Privacy Policy

Lyd controls your Sonos system from your iPhone, iPad and Apple Watch. Here is everything that leaves your devices, and who receives it.

The Short Version

Six things worth knowing before the details.

  • There is no account with us.

    No name, no email address, no location, no identifier that points at you. The only account involved is your Sonos one, and Sonos manages that.

  • Your music stays yours.

    Playback runs between your devices, your speakers and Sonos. The exception is finding a cover picture, which sends a track or station name and nothing else.

  • Our server does five narrow jobs.

    The Sonos sign-in, signing in on the watch, Sleep Timers, cover art and Voice Messages. Each is listed below with what it receives.

  • Voice Messages, gone in minutes.

    Held in our server's memory behind a random 256-bit password, then deleted once the speaker has played them.

  • Crash reports and two usage counts.

    From the iPhone app only, through Firebase, with no name attached. The Apple Watch app sends neither.

  • This website counts visits.

    Google Analytics counts page views. Cookies only if you accept them in the banner; declined, it counts without cookies and without any stored identifier.

Who We Are

Lyd for Sonos ("Lyd", or "the app") is an iPhone, iPad and Apple Watch app made by App Lane OÜ, Ahtri tn 12, 15551 Tallinn, Estonia, registry code 17207691, the controller for everything on this page within the meaning of the GDPR.

How Lyd Reaches Your Speakers

Lyd controls your system over two paths. Most commands go through Sonos's own cloud API, which is what signing in to Sonos is for. Alongside that, the app talks to your speakers directly on your local network: to find them, to react faster, to reach things the cloud API does not cover, and to fetch cover art the speaker is holding. iOS asks for local network permission the first time.

Either way, that traffic runs between your device, your speakers and Sonos, and it does not reach us. Your rooms and speakers, what is playing, queues, playlists, favorites, volumes, groups and settings live on your device and in your Sonos account. A few features do route through a small server of ours; the sections below are the complete list.

Some things never leave the device at all. Widgets, Live Activities, the Dynamic Island, Complications, Shortcuts and Siri phrases are handled by iOS and watchOS on your device. The volume-key feature on iPhone reads the hardware buttons through Apple's own media controls and sends the new volume to your speakers, nothing else. Lyd never reads your Apple Music or iTunes library; it has no permission to and makes no call that could.

Signing In to Sonos

You sign in on Sonos's own page, in your browser. Your Sonos password is never typed into Lyd and we never see it. Completing that sign-in needs Sonos's confidential key for Lyd, and that key is kept on a small server we run on Heroku at backend.lyd-for-sonos.app rather than inside the app, where anyone could read it out. So the sign-in, and each later token refresh, is relayed by that server. It hands the tokens straight back to your device and stores none of them.

Like any web server, it writes an ordinary request log, and the sign-in and refresh requests appear in it. We do not read those logs as statistics, and Heroku deletes them on its own schedule.

One thing is counted while a token is refreshed: a number in a database of ours goes up by one, so we know roughly how many people used Lyd that day. The row holds a date, a count and which app it was. Nothing about you is stored with it. Legal basis: our legitimate interest in knowing how much the app is used, Art. 6(1)(f) GDPR.

Signing In on the Apple Watch

The Apple Watch app can sign in to Sonos without the iPhone app. It shows a QR code, you scan it with your phone's camera, and you sign in to Sonos on the page that opens. The QR code holds a link and a random one-off identifier for that sign-in, nothing else: no token, no password, no account name.

What happens to the token in between

  • Your watch generates a random 256-bit key before anything starts and sends it to our server.
  • Our server receives the Sonos token, encrypts it with that key, and holds it in memory. It is never written to a disk or a database.
  • Your watch polls for it, decrypts it, and then asks our server to delete it. That request is retried until it succeeds.

Legal basis: performing the sign-in you asked for, Art. 6(1)(b) GDPR.

What Our Server Receives

Besides the sign-in and the watch pairing above, our server handles three jobs that cannot run on your device alone. What it receives, and why:

  • For a Sleep Timer: the speaker group, the time, and a Sonos access token, because the app cannot be relied on to still be running at the moment playback should stop. The token is held in memory until the timer fires, then dropped.
  • For cover art: the title and artist of a track. Its own section is next.
  • For a Voice Message: the recording, a Sonos access token and a password, covered two sections down.

Each is used for that one job and dropped when it is done. Nothing here is written to a database.

Cover Art and Station Logos

Most cover pictures come from the speaker itself, over your local network, or from a Sonos address. When neither works, which in practice means radio and being away from home, Lyd goes looking for the picture. That is the one time something about what you are playing leaves your device.

