- Optional telemetry is off by default. Usage analytics and crash diagnostics are separate, optional controls. You may enable either in Settings → Privacy and change your choice at any time.
- A few connections are required rather than optional. Checking a paid tier, checking for an update outside Steam, and completing a deletion request all contact a server so the feature can work. They carry your install ID and app version, they are not telemetry, and the telemetry toggles do not switch them off. They are listed in full below.
- Optional app analytics are tied to a random install ID generated on your machine, not a Steam account identifier.
- For app telemetry, we derive a coarse region (country level) from your connection to see where IKANDY is used. Our application database does not store the raw IP address.
- We do not ask for your name or email to use the app. We do not collect music or audio content, file names, or account credentials for our own servers.
- You control optional telemetry. View your ID, toggle diagnostics and analytics, and request deletion from inside the app.
- Website analytics require a separate choice. Google Analytics does not load on ikandy.app unless you select Allow analytics; declining does not limit the site.
01
What This Document Covers
This Privacy Policy explains how IKANDY ("the Software") and ikandy.app ("the Website"), operated by L&R Entertainment LLC ("we", "us"), collect and process data when you use them. It reflects the data practices implemented in IKANDY version 1.0 and later.
This policy mirrors the data sections of the License Agreement in plain language. The License Agreement is the binding contract for your use of the Software; where the two documents describe data practices differently, this Privacy Policy controls.
02
Data Required to Use IKANDY
Steam builds. IKANDY is sold and installed through Steam. The app uses the local Steam client to confirm ownership and unlock the purchased tier. The table below describes data IKANDY processes for the app itself.
| Data | What it is | Why we need it |
|---|---|---|
| Nothing, for ownership | Ownership and tier verify locally through the Steam client on your machine. Our servers are not involved and never receive your Steam identity. | Unlocks the tier you purchased for core local playback. Steam and optional online features may require a connection. |
| Pseudonymous install ID | A random UUID generated on your machine at first launch. It is not derived from your Steam account and is not used by IKANDY to identify you by name or email. | Identifies your install for telemetry (if you enabled it), bug reports you send, and the "delete my data" flow. |
| App version, platform | Strings like "1.2.0" and "win32". | Routes you to the correct logic for your build. |
| EULA acceptance record | Hash of the agreement you accepted plus a timestamp. | Records that you agreed to the current terms. |
Historical beta builds (pre-release). Before the beta closed, access could validate against our server with a random Beta ID (a UUID generated on first install) and a one-way SHA-256 device-fingerprint hash derived from device attributes. Historical records may remain subject to the retention and deletion terms below. The original device attributes are not recoverable from the hash, but the resulting value is treated as a pseudonymous identifier where applicable law considers it personal data.
Connections that are not telemetry
Some features contact a server in order to work at all. These are separate from the optional telemetry described in the next section: they are not covered by the telemetry toggles, and each one happens only when the feature it belongs to actually runs. None of them carries your name, email, Steam identity, or anything about what you are playing or making.
