Leap Music Privacy Policy
Leap Music plays music you already own — in your own OneDrive or Google Drive, or already on your iPhone. It has no music server of its own, keeps no copy of your library, and never sends your files or their names anywhere.
The short version
Leap Music is a player, not a service. It talks to Microsoft and/or Google to sign you in and to read the folder you choose, and it can read the songs already stored on this iPhone. Everything else stays on the device.
There is no advertising, no ad identifier, and no tracking of you across other apps or websites. Solo Leap Inc. runs no music server for this app and never receives your files or your library.
Leap Music does measure anonymous, aggregated usage of its own features so we can tell what is worth improving. That measurement never includes your files, their names, your folder names, your track, album or artist names, your e-mail address or your credentials.
Signing in with Google
Sign-in uses Google’s OAuth 2.0 authorization-code flow with PKCE in an ASWebAuthenticationSession. There is no client secret, and Leap Music never sees your Google password.
Leap Music requests drive.readonly so it can list and read the audio files in the folder you choose. It also requests userinfo.email and userinfo.profile so Settings can show which account is signed in.
Access and refresh tokens are stored in the app’s own keychain access group on your device and are deleted when you sign out.
Your Google name, email and profile picture are read once for the Settings screen, are never transmitted anywhere else, and are discarded on sign-out.
Your Google Drive library
When you pick a folder, Leap Music lists that folder and its subfolders directly from the Google Drive API on your device, reading audio metadata such as title, artist, album, release year, duration and file ids.
Playback streams directly from Google’s own download URLs to your device.
Artwork comes from a Drive thumbnail or by reading only the leading tag bytes of the audio file itself with a range request.
Access is read-only. Leap Music never creates, edits, moves or deletes anything in your Drive, and your files are never copied to any Solo Leap system.
How your data is protected
There is no Solo Leap server in the middle. Leap Music talks straight from your device to Microsoft and Google, so your files, your file listings and your credentials never pass through, and are never stored on, any system Solo Leap operates. There is no company database holding your data to be breached, and no employee, contractor or automated process at Solo Leap can reach your Drive content.
In transit: every request the app makes is HTTPS, protected by TLS. Leap Music ships with no App Transport Security exemptions, so iOS and macOS refuse any cleartext connection the app might attempt, and the OAuth exchange itself uses the authorization-code flow with PKCE inside a system ASWebAuthenticationSession — there is no embedded client secret and your password is entered on Google’s own page, never in the app.
At rest, credentials: Google access and refresh tokens are held in the operating system’s Keychain, encrypted by the system with keys protected by the device hardware, in an access group private to this app. They are marked as readable only after the device has been unlocked once since it was switched on, and they are never marked for synchronisation, so they are not copied to iCloud Keychain or to any other device.
At rest, content: the cached track listing is written with the system’s complete-until-first-user-authentication file protection, so it is encrypted on disk while the device is locked after a restart. Cached audio lives inside the app’s sandboxed container under the same operating-system Data Protection, and the temporary skip-ahead cache is additionally excluded from iCloud and iTunes backups. Nothing the app stores is readable by other apps.
Least privilege: Leap Music asks Google only for drive.readonly, which cannot create, modify, move or delete anything in your Drive, plus your email and profile so Settings can show which account is signed in. It requests no write, no delete and no administrative scope, and it reads only the folder you choose rather than your whole Drive.
Retention and deletion: signing out deletes the stored tokens, the cached library and the folder you selected. Deleting offline downloads removes those files immediately, and deleting the app removes every cached track, setting and credential it held. You can also revoke the app’s access at any time at https://myaccount.google.com/permissions, which invalidates the tokens on your device.
No secondary use and no onward transfer: the anonymous usage measurement described under Analytics records only how Leap Music’s own features are used, and is kept strictly separate from your library. No Google or Microsoft user data ever enters it — no file contents, file names, folder names or file ids, no track, album or artist names, no search terms, no e-mail address or account identifier, and no tokens. The app carries no advertising SDK and no data-broker SDK. Google user data is never sold, never transferred to a third party, never read by a human, and never used to train AI or machine-learning models.
If you believe you have found a security problem in Leap Music, please report it to sololeapinc@gmail.com and it will be investigated.
Google Limited Use
Leap Music’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the music library, playback, artwork, account display and offline caching features you can see in the app. It is never used for advertising, never sold, never transferred to third parties, never read by a human, and never used to train AI or machine-learning models.
Analytics
Leap Music uses Google Analytics for Firebase to count how its own features are used — for example whether a library scan succeeded, whether offline downloads are used, or which screen playback usually starts from. These events are anonymous and aggregate.
Leap Music does not set a user identifier, does not use the advertising identifier (IDFA), does not ask for tracking permission, and does not build a profile of you. Events are counted against the anonymous app-instance id Firebase generates on this device.
Your music never enters analytics. No file, file name, folder name or file id, no track, album or artist name, no search term, no e-mail address, no account identifier and no credential is ever sent, so no Google user data reaches it and nothing in it can be used to reconstruct what you listened to.
Third parties
Microsoft is involved when you sign in with OneDrive, through the Microsoft identity platform and Microsoft Graph. Microsoft’s handling of those requests is covered by Microsoft’s privacy statement.
Google is involved when you sign in with Google Drive, through Google Sign-In and the Google Drive API. Google’s handling of those requests is covered by Google’s privacy policy.
Google is also involved as the provider of Google Analytics for Firebase, which processes the anonymous usage events described above under a Firebase account belonging to Solo Leap Inc.
Leap Music does not use advertising networks or data brokers, and no third party ever receives your files, your library or your credentials.