  • The track's title and artist go to our server, which searches the Apple Music catalog and answers with an image address. The request carries no identifier at all, so it cannot be tied to you or to your other requests, and Apple sees it arriving from our server rather than from you.
  • For a radio station, the station's name goes to radio.net and to TuneIn to find the station's logo. Those two requests go straight from your device, so both services see your IP address. We are not involved in them and receive nothing from them.

The Apple Music lookup runs on iPhone and iPad only; the Apple Watch never makes it, to spare its battery and its data. The station-logo lookup runs on every device.

Legal basis: our legitimate interest in showing you the right picture, Art. 6(1)(f) GDPR.

Voice Messages

Voice Messages records up to 30 seconds on your Apple Watch and plays the recording on a speaker. It needs microphone access, which watchOS asks for the first time and which you can withdraw at any time in the Watch app under Privacy.

A Sonos speaker can only play audio from an address it can reach itself, so the recording is uploaded to our server, and Sonos's cloud fetches it from us and hands it to the speaker. The upload also carries a Sonos access token, because it is our server that asks Sonos to play the clip.

How the recording is protected

  • HTTPS, behind a 256-bit password your watch generates at random for that single message. Without both that password and the message's random address, the request returns nothing.
  • Held in the server's memory only. It is never written to a disk or a database.
  • Deleted the moment every speaker it was sent to has fetched it, and swept from memory within about ten minutes even if that never happens.
  • Never listened to, transcribed or analyzed by us.
  • No account, name or identifier attached to it, beyond the app's own bundle identifier.
  • The copy on your watch is deleted as soon as the upload succeeds, and immediately if you cancel the recording.

Legal basis: performing the feature you asked for, Art. 6(1)(b) GDPR. Microphone access rests on your consent, Art. 6(1)(a), which you can withdraw at any time.

Scenes and iCloud

Scenes are the one thing that leaves your device by design. If you have bought Lyd or are in the trial, they sync through your own private iCloud database so your iPad, and Menu Bar Controller for Sonos on a Mac, see the same set. That is Apple's storage under your Apple Account, not ours. We cannot read it, and the sync can be switched off in the app's settings, where it is on by default.

A Scene carries what it needs to rebuild a moment: its name, the identifiers of your system, speakers and groups, the volume and EQ per speaker, which favorite or playlist it starts, a Sleep Timer length if you set one, and when it was last changed.

Two smaller things use your private iCloud storage as well. Your purchase status is stored there so a new device unlocks without asking you anything. A marker records which of our two apps last used the Scenes database, which is how Lyd knows whether suggesting the Mac app makes sense. Neither leaves your Apple Account.

The Apple Watch app never touches the Scenes database. It receives Scenes from your iPhone over Apple's Watch Connectivity, on the local link between the two devices; the only thing it puts in iCloud is the same purchase flag.

Legal basis: performing the feature you asked for, Art. 6(1)(b) GDPR.

Guest Mode

Guest Mode is the local path. Lyd finds the speakers on the Wi-Fi you are on and sends every command straight to them over your local network. There is no Sonos account and no call to the Sonos cloud, which is also why streaming services, Sonos Favorites and playlists are unavailable in it: those live in an account you have not signed in to.

What the App Sends

Two things leave the iPhone and iPad app on their own, both without your name on them. Crash reports go through Firebase Crashlytics: the stack trace, the app and iOS version, your device model, and a random per-installation identifier that groups reports from the same installation. Usage events go through Google Analytics for Firebase.

There are exactly two events of our own, both about the purchase screen: that it was shown, and that a purchase went through, each with a note of which state the screen was in. Everything else is Firebase's own automatic measurement: a first open, a session starting, a screen being shown, a purchase completing. We log nothing about your rooms, your speakers or what you play.

The Apple Watch app contains neither SDK. It sends no usage events and no crash reports.

Google receives your IP address with the request and derives an approximate country from it; we never see it. The app never asks for permission to track you, so iOS gives it no advertising identifier, and we use none of Firebase's advertising features. Crash reports are kept for up to 90 days and usage events for up to 14 months. Legal basis for both: our legitimate interest in a stable app and in knowing which features are worth our time, Art. 6(1)(f) GDPR.

One more request leaves the app on its own. If you open the short preview video inside the app, it is streamed from a storage bucket we rent at Cloudflare, which sees your IP address and which of the two language versions you asked for.

