Privacy Policy
In short: Kalinka does not collect, store or share your personal data. There are no accounts, no analytics, no advertising and no tracking. The app talks to the Kalinka server you run on your own hardware, and nothing it sends there reaches us. Some features fetch things from the internet, such as album art and updates; they are listed below.
Who we are
Kalinka Player is an independent, open-source project. The source code for the server and the apps is public, so anyone can check what the software does. For any privacy question, contact support@kalinkaplayer.com.
How Kalinka works
Kalinka has two parts: a server that you install on a Linux machine you own, and remote-control apps (Android, Windows, Linux or a web browser) that connect to that server over your local network.
When you use the app, it exchanges information with your server so that it can do its job: browsing your library, running searches, managing the play queue, controlling playback and changing settings. This information goes to the server you chose. It is not sent to us, and we have no access to your server, your music collection or your searches.
Mood search runs on your own server: a model on the server matches your words against your music, with no cloud service involved. If you connect Jamendo, your searches also go to Jamendo, as described under When Kalinka goes online.
Data we collect
None. The Kalinka apps and server do not include analytics, advertising or tracking libraries, and do not send usage data, crash reports or identifiers to us.
If this ever changes, for example if we add crash reporting to help fix bugs, it will be opt-in, we will update this policy before the change is released, and we will describe exactly what is sent.
Logs you choose to send us
To help you report a problem, the app can download your server's logs as a ZIP file (Settings › General › Support › Download server logs). Downloading the logs does not send them anywhere: your server prepares the file, the app saves it on your device, and the server deletes its copy after 30 minutes. Nothing is uploaded to us.
If you choose to email the file to us, we receive what it contains: file and track names, listening times, device names, addresses on your local network, and the versions of Kalinka, its plugins and your operating system. The server leaves out lines that look like passwords or keys. You can open the file and check it before you send it. If you attach it to a GitHub issue instead, anyone can read it.
We use logs and support emails only to answer your request and fix the problem, we do not share them, and we delete them once they are no longer needed for that.
Data stored on your device and your server
The app keeps a small amount of information on your phone or computer: the name and address of your Kalinka server, your app preferences and saved filters, and your last five searches, which you can clear from the search screen. The browser player also keeps a random identifier so that your server can tell it apart from other players.
Your server stores your library index, including details it looks up online and data for AI search, along with your playlists, play queue, settings and the configuration of any plugins you enable. Passwords and keys that plugins need, such as for a network share or Jamendo, are kept in a settings file that only the Kalinka service can read. They are not encrypted, and they are never sent to the app or to us. The server does not keep a listening history or play counts. Its logs go to the system journal on the server, can include file paths, searches and device names, and are removed automatically as the journal fills up. All of this stays on hardware you control.
You can remove the app's data by uninstalling it or clearing its storage, and you can remove server data by deleting it from the server. If you use Android's device backup, Android may include the app's data in your backup, which Google stores under its own privacy policy.
Permissions the Android app uses
- Network accessTo find your Kalinka server on your local network and connect to it.
- NotificationsTo show what's playing, with playback controls, in the notification shade and on the lock screen. Android shows the track, artist and cover art there, and may pass them to devices you connect, such as a car or a watch.
- Background playbackTo keep those controls working while the app is in the background.
- VibrationFor haptic feedback when you use the controls.
The app does not ask for location, Bluetooth, contacts, camera, microphone or storage permissions. The permissions above are used only for the features described, not to collect information about you.
When Kalinka goes online
Kalinka works on your local network, but some features need the internet. In each case below, your server or the app contacts the service directly, without going through us. Every service it contacts receives your IP address and handles it under its own privacy policy.
- Music information · on by defaultTo add album covers, artist photos, genres and other details, your server looks up the artist, album and track names from your music files on MusicBrainz, Wikidata and Wikimedia Commons, Deezer and the Cover Art Archive. You can turn each source off, or all of them at once, in My Library's settings. If you add your own AcoustID key, the server also sends audio fingerprints of your tracks to AcoustID to identify them.
- Update checks · always onOnce an hour, your server asks GitHub whether a new version of Kalinka is out. The request carries nothing about you or your music.
- AI search modelsWhen the server first starts, it downloads the model and index for Jamendo mood search from GitHub. If you turn on AI search for your own library, it downloads that model too. After that, searching does not need the internet.
- Jamendo · once you add a Client IDYour server sends Jamendo the searches you type, your browse filters and the IDs of tracks that mood search found. The music and its cover art then come directly from Jamendo to your player and the app.
- Browser player fontThe browser player is served by your own server, but each time it opens it downloads a font from Google Fonts.
- Cover art from other sourcesWhen you browse another media server on your network, the app may load cover art directly from it, and that server can tell which cover was requested.
- Installing and upgradingInstalling or upgrading Kalinka downloads install scripts from kalinkaplayer.com and Kalinka's packages from GitHub, and installs other software from your Linux distribution's package repositories and from Python's package indexes (PyPI and piwheels). The ready-made images are built on Debian, or DietPi on Raspberry Pi, whose own update tools may contact those projects' servers. kalinkaplayer.com and GitHub may keep standard technical logs of these requests, such as IP addresses and times. We do not use them to identify or track anyone.
Jamendo and any other sources are added through plugins that you enable yourself, so please read those services' privacy policies before you connect them.
This website
kalinkaplayer.com has no accounts, no analytics, no advertising and no cookies. It is hosted on Cloudflare, which handles every request and may keep standard technical logs of it.
The Jamendo mood search page runs your search on our Cloudflare server. To stop any one visitor from overloading it, the server remembers your IP address for about a second; it does not store it. Searches are cached for up to an hour by their text alone, without your IP address, so repeated searches can be answered quickly. Error logs and request logs, which can include the search text and your IP address, are kept by Cloudflare for a few days to keep the service running and are then deleted automatically. The cover art and music on that page are loaded directly from Jamendo, which receives your IP address under its own privacy policy.
The pages load fonts from Google Fonts, and the homepage asks GitHub for the latest version numbers, so your browser contacts Google and GitHub, which receive your IP address. Your browser also remembers, on your own device only, a few things that make the site faster or quieter: the latest version numbers for an hour, and whether you closed the banner on the Jamendo page.
Network security
On your local network, the app and your server communicate over plain HTTP, which is not encrypted. That includes your searches and any passwords you type into the server's settings, for example for a network share. The server also does not ask anyone to sign in, so anyone on the same network can control playback, change settings and download the logs. Run Kalinka on a network you trust, such as your home network.
Children
Kalinka is not directed at children under 13 and does not knowingly collect personal information from anyone, including children.
Your rights
Because we do not collect or hold personal data about you, there is nothing for us to access, correct or delete. If you have emailed us, you can ask us to delete your messages and anything you attached. If you think we hold other information about you, or have any other privacy concern, contact us at support@kalinkaplayer.com. If you are in the UK or EU, you also have the right to complain to your data protection authority (in the UK, the Information Commissioner's Office).
Changes to this policy
We will update this page if Kalinka's handling of data changes, and change the effective date at the top. Significant changes will also be noted in the release notes.
