Privacy Policy
1. Who I am
Pladio is made and operated by Patrick Diezi, trading as KREANIQS, Lehmbergstrasse 8, 8514 Amlikon-Bissegg, Switzerland. I am the data controller for the purposes of the GDPR and the revised Swiss Federal Act on Data Protection.
Privacy questions: privacy@pladio.app. I answer within 30 days.
2. The short version
Pladio has no user accounts, no advertising, and no cross-app tracking. It does not ask permission to track you, because it has nothing to track you with: there is no advertising identifier and no App Tracking Transparency prompt anywhere in the app. Your favourites and your own stations are stored in your own iCloud, not on a server of mine.
Three things do leave your device: requests to the radio-station catalogue I operate, requests to third-party services that identify songs and fetch lyrics, and — only if you leave it switched on — anonymous product analytics.
3. What differs by platform
- Song recognition is available on iPhone, iPad, Mac (including the menu bar mini player), Apple TV, Apple Watch and CarPlay. On CarPlay the button identifies the current song but offers no re-identify gesture. The Apple Watch app shows recognition state relayed from your iPhone and sends your tap back to it; the iPhone performs the recognition.
- Location-based station filtering is available on iPhone, iPad and Mac. The Apple TV and Apple Watch apps do not use location at all.
- Lyrics are available on iPhone, iPad, Mac and Apple TV.
- Analytics are not sent from the Apple Watch app in this version. Its privacy manifest declares no collected data at all.
- Station alarms exist on iPhone and iPad only.
4. What Pladio stores about you
4.1 On your device and in your iCloud
- Favourites, recently played, and your own manually added stations. Stored in iCloud key-value storage so they follow you between your devices. Recently played is capped at the last 30 stations.
- Preferences — language, appearance, display settings, equalizer presets, sleep-timer presets, station alarms, volume and mute state, autostart.
- A local cache of the station catalogue, so the app opens and lists stations without a network round trip.
- A local usage counter for song recognition, kept in a small database on the device purely to stay within the daily limits of the recognition service.
I have no copy of any of this. It is in your iCloud account, under your control, and removing the app or turning off iCloud sync removes it. One qualification: if analytics are on, the name you give a station you add yourself is sent to PostHog as part of the "station created" event — the name, not the stream address or anything else — so I may see the names of stations you created, but hold no copy of the stations themselves.
Apple encrypts this data in transit and at rest. It is not end-to-end encrypted unless you have turned on Advanced Data Protection for your iCloud account, which is a setting on your side rather than something Pladio controls.
4.2 What leaves your device
-
Station catalogue requests to my own API at
api.pladio.app, which reads from a database I operate. These requests carry no identifier for you. - Short audio samples, only when you press the recognition button. The app takes roughly ten seconds of the station's own broadcast, from the stream — not from your microphone, so the sample contains no ambient sound and no voice of yours — sends it to ACRCloud for identification, and deletes its own temporary copy immediately afterwards. Pladio attaches no identifier to the sample. What reaches ACRCloud beyond the audio is what reaches any server you contact: your IP address and the time of the request. Samples go to ACRCloud's endpoint in the EU. ACRCloud itself is a Singapore company; any access to that data from outside the EU is governed by their policy. ACRCloud states that it does not retain samples after identifying them — that is their undertaking, on their systems, and I can vouch for what Pladio sends but not for what happens to it after that.
- Song title and artist to Apple Music, to fetch artwork and album details, and to add a track to your library when you ask it to.
- Song title and artist to the lyrics provider, only when you ask for lyrics. Both come from the station's broadcast or from a recognition match — not from anything you typed — and Pladio attaches no identifier. What reaches MusixMatch beyond that is what reaches any server you contact: your IP address and the time of the request. MusixMatch publishes no statement about how long it keeps lyrics requests: its privacy policy covers its own app and website, and its API terms are not public. I can vouch for what Pladio sends, not for what happens after receipt.
- Anonymous product analytics, if enabled — see section 6.
Pladio never listens on its own. Audio is sampled only in response to you pressing the button. Earlier versions sampled automatically on a schedule; 1.5.0 removed that.
