Addit
Hollowpoint Collective

Addit — Privacy Policy

Addit has no servers. Your music, your account details and your listening all stay on your device or inside your own cloud storage. We have no infrastructure that could receive them, and no analytics or advertising code in the app.

Addit is an iOS music player that plays audio you already keep in Google Drive, Microsoft OneDrive, or on your iPhone. This policy explains what the app touches, where it stays, and the few narrow cases where something reaches us.

What stays on your device

All of the following is written only to Addit's own storage on your iPhone. None of it is transmitted to Hollowpoint Collective.

Your cloud storage

When you connect a Google or Microsoft account, Addit talks to that provider directly from your device. Nothing is proxied through us.

Google Drive

Addit requests Google's full drive scope, plus the basic sign-in scopes (openid, email and profile). It needs the full scope because albums are ordinary Drive folders that you or your collaborators own — including folders shared with you by other people, whose contents change over time — and a narrower scope grants access one file at a time, which cannot reach a folder's contents.

What Addit accesses. From your Google account: your email address, name and profile-photo URL. From Google Drive: the names, identifiers, types, sizes, dates and descriptions of folders and files; the audio files in the folders you add as albums; album artwork; each album's .addit-data file; who an album's folder is shared with (their names, email addresses and roles); the comments that make up album chat; and how much storage you have used.

What it does with it, each only when you use the feature concerned:

Addit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the features described above. It is never sold, never transferred to third parties except as described under "Who your data goes to", never used for advertising, and never read by a human — including us — except where you have explicitly asked us to help with a problem, or where required by law. Addit does not create aggregated or anonymized data from it, does not use it to develop, improve or train artificial-intelligence or machine-learning models, and does not send it to any AI service.

Microsoft OneDrive

Addit uses Microsoft Graph with the permissions needed to read and write files in your OneDrive, for the same purposes described above. The same restrictions apply: no selling, no advertising, no transfer beyond what the feature itself requires. A track you delete goes to the OneDrive recycle bin.

Album chat

Addit's per-album chat is built on Google Drive's comments feature. Messages you send are stored by Google as comments on the album's .addit-data file, and are visible to anyone you have shared the album's folder with. They do not pass through us, and we cannot read them.

Who your data goes to

The app sends none of it to us. Google user data moves only between your iPhone and Google, and it is never sold, rented, or passed to advertisers, data brokers or anyone else. The one thing that reaches our website is what you put in a link you share — its album title and artist, read from the address to draw the link's preview. We don't store them; our host, Cloudflare, may cache a preview for up to an hour, including the cover image of a folder that is already shared with anyone who has the link.

It reaches other people or services only where you direct it to:

How your data is protected

How long it's kept, and deleting it

Sharing a link

When you share an album or a song, Addit builds a link pointing at the folder in your cloud storage. So that the link shows a card instead of a bare address, it carries the album's title and artist in the address itself, along with the identifier of the cover file. All of that is read from your own device at the moment you tap share — we are not consulted, and nothing about the link is stored on our side.

In Messages, the cover you see in the card is the one already on your phone: Addit attaches it to the message itself. That is why the card looks right even for an album nobody else can open — the image travels inside your message, not through us.

Pasted anywhere else, the card's image is fetched by our server from your cloud provider with no credentials of any kind. It therefore appears only when the folder is already shared with anyone who has the link, and falls back to a plain tile otherwise. It can never surface a cover your provider would have withheld from a stranger making the same request.

Before you share an album whose folder is restricted, Addit says so and asks you to confirm. The person you send it to will not be able to open the album — but the title and artist travel with the link either way, so the choice is yours to make knowingly.

Photo library

If you choose an album cover from your photo library, Addit reads only the image you select and copies it into the album. It does not browse, index or upload anything else, and it does not request access until you ask it to pick a photo.

Bug reports

"Pls report bugs" in the app composes an email to us. Because Addit has no server, it hands the message to your own mail app rather than sending anything itself: you see the complete message and press send yourself, from your own email account. Nothing leaves your device unless you do that.

The message contains whatever you type, plus a single automatically appended line with the app version and build number, your iOS version, and your device model (for example iPhone17,1). That line is visible to you in the composer before you send, and you can delete it.

Because you send it by email, we necessarily receive the email address you send from. Reports are used only to diagnose and fix problems, and are not added to any mailing list. Ask and we will delete yours.

The beta

Addit's beta is open to anyone through Apple's TestFlight, from the link on hollowpoint.tv/addit. We don't ask you for anything to let you in. TestFlight is Apple's service and is covered by Apple's privacy policy; through it, Apple may share with us information about how the beta is running, such as crash reports, and any feedback you choose to send through TestFlight. We use that only to find and fix problems.

This website used to keep a waitlist for the beta. It no longer does. The addresses given to it before 28 September 2026 are not sold, shared or used for anything else; they are deleted in full when the beta ends, and yours is deleted sooner if you ask at the address below.

What Addit does not do

Addit uses Google's official sign-in library to authenticate with Google. That library is governed by Google's privacy policy. Microsoft sign-in is handled by Apple's own ASWebAuthenticationSession talking to Microsoft, covered by Microsoft's privacy statement.

Children

Addit is not directed at children under 13, and we do not knowingly collect information from them.

Your control

Changes

If this policy changes materially, the effective date above will change and the revision will be posted at this address.

Contact

Questions about this policy, or requests concerning your information: legal@hollowpoint.tv