Privacy Policy
Last updated: July 19, 2026
Cyrics ("we," "our," or "us") is operated by Steven Hsu. This Privacy Policy explains what information we collect through the Cyrics mobile app and support website, how we use it, and your rights in relation to it.
Information We Collect
We may collect the following types of information:
- Usage and analytics data (anonymized) - Apple may provide aggregated app analytics and diagnostics if you have enabled sharing with app developers.
- Device and app information - device type, iOS version, app version, and identifiers necessary for app functionality, diagnostics, purchases, widgets, and Live Activities.
- Music playback information - currently playing track metadata such as title, artist, album, duration, playback position, artwork URL, track identifiers, and provider information.
- Subscription and purchase data - StoreKit entitlement and product information processed by Apple; we do not store your payment details.
- Lyrics data - lyrics, lyric timing, translation, romanization, and cached lyric data needed to display lyrics in the app, widgets, and Live Activities.
- Social account and profile data - if you create a Cyrics social account, we collect your phone number, display name, username, birthday, profile photo, account settings, friend relationships, contact discovery preferences, push tokens, and related account state.
- Contacts data - if you allow contact access, Cyrics processes phone numbers from your contacts to help find friends. Contact matching uses hashed phone numbers where possible, and contact access can be skipped.
- User content - if you use social features, we may store posts, captions, kudos, direct messages, shared track or Journey previews, moderation reports, block records, and related metadata needed to operate those features.
- Station data - while you participate in a private Station, we temporarily process membership, invitations, queue activity, contributor attribution, the host's playback state and availability, and Station control requests. Station data is deleted when the host ends the Station or after the host remains offline long enough for the Station to expire.
- Live Activity data - when you use Pro Live Activity, Lock Screen, or Dynamic Island lyrics, your device may send an ActivityKit update token, Live Activity session ID, current playback state, track metadata, synced lyric schedule, and, for Spotify playback continuity, a Spotify access token to our push notification server. This data is used to deliver real-time lyric updates and is intended to expire after the activity ends or after a short retention period.
- Journey data - if you record a Journey, Cyrics stores route coordinates, song pins, timestamps, lyric snapshots, and selected photos on your device. If you are signed in with a Cyrics social account, Cyrics also backs up recent Journey archives (route, song pins, and photos) to our cloud storage so you can restore them on another device. Guests who do not create a social account keep Journeys on-device only unless they export or share them.
Music Service Integrations
Cyrics integrates with Apple Music via MusicKit and Spotify via the Spotify iOS SDK. When you connect these services, Cyrics reads your currently playing track and playback state to retrieve and display matching lyrics. Cyrics does not store your music library or full listening history on our servers. Spotify access tokens may be stored on your device and may be sent temporarily to our Live Activity push server when needed for Pro Live Activity playback updates.
Social Features
Cyrics social features are optional. If you create a Cyrics social account, we use Firebase services to authenticate your phone number, store your profile, help match friends, deliver direct messages, publish posts you choose to share, and send notifications. You can skip contact access and use the core lyrics app without a social account.
Posts, direct messages, kudos, friend relationships, block records, and moderation reports are stored on our backend so the social features can work across devices and so we can respond to safety concerns. You can report posts or messages and block other users from inside the app. We may remove content or limit access when necessary to enforce our Terms or protect users.
Stations
Stations are private, temporary listening rooms for signed-in Cyrics users. A Station can be joined only through a friend invitation, six-digit code, or shareable link supplied by the host. The host's Apple Music account and device provide the audio; other members can collaborate on the queue and, when allowed by the host, request playback controls. Cyrics stores only the live Station state needed to operate the room and hard-deletes it when the Station ends or expires. Anyone who receives a valid code or link may join while the Station is active, so share credentials only with people you intend to invite.
Location
Cyrics uses location only while you record a Journey. Continuous location updates may continue after the app is backgrounded or your phone locks so the route and song pins stay accurate; this uses additional battery. Location data is used to record your route, place song pins, and attach selected photos to route positions. Journey routes, photos, and song pins are stored on your device. For signed-in social accounts, recent Journey archives that include route coordinates and photos are also uploaded to our private cloud backup (owner-only access) until you delete them or delete your account. Guests remain local-only unless they export or share a Journey. Review shared Journey images before sending them, because they may reveal route, location, photo, and listening details.
Analytics
We use Apple's built-in developer analytics tool to understand app usage and improve the user experience. To opt-out of analytics tracking, please go to Settings > Privacy & Security > Analytics & Improvements and toggle off "Share with App Developers".
Purchase Management
Subscriptions are managed through Apple's App Store purchase system. We do not store any payment information. To manage subscriptions, please go to Settings > [Your Name] > Subscriptions.
Lyrics
Lyrics are sourced from LRCLIB and, for Pro requests, from Cyrics-hosted lyrics services that may query additional lyrics sources. We do not claim ownership of any lyrics content. Track metadata is sent to lyrics services so they can return matching lyrics. Lyrics may be cached on your device, and synced lyric schedules may be sent temporarily to our Live Activity push server to keep Lock Screen and Dynamic Island lyrics in sync.
How We Use Your Information
We use collected information to:
- Provide and improve Cyrics and its features
- Deliver real-time lyric updates to your Lock Screen and Dynamic Island
- Manage purchase entitlements
- Operate optional social features, friend discovery, messaging, reporting, blocking, and moderation
- Operate private, temporary Stations and synchronize their collaborative queues and playback state
- Back up signed-in Journey archives privately so you can restore recent trips across devices
- Analyze anonymized usage patterns to improve the app experience
- Maintain app security, prevent abuse, and diagnose technical issues
Data Storage and Security
Some Cyrics data, including cached lyrics and appearance settings, is stored locally on your device or in the app group shared with Cyrics widgets and Live Activities. Journey data is stored on-device and, for signed-in social accounts, recent Journey archives are also stored in private cloud backup. Social account data, posts, messages, moderation reports, and push tokens are stored on our backend when you use those optional features. Pro Live Activity sessions are processed by our cloud push service and are intended to expire when the Live Activity ends or after a short retention period. We use reasonable technical and organizational measures to protect data. We do not sell your personal information to third parties.
Your Rights
Depending on your location, you may have rights to access, correct, or request deletion of personal data we hold about you.
If you created a Cyrics social account, you can delete it in the app under Settings → Account → Delete Account. Deletion is scheduled with a 7-day grace period. Signing back in with the same phone number before then cancels deletion and restores the account. After the grace period we permanently delete your Auth account, social profile, posts, messages, moderation records we can associate with you, and cloud Journey archives. Local Journey history that remains only on your device is not wiped by cloud deletion. You can also contact the developer at stevenhsu5679@gmail.com for residual privacy requests.
Children
Cyrics is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
Third-Party Services
Cyrics uses the following third-party services, each governed by their own privacy policy:
- Apple App Store, StoreKit, MusicKit, developer analytics, Apple Push Notification service, and on-device Translation where available (Apple Inc.)
- Spotify iOS SDK (Spotify AB)
- LRCLIB (open community database)
- DigitalOcean (cloud hosting for lyrics and Live Activity push services)
- Firebase and Google Cloud (authentication, database, storage, cloud functions, messaging, and moderation support for optional social features)
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last updated" date.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: stevenhsu5679@gmail.com