Ohm Privacy Policy
Last Updated: August 8, 2026 Applies to: Ohm for iOS, including beta versions distributed through Apple TestFlight.
Introduction
Ohm is an iOS app that plays music from your Apple Music library and the Apple Music catalog based on your context — the time of day, whether you’re moving, what you’re connected to, and where you tend to be. To do this, Ohm processes data about your listening and your surroundings. This policy explains exactly what we collect, what stays on your device, what is sent to our servers, and what we will never do with it.
Unlike a purely local app, Ohm operates a backend service. Some of your data is transmitted to and stored on our servers so that recommendations can be computed for you. This policy is specific about which data that is.
Who We Are
Ohm is operated by Ohm LLC, based in Accra, Ghana. You can reach us at desmond@sofua.co.uk with any question about this policy or your data.
Data We Collect
Account data
You sign in with Sign in with Apple. We receive and store the stable, anonymous identifier Apple issues for your account (the “sub” claim), which is the key all your data is stored under. If you choose to share your name or email address during Sign in with Apple, we store those too; if you use Apple’s “Hide My Email” option, we only ever see the relay address. We issue our own session tokens to authenticate your app to our servers; Apple Music tokens are treated as short-lived playback credentials, not identity.
Apple Music data
With your permission, granted through the iOS Media & Apple Music authorization prompt, Ohm reads from your Apple Music account and sends the following to our servers:
- Your saved music library (tracks, albums, artists)
- Your playlists, including titles, tracks, and track order
- Your Apple Music Replay listening history for the current year
- Recently played tracks, sampled from Apple’s recently-played API
- Playback events generated inside Ohm: what played, when, how much of it you listened to, skips, rewinds, and your feedback (star, “not now”)
Ohm can only observe listening through Apple Music. It cannot see listening in Spotify, YouTube Music, or any other service.
Context data
Ohm reads contextual signals on your device and combines them into a “context bin” — a coarse description of your situation. When your context changes, a time-stamped context-bin event is sent to our servers. The signals are:
- Time of day (morning, afternoon, evening, night) and weekday vs. weekend
- Motion class from Apple’s CoreMotion activity classifier: stationary, walking, running, or in a vehicle. Ohm never receives raw accelerometer or fitness data on its servers — only the activity class.
- Audio route: whether sound is going to headphones, CarPlay, an AirPlay speaker, or the built-in speaker
- Focus mode state (e.g., Work, Sleep, Do Not Disturb, or off)
- Local weather conditions, retrieved on your device from Apple WeatherKit using your approximate location. Only the resulting weather condition becomes part of your context bin; your location is used for the lookup on-device and is not sent to our servers
- Location cluster — described in detail below
Location: what leaves your device and what never does
Location is handled with a deliberate architectural separation:
- Your device uses Apple’s CoreLocation and an on-device machine-learning model to identify places you return to often and groups them into clusters.
- Each cluster is assigned a randomly generated, meaningless label (for example, “loc_4”). The label carries no address, no place name, and no coordinates.
- Only the cluster label is ever transmitted to our servers. Raw location coordinates never leave your device. We cannot determine where you are or where any cluster is from the data we hold.
Technical and diagnostic data
Our servers record standard request metadata (timestamps, app configuration version, session identifiers) needed to operate the service and diagnose faults. During the beta, Apple may also share crash logs and usage statistics with us through TestFlight, subject to the consent you give Apple when joining a TestFlight beta.
Data We Do NOT Collect
- Raw location coordinates, addresses, or place names
- Raw motion, accelerometer, or health data
- Contacts, photos, messages, or browsing activity
- Advertising identifiers, and we embed no advertising or third-party analytics SDKs
How We Use Your Data
All collected data is used solely to generate music recommendations for you and to operate, debug, and improve Ohm. Specifically:
- Building candidate pools of tracks matched to your context bins
- Learning which music fits which of your contexts from your listening behavior and feedback
- Diagnosing playback and recommendation faults
- Aggregated, non-identifying statistics for product improvement
We do not use your data for anything else. In particular:
- Your data is not sold.
- Your data is not shared with advertisers.
- Your data is not used to train models for any product other than Ohm.
- Your data is not provided to third parties, except the service providers listed below acting on our instructions, or where required by law.
Where Your Data Lives
- On our servers: account data, Apple Music data, context-bin events, playback and feedback events. Our backend is hosted on Fly.io infrastructure in London, United Kingdom.
- On your device: raw location data, the location-clustering model, cached track pools, and local app state. This data is protected by your device’s passcode, Face ID, or Touch ID and is removed when you delete the app.
If you use Ohm outside the United Kingdom, your data is transferred to and processed in the United Kingdom.
Third-Party Services
| Service | Role | What it receives about you |
|---|---|---|
| Apple (MusicKit, Sign in with Apple, TestFlight, push notifications) | Identity, music playback, beta distribution | Governed by Apple’s own privacy policy; Ohm makes standard API requests on your behalf |
| Fly.io | Server hosting | Hosts the data described above on our instructions |
| Apple WeatherKit | Local weather conditions | Your device requests weather from Apple using your approximate location; governed by Apple’s privacy policy. Weather data attribution: Apple Weather |
| Last.fm, MusicBrainz, AcousticBrainz | Track metadata enrichment | Nothing about you. Our servers query these services with track identifiers only; results are cached per track and shared across all users |
We have no analytics, advertising, or tracking integrations.
Retention and Deletion
- Your data is retained while your account is active.
- Ohm includes an in-app account deletion flow in Settings. Deleting your account marks it deleted immediately and signs you out. There is a 30-day recovery window, disclosed at the point of deletion, after which a scheduled job permanently purges your data from our servers.
- Aggregated, non-identifying statistics may be retained after deletion.
- Deleting the app from your device removes all locally stored data immediately, but does not by itself delete your server-side account — use the in-app deletion flow or contact us at desmond@sofua.co.uk.
Your Rights and Controls
- Permission revocation: you can revoke Ohm’s access to Apple Music, location, or motion at any time in iOS Settings. Ohm continues to work with whatever permissions remain, with recommendation accuracy degrading accordingly.
- Deletion: via the in-app flow described above, or by emailing us.
- Access and correction: email us at desmond@sofua.co.uk and we will provide a copy of the personal data we hold about you, or correct it.
- If you are in the UK, EEA, or another jurisdiction with statutory data rights (such as GDPR or CCPA rights), you may exercise those rights through the same contact address. You also have the right to complain to your local data protection authority.
Beta Program
If you additionally join Ohm’s structured beta feedback program (interviews, daily check-in prompts), participation is voluntary, separate from the app itself, and governed by the consent you give when enrolling. Contact details you provide for the program are used only to run it.
Children
Ohm is not directed at children under 13 and requires an Apple Music subscription, which carries Apple’s own age requirements. We do not knowingly collect data from children under 13; if you believe we have, contact us and we will delete it.
Security
Data in transit between your device and our servers is encrypted. Server-side data is stored in access-controlled infrastructure. On-device data is protected by iOS system security. No system is perfectly secure; we will notify affected users of any breach as required by law.
Changes to This Policy
We will update this policy as Ohm changes — and during the beta, Ohm will change often. Material changes will be flagged in the app or by notification, and the “Last Updated” date above always reflects the current version.
Contact
Summary: Ohm sends your Apple Music library, playlists, listening history, and coarse context events to our servers in London to compute recommendations for you, and for no other purpose. Your exact location never leaves your device — only anonymous cluster labels do. Nothing is sold, shared with advertisers, or used to train anything other than Ohm. You can delete everything, in-app, at any time, with a 30-day recovery window.