Effective Date: August 2026
Audio Hero respects your privacy. The application has no automatic telemetry, no advertising, and no tracking. There is no Audio Hero user account. Core playback and device control happen entirely on your local network. A small number of optional features (listed below) make requests to services on the internet, and only when you turn them on or use them. This includes an optional, user-initiated bug report that is stored temporarily on the Audio Hero website. The Pro cloud-sync feature uses your own Microsoft account and stores its single sync file inside your own OneDrive; the Audio Hero website never sees that file.
1. Data Collection
Audio Hero does not automatically collect personal information, usage analytics, or crash reports.
The application:
- Does not require an Audio Hero account. The optional cloud-sync feature uses your own Microsoft account and your own OneDrive (see Section 2.3).
- Does not automatically collect names, email addresses, device identifiers, or other personally identifying information.
- Does not automatically track usage, behavior, sessions, crashes, or analytics of any kind. A diagnostic report is sent only after you open the bug-report window, review the explanation, and click Submit report (see Section 2.5).
- Does not use cookies, fingerprinting, or similar tracking technologies of its own. (The optional PC-streamed web players described in Section 2.4 open third-party music sites in a built-in browser window; those sites keep their own sign-in cookies on your PC, exactly as they would in any web browser.)
- Does not transmit your listening history, ratings, or playlists in a bug report. A diagnostic message can contain a station or file name involved in the reported problem.
2. Network Communication
2.1 Local network only (always)
The following traffic stays entirely inside your home network:
- HEOS device discovery: SSDP multicast on
239.255.255.250:1900. - HEOS device control: JSON commands over a TCP socket on port
1255to the IP address of your HEOS-compatible speaker, receiver, or amplifier. - Legacy Denon receivers: HTTP control on port
8080or80, and optionally telnet on port23, to the IP address of the receiver. - Local file streaming (Pro): a temporary HTTP server is launched on a random local port and bound to your LAN IP. It serves only the audio file you have chosen, and only to the LAN IP of the device that is going to play it. It is not exposed to the internet.
- Device discovery across your own subnets: some homes are split into more than one private network range (a guest or IoT network, a second router range, a range extender). Because a multicast search does not cross between them, Audio Hero can also look for devices on those other ranges. It builds the list of ranges from your PC's own network connections, the Windows routing table, addresses that devices have announced, and addresses of devices you have used before, plus any range you add yourself; you can view, disable, or remove them under Settings > Devices & sources > Network discovery > Manage local subnets, or switch the whole feature off. Only private address ranges are ever considered, and Audio Hero only attempts the specific control ports of the device families you have enabled. No part of this contacts a public internet address, and no information about your network is transmitted anywhere.
- All other supported device families: the same applies to every other device type Audio Hero can control (Sonos, Roku, Onkyo/Integra, Chromecast, AirPlay, DLNA, Yamaha MusicCast, Snapcast, Squeezelite, WiiM, Bluesound, Samsung Wireless Audio, kiosk tablets, Kasa smart plugs, and so on). Each is discovered and controlled with its own local protocol and ports, always directly between your PC and the device on your own network. None of this traffic leaves your LAN.
2.2 Optional internet requests
The following requests are sent to the public internet only when you use or enable the related feature. Routine service requests use no Audio Hero account or tracking identifier. A submitted bug report has a random report number so the developer can identify it.
| Service | Purpose | When it is contacted |
|---|---|---|
| Microsoft Store | Pro upgrade purchase, license check, and app update checks | On startup and when you check for updates or purchase Pro |
Microsoft Identity Platform (login.microsoftonline.com) |
Sign-in for the optional Pro cloud-sync feature | Only if you click "Sign in with Microsoft" in Settings (Pro) |
Microsoft Graph (graph.microsoft.com) |
Reading and writing the single audiohero-sync.json file inside the private Audio Hero folder of your own OneDrive |
Only while you are signed in for cloud sync (Pro) |
| radio-browser.info | Internet radio catalog search | When you use the internet radio browser |
| somafm.com | SomaFM channel list | When you open the SomaFM section of the radio catalog |
| Internet radio stream hosts | The actual audio stream you selected (e.g. Radio Paradise, KEXP, BBC, NPR, etc.) | While that station is playing |
| TheAudioDB | Artist and track metadata for the Track Info panel | Pro: while a track is playing, if Track Info is enabled |
| Deezer (public API) | Artist and track metadata for the Track Info panel | Pro: while a track is playing, if Track Info is enabled |
| Wikipedia | Artist biographies for the Track Info panel | Pro: while a track is playing, if Track Info is enabled |
| MusicBrainz | Music metadata cross-references for the Track Info panel | Pro: while a track is playing, if Track Info is enabled |
| bommerts.com | Receiving an optional sanitized diagnostic report for developer support | Only after you click Submit report in the bug-report window |
MusicBrainz and Wikipedia require a User-Agent header that identifies the calling application. Audio Hero sends the literal string AudioHero/<version> (https://bommerts.com/audiohero) for this purpose. No other identifying information is sent.
