MusicControl
Privacy
How MusicControl uses information, which services receive it, and the choices you control.
Who is responsible
The controller of the personal data described here is Seoksoon Jang, an individual trading as Studio Moota, in Seoul, Republic of Korea. Email hello@moota.studio for anything in this notice, including to exercise any of the rights set out below. Email is how to reach us, and a request sent there is answered by a person.
This notice covers MusicControl only. Each app we make has its own, because each asks your Mac for different things and touches different material. The website has its own notice as well.
Optional analytics and crash reports
Usage analytics and crash-report uploads are off when MusicControl is first installed. You can enable them separately in Settings. Choosing to send a waiting crash report also turns crash reporting on.
Turning off usage analytics stops its collection and resets the analytics identity on this Mac. Turning off crash reporting stops future crash uploads. Neither action deletes reports already sent to a provider.
A crash report may be held on your Mac until you decide whether to send it. Discarding it deletes that waiting report. It is not uploaded while it waits for your decision.
These choices cover analytics and crash reporting. Licence checks, downloads and the network features described below have separate purposes.
What can be sent, and on what basis
The apps share the following services. App-specific requests are described separately below.
- Usage analytics — consent
- Our usage events contain a fixed list of command names, rounded counts, rounded durations and yes/no flags. Rounding reduces detail; it does not make an installation anonymous. Google Analytics also processes standard app and device information and an analytics identifier for the installation. Basis: your consent, withdrawable in Settings.
- Crash reports — consent
- Crash traces, app and device diagnostics, timestamps and installation identifiers, processed by Google Firebase Crashlytics. Diagnostics can include exception messages and loaded software information. We restrict the custom fields MusicControl adds, but those restrictions do not describe every standard diagnostic field. Basis: your consent, withdrawable in Settings.
- Licence checks — performance of a contract
- Your licence key and an instance name, sent to Lemon Squeezy to confirm the licence is valid and how many Macs are using it. The instance name is the app name plus eight characters of an identifier generated at random on your Mac and stored there. It is not derived from your hardware, your serial number, your network address or your name. It identifies an installation so activations can be counted, and nothing else.
This website and update feeds use Firebase Hosting. Installer and update archives are delivered through GitHub Releases. Requests can expose an IP address, time and requested resource to the delivery provider. These requests serve the download or update you requested or enabled.
What we keep out of usage reports
We do not add a track or an artist, what you listen to, a file path, a URL, an email address, a licence key, the contents of your screen, error text to our usage events or custom crash details.
These events and custom crash fields are checked against a fixed list of allowed names and values. This boundary does not cover licence validation, completion prompts, music-service requests or the standard diagnostics described above.
We do not add a customer name or email to analytics events or crash reports. Installation identifiers can still distinguish installations; these reports should not be treated as anonymous.
What MusicControl asks your Mac for
macOS controls protected permissions such as Accessibility, Automation and Screen Recording. You can review or withdraw those grants in System Settings › Privacy & Security. A local permission grant and a network request are separate; the app-specific sections explain network use.
- Now Playing
- the information macOS already publishes about what is playing, without a separate permission prompt. Core control needs neither Accessibility nor Automation.
- Automation (Apple Events)
- only for the parts that reach into another app: reading songs and playlists from Music so you can search them here, and showing the exact browser tab when you choose Open Source. macOS shows you this as: “MusicControl reads songs and playlists from Music so you can search and play them here. It also controls the exact browser media tab and shows it when you choose Open Source.”
Music services and lyrics
Lyrics lookup sends the track title, artist, and where available album and duration to LRCLIB. A manual lyrics search sends the search query. These requests are needed to find matching lyrics.
YouTube features request video metadata, artwork and video playback from Google or YouTube. Those requests can include video identifiers. Connecting a YouTube library uses your Google authorization to access the library; searches and library requests go to Google.
These services receive ordinary connection information, including your IP address, when a feature contacts them. Their privacy policies apply to their services. Turning off usage analytics or crash reporting does not stop network requests needed for lyrics, artwork, video or a connected library.
Who receives what
- Google Ireland Ltd / Google LLC
- Google Analytics and Firebase Crashlytics. Receives only what is described above, and only after you consent.
- Lemon Squeezy LLC
- Merchant of record for the sale, and the licence service. Receives your email address, billing and tax details as a payment requires, and licence keys and instance names as checks require. We never see your card details.
- Google (Firebase Hosting)
- Serves this website and the update feed. Keeps standard server logs.
- GitHub
- Delivers installer and update archives. Receives connection and request information when you download them.
We do not sell personal data, and we do not share it for advertising. There is no advertising in these apps and no advertising network in them.
Where it goes
Google, Lemon Squeezy and GitHub operate internationally. Requests and records can be processed in the United States and other countries outside where you live. The app-specific external providers described above also process the requests you send to them.
The providers describe their locations and transfer safeguards in their published privacy and processing terms: firebase.google.com/support/privacy/, lemonsqueezy.com/privacy and docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement. These are provider disclosures; this notice does not certify a particular contractual safeguard for every transfer.
How long it is kept
- Usage analytics
- The Google Analytics event and user retention settings are 2 months, with extension on new activity turned off. These settings were saved on 14 September 2026 and Google allows 24 hours for changes to take effect. Standard aggregate reports are not covered by this retention setting.
- Crash reports
- Google states that Crashlytics retains crash traces and associated identifiers for 90 days before starting removal from live and backup systems.
- Licence records
- Kept by Lemon Squeezy for as long as the licence exists, and afterwards for as long as tax and accounting law requires them to keep a record of the sale.
- Delivery records
- Google states that Firebase Hosting retains IP data for a few months. GitHub applies its own privacy and retention policy to archive-download requests.
Your rights
You can ask what we hold about you, ask for a copy, ask for it to be corrected or deleted, ask us to restrict or stop processing, and object to processing. Where processing rests on consent, you can withdraw it — in the app, immediately, without asking us.
Write to hello@moota.studio. We answer within one month.
If you are in the UK or the EEA you may also complain to your data protection authority. In the UK that is the Information Commissioner’s Office.
Our analytics and crash reports use installation identifiers rather than your customer name or email. We may need additional information to locate a report. We will explain what we can identify and act on.
Automated decisions, and children
There is no automated decision-making with legal or similarly significant effects, and no profiling.
These are productivity and developer tools for adults. They are not directed at children, and we do not knowingly collect anything from anyone under 16.
Changes
If this notice changes in a way that affects what is collected, MusicControl will say so in the app before the change takes effect, not after. The date at the top is when this version was published.
