Privacy Policy

Effective July 21, 2026

Headroom does not operate a central media library or advertising service. Your library belongs to you and remains on the media servers and devices you choose.

Information stored on your device

Headroom stores server URLs and names, account names and server-issued user identifiers, preferences, library indexes, artwork caches, diagnostics, playback state, and downloaded media on your device. Passwords, access tokens, and refresh tokens are stored using the operating system's secure credential storage where the platform makes it available. Removing an account or uninstalling the app removes app-managed local data subject to your operating system's backup and retention behavior.

Your media servers

When you connect Jellyfin, Emby, Plex, an OpenSubsonic-compatible server, or Audiobookshelf, Headroom sends the credentials and requests required to authenticate, browse, stream, download, and update playback state. Those requests go to the server URL you supplied. That server's operator controls its logs and retention. Plex sign-in additionally contacts Plex's cloud authentication service when you choose the PIN flow.

Headroom supports plain HTTP because many personal servers run only on a trusted local network. HTTP does not encrypt credentials, tokens, or media. Use HTTP only on a trusted LAN or through a VPN; use HTTPS for remote access.

Optional and task-specific services

Apple and Google may independently provide store, TestFlight/Play test, and crash information under their own privacy policies. If you send a support message or diagnostic export, the maintainer receives only the information you choose to include.

Advertising, tracking, and sale

Headroom contains no advertising SDK, does not track you across other companies' apps or websites, and does not sell personal information.

Retention and deletion

Headroom does not maintain a central account database. Local data remains until you remove the relevant account/data or uninstall the app. Store transaction records and processor records are retained by Apple, Google, RevenueCat, or another service according to their policies and legal obligations. Optional crash reports follow the Sentry project retention settings. Contact support if you need help locating or deleting app-managed data.

Children and changes

Headroom is not designed to collect information from children and does not provide public social or advertising features. This policy may be updated as the app changes. Material changes will be dated here and, where appropriate, disclosed in the app or release notes.

Contact

Use the current instructions on the support page for privacy requests or questions.

External services maintain their own policies: RevenueCat, Sentry, ListenBrainz, Last.fm, and MetaBrainz/MusicBrainz.