You can avoid all optional internet traffic by not using the Internet Radio feature, by turning off the Track Info panel in Settings, by not signing in to cloud sync, and by not submitting a bug report. The Microsoft Store update and license checks are handled by Windows itself and run only on app startup.
2.3 Optional Pro cloud sync (Microsoft account + OneDrive)
Pro users can optionally sign in with a personal Microsoft account so their Audio Hero settings, votes, starred favorites, saved streams, and music-source order stay in sync between PCs. This feature is off by default. When you sign in:
- Sign-in is handled by the Microsoft Authentication Library (MSAL). Your password is entered into the Microsoft sign-in page (or the Windows account broker in the Microsoft Store build) and never passes through Audio Hero.
- Audio Hero asks for the smallest possible OneDrive permission:
Files.ReadWrite.AppFolder. This grants access only to a private folder named after the app inside your OneDrive. Audio Hero cannot read, write, or list any of your other OneDrive files. - Audio Hero also requests
User.Readso it can display the email address of the signed-in account in Settings, andoffline_accessso you do not have to re-enter your password on every launch. - Inside the app folder, Audio Hero maintains a single JSON file named
audiohero-sync.jsoncontaining your settings, votes, starred favorites, saved streams, and music-source order. The same data already stored in%LOCALAPPDATA%\Audio Hero\settings.json. - The sync file is uploaded to and downloaded from Microsoft Graph (
graph.microsoft.com) over HTTPS. The Audio Hero bug-report server is not involved and has no way to read the file. - You can sign out at any time from Settings. Signing out clears the cached MSAL tokens on your PC. To delete the sync file itself, remove the Apps -> Audio Hero folder from onedrive.live.com.
2.4 Optional PC-streamed web players (YouTube Music, Apple Music, Device + This PC)
Audio Hero can play certain web music services on your speaker by opening the service's own website in a built-in browser window on your PC, capturing the audio locally, and streaming it to your device over your local network. This covers the YouTube Music and Apple Music sources and the Device + This PC source (which can also play Amazon Music, Pandora, Tidal, Deezer, SiriusXM, Spotify, iHeartRadio, and TuneIn). These features run only when you open one of those sources.
- The built-in browser connects directly to the chosen service (for example
music.youtube.comormusic.apple.com), the same way your normal web browser would. Audio Hero does not proxy or store this traffic, and there is no Audio Hero server in between. - You sign in with your own account for that service, inside the service's own web page. That sign-in is kept in a private browser profile stored on your PC so you do not have to sign in every time. Audio Hero never sees or stores your password for these services.
- You can optionally run the Audio Hero Companion on another PC on your local network (in the Audio Hero Companion settings). When you do, the service's sign-in page is shown to you on this PC and the mouse and keyboard you use are sent to the other PC to complete the sign-in. That connection stays on your local network and is encrypted (TLS); you can additionally require a 4-digit PIN on both ends for extra security. The sign-in is then kept in a browser profile on the Companion PC, and each person who uses the Companion gets their own separate browser profile there. Audio Hero still never sees or stores your password.
- When you play local files (Pro) through a Companion, the Companion keeps a copy of each queued file in a cache on that PC so playback can continue after Audio Hero closes. The Keep copied local music on this Companion setting (on by default) controls whether those copies are kept for next time or deleted when they are no longer playing. The copies never leave your local network.
- The captured audio is streamed only to the LAN IP of your device, over the same kind of temporary local HTTP server described in Section 2.1. It is not exposed to the internet.
- Each service has its own privacy policy and terms that govern your use of its site.
2.5 Optional bug reports
Settings > System & advanced includes a Submit bug report to developer action. It first opens a review window explaining what will be sent. Nothing is transmitted automatically, and closing the window sends nothing. If you click Submit report, Audio Hero creates a compressed report with a random report number. It contains the Audio Hero and package versions; edition and connection state; Windows and .NET runtime descriptions and architectures; culture, time zone, app uptime, and a summary of network-adapter types and states; recent diagnostic logs; and basic device type, manufacturer, model, firmware, and connection information. Your optional written description is included exactly as entered.
- The report does not include
settings.json, passwords, access tokens, cookies, browser profiles, media files, playlists, ratings, or saved favorites. - Common secret patterns, email addresses, the Windows account and computer names, known device names, IP addresses, MAC addresses, and user-folder paths are removed or replaced with report-local aliases before upload. Diagnostic logs are free-form text, so a station name, file name, service display name, or other text involved in the problem can remain.