4.3 What Pladio does not collect
Your name, email address or phone number. Your precise location. Your contacts or photos. Your Apple Music library contents. Any advertising or cross-app identifier. Biometric data. Payment details — those are handled entirely by Apple and never reach me.
5. Location
If you turn on the local-stations feature and grant permission, the app asks the system for your approximate position in order to sort stations by distance from you. It is used on the device, for that, and is not stored and not sent to any third party. You can revoke the permission at any time in system settings, and switch the feature off in Settings → Privacy.
6. Analytics
Pladio can send anonymous product analytics to PostHog: which features are used, session length, playback events, and health metrics for the station database. Events carry no account and no advertising identifier, and the app never calls PostHog's user-identification API, so events are attached only to a random installation identifier. One exception I have to name: the analytics library sends the device's name as a property. On iPhone, iPad, Apple TV and Watch that is a generic model name; on a Mac it is the computer's name, which may contain a personal name — and I can see it. A future version of the app will stop sending that property; this sentence stays until a shipped build has been measured not to.
You can switch this off in Settings → Privacy. When you do, Pladio stops sending analytics entirely: every event is dropped before it leaves the device, with no exception by category or event type.
That switch governs Pladio's own analytics, and nothing beyond them. It does not stop the app contacting the services you actually use: pressing the recognition button still sends an audio sample to ACRCloud, showing lyrics still sends a title and artist to MusixMatch, and playing a station still fetches the catalogue from my API. Those requests are how those features work. What each of those companies records at their own end is governed by their policies, not by a setting in Pladio.
Earlier versions of this policy described an exception, under which recognition and lyrics requests were logged even after opting out, for cost control. There is no such exception, and none will be built. The wording was wrong rather than the code, and building the exception would have meant collecting more from exactly the people who asked not to be measured. The switch is total.
Every request to any server carries your IP address, and PostHog is no exception. Since 3 September 2026, PostHog discards the IP address as each event arrives and derives no location from it — I switched both on that day, after finding that until then every event had carried the address and a city-level location derived from it, which I could see. Events recorded before that date still carry both, and will until they are deleted; the profile PostHog keeps per installation may also still show the last location derived before the change.
Analytics are processed in the European Union. Events are retained for up to seven years — the platform's default, which I have not shortened. An earlier draft of this page said 30 days; that was a misreading of a different setting, and it was wrong.
7. Crash reports and diagnostic logs
If you have enabled "Share With App Developers" in your device settings, Apple may send me anonymised crash reports. That is Apple's mechanism, not mine, and it is governed by your device settings. Pladio contains no third-party crash-reporting SDK.
Diagnostic logs are different: you send them, and they come to me. Settings → Support → Send Diagnostic Logs composes an e-mail to support@pladio.app with an attachment. Before it does, the app shows you exactly what the attachment contains, and it is this: the app's log entries (up to 5,000 lines, at debug level, which includes station names and stream addresses you played and the outcome of recognition and lyrics requests), the app version and build number, your device model, operating system version, language and region settings, and available storage space. Nothing is sent until you press send in your mail app, and you can read the attachment before you do. Once I have handled the e-mail I delete it; whatever is needed for follow-up work is carried over into a feedback ticket, and you are told when that happens.
8. Who else is involved
These are the services the app talks to, and what each one receives.
- Apple — iCloud sync of your favourites and settings; Apple Music for artwork, metadata and library changes; StoreKit for purchases. Pladio uses StoreKit directly and no third-party subscription provider, so I receive only an anonymised entitlement status: no payment details, no name, no email address.
- ACRCloud — receives a short sample of the station's broadcast when you press the recognition button, at their endpoint in the EU, and returns a match. Retention and handling are governed by their privacy policy, not by mine.
- MusixMatch — receives the song title and artist when you ask for lyrics, and returns them. It publishes no retention statement for API requests; handling is governed by their privacy policy, which covers their own app and website, not by mine.
- Cloudflare — operates the edge in front of my API. Requests carry standard HTTP metadata. The API code itself neither reads nor logs your IP address; Cloudflare's own platform logs are separate and short-lived.
- Supabase — hosts the radio-station catalogue that my API reads from. It receives the catalogue queries my API forwards — including the text you type into station search — and nothing that identifies you: my API does not pass your IP address or any device detail on to it.
