Turbo Music · Privacy
Turbo Music Privacy Policy
A music player learns a lot about you — what you play, when, and how often. This page says exactly what Turbo Music keeps to itself, what it asks other services, and who else is involved.
- Last updated
- 16 September 2026
- Issued by
- Turbo Ventura, Dubai, United Arab Emirates
- Applies to
- Turbo Music: Offline Player for iPhone, iPad, Mac and Apple Watch
In short
- Your library and listening history stay on the device.
- No account, no sign-in, nothing that identifies you.
- Lyrics are made on the device; songs are never uploaded.
- Anonymous usage and crash events go to Firebase, with no titles or file names.
- The free version carries AdMob advertising; Premium removes it.
- Sync runs through your own iCloud; purchases through Apple.
- A recovery code is mailed only when you ask, and only to you.
A summary, not the agreement. The sections below are what applies.
01 What this policy covers
This policy covers Turbo Music: Offline Player for iPhone, iPad, Mac and Apple Watch, published by Turbo Ventura of Dubai, United Arab Emirates. It is the policy referenced by the app’s App Store listing.
The company and this website are covered by our general privacy policy; where the two overlap, this page is the more specific and it governs the app.
For anything here, write to [email protected].
02 Your library stays on your device
Turbo Music plays files you bring in yourself, and it keeps what it knows about them on the device. We run no service you log in to and no server that receives your music. The following never reaches us, and there is no mechanism in the app by which it could:
- Your music, videos, podcast downloads and anything else you import.
- File names, folders, tags, covers and the lyrics you save or edit.
- Your playlists, favourites, play counts, listening history and statistics.
- Anything you type — searches, server addresses and passwords, and the Wi-Fi Transfer PIN.
The library is a database inside the app’s own container. Passwords and sign-in tokens are held in the iOS Keychain. Deleting the app removes the container and everything in it; the Files app folder of your music goes with it unless you moved it elsewhere.
03 Usage analytics and crash reports
To understand which parts of the app are used and where people get stuck, Turbo Music sends anonymous usage events through Google Analytics for Firebase, and crash diagnostics through Firebase Crashlytics. Google acts as our processor for both.
What is sent
- Screen views, and feature events carrying only counts and kinds — that an import finished and how many files it brought, which source was used, that a sleep timer was set, and a coarse reason when something failed.
- Purchase events — which plan was bought or restored, and whether it succeeded.
- Device model, OS version, app version, language and country, plus a pseudonymous app-instance identifier generated by Firebase.
- For a crash: the stack trace, the app state at that moment, and the same device fields.
What is never sent
No song titles, artists, file names, folder paths, station or podcast names, addresses, or anything you have typed. We never call Firebase’s user-identifier API, so events cannot be tied to a person. Where the law requires consent, analytics storage follows the choice you make in the consent form described in section 4.
04 Advertising in the free version
The free version can show advertising supplied by Google AdMob, which acts as an independent controller of the data it receives under Google’s privacy policy. No ad plays over your music, none appears in the full-screen player, during setup or on the purchase screen, and Premium removes advertising entirely.
To request, show and measure an ad, the SDK may process your device’s advertising identifier (IDFA, only if you allow it), the IDFV, IP address, device and operating-system information, a coarse location derived from that IP address, and your interaction with the ad. Nothing from your library is ever part of an ad request.
- App Tracking Transparency. iOS asks your permission before the advertising identifier may be used. Decline and ads are non-personalised. You can change the answer in Settings › Privacy & Security › Tracking.
- Consent in the EEA, the UK and Switzerland. Where required, Google’s consent form (UMP) is shown before personalised advertising or analytics storage is enabled, and it can be reopened from the app’s settings.
05 Purchases and subscriptions
Premium is sold through Apple’s In-App Purchase system using StoreKit. Apple takes the payment and holds the payment details; we never see your card, your billing address or your Apple Account credentials. The app keeps only the entitlement on the device, checked against Apple’s service. Refunds are handled by Apple at reportaproblem.apple.com.
06 App lock and recovery code by e-mail
If you lock the app, the passcode check is held in the iOS Keychain on the device and never leaves it. If you add a rescue e-mail address and then ask for your recovery code to be mailed, the app sends that address and the recovery code over HTTPS to our mail relay, which uses them only to deliver that one message. Nothing else about you or your library is sent. If you never ask for a mail, nothing is sent at all — adding an address only stores it on your device.
The link in that mail opens the app. The code travels in the part of the link a browser never sends to a server, so it does not reach this website either.
07 Services the app looks things up with
A few features need to ask a public service a question. Each request goes from your device straight to that service, carries only what the question needs, and is answered under that service’s own privacy policy. Like any request, it shows the service your IP address.
