From the deadwax
What Leaves Your Mac When You Click Identify
An album has incomplete tags, and you want to know which release it belongs to. Identify looks like a single action. Underneath it, the app reads local files, computes fingerprints, sends a request, and evaluates the returned candidates. If privacy matters to you, knowing where the computation happens is only the beginning. You also need to know what the request contains and who receives it.
Private Press calculates a Chromaprint fingerprint on your Mac. A fingerprint is a compact audio pattern used to help match a recording. When available, that value and the album and track details go to Keynell; calculating it locally does not hide the request from the service that receives it.
The Keynell request contains recognizable metadata
The album identification body includes the album title, album artist, a parsed year when available, the number of submitted tracks, and a country hint normally taken from the Mac's locale region. That region is a matching hint; it is not a GPS location.
Each submitted track includes an ID used to connect the reply to that track, its track position, an optional disc number, title, duration in milliseconds, an ISRC when present, and a Chromaprint string when generation produced one. An ISRC is a recording identifier that can help matching.
The request includes tracks the app can edit and whose recorded duration is positive. A track can be submitted without a fingerprint if its metadata qualifies. That is why it would be inaccurate to describe Identify as sending only an audio fingerprint.
Album and track names go to the service as readable text, rather than hashes that conceal the names from it. The request uses HTTPS, but the server still needs to read its contents. The request body does not include a folder path or upload the complete audio file. Those narrower observations describe this identification body; they do not describe every network operation the application can perform.
Consider a hypothetical collection containing an album called Evening Sessions [Vinyl rip 2019, my copy]. Before building the request, Private Press removes certain album-title annotations that the identification service already removes for matching, including square-bracket content. The outbound title in this example becomes Evening Sessions.
That reduces an unnecessary disclosure. It is a limited cleanup, though. It does not promise to remove personal information from every title, artist name, or track field. The remaining musical metadata still identifies what you are asking the service to match. Keep personal filing notes out of descriptive tags if you do not want those notes included in identification requests.
Authorization is a separate request
The identification request uses an authorization token. When the app needs to obtain one, it contacts Keynell's token endpoint separately from the album identification endpoint.
If a license key is present, the token request includes that license key. It omits the installation identifier. Without a license key, the current app uses a randomly generated installation identifier in the request's device_id field. The field name should not be mistaken for a hardware serial number: the value is generated from random bytes, with no hardware input.
The app stores that identifier in a non-synchronizable Keychain item. With the stored item available, it remains stable across launches and can survive reinstalling the app. It is not an identifier intentionally shared through iCloud Keychain to your other Macs. Apple's Keychain synchronization documentation explains the distinction between synchronizable and non-synchronizable items.
Stable is the important word for privacy. A service can associate repeated token requests carrying the same value. The identifier is pseudonymous, rather than anonymous. Random generation avoids deriving identity from the hardware; it does not prevent the recipient from recognizing the identifier again. If Keychain access or storage fails, the app can retain a generated value in memory for that process instead, so persistence depends on successful storage and later access.
AcoustID receives a different lookup
Private Press also has a track identification path using AcoustID, including a fallback from server identification in applicable cases. Calling that path local refers to client-side orchestration and fingerprint computation. Its AcoustID lookup still uses the network.
The direct lookup sends the encoded fingerprint, the whole track duration in seconds, an application client key, and a request for associated recording and release details. It does not send the Keynell album request's title, artist, country hint, or track identifier as fields in that lookup. AcoustID documents fingerprint and duration as required lookup inputs and describes the client key as the application's API key. See the AcoustID web service documentation.
These are distinct requests to distinct services. A fingerprint is useful because it can identify a recording. That same purpose means you should treat it as information about the music being identified. Avoid assuming that omitting a filename makes the lookup uninformative to its recipient.
Identification and press accounting have different boundaries
Press-credit accounting uses a different request from Identify. The current album pseudonyms used for credit accounting are not private from Keynell, and they are separate from the installation identifier described above. Treat them as service-visible identifiers, rather than an anonymity feature.
For a collector, Identify's value is that it combines evidence from audio and metadata to propose a useful release match before you change the files. You can review that result and decide whether it fits your edition. The privacy tradeoff is concrete: selected musical metadata and fingerprints leave the Mac for identification, and authorization carries a license key or a persistent pseudonymous installation identifier.
If that disclosure fits your needs, identify the albums you want to resolve and inspect the candidates. If it does not, work from the tags and artwork you can review manually. Knowing the actual fields lets you make that choice without relying on an ambiguous promise that the whole operation happens locally.
See which services identification contacts and which details are sent.
Read the privacy policyFrom the deadwax
Subscribe to Deadwax
New posts on music collections, artwork quality, and the tech behind Private Press.
We respect your privacy. Unsubscribe anytime.