Sword-X

Privacy Policy

Privacy Policy Sword-X HiFi Companion

Effective August 31, 2026. Sword-X is a local-first audio player. It requires no account and does not upload your music library or listening habits to the developer.

Privacy Policy — Sword-X HiFi Companion

Effective date: August 31, 2026.

Sword-X HiFi Companion (“the App”) is a local-first Windows audio player. This policy applies to the website download of the App provided by xinhe. We do not require an account and do not upload your music library or listening history to our own servers. The App does not include advertising or developer telemetry/analytics SDKs. This website requires no sign-in and sets no advertising-profile cookies; its hosting provider may retain essential server access logs under its own policy.

Data stored on your device

Data stored only on your device (default path %LOCALAPPDATA%\Sword-X HiFi Companion\) may include settings, media-library indexes for folders you choose to watch, playlists, session state, playback statistics, and optional local caches for lyrics and cover art. Test builds may create local diagnostic logs. You can clear caches in Settings, delete the data folder, or uninstall the App.

Optional network features

The first time you actively use one of these capabilities, the App explains what metadata will be sent and which third-party services receive it. The feature is enabled only after your explicit consent. If you decline, the App will not repeatedly prompt you. You can enable or disable each feature at any time under Settings → Network & Cache.

  • Online lyrics (LRCLIB, NetEase Cloud Music, Kugou Music, lyrics.ovh, and similar services) typically sends track title, artist, album, and duration—not the audio file.
  • Online cover art (such as iTunes Search) sends search terms and caches downloaded images locally.
  • Online CD metadata (such as MusicBrainz and GnuDB) sends Disc ID or CDDB-style queries when you play an Audio CD.
  • Optional tag lookup queries MusicBrainz or iTunes only when you request it in the tag editor.
  • For Internet radio or stream URLs that you enter, the App connects only to the server you specify.

Third-party services have their own privacy practices and may log IP addresses, request times, and query parameters. You control these features through the first-use consent prompt and Settings, and may withdraw consent at any time. We do not sell your personal data.

Retention, sharing, and security

Local data remains on your device until you clear it in Settings, delete the App data folder, or uninstall the App. Because it is not uploaded to us, we do not sell, rent, or use it for cross-service advertising profiles. When you enable an optional online feature, only the query information needed for that request is sent directly to the third-party service identified above. Supported services are contacted over HTTPS. No local storage or Internet transmission can be guaranteed absolutely secure; HTTP stream URLs entered by you may be unencrypted.

Your choices and deletion

You may change settings, disable optional network features, clear lyrics and artwork caches, or remove all locally retained App data by closing the App and deleting %LOCALAPPDATA%\Sword-X HiFi Companion\. Back up playlists or settings first if you want to keep them. Since we do not hold your library or usage history, there is no cloud profile that you need to ask us to delete.

Children

The App is intended for a general audience, is not directed primarily at children, and does not knowingly collect children's personal information.

Changes and contact

We may update this policy as the App changes. The effective date above will be updated when we do. For privacy questions, contact us through swordx.net or the project issue tracker. Information you voluntarily include in a support request is used only to handle that request. Do not submit passwords, payment information, or unnecessary personal information.

Community and private messages

Account email addresses are used for registration verification and password recovery, and are not shown on public profiles. When we send verification email, the recipient address and message content are processed by our email provider.

Display names, post and reply content, attached images, and timestamps are shown publicly and stored on our servers. New posts require registration and sign-in. Display names, member roles, and posts are public; historical guest nicknames do not represent registered accounts. Passwords are stored as salted digests, and sign-in uses a session cookie. Topic images are compressed to JPG with image metadata removed before storage; unpublished images are not made public.

The site owner can send private messages; members can only receive them. Message content is stored on our servers and can be read on the website only by the recipient and the sending owner. A read time is recorded after a message is opened.

To limit spam, the server temporarily processes network addresses and stores a keyed digest; raw IP addresses are not written to the forum database. Network providers may process access logs under their own policies. Moderators may hide inappropriate content.

Do not post contact details, payment receipts, or other sensitive information in topics. To request changes to published content, describe the topic in the community.