Data Protection
Effective date: September 20, 2026
This page supplements our Privacy Policy with the specific information required under data protection laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA) — who the data controller is, what legal bases apply, and what rights you have.
Summary: Arcfin has no backend of its own. The only personal data involved in using the app either stays entirely on your device, or is sent directly from your device to a server you yourself operate or have chosen to connect to. We are not a data controller for that server-side data — you are, for your own server. We hold essentially nothing about you.
Data controller
For the very limited data described below that relates to your use of the app itself (not your Jellyfin server's own data), the controller is:
Puranjay Savar Mattas
Contact: privacy.arcfin@psmattas.com
We have not appointed a Data Protection Officer, as one is not required given the scope and nature of processing described here.
What we process, and on what basis
| Data | Where it's processed | Legal basis |
|---|---|---|
| Sign-in credentials for your Jellyfin/Seerr/Streamystats server | Locally on your device (Keychain) and directly with the server you configured — never with us | Performance of a contract (providing the app's core function) — Art. 6(1)(b) GDPR |
| Playback position, downloads, local preferences | Locally on your device only | Performance of a contract / legitimate interest in the app functioning as expected |
| Wi-Fi network name (for home/away server switching) | Locally on your device only, transient | Consent (the location permission prompt) — you can decline it and the feature simply won't auto-switch |
| Crash/diagnostic logs, if you choose to share them with Apple | Apple's own crash reporting, not visible to us unless you separately send us a report | Your own choice, governed by Apple's policies, not ours |
We don't process any data for advertising, profiling, or automated decision-making.
Your Jellyfin server's own data
Your watch history, library contents, user accounts, and similar data live on your Jellyfin (and, if connected, Seerr/Streamystats) server — a system you control, not us. We're not the controller or processor for that data. Requests to access, correct, or delete it should go to whoever administers that server (which may be you).
International data transfers
Because Arcfin has no server of its own, there is no transfer of your data to us across borders. Data you enter goes directly from your device to the server you specified, wherever that server is hosted — a choice and a transfer you control, not us.
Retention
Data stored locally on your device (credentials, downloads, preferences) is retained until you delete it, sign out, or delete the app — at which point it's removed. We hold nothing server-side to retain, because we have no server.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port data we hold about you, and to object to its processing or withdraw consent at any time. In practice, for the small amount of data described above that involves us at all:
- Access / deletion / portability — the data lives on your device; you already have full access to it, and deleting the app deletes it.
- Withdrawing consent — turn off local network or location permission in iOS Settings at any time; the relevant Arcfin features will simply stop working rather than failing silently.
- Any other request — email privacy.arcfin@psmattas.com and we'll respond within 30 days.
EU/UK residents also have the right to lodge a complaint with their local data protection supervisory authority.
California residents (CCPA/CPRA)
We don't sell or share personal information, and haven't in the preceding 12 months, because we don't collect any to sell or share. Since we hold no personal information server-side, there is nothing for us to disclose in response to an access request beyond what's already described on this page.
Security
Credentials are stored using iOS Keychain, encrypted at rest by the operating system. Network requests to your server use whatever transport (HTTP/HTTPS) your server is configured for — we recommend configuring your Jellyfin server with HTTPS, which is outside Arcfin's control but strongly advised for anything reachable outside your home network.
Changes to this page
If this page changes, the updated version will be posted at this same URL with a new effective date.