MetaMusic

Privacy policy

What this bot can see, and how long we keep it

Last updated 14 September 2026. This page is for people using MetaMusic, and for Google and Telegram review.

MetaMusic is a Telegram bot that tags FLAC files you send it. Drive is optional. We wrote this in ordinary language so you do not have to decode permission names to know where you stand. Step-by-step use is in the manual.

Google Drive

We cannot read your entire Drive

When you tap Connect Google Drive, Google shows a permission screen. That screen does not mean “let this bot open everything in Drive.”

MetaMusic uses Google’s limited drive.file access. In practice that means the bot can create its own folders (a library and a review folder) and can upload or update the music you sent it in Telegram. It cannot list, search, open, or download the rest of your Drive. Your photos, PDFs, other people’s shares, and folders you already had are out of reach.

We also see the email address of the Google account you linked, so the settings screen can show you which account is connected. We do not use that email for marketing.

Retention

One week for music. Three months if you go quiet.

1 week Music files on our servers
3 months Your bot session if unused

These two clocks are the whole retention story on our side. They are not “up to,” and they are not hidden in a footnote.

Music files: one week on our servers

While the bot tags a track, it may keep a copy on our server: the file you sent, a cache copy, or a temporary file waiting to upload. Each of those copies has its own timestamp. After one week (seven days) from that timestamp, a daily cleanup job deletes it. We do not keep a permanent music library on our machines.

If you already saved a tagged copy into your Google Drive, that copy is yours. Deleting our server copy does not delete the Drive copy. Remove it in Drive if you want it gone there. Files still being processed or uploaded are not wiped mid-job.

Your session: three months of silence

A “session” here is not your Telegram login. It is the record we keep so the bot knows you: your Telegram user id, settings, and — if you connected Drive — the stored Google login (a refresh token) that lets us upload into those MetaMusic folders.

If you do not use the bot for three months, we treat you as idle. We drop the stored Google login first, then forget the rest of that bot session on our servers. You can talk to the bot again later and connect Drive again if you still want it.

You can also unlink Drive yourself in the Mini App settings at any time. That throws away the stored Google login immediately, without waiting three months.

What we receive from Telegram

Telegram sends us what you would expect a bot to see: your user id, the chats where the bot is used, files and captions you send it, button taps, and reactions on its messages. The Mini App sends a short signed packet (initData) so we know the request is really you. We use all of that only to run tagging, library, review, and settings — not to profile you for ads.

If you send a FLAC in a group, people in that group can see it. That is Telegram, not a MetaMusic share setting.

Lookups that are not Google

To guess tags, we send an audio fingerprint to AcoustID. We may ask MusicBrainz or Last.fm for titles, artists, and related metadata. Those services never receive your Google password or Drive token. The audio itself is not re-encoded.

What we do not do

We do not sell your data. We do not use Google user data for advertising. We do not share your Drive token with other apps. The Google client secret stays on the bot server. Login happens on https://music.avje.in (the same site as the Mini App), not on this www site.

Who to ask

MetaMusic is run by the person behind @MetaMusicProBot. Message that bot in a private chat if you want your server-side session wiped sooner than the three-month idle timer. Do not paste secrets or OAuth links in a public group.