Overview
Vaughan is an independent macOS music dock that lets you browse and control your Spotify library. This Privacy Policy explains what Vaughan accesses, where that information goes, how long it is kept, and the choices available to you.
Vaughan is not affiliated with Spotify or Apple.
Summary
- Vaughan does not collect, sell, rent, or share your personal information with Vaughan’s developer or any Vaughan-operated server.
- Vaughan does not use analytics, advertising SDKs, crash-reporting services, or cross-app or cross-site tracking.
- Vaughan communicates directly with Spotify only after you choose to connect your Spotify account and approve Spotify’s authorization request.
- Your Vaughan data is stored locally on your Mac unless it is sent directly to Spotify to provide a Spotify feature.
Information Vaughan accesses
When you choose to connect Spotify, Vaughan uses Spotify’s authorization flow. Vaughan asks Spotify for the following access necessary for its music-library and playback features:
| Information | How Vaughan receives it | Why Vaughan uses it |
|---|---|---|
| Spotify authorization credentials | From Spotify after you authorize Vaughan | To keep your Spotify connection active and make authorized Spotify requests. |
| Spotify library information | Directly from Spotify’s Web API | To show your saved albums, liked songs, followed artists, and playlists. |
| Playlist information | Directly from Spotify’s Web API | To display playlists and, where Spotify permits, their tracks. |
| Playback information and device identifiers | Directly from Spotify’s Web API and the local Spotify desktop app | To show the current track, queue, available playback devices, and playback state. |
| Recently played and top-item information | Directly from Spotify’s Web API | To support Vaughan’s library and music-browsing experience. |
| Search terms | Typed by you into Vaughan and sent directly to Spotify only when using Spotify search | To return Spotify search results. |
| Album artwork | Downloaded directly from the artwork URL supplied by Spotify | To show cover art in Vaughan. |
| Spotify developer Client ID | Entered by you | To identify your own Spotify developer application during authorization. |
| Vaughan settings and organization data | Created by you in Vaughan | To remember preferences, pins, and custom shelves. |
Vaughan does not request access to your contacts, photos, camera, microphone, precise location, health information, Apple ID, payment information, or other apps’ data.
How information is used and shared
Vaughan uses the information above only to provide its music browsing, organization, search, and playback-control features. It does not use the information for advertising, profiling, analytics, marketing, or tracking.
The only external recipient of information from Vaughan is Spotify, and only when you connect Spotify or use a feature that communicates with Spotify. For example, Vaughan sends Spotify authorization requests, search queries, and playback-control requests directly to Spotify. Spotify’s handling of information is governed by its own privacy policy and terms.
Vaughan has no application-owned backend and does not transmit your information to the developer. It does not integrate third-party analytics, advertising, crash-reporting, or AI services. It does not sell or share personal information for targeted advertising.
Vaughan does not track you across apps or websites owned by other companies, does not use Apple’s advertising identifier, and does not request App Tracking Transparency permission.
Local storage and security
Vaughan keeps the following data on your Mac:
| Data | Storage location | Retention |
|---|---|---|
| Spotify refresh token | macOS Data Protection Keychain | Until you disconnect Spotify or reset Vaughan data. |
| Spotify Client ID and app preferences | macOS UserDefaults | Until you change them or reset Vaughan data. |
| Cached library metadata, pinned items, custom shelves, and artwork | ~/Library/Application Support/Vaughan |
Until you reset Vaughan data or remove the app’s data. |
| Current Spotify access token | Memory only | Until it expires, is refreshed, you disconnect Spotify, or Vaughan quits. |
Vaughan uses macOS’s Data Protection Keychain for the stored Spotify refresh token. Vaughan does not guarantee the security of data once it has left your device for Spotify; Spotify’s security practices apply to information it receives.
Your choices, consent, and deletion
Connecting Spotify is optional. You may decline or cancel Spotify authorization; Vaughan will not receive Spotify authorization credentials in that case.
You can revoke Vaughan’s access and delete locally stored data at any time:
- In Vaughan, open Settings → Spotify → Disconnect Spotify to remove the saved Spotify refresh token and stop future Spotify requests from Vaughan.
- In Vaughan, use Settings → Data → Reset Vaughan Data to permanently delete the Spotify connection, local library cache, artwork cache, pins, custom shelves, and preferences.
- You can also revoke Vaughan’s authorization through your Spotify account settings, subject to Spotify’s controls.
Deletion from Vaughan removes data stored by Vaughan on your Mac. It does not delete data that Spotify maintains under its own policies. Vaughan does not maintain user accounts or personal data on its own servers, so there is no Vaughan server-side account or data to delete.
Changes to this policy
We may update this policy when Vaughan’s data practices change. We will post the revised policy here and update the effective date. If a change requires consent under applicable law, Vaughan will request it before collecting, using, or sharing the affected information in the new way.
Contact
For privacy questions or requests, contact the Vaughan maintainer at contact@mobarak.ca. Please do not include Spotify credentials, access tokens, or other sensitive information in your message.
App Store privacy disclosures
This policy describes Vaughan version 1.0’s current data practices. The App Store privacy details submitted for a release must match the version actually submitted, including any new SDKs, permissions, or data flows added later.