Privacy Policy
QBox Player ("QBox Player," "the app," "we," "us," or "our") is developed and operated by OpenRise Studio. This Privacy Policy explains what information is collected when you use QBox Player, how that information is used, how long it is retained, and the choices available to you.
QBox Player does not require an account or login. We do not ask you to provide your name, phone number, postal address, or payment information to use the app.
1. Information We Collect
Device Identifier
QBox Player generates an identifier the first time the app is opened and stores it only on your device. This identifier is transmitted to our servers when you use online features (creating or opening a drop, or the app's periodic activity signal).
On Android, this identifier is derived from your device's Android system ID (Settings.Secure.ANDROID_ID) using a one-way transformation — the underlying system ID itself is never transmitted or stored, only the derived value. Because of this, the identifier normally stays the same across an uninstall and reinstall of the app on the same device. It can still change after a factory reset, a change to the device's user profile, or on some devices, if the app is reinstalled under different signing circumstances. On other platforms, or if the system ID is unavailable, a random identifier is generated instead and does not survive a reinstall.
We use the device identifier to:
- Recognize requests made by the same device;
- Associate a QR drop with the device that created it;
- Calculate basic statistics, such as daily active devices;
- Apply usage limits and prevent spam, fraud, and abuse;
- Let a recipient locally block future drops from a sender's device (see "Reporting and Blocking" below);
- Apply reporting, blocking, moderation, or enforcement actions where necessary.
The device identifier is not connected to an account, name, email address, or phone number. However, because it can recognize the same device over time, it is a pseudonymous device identifier and should not be considered completely anonymous information.
Basic Technical Information
The app may transmit basic technical information such as the app version, operating system, Android platform, language, request timestamps, and technical information needed to operate and secure the service.
Our servers and service providers may also process your Internet Protocol ("IP") address when your device connects to the service. An IP address may be used to estimate an approximate location, operate network connections, prevent abuse, apply rate limits, and protect the service.
QBox Player does not request or collect your device's precise GPS location.
Audio Files and Drop Information
When you voluntarily create a QR drop, the selected audio files are uploaded to our servers so that a person who scans or opens the drop can download them.
Information connected with a drop may include:
- The uploaded audio files;
- Track titles and filenames;
- Artist, album, or other metadata available in the selected files;
- A title or description entered for the drop;
- The drop identifier and creation and expiry timestamps;
- The device identifier associated with the device that created the drop;
- Basic statistics relating to the creation, access, scan, or download of the drop;
- Reports, blocking records, moderation status, and enforcement information associated with the drop.
Creating a drop is optional. You can continue using QBox Player as a local music player without uploading audio files to our servers.
When you create a drop, you intentionally direct us to make its contents available to people who receive or scan its QR code or link. You should treat a drop code or link as shareable information and avoid sending it to anyone who should not receive the files.
Reports and Blocking Information
QBox Player has two separate safety controls, available from a received drop's menu:
- Report a drop — sends a report to our servers, reviewed by our team. When you report a drop, we process the drop identifier, the reason you selected or entered, and technical information needed to investigate the report.
- Block a sender — a purely local preference stored only on your device. Blocking a sender is never sent to our servers and never affects other users; it only stops your own device from opening future drops from that sender.
We use report information to investigate complaints, prevent future unwanted drops, enforce our Terms of Service, and respond to legal or copyright requests.
Crash Reports and Diagnostics
We use Sentry to detect crashes, errors, and performance problems. Depending on the error and our Sentry configuration, diagnostic information may include:
- Stack traces and error messages;
- App version and operating-system version;
- Device model and technical environment;
- Actions or technical events leading up to an error;
- Performance and diagnostic information;
- Network or request information relevant to diagnosing the error.
We use this information to identify bugs, investigate failures, improve performance, and maintain the security and reliability of the app. We do not intentionally send uploaded audio files to Sentry.
Usage and Playback Statistics
The app periodically reports basic usage statistics to our servers, associated with your device identifier. This includes:
- How much time the app spends in the foreground, and how many separate times it is opened ("sessions");
- How much of that time is spent actively playing audio;
- The title and artist of songs played, and how many times each has been played;
- How many songs are present in your local on-device music library (a count only — the list of songs itself, and files not involved in a drop, are never uploaded);
- Which features or screens of the app you use.
We use this information to understand how the app is used, calculate aggregate statistics such as average session length and time spent listening, identify which features are used most, and improve the app. This data is tied to your device identifier, not to a name, email address, or other directly identifying information, but as noted above the device identifier is a pseudonymous identifier, not a completely anonymous one.
Advertising Data
QBox Player uses Google AdMob to display and measure advertisements. The Google Mobile Ads SDK may automatically collect or process information such as:
- Your IP address, which may be used to estimate an approximate location;
- Advertising identifiers, App Set ID, and other device identifiers;
- App launches, advertisement views, taps, and other app or advertisement interactions;
- Diagnostic and performance information;
- Information used to detect fraud, invalid traffic, and security incidents.
Google may use this information for advertising, advertisement measurement, analytics, security, and fraud prevention in accordance with the Google Privacy Policy.
Where legally required, including in the European Economic Area, the United Kingdom, and Switzerland, the app uses Google's consent tools before requesting advertisements that require consent.
Where required, you can review or change your advertising consent choices at any time from the app's About screen ("Privacy Choices"). You may also manage or reset your Android advertising identifier through your device settings.
2. How We Use Information
We use the information described above to:
- Provide local music playback and QR drop functionality;
- Upload, host, transmit, and deliver files at your request;
- Recognize drops created by the same device;
- Measure general app and feature usage;
- Maintain, troubleshoot, secure, and improve the app;
- Show and measure advertisements;
- Prevent spam, fraud, copyright abuse, malicious activity, and misuse of the service;
- Allow recipients to report drops and locally block senders;
- Investigate reports and enforce our Terms of Service;
- Comply with legal obligations and valid legal requests.