- PostHog — receives the anonymous analytics described in section 6, if you leave them on.
- Upvoty — the feedback board, and where support e-mail is worked; see section 9.
I do not sell, rent or trade personal data. There is no advertising business here to sell it to.
9. This website
This site is a set of static files. It runs no analytics of its own, and it embeds no fonts, images or scripts from anyone except the feedback widget described below.
This site sets no cookies and stores nothing in your browser. Measured on 2026-09-01 across every page, with the feedback widget loaded: no cookies, nothing in local storage, nothing in session storage.
9.1 The feedback widget
The feedback board is provided by Upvoty, and it is the only third party on this site. It appears as a button on every page, and as an embedded board on the feedback page. Loading any page contacts two Upvoty addresses — one for the widget's own code, one for its configuration — and opening the board embeds a page from feedback-portal.pladio.app. The site's Content-Security-Policy permits those three and nothing else.
The embedded board is a page in its own right, running under Upvoty's control rather than mine. While it is open it loads its own code and images, icons from Iconify, fonts from Google Fonts, and avatar images from Google's user-content service. It stores a handful of values in your browser under its own address — sort order, view preferences, and a guest token — and sets no cookies.
9.2 Reading the board is anonymous. Taking part is not.
You can read every post without identifying yourself. To post, comment, or vote, Upvoty requires you to sign in, with an email address or a Google account, and the sign-in form is protected by Google reCAPTCHA. Signing in creates an account with Upvoty, not with me, and I never see a password. But I administer the board, and the admin panel shows me the name and e-mail address you signed in with, attached to everything you do there — posts, comments and votes — alongside what you wrote. Anything you post is also public to every other reader.
There are two ways a report reaches me, and both are worked in the same feedback system. If you post on the board, you chose Upvoty: you created the account, and you know where the text lives. If you e-mail support@pladio.app, you chose me — and I work e-mail in that same system, so what a follow-up needs, which can include technical details from a diagnostic log you sent, is recorded there as a ticket. The ticket is created under your e-mail address, so from then on Upvoty holds you as a portal user, as if you had signed in — and you are told when that happens. What Upvoty does with a ticket after that is governed by their privacy policy, not by mine.
9.3 Earlier versions of this policy
Previous versions described cookies set by Squarespace Analytics and a Google Search Console verification cookie. Those belonged to the site this one replaces. Neither exists here.
10. Your rights
Under the GDPR and Swiss data protection law you may request access to your personal data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.
In practice, most of this you can do yourself and immediately: your data lives in your iCloud account, so deleting the app or turning off iCloud sync removes it, and analytics can be switched off in Settings → Privacy. For anything else, email privacy@pladio.app.
You may also complain to a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner (edoeb.admin.ch); in the EU, your national authority; in the UK, the Information Commissioner's Office.
11. Legal bases
Streaming, syncing and purchases are processed to perform the contract you enter into by using the app. Analytics and location are processed on your consent, which you can withdraw at any time. Crash reporting, security and protecting my infrastructure from abuse rest on legitimate interests.
12. Children
Pladio is not directed at children. I do not knowingly collect personal data from anyone under 16, and the Terms & Conditions set 16 as the minimum age for agreeing to them.
Pladio carries a 4+ rating on the App Store. That rating describes the app's content — there is nothing in it unsuitable for any age — and it is a separate matter from the age at which someone can enter into an agreement or give valid consent to data processing. The two coexist: suitable content, and an adult-or-near-adult audience.
If you are a parent or guardian and believe a child has provided personal data through Pladio, write to privacy@pladio.app and I will delete it.
13. California
If you are a California resident, you have the right to know what personal information is collected, to have it deleted, to opt out of its sale — I do not sell it — and not to be discriminated against for exercising those rights. Email privacy@pladio.app and I will respond within 45 days.
14. Changes
For material changes I will give notice in the app 30 days ahead. For minor ones I will update the date at the top of this page. The current version is always the one published here.
15. Contact
Privacy: privacy@pladio.app
General support: support@pladio.app
Patrick Diezi / KREANIQS, Lehmbergstrasse 8, 8514 Amlikon-Bissegg, Switzerland