Media Center for iPhone, iPad, Apple TV, Mac, Android, Android TV and Fire TV
Privacy Policy
Last updated 10 September 2026
Media Center is an aggregator for the Plex and Jellyfin servers you already run: it brings them together in one app. It ships with no content of its own, owns none of what you watch, and is not an advertising business. This page explains exactly what the apps send us, what they never send, and what your household administrator can see. It covers every version of the app — iPhone, iPad, Apple TV, Mac, Android phone and tablet, Android TV and Fire TV — which all collect the same six things and no more.
Your media never passes through us
When you play something, the app connects directly to the media server your household administrator configured. The video, the audio and the subtitles travel from that server to your device. They do not travel through our systems, and we do not store, host, cache or inspect any of it.
All connections are HTTPS. The apps refuse plaintext http:// sources outright, so a misconfigured server fails to play rather than sending your session over an unencrypted connection.
What we collect
Six categories, and no more. This is the same list declared in the apps’ privacy manifests, on the App Store product page, in Google Play’s Data safety section and in the Amazon Appstore submission. All of it travels over HTTPS.
| Data | Why | Tied to you |
|---|---|---|
| Email address | Signing in, and identifying your household account. | Yes |
| Name | The display name on your household account and on each profile. | Yes |
| Account and profile identifiers | Keeping profiles separate so each person sees their own list and their own place in a title. | Yes |
| Viewing activity | What was played and how far you got, plus your saved list. This drives Continue Watching, the rows on the home screen, and the usage summary your administrator sees. | Yes |
| Crash reports | Diagnosing crashes. Collected by Firebase Crashlytics. | No |
| Other diagnostic data | Technical information sent alongside crash reports by the same Firebase components. | No |
Crash reports and diagnostics are not linked to your account. The apps never attach an account, profile or email to a crash report.
What we never collect
- No tracking, and no advertising. The apps show no ads and contain no advertising SDK. They never request Apple’s advertising identifier — it is not linked into the builds, and it does not exist on Apple TV — and the Android build declares no
AD_IDpermission, so it cannot read Google’s advertising ID either. Nothing is shared with data brokers or combined with data from other companies for advertising. - No usage analytics product. Firebase Analytics is not built into any version of the app: the library is not linked into the Apple apps or the Android one, so there is nothing to switch on. Crash reporting is the only Firebase service that runs.
- We never see what you search for. A search is answered by your household’s own media server — the same server the video comes from, asked directly by your device. The words you type never reach us, are never stored by us, and are never used to build a profile of you. What that server logs is its operator’s decision, the same as for everything else you play from it.
- No location, contacts, photos, microphone, camera, health or fitness data. The apps do not ask for any of these permissions. The Android build asks you for nothing at runtime: the four permissions it declares are all granted at install and none of them can identify you —
INTERNETandACCESS_NETWORK_STATEto reach your server,WAKE_LOCKso a film does not stop when the screen dims, and one app-private permission Android itself generates so no other app can talk to our player. - No payment information. There are no in-app purchases and no subscriptions inside the apps.
What your household administrator can see
Media Center is organized around households. An administrator sets up the media server, creates the accounts, decides what a kids profile is allowed to see, and can view a usage summary for the households they created — including which titles were watched and when.
If you did not set up your own household, the person who invited you can see your viewing activity. That is worth knowing before you use a shared account. Administrators can also reset a household member’s password and remove their account.
Other services the apps talk to
- Your own media server. The Plex or Jellyfin server your administrator configured. Its operator decides what it logs.
- Amazon Web Services. Hosts our accounts and API in the United States.
- Google Firebase Crashlytics. Receives crash reports and the diagnostic data described above.
- Artwork and subtitle providers — TMDB, OpenSubtitles and SubDL, used to match posters, descriptions and subtitles to your library. These run on your administrator’s own accounts with those services, not ours, and the apps call them directly from your device. A title or an identifier is sent so the lookup can be answered; we do not receive or store those queries. If your administrator has not configured a provider, the app does not contact it at all.
- The app stores. Apple distributes the iPhone, iPad, Apple TV and Mac apps; Google Play distributes the Android phone, tablet and Android TV app; the Amazon Appstore distributes the Fire TV app. Each handles its own store accounts, purchases and install reporting under its own privacy policy, and none of them tells us who you are beyond the aggregate install counts every developer sees.
Children
Media Center is a general-audience app and is not directed to children. A kids profile is created and controlled by the household administrator, and it is restrictive by default: a kids profile sees only the categories the administrator has explicitly allowed. Content classified as adult is filtered out of every profile, in every mode, and there is no setting that turns that filter off.
We collect the same six categories for a kids profile as for any other, and no more.
Keeping it safe, and how long we keep it
Traffic is HTTPS end to end. Sign-in tokens are stored in the protected store the platform provides: the system Keychain on Apple devices, and on Android an encrypted file whose key lives in the Android Keystore and never leaves it, so the file is useless if it is lifted off the device. Neither store is readable by another app. The credentials an administrator enters for a media server are encrypted before storage and are only ever decrypted to serve that household’s own apps.
Account details and viewing activity are kept while the account exists. Crash reports are retained by Firebase Crashlytics under Google’s retention schedule, currently up to 90 days.
Your choices
- Accounts are not created in the apps. A household administrator creates yours, or an administrator registers on this site.
- Deleting an account. Ask your household administrator to remove it, which deletes the account and its profiles along with their viewing history. If you are an administrator, or you cannot reach yours, email us at the address below and we will delete it.
- Clearing viewing activity. Deleting a profile removes that profile’s history and saved list.
- Access and correction. Email us to ask what we hold about your account, or to have it corrected.
Changes and contact
If this policy changes materially we will update the date at the top of the page and, where the change affects what we collect, note it in the app’s release notes.
Questions, or a request about your data: privacy-mediacenter@webbits.dev.