Remote Play Privacy Policy
Developer: Kubgix Software · Last updated: September 2026
This privacy policy applies to the Remote Play mobile application published by Kubgix Software (Android package com.kubilaygurler.remoteplay, iOS bundle ID com.kubilaygurler.remoteplay). It explains how Remote Play collects, uses, stores, shares and protects personal data.
Data we collect
Remote Play can be used in two ways. In guest mode no account is created and no data linked to you is kept on Kubgix servers. When using an account, the following data is processed:
- Account information: email address, display name and password. Your password is not processed inside the app; it is sent directly to our authentication service (Supabase Auth), where it is stored only as a one-way (bcrypt) hash. Kubgix staff cannot see your password.
- Device information: device name, a random per-installation identifier (install ID) and the time the device was last seen (to show online/offline status).
- Playback and session data: the playback state of devices linked to your account (Apple Music catalog ID of the current track, playing/paused status, shuffle and repeat settings), rooms, shared sessions, and the Apple Music catalog IDs of tracks you send to another device or add to a shared queue. Music (audio) content is not transmitted or stored by Kubgix.
- Subscription status: whether your Premium subscription is active and when it expires. Payment details such as card numbers are processed by Apple or Google and never reach Kubgix.
- Security and abuse prevention: IP address and device attestation records (rate limiting, App Attest / Play Integrity verification). Password reset and device link codes are stored only as hashes, for a short time, not as plain text.
The app does not show ads and does not include advertising SDKs or third-party analytics or crash-reporting SDKs.
Data stored on your device
Your local queue, Apple Music developer and user tokens, guest-mode preference and installation ID are kept on your device in secure storage protected by iOS Keychain or Android Keystore. This data is removed from the device when you uninstall the app or clear its data.
Apple Music data
To use Apple Music features you must grant Apple Music access in the system permission dialog. If you do, Remote Play uses Apple’s MusicKit framework and Apple Music API to search the catalog, list songs and playlists in your library, play the tracks you select and read playback status. Your Apple Music user token is stored in secure storage on your device and is used only for requests to Apple’s services; it is not sent to Kubgix servers. Your library contents (for example playlist names) are not stored on our servers. You can revoke access at any time in your device settings.
How we use data
Your data is used only to create and verify your account, provide remote control and shared queues across your devices, verify Premium status, send verification and password reset emails, prevent abuse and keep the app stable. Your data is not used for advertising, profiling or sale, and is not used to train AI models.
Sharing with third parties
We do not sell, rent or trade your personal data. To operate the app we share data with the following service providers:
- Supabase: hosting, authentication, database and real-time messaging infrastructure. Account, device, session and queue data is stored here.
- RevenueCat: subscription management. Your account ID, purchase and subscription status and technical device information are shared.
- Apple and Google: Apple Music, App Store / Google Play purchases, iOS App Attest and Android Play Integrity verification.
- Brevo: your email address and the message containing the code, used to send verification and password reset emails.
- Legal authorities: only when required by law.
Data protection and security
All communication between the app, our servers and third-party services uses HTTPS/TLS encryption. Tokens and the local queue are kept in the operating system’s secure storage (iOS Keychain / Android Keystore). Row-level access control is enforced in the database so that only you can access your account data. Apple’s developer private key is never embedded in the app and is kept on the server. Requests for the developer token are verified with iOS App Attest or Android Play Integrity attestation.
Retention period
Your account data is kept until you delete your account. When an account is deleted, your profile, devices, rooms and sessions are permanently deleted. Tracks you added to other people’s queues in shared sessions may remain in the session with the “added by” information removed. Shared session queues that have not been read for one hour are cleaned up automatically. Password reset codes are valid for 10 minutes and device link codes for 5 minutes. Limited records may be kept longer where needed for legal, security or fraud-prevention obligations. Records held by Apple, Google and RevenueCat are subject to their own policies.
Your rights
Depending on your location, including under KVKK and GDPR, you may have rights to access, correct, restrict or delete your personal data. You can submit a request in the Profile screen of the app or by emailing info@kubgix.com.
Account and data deletion
You can delete your account from within the app. See the Account Deletion and Data Deletion pages for the steps.
Contact
For privacy questions or requests, contact info@kubgix.com.