Privacy Policy — Three Albums
Last updated: 1 August 2026
Three Albums lets you commit to three albums each week and listen to them through your Apple Music subscription.
The app has no user accounts and no passwords. It uses no advertising networks, no third-party analytics, and no third-party SDKs of any kind — it is built entirely on Apple frameworks. Most of what the app records stays on your device.
What stays on your device
The app stores the following locally, and does not send it to us:
- The albums you draft and seal each week
- How many times you played each album and each track
- How long you spent listening
- Your starred tracks
- Which records handed to you by other people you have already taken
- Your app settings
- A cached copy of album details and cover artwork for the albums you are currently committed to, so they still display without a connection
None of this is uploaded to our database. It is not used for advertising or analytics, and we do not receive it.
Depending on your device and backup settings, Apple may include local app data in an iCloud or computer backup. We cannot access or control those backups.
Deleting the app removes the active local copy of this information from your device. Copies inside device backups remain governed by your Apple backup settings.
What the app sends off your device
The app sends information off your device in the circumstances described in this section, and we have tried to list all of them.
1. When your shelf is visible
Your shelf's visibility is a single setting on your card, under Who sees your three. It has two states: No one, and the people you have added.
Important: this setting applies to every week you have sealed, not only to future ones. Making your shelf visible publishes all the weeks you have already sealed, including weeks you sealed while your shelf was set to No one. Setting it back to No one takes them all back down. If there is a week you do not want published, keep your shelf set to No one.
You choose this setting when you create your card. It starts on the visible option, shown on screen above the button that creates the card, and one tap changes it before anything is created. Until you create a card, nothing is published at all.
When your shelf is visible, the following is stored in Apple's iCloud through CloudKit, in a database belonging to Three Albums:
- The name you choose. You pick it yourself. It does not have to be your real name, and it is not read from your Apple Account or your contacts.
- A short invite code the app generates so other people can add you.
- The weeks you have sealed — album titles, artist names, cover-artwork references and colours, the week's dates, and the time you sealed it.
- An app-specific iCloud identifier provided by Apple. It is unique to Three Albums, is not shown to other users, and cannot be used by us to identify your Apple Account outside this app.
Drafts are never published. Only a sealed week can go up.
2. When you pass a record on
You can hand one of your three to one person you have added. This works regardless of your shelf's visibility setting — passing a record on is not covered by Who sees your three, and a private shelf does not prevent it.
Passing a record on stores the following in the same database:
- Your app-specific identifier and the name on your card
- Who you sent it to
- The album, and the week it came from
- The note you write on the slip, if you write one, in full
The person you sent it to is not told whether you looked at your own record again, and you are not told what they did with theirs.
3. When you report someone
Filing a report stores your app-specific identifier, the reported person's identifier and the name they were using at the time, the reason you chose, and the first 500 characters of any note you write. Reports are readable only by their author and by us. The reported person is not told.
4. When you add or block someone
Who you have added, and who you have blocked, are stored in your own private iCloud database rather than the shared one. Other users cannot read those lists.
5. Apple Music
Searching for albums and playing them goes to Apple through MusicKit, and Apple receives those requests under its own privacy policy. We do not receive your Apple Music listening history from Apple. The play counts and listening time described above are measured by the app on your device.
Who can see what you publish
Your shelf is intended for people you have given your invite code to, and the app provides no public browse, no user search, no directory, and no feed of strangers. The only way someone reaches your shelf is with your code.
We want to be precise about the limits of that. Published shelf records and passed records are stored in a shared database, with access controlled by Apple's CloudKit permissions. They are readable by other signed-in users of the app who can query that database, not only by the people you gave your code to. There is no listing or search that would let someone find you, so in practice this is obscurity rather than secrecy. Do not put anything in your display name or on a slip that you would not want read by someone other than the recipient.
Invite codes can be copied and forwarded by anyone you give them to. Give your code only to people you trust.
People are not notified when you view their shelf, and cannot see that you did.
