This Privacy Policy explains how the Lunarr mobile application (the "app"), published by Sayem Chowdhury (the "developer" or "we"), handles information. Lunarr is a media library and streaming client for movies, TV shows, and episodes. It is a client for a self-hosted "Lunarr" server that you operate and control yourself (similar to Plex or Jellyfin). The app does not host, store, or stream media from the developer.
Because the app connects only to a server that you provide and control, the developer cannot see your media, your watch history, or any personal data that lives on your server. This policy describes only what the app itself does on your device.
We want to be explicit about what we do not do:
The app stores only two pieces of information on your device, in the operating system's secure storage (Expo SecureStore on Android using the Android Keystore, and the iOS Keychain):
http://192.168.x.x or an HTTPS reverse-proxied
address you configure).These two values are stored solely so the app can connect to your server. They are used only to communicate with that server and never leave your device except to talk to the server you configured. No other personal data is stored by the app locally.
All API and streaming traffic travels exclusively between your device and the self-hosted server you supplied. No data is sent to the developer or to any third-party vendor.
To reach a server on your Wi-Fi or local network, and to discover Cast-enabled playback devices, the app may request the Local Network permission on iOS (and equivalent LAN access on Android). The app does not request camera, microphone, contacts, photos, or location permissions.
The app may use your device's biometrics (Face ID or fingerprint) to protect access to the credentials stored on your device. This is performed by the operating system's secure enclave. The app does not collect, store, or transmit any biometric data.
Media metadata, watch progress, user accounts, and any other personal data live on your self-hosted server, which is infrastructure that you own and control, not the developer. The developer does not operate servers that process end users' personal data.
Because that data is yours, its storage, security, and deletion are your responsibility. To delete this data, manage it directly on your server (for example, by removing users, clearing watch progress, or uninstalling/resetting your server instance). The developer cannot access or delete server-side data for you.
The app is not directed to children under 13 and is not intended for use by children without the involvement of a parent or guardian. Because Lunarr is a media client, the content available through your server may include age-rated or mature material. Supervision of what is served from your own server is your responsibility. We do not knowingly collect personal information from children.
Depending on your location, you may have rights under laws such as the EU GDPR or the California CCPA/CPRA, including access to, rectification of, and deletion of your personal data.
Because the app stores only your server URL and API key on your device, you can exercise those rights directly: remove the app, or clear its stored data through your device settings, to delete the on-device credentials. Any personal data residing on your self-hosted server must be deleted by you on that server, as described in Section 6. The developer does not hold personal data about you and therefore has nothing further to disclose, correct, or erase on your behalf.
On-device credentials are kept in the platform secure storage (Android Keystore / iOS Keychain).
When your server is reachable over HTTPS, the app uses TLS to protect traffic in transit. If you
connect over a plain-text local network address (for example http://192.168.x.x),
traffic between the device and your server is not encrypted. You are responsible for securing your
own network.
We may update this policy from time to time. If we later add features that change our data practices (for example, optional crash reporting such as Sentry), we will update this document and revise the effective date. The current version remains available at this URL.
Questions about this policy can be directed to: Telegram group: @LunarrApp.