chroma

Privacy

Last updated 4 October 2026

Chroma is made and run by one person in the Czech Republic. This page covers what the Chroma app and chroma.pw collect, why, and who else handles it. Chroma blocks the music app's own telemetry; what you share with that app's maker otherwise is between you and them.

The daily check

The app asks chroma.pw whether a new release is out, once a day and at most every six hours. The request carries:

  • a random install ID made on your phone, not tied to your name, Apple ID or music account
  • the Chroma, music app and iOS versions, and the iPhone model
  • how the app was installed and the kind of signing certificate
  • your language and region settings
  • which of a fixed list of features are on, and which lyrics sources

It shows which versions and features are in use and what to fix first. The records are kept per install and day and can't be matched to a person. Your IP address is used only to limit abuse: it is held in memory, hashed with a key that changes on every restart, and never stored.

Your account

An account is optional. Plus needs one. It holds:

  • your e-mail address, and a password if you set one, stored only as a hash
  • the devices you sign in on: a key made on the device, its name, model, iOS and Chroma version, its install ID, and when it was added and last seen
  • your Plus status, including gift codes you redeem
  • a log of sign-ins, device changes and Plus changes, with a short code derived from the IP address, not the address

Sign-in codes are sent by e-mail through Brevo and expire after use. The account stays until you ask for it to be deleted, which removes it with its devices and log.

Plus and Patreon

Plus is paid through Patreon. Chroma never sees your card or payment details. When you link Patreon, chroma.pw receives your Patreon user ID and your membership's status and tier, and Patreon tells it when they change. What you give Patreon is covered by Patreon's own privacy policy.

Linking Discord is optional. chroma.pw then keeps your Discord user ID, and the Discord bot gives that user the Plus role while Plus is on. Unlinking deletes the ID.

Plus features that go through chroma.pw

  • Animated covers and artist logos. The app sends the album and artist name; chroma.pw asks Apple Music and keeps the answer for everyone who asks next. Daily totals per album or artist are kept without who asked; a per-device count for the daily limit is deleted after two days.
  • Sing. The voice model downloads through links made for your device that expire.
  • Audio presets and AutoEq. The lists are downloaded from chroma.pw.

Straight from your phone

These go from the app to someone else without passing through chroma.pw:

  • Lyrics: the sources you turn on (Musixmatch, LRCLIB, Genius, Spicy Lyrics) receive the song being looked up.
  • Translate with Gemini: the lyrics lines and your own API key go to Google.
  • The update check falls back to GitHub when chroma.pw doesn't answer.

This website

chroma.pw counts visits with Umami, hosted by Chroma, without cookies: the page, the referring site, the browser, the kind of device and the country. The account and sign-in pages load no analytics and use cookies only for signing in and linking Patreon or Discord. The patcher works in your browser and never uploads your IPA.

Who else handles data

  • Hetzner runs the server and database.
  • Cloudflare carries the traffic to chroma.pw and stores the Sing model.
  • Brevo sends sign-in e-mails.
  • Patreon takes payments and memberships.
  • Discord runs the community server and learns who holds the Plus role.
  • GitHub hosts the releases.

Nothing is sold or used for ads.

Your rights

You can ask what is stored about you, have it corrected or deleted, or object to its use; write via the Discord server. You can also complain to the Czech data protection authority (Úřad pro ochranu osobních údajů) or the one in your country.