This policy covers the Credenza Android app (com.credenza.client), published on Google Play,
and this website, credenza.tv. Google requires every listing to link a privacy policy, including
one for an app that collects nothing, which is what the app is. The website is different, and
says what it counts below.
The short version
The Credenza app collects no personal data, sends nothing to us, and contains no analytics, advertising or crash-reporting services. We do not operate a server that it talks to. We receive nothing from it and could not identify a user of it if we wanted to.
What the app actually is
Credenza is a self-hosted media server. You run the server, on your own hardware or hosting, and the Android app is a window onto it. When you open the app you type the address of your server, and from that point the app displays whatever that server sends it.
Everything the app shows you — your films, your programmes, your games, your account, your viewing history — lives on your server and travels between your server and your device. It does not pass through us, because there is no “us” in that path: no intermediary service, no relay, no cloud account.
What is stored on your device
Only what the app needs in order to be the app:
- The addresses of servers you have connected to, so you do not retype them, and which one is current. Removing a server from the list, or uninstalling the app, removes them.
- Certificate fingerprints you explicitly approved. If your server presents an HTTPS certificate Android does not trust — normal for a server on your own network — the app shows you the certificate’s fingerprint and asks. If you accept, the fingerprint is remembered for that one host so you are not asked again. A host that later presents a different certificate is untrusted again and you are asked again.
- Your sign-in session with your own server, held as an ordinary cookie by the system WebView, exactly as it would be in a browser. Signing out clears it.
None of this leaves your device. The app requests no storage, camera, location, contacts or
notification permissions — its entire permission list is INTERNET and ACCESS_NETWORK_STATE, and
you can read that in the published manifest.
What your own server records
Your Credenza server keeps what a media server keeps: which accounts exist, what has been watched and how far through, what has been played, and reports anyone has filed about a title. That is your data on your machine, governed by whatever you decide, and it is outside the scope of this policy — we have no access to it.
If you connect to somebody else’s Credenza server, the person running that server decides what it records. Ask them.
Third parties
The app itself contacts nothing except the server address you typed.
Your server may contact metadata providers on your behalf when it scans your library — TMDB, ScreenScraper, IGDB — using credentials you supply, in order to fetch titles, descriptions and artwork. Those requests come from your server, not from your phone, and each is optional: a server with no such credentials configured simply files what it finds by filename.
Your server also periodically reads one public file from credenza.tv —
credenza.tv/releases/latest.json, every twelve hours unless its operator changes that — to learn
whether a newer release is out. The request carries nothing about your server — no version, no
identifier, no account — goes through the same outbound proxy as the metadata requests when one is
set, and the operator can switch it off.
This website
The app sends us nothing. This website does count its visitors, using PostHog, so that we can tell whether anybody reads it and where they stop on the way to installing.
- What is recorded: the pages you open and how long you stay on each, the site that sent you here, your browser, operating system and screen size, and the links and buttons you click — including their text — which is how we see which install snippets are copied, which platform is opened on the install page. Never what you type.
- Until you choose, no cookie. Visits are counted with nothing stored in your browser: PostHog derives a daily, salted hash on its servers that cannot follow you from one day to the next, and discards your IP address without looking up where it is.
- If you choose “No thanks”, that stays true, and the only thing stored is your answer, in this site’s local storage, so that you are not asked again.
- If you choose “Allow”, PostHog stores an anonymous identifier in first-party cookies and local storage, so a second visit is counted as a return, and your IP address is used to estimate your country. Change your mind at any time with Cookie choice at the foot of every page, or by clearing this site’s data.
- Where it goes: requests travel through relay.credenza.tv, ours, and on to PostHog’s United States region. There is no session recording, no heatmap and no mouse tracking, and nothing is shared with advertisers.
Children
The app is not directed at children and collects no data from anyone, children included.
Changes
If this policy changes, the date at the top changes with it. This page, at credenza.tv/privacy, is always the current version.
Contact
Questions about this policy, or about the app: hello@credenza.tv.