We may access published records when reasonably necessary to operate the service, investigate technical problems or misuse, respond to support requests, protect users, or comply with legal obligations. We do not use them for advertising or behavioural analytics.
Notifications
The app sends one notification, on a Sunday, telling you your week is over.
If somebody has passed a record to you and you have not taken it yet, that notification names them — up to two people by name, and a count beyond that. It is generated on your device. The app sends no other notifications, and never tells anyone else what you are doing.
Where information is stored
Published records are stored using Apple's CloudKit. Apple processes and stores them on our behalf under Apple's terms and privacy policy, which you can read at https://www.apple.com/legal/privacy/.
How we use information
We use what is stored in CloudKit only to:
- Publish your shelf when it is visible, and show it to people with your code
- Deliver a record you passed to the person you sent it to
- Operate and maintain those features
- Respond to support requests
- Investigate technical problems, abuse or misuse
- Meet applicable legal obligations
TestFlight
While Three Albums is distributed through TestFlight, Apple may provide us with information about your beta installation, app sessions, crashes, and device or operating-system details, along with any feedback or screenshots you choose to submit. If you were invited by email, Apple may show us the name and email address on the invitation; people who join through a public link may appear anonymously.
We use this only to test, troubleshoot and improve the app. Apple processes TestFlight information under its own policies, and retains it for periods Apple determines.
What we do not do
- We do not sell your personal information.
- We do not disclose it to advertisers or data brokers.
- We do not track you across other companies' apps or websites.
- We do not use advertising networks, third-party analytics, or third-party SDKs.
- We do not use your information for targeted advertising.
- We do not collect your precise location, contacts, photos, or health data.
- We do not publish what you played, how often, how long you listened, or which tracks you starred. No field for any of it exists in our database.
Information is disclosed only as described in this policy: to Apple as necessary to provide CloudKit, MusicKit and TestFlight, and to other users as described above.
Stopping sharing, and deleting what you published
To stop sharing without deleting anything, open Others › your card and set Who sees your three to No one. This takes every published week back down. People who added you stop seeing your shelf.
To delete what you have published, open Others › your card › Close your account. This deletes:
- Your chosen name and your invite code
- Every week you have published
- Every record you have passed to anyone, including its slip
- Your list of people added and your list of people blocked
It cannot be undone.
Two things it does not delete, both deliberate:
- Reports you have filed are kept. A report is evidence about someone else, and closing your own account should not withdraw a complaint that has not been acted on. A kept report still contains your app-specific identifier and anything you wrote in it.
- Records other people passed to you belong to the person who sent them, not to you, and are removed by their sender or by expiry.
Your local weeks, plays, listening time and starred tracks are not affected, because they were never uploaded. Deleting the app removes the active local copy of those.
Retention
Published weeks remain until you take them down, close your account, or set your shelf to No one.
A record you pass to someone waits about three weeks before it stops being offered to them. The app deletes expired records the next time you pass one on, so an expired record may remain in the database until then. If you close your account, all of them are deleted at that point.
Reports are kept as described above.
We do not maintain a separate archive of deleted records. Apple may retain temporary or residual copies through its own backup, security and data-retention practices, which we do not control.
Security
Three Albums relies on Apple's platform security and CloudKit's access controls. We do not add encryption of our own beyond what Apple provides, and — as set out under Who can see what you publish — published records are not restricted to the people you gave your code to.
No method of electronic storage or transmission is completely secure. We take reasonable steps to protect the app and its data, but cannot guarantee absolute security.
Children
Three Albums is not directed at children under 13, and we do not knowingly collect personal information from children under 13. Playback requires access to an Apple Music subscription.
If you believe a child has provided personal information through Three Albums, contact us and we will review it.
Changes to this policy
We may update this policy if the app's features, data practices or legal obligations change. If a change is material, we will update the date at the top and publish the revised version before the change takes effect.
Contact
For privacy questions, support, or concerns about something another person has published:
We aim to respond within a few days.