Your Purchase

Lyd is sold through the App Store. Apple handles the purchase, receipt, refund and license; we never see your name, address, payment details or Apple Account, only aggregated sales reports with no individual in them. The 14-day trial needs no account at all.

When You Write to Us

If you email support, we get your address and whatever you send, and we use it to answer you and nothing else. There is no mailing list. Our mail is hosted by Gandi in France.

This is the one place we hold data that identifies you. It is deleted after at most 24 months. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.

This Website

These are static files, and the fonts are served from this domain rather than from Google Fonts. One measuring script runs here: Google Analytics, which shows us which pages are read, where visitors come from, and whether they use a phone or a desktop.

Legal basis: your consent for cookies, Art. 6(1)(a) GDPR; our legitimate interest in knowing how the site is used for the cookieless counting, Art. 6(1)(f).

Where a guide embeds a video, it comes from YouTube in its privacy-enhanced mode: the page makes no request to YouTube until you press play. From that click on, YouTube (Google) receives your IP address and applies its own policy. Legal basis: Art. 6(1)(b) GDPR, since you request the playback.

Netlify hosts the site and keeps ordinary server logs (IP address, time, page, user agent) to deliver pages and fend off attacks, for a short period Netlify sets; we do not read them as statistics. Links that leave the site are ordinary links, and from there the other service's policy applies. Legal basis: Art. 6(1)(f) GDPR.

Who Processes Data for Us

The complete list of everyone who touches any of this. The processors acting on our behalf are bound by a data-processing agreement and may use the data only to provide their service to us; the US-based ones operate under standard contractual clauses, Google additionally under the EU–US Data Privacy Framework. Sonos, radio.net and TuneIn are not our processors: they are services your device talks to directly, under their own policies. We do not sell personal data and never share it for advertising.

  • Sells and distributes the app, stores your Scenes if you sync them, and holds the music catalog our cover-art lookup searches.

    Data
    Purchase, receipt and license data, held by Apple. We receive only aggregated reports. Your Scenes and your purchase status, in your own private iCloud database. A track title and artist when a cover picture is looked up, arriving from our server rather than from you.
  • Authenticates your Sonos account and provides the speaker APIs.

    Data
    Your Sonos credentials, entered on Sonos's own login page. Every command Lyd sends through the cloud API, and the address a Voice Message is fetched from.
  • Heroku (Salesforce)

    Privacy policy ↗

    Runs our own server: the Sonos sign-in relay, watch pairing, Sleep Timers, cover-art lookups and short-lived voice recordings. Their Postgres service holds the daily use counter.

    Data
    Voice recordings for up to about ten minutes; a Sonos access token while a Sleep Timer is pending or a watch pairing is in flight; song title and artist for cover-art lookups; a daily count per app; request metadata in server logs.
  • Google (Firebase)

    Privacy policy ↗

    Crash reports and usage counts from the iPhone and iPad app; visit statistics for this website.

    Data
    Crash reports, two purchase-screen events, website page views, a random per-installation identifier, device and OS version, IP address (coarse location; not stored by us). Analytics cookies on this website only with your consent.
  • Stores the short preview video the app can play.

    Data
    Your IP address and the language version requested, when you open that video.
  • radio.net and TuneIn

    Privacy policy ↗

    Provide the logos of radio stations.

    Data
    The name of the station you are listening to, and your IP address, sent from your device.
  • Hosts this website.

    Data
    Server logs: IP address, time, page requested, browser user agent.
  • Hosts our email, and therefore anything you send to support.

    Data
    Your email address and the contents of your messages to us.

Your Rights

The law gives you a set of rights over your own data. In plain terms, you can ask us to:

  • Tell you what we hold about you, and give you a copy.
  • Correct anything that is wrong.
  • Delete it.
  • Stop using it, or use it only in a limited way.
  • Hand it over in a form you can take elsewhere.

In practice there is very little to act on. The app sends nothing that identifies you, so we cannot look you up in crash reports or usage counts. There is no “you” in there to find. The exception is email you have sent us, which we can find, change or delete whenever you ask.

Deleting the app ends everything on your side. Signing out of Sonos in the app removes the token from your Keychain; you can also revoke Lyd's access in your Sonos account.

Children's Privacy

Lyd is not directed at children and we do not knowingly collect data from anyone under 16. If a child has emailed us, tell us and we will delete it.

Changes to This Policy

When something changes, this page and the date at the top change with it. Anything material is also called out in the app's release notes.

Governing Law

This policy is governed by the laws of St. Gallen, Switzerland.

Still have a question about your data?

Ask. It goes to the same address as everything else, and the developer answers.

Email Us