3. How Information Is Shared
People You Choose to Share With
Audio files and drop information are made available to people who receive or scan the QR code or link that you choose to share.
Service Providers
We use service providers to operate and maintain QBox Player. These may include cloud hosting and storage providers, Google AdMob for advertising, Sentry for crash reporting and diagnostics, and platform providers such as Google Play.
These providers may process information as necessary to provide their services to us and according to their own privacy terms.
Legal, Safety, and Enforcement Reasons
We may preserve or disclose information when we reasonably believe it is necessary to comply with applicable law, respond to a valid legal request, protect users or the public, investigate fraud or abuse, enforce our Terms of Service, respond to copyright complaints, or defend the rights and security of QBox Player and OpenRise Studio.
Business Changes
If OpenRise Studio or QBox Player is involved in a merger, acquisition, restructuring, financing, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
We do not sell your personal information for money. Third-party advertising providers may process information for personalized advertising where permitted and where any legally required consent has been obtained.
4. Data Retention
Uploaded Audio Files
A drop expires 24 hours after it is created. This period is fixed and is not chosen per drop. An admin may extend a specific drop's expiry where appropriate.
After a drop expires, an automated process runs approximately once per hour and deletes its uploaded audio files from active storage. Files are normally deleted within about an hour after expiry.
Files may be removed earlier if the drop is deleted, reported, found to violate our rules, or removed for technical, security, copyright, moderation, or legal reasons.
Usage and Activity Data
Detailed activity records — a list of which in-app actions were taken and when, stored as numeric action types rather than as any description of the songs, playlists, or searches involved — are automatically deleted 14 days after they are recorded.
Day-by-day usage counts are automatically deleted after 90 days. Before deletion they are combined into per-month totals, and those monthly totals are retained. Aggregate statistics of this kind, and the drop and track metadata described below, are not deleted on a schedule.
Drop and Track Metadata
After uploaded audio files are deleted, records relating to the drop may remain in our database — track titles, filenames, artist information, drop identifiers, device identifiers, timestamps, access statistics, expiry information, reports, and moderation status.
These metadata records are currently retained indefinitely unless manually deleted following an accepted deletion request, removed during maintenance, or deletion is required by applicable law.
Device and Usage Records
Device identifiers and daily-active-device records are currently retained indefinitely unless manually deleted following an accepted deletion request, removed during maintenance, or deletion is required by applicable law.
Reports and Enforcement Records
Reports, moderation decisions, and enforcement information may be retained for as long as reasonably necessary to investigate abuse, prevent repeated violations, resolve disputes, respond to copyright complaints, enforce our Terms, or comply with legal obligations. Locally-stored blocks (see above) stay on your device only and are never sent to us, so we have no record of them to retain or delete.
Sentry Diagnostics
Sentry retains crash and diagnostic information according to the retention settings applicable to OpenRise Studio's Sentry account. These settings are managed through Sentry and may vary by plan and data type.
Advertising Information
Information processed by Google AdMob is retained according to Google's policies, account settings, and legal obligations.
5. Your Choices and Deletion Requests
Optional Uploads
You do not have to create drops or upload audio files. Local music playback can be used without uploading your songs to our servers.
Advertising Choices
Where available or required, you can review or change consent choices via "Privacy Choices" on the app's About screen. You may also manage or reset your Android advertising identifier through your device settings.
Reporting and Blocking
From a received drop's menu you can report it to us, or block the sender locally on your own device — see "Reports and Blocking Information" above for how each works.
Resetting the Device Identifier
On Android, the device identifier is derived from your device's system ID and normally stays the same across an uninstall and reinstall (see "Device Identifier" above). It changes if you perform a factory reset, switch to a different device user profile, or in some cases reinstall under different signing circumstances. Simply updating the app (without uninstalling) never changes it.
Changing the device identifier does not automatically delete information already transmitted to our servers, Sentry, Google, or other service providers under the old identifier.
Requesting Access or Deletion
You may request access to or deletion of information associated with your device or a specific drop by emailing support@openrisestudio.com. Step-by-step instructions are also available on our Data Deletion page.
To help us locate the relevant information, include the device identifier shown on the app's About screen, the drop identifier, or the QR code or link connected with the request.
Because QBox Player does not use accounts and does not normally collect your name or email address, we may be unable to locate information if you cannot provide an identifier associated with the relevant device or drop.
We may ask for reasonable verification before processing a request. We may also retain information where retention is required by law or reasonably necessary for security, fraud prevention, copyright enforcement, dispute resolution, or legal claims.
6. Security
Information transmitted between the app and our servers is protected in transit using HTTPS/TLS. We use reasonable technical and organizational safeguards designed to protect stored information, restrict unauthorized access, and reduce the risk of loss, misuse, or alteration.
No electronic transmission or storage system is completely secure, and we cannot guarantee absolute security.
7. International Processing
QBox Player and its service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws. Where required, we and our service providers use appropriate legal and contractual protections for international processing.
8. Children's Privacy
QBox Player is intended for users aged eighteen and older and is not directed to children. We do not knowingly collect personal information from children.
If you believe that a child has provided information through the app, contact us at support@openrisestudio.com so that we can investigate and take appropriate action.
9. Changes to This Privacy Policy
We may update this Privacy Policy when our practices, features, service providers, or legal obligations change. The updated version will be posted on this page with a revised "Last updated" date. Where required by law, we will provide additional notice or request consent.
10. Contact Us
Questions, privacy requests, and complaints may be sent to:
OpenRise Studio
Email: support@openrisestudio.com