legato.fm Terms

legal

Privacy policy

Last updated October 1, 2026

Legato is a music player you run on your own hardware. Most of it never talks to us at all. This page covers the parts that do: this website, its waitlist, and the optional legato.fm account and remote-access service. It says what we collect, why, where it's kept, and how to have it removed.

"We" and "us" mean Daniel Churchill, who builds and runs Legato. Write to [email protected] about anything on this page.

The short version

  • Your music library, its metadata, and your play history stay on your own machine. We never receive them.
  • This website has no analytics, no tracking, no third-party scripts, and sets no cookies.
  • If you join the waitlist, we keep your email address so we can tell you when Legato is ready to install.
  • If you create a legato.fm account, we keep the name, email, and profile picture your sign-in provider shares, so you can sign in and link your servers.
  • We don't sell your data, show ads, or share it with anyone except the providers listed below, who run parts of the service for us.

The Legato app and your own server

The Legato desktop app and the Legato server run on hardware you control: your computer, a NAS, a Raspberry Pi. Your music files, everything Legato works out about them, your playlists, favourites and play history, and the owner account you create on your server (its password is stored only as a one-way hash) all stay there. We don't receive copies, and the app sends us no usage statistics.

To fill in details about your music, your server looks things up in public music databases directly, without going through us: MusicBrainz, the Cover Art Archive, LRCLIB (lyrics), Deezer (artist photos), and Wikipedia and Wikidata (descriptions). If you add an AcoustID key yourself, it also sends audio fingerprints to AcoustID. These lookups send the names of artists, albums and recordings in your library, and those services see your server's IP address. Their own privacy policies apply to what they receive.

This website

legato.fm is hosted on Cloudflare. Like any web host, Cloudflare handles your IP address and browser details to deliver the page and protect it from attacks. We don't add anything on top: there's no analytics, no tracking pixel, no embedded third-party content, and no cookies. Fonts and images are served from legato.fm itself.

The waitlist

When you join the waitlist, we store your email address and the time you joined, in Cloudflare's storage. We use it for one thing: to email you when Legato is ready to install. There's no newsletter and no mailing-list company. To stop abuse of the form, your IP address is kept for up to 10 minutes to limit repeated sign-ups, then deleted automatically.

We delete the waitlist on request only. Email [email protected] at any time to have your address removed.

legato.fm accounts

A legato.fm account is optional. A Legato install at home works without one. You need one to reach your own server from outside your home network, and later to use Legato in a browser or join a friend's server.

You sign in with Google or GitHub. We never see your Google or GitHub password. We ask those providers only for your basic profile, and we store:

  • which provider you used, and the account ID it gives us;
  • your email address (from GitHub, your primary verified address);
  • your display name and profile picture link;
  • when you created the account and when you last signed in;
  • your active sign-in sessions, so you stay signed in on your devices;
  • for each Legato server you link to your account, the credential it uses to connect, and the short-lived code you used to link it.

From Google we request only openid, email and profile. From GitHub we request only read access to your profile and email addresses (read:user, user:email). We can't see your contacts, files, repositories, or anything else in those accounts.

Legato's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Remote access (Legato Relay)

When you open your own server from outside your home network, your device and your server connect through the legato.fm service. Requests from your apps, including the audio you play, pass through it on the way. The service relays this traffic and doesn't store it, read it, or keep copies of your music. Because it sits in the middle, it's technically able to see that traffic as it passes. We say so plainly because it's true of any relay.

Like most web services, it keeps request logs: the time, your IP address, and the address requested. We use them to keep the service running and to deal with abuse, and they're kept for up to 30 days.

Remote access will be a paid service. Payments will be handled by a separate payment provider, and this page will be updated to name it before we take any money.

Who else handles your data

These companies run parts of Legato for us. Each only gets what it needs for its job:

  • Cloudflare: hosts this website and the waitlist, and runs legato.fm's DNS.
  • Fly.io: hosts the legato.fm account and remote-access service, in the United States (Ashburn, Virginia).
  • Google: our email (Google Workspace), and sign-in if you choose "Sign in with Google".
  • GitHub: sign-in, if you choose "Sign in with GitHub".

We'll also share data if the law requires it, and only as much as it requires. Apart from that, we don't share, sell, or rent it to anyone.

Where it's kept, and for how long

  • Waitlist: in Cloudflare's storage, as described above.
  • Account and linked servers: on the legato.fm service in the United States, for as long as you keep the account.
  • Sign-in sessions: up to 30 days after last use, or until you sign out.
  • Server-linking codes: 10 minutes.
  • Request logs: as stated under remote access.

If you're outside the United States, using legato.fm accounts means your account data is stored there.

Your choices and rights

You can ask us at any time to show you the data we hold about you, correct it, send you a copy, or delete it. Email [email protected] from the address on your account or waitlist entry, and we'll do it within 30 days. Deleting your account removes your profile, sessions and linked-server credentials. Your servers keep working at home and keep everything stored on them. Self-service export and deletion are coming to account settings.

Depending on where you live, privacy law may give you further rights, such as objecting to how we use your data or complaining to your local data protection authority. Get in touch and we'll help.

We keep your account data because you asked for an account, and your waitlist email because you asked to be told when Legato launches. Where the law asks us to state a legal basis, those are ours: providing the service you signed up for, and your consent.

Security

Everything between your browser and legato.fm is encrypted (HTTPS). Access to our systems is limited to the person running them. No system is perfectly secure, so if we ever find a breach that affects your data, we'll tell you without delay.

Children

Legato isn't directed at children under 16, and we don't knowingly collect data from them. If you think a child has given us their details, email us and we'll delete them.

Changes

Legato is pre-release, and this page will change as features launch: a browser version, Spotify import, invites, paid remote access. We'll update the date at the top each time. Before anything that collects new kinds of data goes live, we'll update this page first, and email account holders about any significant change.

Contact

[email protected]

legato
Privacy · Terms legato.fm