| Connection | What it involves | When it happens |
|---|---|---|
| Pro or Studio entitlement check | Your install ID, used to look up whether a paid tier is recorded for it. The answer is signed by our server and cached on your machine, so your paid features keep working offline for up to 37 days between checks. IKANDY itself never stops working offline: if the cached answer does go stale, the app continues on the free tier rather than shutting you out. | When a Pro or Studio feature is used, and in the background roughly once a week to renew the cached answer while you are online. Ownership bought through Steam is confirmed locally by the Steam client instead, and our servers are not involved in that check. |
| Concurrent-device check | Your install ID and the one-way device hash described above, so that one paid licence is not run on many machines at once. | Periodically while a paid tier is active. If the check fails or cannot be reached, the app leaves your features enabled. |
| Deletion-proof registration | Your install ID and a random value generated on your machine, stored together so that a later deletion request can be proved to come from your installation. | Once per installation, automatically, on an early launch. It is a safeguard on your deletion right rather than analytics, so it deliberately runs whether or not telemetry is on. |
| Deletion request | Your install ID and that same value, so we can verify the request before acting on it. | Only when you use the delete button described under Your Rights. |
| Update check | A request to our release feed, which is hosted on GitHub, asking whether a newer version exists. It carries no install ID. GitHub receives your IP address and standard request information as the host of that feed. | At launch, on builds installed outside Steam. Steam builds skip this entirely, because Steam handles their updates. |
| Agreement validation | The Beta ID and device hash described above. | Pre-release beta builds only. Retail builds record your acceptance of the agreement on your own machine and make no such call, so a retail install works fully offline. |
| AI price list | A request to ikandy.app for a small published price file, so the Create panel can show an estimated cost before you generate. It carries no ID and sends nothing about your prompt. | At most once a day, while the Create panel is open. If it fails, a built-in price table is used instead. |
03
Diagnostics & Usage Analytics
IKANDY has two telemetry channels: usage analytics and crash diagnostics. Both are off by default and are enabled only through separate, affirmative choices in Settings → Privacy. You can change either choice at any time; future events stop when you turn the relevant control off.
These two controls govern the telemetry described in this section. They do not govern the required connections listed in the previous section, which run because the features they belong to cannot work without them.
Usage Analytics
When on, IKANDY records:
- Launch timestamp, app version, and platform
- Session duration (recorded on app close)
- Feature usage events: which features get used, never what you play or make with them
- The kind of audio source in use (e.g. "Spotify", "MusicBee", "system audio") and whether auto-cycle was on: the feature, never the content
- Whether the install is new
- A coarse region (country level), derived from your connection at the moment of ingestion; the IP address itself is not stored
- Your install ID (see above), rather than a Steam account identifier
We do not collect playback choices, music library contents, song titles, or the contents of anything you create.
Crash & Bug Diagnostics
When on, IKANDY sends a technical report if the application crashes, and diagnostic traces when you report a bug. Before anything leaves your device it is automatically sanitized:
- Your Windows username is replaced with
<user> - File paths from your user directory are stripped or generalized
- Development paths are masked
The resulting report contains the error type, a sanitized stack trace, recent technical log lines leading up to the problem, app version, platform, OS version, GPU model, and the same install ID as above. Sanitization happens on your device before transmission; we aim to remove usernames and full file paths before transmission. Verbose diagnostic trace files that some debug options write stay on your machine unless you choose to send them.
04
What We Do Not Collect
Under normal operation, IKANDY does not intentionally transmit the following to our servers:
- The contents of audio playing on your computer
- The names of songs, artists, or albums you play
- Your music library or playlists
- Your Spotify, MusicBee/MBXHub, foobar2000/Beefweb, VLC, or other source credentials and local-service passwords
- Your real name or email address (unless you choose to type an email into a bug report, described below)
- The names of files on your computer
- Screenshots or video
- Biometric data of any kind
Those statements are about our servers. Separately, a few features send limited information from your device straight to someone else, without it passing through us. Those are listed next, and the artist lookup in particular does send the name of the artist you are playing.
Optional features that talk to other services
A few features send limited information beyond your own machine, and only while you use them:
- Lyrics. Lyrics load from your own local files (a synced .lrc beside the track, or your linked lyrics folder). Nothing is sent to any lyrics service.
- Artist Bio card. When you open the Artist Bio card, IKANDY looks the playing artist up directly from your device on Wikipedia and Wikimedia Commons. The artist name is sent to those services, and each receives your IP address and a header identifying IKANDY as the client, as any web request would. Our servers play no part in this and receive nothing from it. Nothing is looked up until you open the card, and attribution for whatever comes back is shown inside the card.
- Media player connections. Connecting MusicBee, foobar2000, or VLC sends requests to the address you configure for that player, which is your own machine by default. Those requests stay on the network you point them at and are not sent to us.
