Privacy Policy

Lunarr mobile app for iOS and Android

Effective date: July 12, 2026

Controller / publisher: Sayem Chowdhury

1. Overview & Scope

This Privacy Policy explains how the Lunarr mobile application (the "app"), published by Sayem Chowdhury (the "developer" or "we"), handles information. Lunarr is a media library and streaming client for movies, TV shows, and episodes. It is a client for a self-hosted "Lunarr" server that you operate and control yourself (similar to Plex or Jellyfin). The app does not host, store, or stream media from the developer.

Because the app connects only to a server that you provide and control, the developer cannot see your media, your watch history, or any personal data that lives on your server. This policy describes only what the app itself does on your device.

2. Information We Do NOT Collect

We want to be explicit about what we do not do:

3. Information Stored on Your Device

The app stores only two pieces of information on your device, in the operating system's secure storage (Expo SecureStore on Android using the Android Keystore, and the iOS Keychain):

These two values are stored solely so the app can connect to your server. They are used only to communicate with that server and never leave your device except to talk to the server you configured. No other personal data is stored by the app locally.

4. How the App Communicates

All API and streaming traffic travels exclusively between your device and the self-hosted server you supplied. No data is sent to the developer or to any third-party vendor.

To reach a server on your Wi-Fi or local network, and to discover Cast-enabled playback devices, the app may request the Local Network permission on iOS (and equivalent LAN access on Android). The app does not request camera, microphone, contacts, photos, or location permissions.

5. Biometric Use

The app may use your device's biometrics (Face ID or fingerprint) to protect access to the credentials stored on your device. This is performed by the operating system's secure enclave. The app does not collect, store, or transmit any biometric data.

6. Data on Your Self-Hosted Server

Media metadata, watch progress, user accounts, and any other personal data live on your self-hosted server, which is infrastructure that you own and control, not the developer. The developer does not operate servers that process end users' personal data.

Because that data is yours, its storage, security, and deletion are your responsibility. To delete this data, manage it directly on your server (for example, by removing users, clearing watch progress, or uninstalling/resetting your server instance). The developer cannot access or delete server-side data for you.

7. Children's Privacy

The app is not directed to children under 13 and is not intended for use by children without the involvement of a parent or guardian. Because Lunarr is a media client, the content available through your server may include age-rated or mature material. Supervision of what is served from your own server is your responsibility. We do not knowingly collect personal information from children.

8. Your Rights

Depending on your location, you may have rights under laws such as the EU GDPR or the California CCPA/CPRA, including access to, rectification of, and deletion of your personal data.

Because the app stores only your server URL and API key on your device, you can exercise those rights directly: remove the app, or clear its stored data through your device settings, to delete the on-device credentials. Any personal data residing on your self-hosted server must be deleted by you on that server, as described in Section 6. The developer does not hold personal data about you and therefore has nothing further to disclose, correct, or erase on your behalf.

9. Security

On-device credentials are kept in the platform secure storage (Android Keystore / iOS Keychain). When your server is reachable over HTTPS, the app uses TLS to protect traffic in transit. If you connect over a plain-text local network address (for example http://192.168.x.x), traffic between the device and your server is not encrypted. You are responsible for securing your own network.

10. Changes to This Policy

We may update this policy from time to time. If we later add features that change our data practices (for example, optional crash reporting such as Sentry), we will update this document and revise the effective date. The current version remains available at this URL.

11. Contact

Questions about this policy can be directed to: Telegram group: @LunarrApp.