are useful, on the public tracker where you posted it. Diagnostics exports are written locally and go nowhere unless you attach one yourself.
  • Payments and licences. None of this exists yet. When it does, this page will name the processor, the data involved, the legal basis and the retention period before the first transaction.

Processors, recipients and transfers

The website is hosted by Vercel. Google Analytics is the analytics provider when a visitor consents. Brevo processes the email addresses of people who choose to join the Digr waitlist and is used for Digr marketing/release email. GitHub hosts the releases repository, update manifest and public issue tracker. These providers process data under their own terms and may process or transfer data outside the UK or EEA using their own safeguards. Digr does not use an advertising network and does not sell personal data.

Your rights

Where personal data about you is processed, UK and EU data protection law gives you the right to access it, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable form where that applies, and to withdraw consent where processing relies on consent. For website analytics, withdrawing consent is available directly through Cookie settings. For the waitlist, you can unsubscribe using the link in a Digr email.

For the application there is no personal data to give you, correct or delete, because none is collected. For a bug report you filed, or a request about anything visible on the public tracker, use the route on the support page. When accounts, licences or payments exist, so will a named contact address for exercising these rights, and it will be published here.

Complaints

If you think your data has been mishandled you can complain to a data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the supervisory authority for the country you live or work in. You do not need to raise it with us first, though it is usually faster.

Keeping this page true

The site asks before enabling Google Analytics, and joining the Brevo waitlist requires an explicit form submission. Declining analytics keeps that script unloaded, while ignoring the waitlist form sends nothing to Brevo.

If any of the above stops being true, this page changes with the implementation rather than quietly falling behind it.