- Bug reports. If you submit a bug report you may optionally include an email address so we can follow up. It is used only for that report.
- AI generation (BYOK). IKANDY's AI features currently connect only to Anthropic. Your prompt goes to Anthropic, using the API key you supply, under Anthropic's privacy policy. So do the frames IKANDY renders of the result, which Anthropic's model reads in order to score the scene and improve it.
Local logs stay local unless you choose to send a report. IKANDY writes a diagnostic log on your machine that can include your Windows username and the titles of songs you played. Optional crash diagnostics send the sanitized report described above only when crash diagnostics are enabled; bug reports send only when you submit them.
05
About Your IP Address
Like every internet service, IKANDY makes HTTPS connections that include your IP address at the network level. For optional app usage analytics, we derive a coarse region (country level) when an event arrives, then discard the address; our application database does not store the raw address.
If you allow website analytics, your browser connects directly to Google Analytics. Google necessarily receives your IP address at the network level and may use it to derive approximate location and route the connection. Google states that GA4 discards IP addresses before logging them; L&R Entertainment LLC does not receive the raw address in its Analytics reports. See the Website Analytics section below for the other information involved.
Your IP address may appear transiently in standard Supabase infrastructure logs, which are governed by Supabase's privacy policy.
06
Where Your Data Is Stored
Product telemetry, licence and entitlement records, deletion records, and beta-management records are processed using Supabase. Our release files, and the update check that reads them on builds installed outside Steam, are hosted by GitHub. If crash diagnostics are enabled, sanitized crash reports may additionally be processed by Sentry. If website analytics are allowed, limited website events are processed by Google Analytics. These providers process data for us under their own applicable terms and privacy commitments.
We do not sell or rent personal data. We share data only with service providers that help operate the app, or with a third-party service you choose to use, such as an AI provider or the artist-information sources named above, as described in this policy.
Retention and international processing
We retain optional telemetry, crash records, and website analytics only as long as reasonably needed for the purposes described above, then delete or aggregate them where practical. Google Analytics retention controls do not necessarily apply to aggregated reports. We retain beta-access and agreement records only as long as needed to administer access, keep required records, resolve disputes, or comply with law. Service providers may process data outside your country; where applicable, their contractual and legal transfer safeguards apply.
Legal bases
Where privacy law requires a legal basis, we rely on your consent for optional app telemetry and Google Analytics, on performance of our agreement for licensing and support functions, and on legitimate interests for security, fraud prevention, and operating the service. We may also process data where required by law.
07
Website Analytics
This Website
On the live marketing pages of ikandy.app, we use Google Analytics 4 only after you select Allow analytics. We use a basic consent implementation: before you allow analytics, the Google tag is not requested and no analytics data or consent ping is sent to Google. You may decline and continue using the full Website.
What website analytics records
- The page path and page title, plus the referring website's origin when available. Query strings and URL fragments are removed before transmission, and a referrer is reduced to its origin rather than its full page address.
- Clicks to the IKANDY Steam store page, including whether the link was in the header, hero area, page body, or footer.
- Limited website-error signals: the script file name and line/column number, or that an unhandled promise rejection occurred. We do not send the raw error message, stack trace, or surrounding page content.
- Standard information Google Analytics collects after consent, including a pseudonymous browser identifier, session and timing information, approximate location, and browser, device, operating-system, language, and screen information.
We do not send Google Analytics your name, username, email address, password, Steam identity, sex or gender, form-field contents, music activity, library contents, song titles, prompts, bug-report text, or other user-created content. We do not place user IDs or account identifiers into Analytics. Google distinguishes pseudonymous identifiers from directly identifying information; applicable privacy laws may still treat those identifiers and device information as personal data.
Our tag configuration denies advertising storage and advertising user data, disables Google Signals and ad-personalization signals, and does not send advertising events. Google processes allowed analytics events under its Privacy Policy and Google Analytics Terms.
