The short version

PearTune collects no personal data. Your music never leaves the machine it already lives on, except to stream to a device that has been let in. There is no PearTune account and no PearTune server holding anything about you.

Where your data actually sits

There are two places, and PeerLoom runs neither of them.

On the machine holding the music, which is yours or a friend's. That machine keeps the music files themselves, an index of them so the app can browse quickly, the list of which devices are allowed in, the names people chose for themselves and their devices, and per-person listening history such as favourites, play counts and where you got to in a track.

On your phone. Your device's own identity key, which is what a library recognises you by, the queue you are playing, any albums you have downloaded for offline use, and your app preferences.

Nothing is copied anywhere else. If you stop using PearTune, deleting the app removes everything on the phone, and whoever runs the library can remove your access and your history from their dashboard.

How your phone reaches the library

Your phone connects straight to the machine holding the music, over the peer to peer network built on the Hypercore Protocol. There is no PearTune server in between, and no copy of your library in a cloud anywhere.

Every connection is encrypted end to end and authenticated in both directions, so the library knows exactly which device is asking and your phone knows it is talking to the right library. There are no passwords or tokens involved: your device's identity key is the whole credential, it is generated on the phone and it never leaves it.

Because that key is what a library recognises, access is a decision the library owner makes and can undo. Removing a device from the dashboard cuts it off immediately, including a device that is connected at that moment.

When a direct connection cannot be made

Nearly all of the time your phone and the library connect to each other directly. On a small number of networks that direct connection cannot be made at all, and mobile networks are the common case. When that happens PearTune can fall back to a relay that PeerLoom runs, which passes the encrypted traffic between the two ends.

The relay cannot read what passes through it. Your music, your browsing and your listening history stay encrypted end to end and PeerLoom holds no key to them. What a relay unavoidably handles is the fact that two ends are talking, identified by random public keys rather than names or email addresses, along with the timing and the amount of data. The relay keeps no record of it and stores nothing.

The relay is a last resort and never the first choice. It is on by default, because it is what makes PearTune work on a mobile network at all, and it is a single switch in the app under Settings, then Connection: "Use the relay when direct fails". Turn it off and PearTune is purely device to library, and will not connect on the networks where a direct connection is impossible. Full detail: The PeerLoom relay.

Being exact about what PearTune asks you, because it does not ask about everything. The first time a library can only be reached this way and you play something, PearTune asks whether to stream that library's music through the relay, and remembers your answer for that library. Say no and the library still plays anything you have downloaded.

It does not ask about browsing. When the relay is the only route to a library, moving around it - the list of albums, searching, the cover art - goes that way without a prompt, whatever you answered about the music. That is a deliberate trade and we would rather state it than let you assume otherwise: it is a small amount of data next to audio, and asking first would mean opening a library to an empty screen and a question. The same limit applies to all of it, so the relay still cannot read any of it and still keeps no copy. If you want none of it crossing the relay, the Settings switch above turns the whole thing off.

Permissions

  • Camera: Used to scan the pairing code shown by a library's dashboard. Nothing is recorded or stored.
  • Network access: Used to reach the library directly, and for the relay fallback described above. No readable data is sent to any server.
  • Playback in the background: Used so music keeps playing when the screen is off or you switch apps, and so the lock screen, car and headset controls work.
  • Storage on the device: Used for albums you choose to download for offline listening, and for cover art. This stays in the app's own private storage.

No tracking or analytics

PearTune contains no analytics, no advertising SDKs, no crash reporting services and no third-party trackers of any kind. Nobody at PeerLoom can see what you listen to, because nothing about it is ever sent to us.

No accounts

PearTune does not require you to create an account or provide an email address. Your device's identity is a cryptographic key pair generated on the phone itself. The name you choose is shown to whoever runs the library you pair with, so they can tell whose device it is, and to nobody else.

If the library belongs to someone else

Worth being plain about, because it is the one thing PearTune cannot decide for you. When you are let into a friend's library, that friend's machine sees which of their music you play, and can see the name you gave yourself. That is how listening history and resume points work at all, and it is the same information they would have if they lent you a hard drive and watched you use it.

PeerLoom never sees any of it. It stays between you and the person whose library you asked to join, and either of you can end that at any time.

Open source

PearTune is fully open source, both the app and the server software. You can inspect the complete source code at github.com/peerloomllc/peartune.

Contact

Questions about this privacy policy? Reach out at peerloomllc@proton.me.

Effective date: July 28, 2026