Privacy Policy
Headroom does not operate a central media library or advertising service. Your library belongs to you and remains on the media servers and devices you choose.
Information stored on your device
Headroom stores server URLs and names, account names and server-issued user identifiers, preferences, library indexes, artwork caches, diagnostics, playback state, and downloaded media on your device. Passwords, access tokens, and refresh tokens are stored using the operating system's secure credential storage where the platform makes it available. Removing an account or uninstalling the app removes app-managed local data subject to your operating system's backup and retention behavior.
Your media servers
When you connect Jellyfin, Emby, Plex, an OpenSubsonic-compatible server, or Audiobookshelf, Headroom sends the credentials and requests required to authenticate, browse, stream, download, and update playback state. Those requests go to the server URL you supplied. That server's operator controls its logs and retention. Plex sign-in additionally contacts Plex's cloud authentication service when you choose the PIN flow.
Headroom supports plain HTTP because many personal servers run only on a trusted local network. HTTP does not encrypt credentials, tokens, or media. Use HTTP only on a trusted LAN or through a VPN; use HTTPS for remote access.
Optional and task-specific services
- RevenueCat: when storefront information or purchase status is requested, RevenueCat receives a random app user identifier, product and transaction information, platform information needed to verify the purchase, and the network IP required to deliver the request. Headroom does not attach your media-server credentials or library to that identifier.
- Sentry: crash reporting is off until you explicitly opt in. Headroom's configuration sends sanitized JavaScript error categories, app version, code location, and an anonymous grouping value. It excludes raw error messages, breadcrumbs, account, device, library, server, screenshot, replay, performance, and native crash payloads. Sentry necessarily observes the connection IP while receiving a report, but Headroom asks it not to attach that IP to the event.
- ListenBrainz: if enabled, Headroom sends recording or release identifiers used to request recommendations. The service also sees the connection IP.
- Last.fm: if you supply an API key, artist and track names needed for matching are sent to Last.fm along with the network request.
- MusicBrainz: metadata identifiers, artist names, or recording names may be sent when Headroom resolves metadata or radio matches.
- AirPlay, Google Cast, CarPlay, and Android Auto: when you use these features, playback metadata and, where required, a media URL are shared with the receiver or vehicle system you selected.
Apple and Google may independently provide store, TestFlight/Play test, and crash information under their own privacy policies. If you send a support message or diagnostic export, the maintainer receives only the information you choose to include.
Advertising, tracking, and sale
Headroom contains no advertising SDK, does not track you across other companies' apps or websites, and does not sell personal information.
Retention and deletion
Headroom does not maintain a central account database. Local data remains until you remove the relevant account/data or uninstall the app. Store transaction records and processor records are retained by Apple, Google, RevenueCat, or another service according to their policies and legal obligations. Optional crash reports follow the Sentry project retention settings. Contact support if you need help locating or deleting app-managed data.
Children and changes
Headroom is not designed to collect information from children and does not provide public social or advertising features. This policy may be updated as the app changes. Material changes will be dated here and, where appropriate, disclosed in the app or release notes.
Contact
Use the current instructions on the support page for privacy requests or questions.