- The report is sent over HTTPS to
bommerts.com. The server verifies the report number and version and inspects every ZIP entry before storing it. It accepts only the expected report text, optional description, and diagnostic-log files. It stores the ZIP in a directory that cannot be accessed through the website and does not extract it. - The server emails the developer only the report number, time, app version, file size, stored filename, and description. Diagnostic logs are not attached to the email.
- Reports are used only to investigate support requests and are automatically removed after 30 days during endpoint cleanup.
- To prevent abuse, the server allows up to six submission attempts per hour from one public IP address. It does not store the raw IP address in the rate-limit file. Instead, it stores a SHA-256 hash of the address in the filename and recent attempt timestamps inside the file. These temporary rate-limit files contain no report data and are removed after two hours during endpoint cleanup.
3. Data Storage
Audio Hero stores everything it remembers in a single JSON file at %LOCALAPPDATA%\Audio Hero\settings.json on your own PC. By default nothing in this file is transmitted off your device. If you opt in to the Pro cloud-sync feature (Section 2.3), a copy of most of these fields is mirrored to a private folder inside your own OneDrive.
What is stored:
- The IP addresses and friendly names of discovered or saved HEOS and legacy devices.
- The list of private network ranges on your own network that discovery may search, and whether each is enabled (see Section 2.1).
- UI preferences such as window size, view mode (full, compact, ultra-compact, tray), and theme options.
- Your thumbs-up and thumbs-down votes on tracks, used to drive the optional skip-on-thumbs-down behavior.
- Starred favorites and your custom music-source order.
- Saved internet radio stations and custom streams you have added.
- Sleep timer preferences and other feature toggles.
Any device or service credentials you choose to store in Audio Hero - your HEOS account password, and device passwords for platforms that need one (for example Fully Kiosk or Dashie kiosk tablets) - are encrypted at rest using Windows Data Protection API (DPAPI) in CurrentUser scope. This means only the same Windows user account on the same PC can decrypt them. Plaintext passwords from older versions of Audio Hero are automatically migrated to the encrypted form on first run after upgrade. Stored credentials are never uploaded to OneDrive even when cloud sync is enabled.
You can delete the entire %LOCALAPPDATA%\Audio Hero folder at any time to reset the application to a clean state.
A bug report is stored separately on the Audio Hero website only when you explicitly submit one, as described in Section 2.5.
4. Third-Party Services
Audio Hero does not use analytics platforms, advertising networks, or user tracking of any kind. The Audio Hero website receives only bug reports that users explicitly submit for support.
The third-party services listed in Section 2.2 (and the PC-streamed web players in Section 2.4) are contacted directly from your PC, only when you use the feature they power. Each of those services has its own privacy policy that governs what they do with the requests they receive:
- Microsoft Privacy Statement (covers the Microsoft Store)
- radio-browser.info
- SomaFM
- TheAudioDB
- Deezer (public API)
- Wikimedia Foundation (Wikipedia)
- MetaBrainz Foundation (MusicBrainz)
Internet radio stream URLs come from radio-browser.info or are added by you. The radio station you choose will see the connection from your PC, the same way it would if you opened the stream in any browser or media player.
5. Security
- All third-party service calls listed in Section 2.2 use HTTPS.
- User-submitted bug reports are sent over HTTPS, limited in size and frequency, and inspected before storage. The server accepts only the expected text report, optional description, and diagnostic-log entries, stores the ZIP in a web-inaccessible directory, and never extracts it.
- Stored device and service credentials are encrypted at rest with Windows DPAPI (CurrentUser scope).
- Microsoft sign-in tokens for the optional cloud-sync feature are stored by MSAL using the standard Windows token cache (DPAPI in CurrentUser scope, or the Windows Account Manager broker in the Microsoft Store build). They never leave your PC.
- The local HTTP servers used for local file playback and for the PC-streamed web players are bound to your LAN IP and are reachable only by devices on the same network. They are shut down as soon as the playback they serve ends.
- The optional link between Audio Hero and an Audio Hero Companion stays on your local network, is encrypted with TLS, and can additionally be protected with a 4-digit PIN.
- The Pro upgrade is processed entirely by the Microsoft Store. Audio Hero never sees your payment information.
- Audio Hero has no remote management surface. The only things that listen for connections are the LAN-only local audio servers and the LAN-only Companion link described above; nothing is reachable from the internet.
6. Children's Privacy
Audio Hero does not knowingly collect information from children. The application has no accounts or profiles. Its optional bug-report form is intended only for technical support and should not be used to submit personal information.
7. Changes to This Policy
This privacy policy may be updated in future versions of the app or as the set of optional internet features changes. Any changes will be reflected with an updated effective date at the top of this page.
8. Contact
If you have questions about this privacy policy, you may contact: