Bugzila Car Play Privacy Policy

App: Bugzila Car Play  ·  Package: com.bugzilacarplay.app
Developer: Bugzila Labs  ·  Effective date: 16 August 2026  ·  Last updated: 18 August 2026
Policy baseline: Bugzila Car Play v6.6.01.227

Bugzila Car Play is designed to minimize personal data collection. The app does not require a Bugzila account, does not sell user data, and does not collect payment card numbers. Some technical, purchase, analytics, diagnostic, search, backup, media, and device/service data may be processed only as described below.
Quick links:
Data we handle Purchases & Premium Firebase & diagnostics Radio search Google Cast Retention Data deletion Contact

1. Overview

Bugzila Car Play is an Android media utility for local music playback, phone-only video playback, online radio, Android Auto media browsing and controls, Bluetooth media metadata/control, Google Cast, Premium features, Backup & Restore, optional Firebase notifications, optional analytics, optional crash diagnostics, and support tools.

Bugzila Car Play does not require users to create or sign in to a Bugzila account to use its main features.

2. Information we do not intentionally collect

Bugzila Car Play is not designed to intentionally collect a user's name, home address, phone number, personal email address inside the app, precise GPS location, contacts, SMS/call logs, advertising ID, payment card number, credit score, health information, or general Google Drive account contents.

Google Play and other third-party services may process information under their own terms when users choose to use those services.

3. Data types that may be processed

The Google Play Data Safety declaration for the current app may include the following data types because they can be transmitted off the device or processed by SDKs/services used by the app:

4. Local media and permissions

Local Music requests audio access only when needed to browse and play audio on the user's device. Phone-only Video requests video access only when needed for that feature. Local media remains under the user's control and is not automatically uploaded to Bugzila servers.

Online Radio can be used without granting local audio or video file access.

5. Backup & Restore

Backup & Restore uses Android's system file picker and Storage Access Framework. Users choose where to save or open a Bugzila Car Play configuration file, including local storage or a document provider supported by the device.

Bugzila Car Play does not use the Google Drive API to browse a user's Drive. A user-selected document provider may process a backup file under that provider's own terms when the user chooses it.

Configuration backups may contain supported app settings such as radio favorites, themes, EQ/audio preferences, radio settings, local music scan settings, Cast preferences, notification preferences, and other supported configuration values. Backups do not contain Premium entitlement, purchase tokens, order identifiers, credentials, Firebase identifiers, FCM tokens, diagnostic reports, API keys, or local music file contents.

6. Google Play purchases and Premium verification

Premium is purchased through Google Play. Google Play handles payment processing, payment-card information, taxes, refunds, and the Google account used for the purchase. Bugzila Car Play does not receive or store payment card numbers.

To verify Premium, the app may send the Google Play purchase token over HTTPS to the dedicated Bugzila billing verification service. The backend validates the purchase with the Google Play Developer API and, for eligible purchased transactions, may acknowledge the purchase with Google Play.

The Android app does not intentionally persist or log the raw purchase token. The billing backend uses a one-way SHA-256-based fingerprint of the purchase token as the ledger identifier and may retain minimal verification metadata such as package/product, purchase state, acknowledgement state, verification decision, test-purchase indicator, timestamps, and replay/verification counters. This is used for entitlement reconciliation, replay/duplicate-processing protection, fraud/security controls, and operational troubleshooting.

The raw purchase token is not stored in the replay ledger and is not included in Analytics, Crashlytics, diagnostic screens, support reports, or configuration backups.

See the separate Billing Disclosure for additional purchase details.

7. Firebase Installation ID, optional Analytics and optional Crash Diagnostics

Bugzila Car Play includes Firebase components. Firebase may create a Firebase Installation ID or other app-instance identifier used by enabled Firebase services.

Usage Analytics

Usage Analytics is optional and controlled by the in-app Privacy & Analytics setting. Analytics collection is disabled by default in the app configuration and is enabled only when the applicable user setting allows it.

When enabled, Analytics may process app version, Android version, language/locale, approximate location derived by the analytics service, feature/screen interaction events, playback/source categories, Cast or Android Auto feature interactions, Favorite interactions, and limited online-radio station identifiers or station names used to understand feature usage.

Bugzila Car Play is designed not to send raw purchase tokens, order identifiers, local music file contents, local music paths, stream URLs, contacts, precise GPS location, credentials, or support-report contents to Firebase Analytics.

Crash Diagnostics

Crash Diagnostics is optional. When enabled, Firebase Crashlytics may process crash logs and diagnostic information such as app version, Android version, device model/manufacturer, app state, feature state, sanitized error messages, stack traces, Firebase/Crashlytics installation identifiers, and technical crash information needed to diagnose defects and improve stability.

Diagnostic handling is designed to avoid intentionally including local media contents/paths, raw purchase tokens, order identifiers, API keys, service credentials, or configuration backup contents.

8. Firebase Cloud Messaging and notifications

Firebase Cloud Messaging (FCM) is optional. The app can request notification consent and, where required by Android, notification permission. After consent, Firebase may create or refresh an FCM registration token and the app may subscribe to service-related topics.

Notifications are used for service announcements, important app updates, radio/server issues, Android Auto-related service alerts, and similar developer communications. Bugzila Car Play does not use FCM for third-party advertising.

When notifications are turned off through supported in-app controls, the app disables FCM auto-init, removes supported topic subscriptions where possible, and requests deletion of the app's FCM token.

Online radio streams and directory/search results may be provided by public radio directories, public radio APIs, and individual radio-station servers.

When the user performs an online/advanced radio search, the search term may be transmitted over HTTPS to a public radio directory service so that matching stations can be returned. This action is initiated by the user and is used for app functionality. Bugzila Car Play does not intentionally store raw radio-search text in a Bugzila server database.

When playing a radio station, third-party streaming servers may receive ordinary connection information such as IP address, user agent/request information, access time, requested stream URL, and connection status under their own privacy practices.

Region-based radio suggestions may use Android language/locale or region settings. This feature does not require precise GPS location.

10. Android Auto and Bluetooth

When using Android Auto or Bluetooth media controls, media information such as station/track title, artist, artwork, playback state, queue information, and control state may be transferred to the connected system to display and control playback. These transfers are used for app functionality and are not used by Bugzila Car Play for advertising.

11. Google Cast

Cast sessions are initiated by the user. To enable playback, the app may send media metadata, artwork references, playback state, online stream URLs, and related connection information to the selected Cast receiver and Google Cast components.

For local music Cast playback, the selected local audio file may be made temporarily available to the selected receiver over the user's local network for the duration needed to play the media. The local audio file is not uploaded to or retained by a Bugzila backend as part of this flow.

When Cast is disconnected, the app attempts to stop the Cast session and clear related playback state.

12. Problem reports and support messages

Support/problem reports are created or sent only when the user intentionally chooses to do so. A report may include app version, Android version, device model, feature/permission state, connection state, and sanitized playback/debug information needed for troubleshooting.

Users should not include passwords, purchase tokens, payment-card information, private keys, or other sensitive information in support messages.

13. Data sharing and service providers

Bugzila Car Play does not sell user data and does not share user data with advertising partners.

Data may be processed by service providers or transferred as part of a specific user-initiated action, including Google Play, Firebase, Google Cast, Android Auto, public radio directories/streams, Android document providers, and user-selected support channels. These providers may process information under their own terms and privacy policies.

The Google Play Data Safety form may classify eligible service-provider processing and specific user-initiated transfers as not being "shared" with third parties under Google Play's Data Safety definitions.

14. Security and transmission

Bugzila Car Play uses reasonable technical and organizational measures appropriate to the data and feature involved. Data sent to Bugzila-controlled billing/integrity services and supported Internet APIs is transmitted using HTTPS/TLS where applicable. Firebase and Google Play communications are handled through their supported secure service transports.

User-initiated local-network media delivery to a selected Cast receiver is a direct playback path selected by the user and is not a Bugzila server-storage path. Users should use trusted local networks and trusted receiver devices.

No Internet or device-to-device system can be guaranteed to be completely secure.

15. Data retention

16. How to request data deletion

Deletion request email: bugzila@gmail.com
Recommended subject: Bugzila Car Play Data Deletion Request

In the request, describe the data or support interaction you want reviewed or deleted and provide only the minimum information reasonably needed to locate it, such as the approximate date and support channel used. Do not send a purchase token, payment-card number, password, private key, or other secret.

Users can delete local app data through Android Settings by clearing Bugzila Car Play storage or uninstalling the app. Users can delete exported backup files from the location/provider where they saved them. Optional Analytics, Crash Diagnostics, and notifications can be disabled through supported in-app Privacy & Analytics controls.

Bugzila Labs will review valid deletion requests for data it controls and can reasonably identify. Some records may be retained when necessary for security/fraud and replay prevention, purchase/entitlement reconciliation, refund or dispute handling, legal compliance, or required record keeping. Some data controlled by Google/Firebase, radio services, Cast/Android Auto components, document providers, email providers, or other third-party services may need to be managed through those providers.

Because Bugzila Car Play does not require a Bugzila account and intentionally avoids storing raw purchase tokens in its ledger, some backend/Firebase records may not be individually identifiable from a deletion request without sufficient non-sensitive context.

17. Children's privacy

Bugzila Car Play is a general media utility and is not specifically directed to children. If a parent or guardian believes personal information was submitted through a support channel, they may contact Bugzila Labs to request review or deletion.

18. Changes to this Privacy Policy

This policy may be updated to reflect app features, SDK/service usage, backend changes, Android/Google Play requirements, security improvements, or legal requirements. The current version will be published at this URL with an updated date.

19. Contact

Developer: Bugzila Labs
Email: bugzila@gmail.com
Official website: https://bugzilacarplay.github.io/
Privacy Policy: https://bugzilacarplay.github.io/privacy-policy/
Billing Disclosure: https://bugzilacarplay.github.io/billing/
Facebook support: Bugzila Car Play