If you discover a security vulnerability within Orbit Music, please report it responsibly.
Do NOT open a public issue for security vulnerabilities.
Instead, please reach out privately via:
- LinkedIn: Rahul Loyal Dalmas
- Instagram: @rahul_.loyal
Orbit Music implements the following security measures to ensure user safety and data privacy:
- Local-First Data Storage — User preferences, playback history, and playlist databases are securely kept on-device using Room Database.
- Secure Endpoints — All network requests and APIs (lyrics, metadata, and audio stream fetching) enforce secure HTTPS protocols.
- Permissions Minimalism — Only essential system permissions are requested (e.g., Internet, Foreground Service), with optional features like microphone/audio record for song recognition prompting user approval.
- Local synchronization safety — Websocket servers utilized during shared playback sessions (Listen Together) are designed to run securely over isolated channels.
| Version | Supported |
|---|---|
| 4.x.x | ✅ |
| < 4.0 | ❌ |
Powered by Shruhh.Inc