Privacy Policy
Effective date: September 20, 2026
Arcfin ("the app") is developed by Puranjay Savar Mattas ("we", "us"). This policy explains what happens to your data when you use Arcfin.
Summary: Arcfin has no server of its own. It connects directly from your device to the Jellyfin server you point it at — a server you run and control, not one we operate. We don't collect, see, or store your media, your credentials, or your viewing activity. There's no account with us, no analytics, and no third-party tracking SDKs.
What Arcfin connects to
Arcfin is a client for services you already run or already have accounts with. When you add a server or turn on an integration, your device talks to it directly:
- Your Jellyfin server — required. This is your own self-hosted media server (or one you've been given access to). Arcfin sends your sign-in credentials and playback requests straight to that server's address; we never see them, because there's no Arcfin server in between.
- Seerr (optional) — if you connect a Seerr instance to browse and request new content, the same applies: your device talks to that server directly.
- Streamystats (optional) — if you connect a Streamystats instance to view watch statistics, your device talks to that server directly.
None of the above are servers we operate. We have no visibility into your library, your watch history, your requests, or your stats.
What's stored, and where
| Data | Where it lives |
|---|---|
| Server addresses, sign-in tokens, Seerr/Streamystats credentials | Your device's Keychain, encrypted by iOS. Never sent anywhere except the server they belong to. |
| PIN / Face ID app lock | Your device only. Face ID data never leaves Apple's Secure Enclave; Arcfin only ever receives a yes/no from the system. |
| Downloaded videos, subtitles, artwork | Your device's local storage, for offline playback. Deleted when you delete the download or the app. |
| Playback position, watch history cache, app preferences | Your device's local app storage (SwiftData/UserDefaults). Mirrors what your Jellyfin server already tracks for your account — Arcfin doesn't add a second copy anywhere else. |
| Current Wi-Fi network name | Read on-device only, to auto-switch between a server's local and remote address depending on whether you're on your home network. Never stored beyond the network name you've told Arcfin is "home," never transmitted anywhere, never used for location tracking. |
What we don't do
- We don't run a server that your data passes through.
- We don't use analytics, advertising, or third-party tracking SDKs of any kind.
- We don't require or collect a name, email, or account to use the app.
- We don't sell or share data, because we don't collect any to sell or share.
Third-party services
Beyond the server(s) you connect, a few features talk to outside services directly from your device:
- YouTube trailer playback — if a title on your server has no local trailer file, Arcfin can optionally play its YouTube trailer in-app (a setting you can turn off). This uses Google's official embedded player, which loads directly from YouTube — subject to Google's Privacy Policy and the YouTube API Services Terms of Service.
- Google Cast (Chromecast) — casting to a Chromecast device uses Google's Cast SDK to discover and communicate with devices on your local network, subject to Google's Privacy Policy.
- Apple services — AirPlay, Picture in Picture, Now Playing/Control Center, and the App Store itself are all standard Apple frameworks and services, subject to Apple's Privacy Policy.
We don't control and aren't responsible for these third parties' data practices — check their policies directly for details.
Local network access
Arcfin asks for local network permission to discover Jellyfin servers and Chromecast devices on your Wi-Fi network. This is used only for discovery and casting — it doesn't send any data off your network by itself.
Children's privacy
Arcfin is not directed at children. It's a client for a media server you already control — any content restrictions or parental controls for what's playable are configured on your Jellyfin server itself, the same way they would be for any other Jellyfin client.
Data deletion
Because Arcfin doesn't hold a copy of your data anywhere but your own device, deleting the app removes everything Arcfin stored locally (downloads, cached preferences, Keychain entries). Your actual library, account, and watch history live on your own Jellyfin server and are unaffected — manage those there.
Changes to this policy
If this policy changes, the updated version will be posted at this same URL with a new effective date.
Contact
Questions about this policy: support.arcfin@psmattas.com