- Lyrics — LRCLIB is sent the title, artist, album and length of the song whose lyrics you open.
- Tags and covers — Apple’s iTunes Search, MusicBrainz and the Cover Art Archive are sent the title, artist and album you look up, only when you ask.
- Podcasts — Apple Podcasts, Podcast Index and fyyd are sent your search terms; the feeds you subscribe to are fetched from their publishers, who see the request like any podcast app’s.
- Radio — the radio-browser directory is sent your searches and filters; a station you play streams from its own server.
- The lyrics model is downloaded once, after you agree, from our content server; the request carries nothing about you or your music. The songs themselves are separated and recognised on the device, using Apple’s on-device speech recognition — audio is never sent to a server, and a language with no on-device model is refused rather than uploaded.
08 Accounts and servers you connect
In every case the connection goes from your device straight to the service you chose — it does not pass through us, and we receive no copy of anything.
- Cloud accounts (Google Drive, Dropbox, Yandex Disk): you sign in with the provider’s own screen, and the token it hands the app is stored in the Keychain.
- Your own server (SMB, WebDAV, Nextcloud, FTP, SFTP, S3) and media servers (Jellyfin, Emby, Plex): the address and credentials you enter are stored in the Keychain and used to talk to that server directly. SFTP remembers the server’s key and refuses a different one.
- DLNA / UPnP devices are discovered and reached on your local network only.
- Last.fm and ListenBrainz, if you connect them, receive the title, artist, album and time of the songs you play — that is what scrobbling is. Disconnect and nothing more is sent.
- iCloud sync of playlists, favourites, subscriptions and play counts is stored in your own private iCloud database. Apple holds it for you; we cannot read it.
- Wi-Fi Transfer and sending to a nearby device run only on your local network or directly between devices, and Wi-Fi Transfer is gated by a PIN.
09 MP3 Converter
When you choose an action MP3 Converter performs — trim, ringtone, convert, repair — the file is placed in a storage area shared only by our own apps on your device, and handed back the same way. Nothing leaves the device. If MP3 Converter is not installed, the App Store page is shown instead.
10 When you write to us
Contact Us opens your own mail app with the topic and message you wrote, addressed to [email protected]. The app version, OS version, device model and language are added only if you leave that switch on, and nothing about your library is ever included. You send the mail yourself; we receive only what you send.
11 Permissions the app asks for
Each request happens only when you use the feature that needs it, and declining one disables that feature and nothing else.
- Photos — to import the videos and audio you pick.
- Media & Apple Music — to read the songs in your Apple Music library and bring in the ones without copy protection. The library is read on the device and never sent anywhere; the app does not change it.
- Speech recognition — to write lyrics on the device.
- Local network — for Wi-Fi Transfer, SMB and DLNA on your own network.
- Bluetooth — to send a playlist to a nearby device.
- Notifications — for new podcast episodes and finished transfers.
- Face ID / Touch ID — only if you add them to the app lock; the match happens inside iOS.
- Tracking — see section 4.
Turbo Music never asks for your location, contacts, calendar, camera or microphone.
12 Retention and deletion
- Files and library data — on your device until you delete them or remove the app; items in the bin are removed after thirty days.
- iCloud sync data — in your iCloud account until you turn sync off and delete it there.
- Analytics and crash events — retained by Google for a bounded period (currently 14 months).
- Advertising data — retained by Google under its own policy.
13 Children
Turbo Music is a general-purpose player and is not directed at children under 13, or the equivalent minimum age where you live. We do not knowingly collect personal data from them and hold no account data by which a child could be identified.
14 Your rights
Depending on where you live you may have the right to access, correct or delete personal data we hold about you, to restrict or object to its processing, to withdraw a consent you gave, and to complain to your supervisory authority — under the GDPR (EEA and UK), the KVKK (Türkiye), the CCPA/CPRA (California) and the UAE Personal Data Protection Law, among others.
We do not sell personal data and we build no profiles of individuals. To exercise a right, write to [email protected]. Because there is no account, we often cannot match a request to data we can identify as yours — that is a consequence of collecting so little, not a refusal.
15 International transfers
Google, Apple and the services named in sections 7 and 8 operate globally and may process data outside your country, including in the United States, under the transfer mechanisms set out in their own policies, such as the EU Standard Contractual Clauses.
16 Changes to this policy
When this policy changes materially — a new processor, a new category of data — the date at the top changes with it, the App Store privacy labels for Turbo Music are updated to match, and where the change affects what is collected we ask for your consent again inside the app.
17 Contact
Privacy questions and data requests: [email protected]
Help with the app: [email protected]
Legal notices: [email protected]
Turbo Ventura
Dubai, United Arab Emirates