Privacy
Exora is a music app. This page says what it collects, why, and how to get rid of it. It is short because there is not much to say.
Last updated: 2026-08-03
Before you sign in
Exora needs an account. The first screen you see asks you to sign in with Google or Apple, and nothing in the app is reachable until you do.
There is still a moment before that happens. On first launch the app generates a random id for itself and records that a session started and that it ended. If the app crashed the last time you used it, iOS hands us a crash report on the next launch and that is recorded here too. If you arrived from an ad, the fact of that arrival is recorded — which campaign and which track.
That id is not your Apple ID, not an advertising identifier, and not derived from anything about you or your phone. Deleting the app destroys it — a reinstall is a new one, and we cannot connect the two.
Nothing you do in the app is recorded in this state, because there is nothing you can do in it yet.
Your account
Signing in is how you use the app. It is also what makes your playlists and likes follow you to another iPhone.
When you sign in we receive your email address. With Google we also receive the basic profile that travels with it — your name and a link to your profile picture. We use and show only the email, so you can see which account you are signed into; the rest sits unused in the account record. No contacts, no friend list. With Apple we ask for the email address and nothing more. We do not email you; there is no mailing list and no mail-sending code anywhere in the system. If you sign in with Apple and choose Hide My Email, we get the relay address and never see your real one.
The handful of events from before you signed in are linked to your account at sign-in. From then on your playlists, likes and listening history are stored on our server against an account id, and usage events — crash reports included — carry that account id. The exception is an event that was still queued when you signed out: it goes up unattached, and a later sign-in links it.
What we record
As you use the app it records usage events: which tracks were played, finished or skipped and where you skipped, what was searched for and how many results came back, playlist and like actions, and when sessions start and end. If the app crashes, it also sends a crash report on the next launch: the exception type and signal that ended the process, the reason iOS gave for terminating it, and your iOS and app version — never the call stack, so we never see what code was running or any data it held. Crash reports come from Apple’s own MetricKit framework, not a third-party crash SDK.
Every event carries the random per-install id described above, and from sign-in on it carries your account id too.
We use those events to work out what people listen to and what they looked for and didn’t find. Searches that return nothing are the most useful thing we collect: they tell us what the catalog is missing.
What we don’t do
- No advertising. There are no ad networks in the app, so there is nothing to opt out of.
- No tracking across other apps or websites. There is no third-party analytics SDK, no attribution SDK and no advertising identifier in the app, which is why iOS never asks you about tracking when you open it.
- We don’t sell your data, share it, or hand it to a data broker. It is not a revenue stream, and there is no arrangement under which it could quietly become one.
- No location, no contacts, no microphone, no photos, no address book. The app is not built to ask for any of them.
Deleting your account
Playlists tab → Account → Delete account.
Confirming deletes your account, the link to your Google or Apple sign-in, your email address and the profile that came with it, and the playlists, likes and listening history synced to it. Playlists stored on your iPhone stay on your iPhone — they were made there and they are yours. Because the app needs an account, deleting yours returns you to the sign-in screen.
Your past usage events are not deleted. They are unlinked: the account id comes off them and they remain as anonymous rows with nothing left in them that identifies you. We keep them because they are only ever counted in aggregate — how many people played a track, how often a search returned nothing — and deleting them would silently rewrite numbers that were already true.
There is no waiting period, no form to send and nobody to ask.
How long we keep things
Usage events are kept indefinitely, because their whole value is the long view — including the ones left anonymous after an account is deleted. Account data — email address, the profile that came with it, playlists, likes, history — is kept while your account exists and goes when you delete it.
Children
Exora is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has given us data, write to us and we will delete it.
Changes
If this page changes, the date at the top changes with it. We will not quietly start collecting something new: anything added here also has to appear in the App Store privacy labels, and the two have to agree.
Contact
support@exora.fm