Your analytics choice
Your choice is stored locally in your browser for up to 180 days so the Website can remember it. If you allow analytics, Google Analytics may set first-party _ga cookies with a configured lifetime of up to 90 days. Select Analytics choices in the Website footer or use the button below to change your choice. Withdrawing consent blocks future events and attempts to remove IKANDY's Google Analytics cookies from the current browser; information already received may remain until it is deleted or aggregated under the applicable retention settings.
The Arcade, browser games, scores page, jukebox, local file copies, and development previews do not enable Google Analytics. If you choose to play an optional product video, it loads from YouTube's privacy-enhanced domain and is then subject to YouTube's own privacy practices.
The Arcade
The IKANDY Arcade is a free browser mini-game site. It never asks for your email, name, or an account. Games show a score while you play, but the arcade does not submit, publish, or retain new scores.
- No arcade identity. The arcade no longer creates or uses an arcade UUID or handle.
- No leaderboard. Scores are not sent to our backend and disappear when you leave a game or the arcade.
- Completed contest. The Hall of Champions permanently names the winners of the contest that ended on July 9, 2026. New submissions are not accepted.
To request deletion of a historical contest record submitted before the closure, email support@ikandy.app with the handle used at the time.
Your Rights
Access
Open Settings → Privacy in IKANDY to view your install ID at any time. You may also contact us to request access to, correction of, or deletion of personal data we hold about you.
Withdraw Consent
Disable either app telemetry toggle at any time. For the Website, select Analytics choices in the footer or in the Website Analytics section and choose Decline. Future events from the relevant channel will not be transmitted. Past records remain unless they are deleted or aggregated under the applicable retention settings.
Delete Your Data
Use the "Delete my data from IKANDY servers" button in Settings → Privacy to request deletion. The flow:
- Deletes your usage records, error and crash records, and any bug reports tied to your installation, together with the stored value that proves a request came from you
- Anonymizes your beta installation record and any record of a declined agreement (removes personal identifiers while keeping the row to prevent beta-slot recycling)
- Generates a fresh pseudonymous ID locally so future sessions start clean
Requests are verified. Your installation registers a random value with us on an early launch, and a deletion request has to present that same value. This exists so that anyone who merely learns or guesses an install ID cannot delete someone else's records. An installation that predates this mechanism, or one whose stored value has been lost, may not be able to complete the request in the app: email support@ikandy.app and we will carry it out for you.
A few records are kept. A small set survives a deletion request, because removing it would defeat what it is there for:
- Your record of accepting the agreement, which is already held in anonymous form, kept as evidence that the terms were accepted
- The anti-abuse records behind the concurrent-device check, kept so that deletion cannot be used to reset a device limit
- Paid licence records, which are never removed automatically, so that a deletion request does not erase a purchase. Ask us if you want a paid record removed as well.
For website analytics already sent to Google, contact support@ikandy.app. We will use the deletion tools reasonably available to us where the relevant data can be identified. Because website events are deliberately not attached to your name, email, Steam account, or IKANDY account, we may need additional non-identifying details such as the approximate date and page involved, and it may not always be possible to isolate a particular event.
Historical Beta Records
The IKANDY beta is closed and beta reactivation is no longer available. Contact support@ikandy.app to request access to or deletion of an identifiable historical beta record.
Additional regional rights
Depending on where you live, you may have rights to restrict or object to processing, receive a portable copy of certain data, and complain to your local data-protection authority. Contact support@ikandy.app to exercise these rights.
08
Children's Privacy
IKANDY, including the public arcade, is a general-audience product and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us immediately and we will remove the relevant records.
09
Changes to This Policy
If we materially change what data is collected or how it is processed, we will update the effective date and, where required, provide notice or request a new choice before the change takes effect.
10
Contact
For questions about this policy, privacy choices, or data deletion requests:
Email: support@ikandy.app
Discord: discord.gg/xYUmSPbve