Privacy Policy

Effective date: September 29, 2026. AllPlayer is developed by an independent developer and distributed on Apple platforms. This policy explains how information is handled when you choose to use its media, connection, sync, and diagnostic features.

Privacy by design

Core playback does not require an AllPlayer account, and we do not sell your personal information. Most app data is handled on your device, by Apple services you enable, or directly between your device and a media source or third-party service you choose.

Information you provide

If you email playersupport.arco@gmail.com, we receive your email address and any text, screenshots, diagnostics, or other information you include. Connection-assistant reports are generated on your device for you to review before sharing. We use support information only to respond, troubleshoot, maintain, and improve AllPlayer, and retain it only as reasonably necessary for those purposes or legal obligations.

Local media and app data

AllPlayer may access files, Photos items, folders, downloads, disc images, playback history, favorites, watch-later items, settings, and local media metadata to provide features you initiate. Local media playback, file management, stream caching, and media-center downloads are handled on your device. We do not operate an AllPlayer media server that uploads or stores your local media files.

  • Photos access is limited by the permission you grant in system Settings.
  • Downloads and cached media remain device-local and are not included in media-state iCloud sync.
  • Local-network transfer or receiver features may expose selected content to reachable devices while you enable those features.

Connections, sign-in, and credentials

When you add a NAS, media server, cloud drive, stream, or Tailscale connection, AllPlayer may store the address, account name, password, authentication key, access token, refresh token, cookie, or similar data needed to connect. Saved secrets use Apple platform storage such as Keychain and app storage where supported. Requests go to the service or source you selected when you browse, play, download, test, or refresh authorization. Those services process information under their own policies.

Google account and Google Drive data

Connecting Google Drive is optional. AllPlayer requests openid, email, and profile to identify the connected Google account and display its name and email address. It requests https://www.googleapis.com/auth/drive.readonly to browse existing Drive folders and files, read metadata such as file names, identifiers, sizes and modification times, and retrieve the media you choose to play or download. This integration does not create, edit, or delete files in your Google Drive.

Google authorization tokens are stored in the device's Keychain and used to access Google APIs. They are not included in Google Drive connection configuration synced through iCloud. Media downloads and playback caches remain on the device. When iCloud sync is enabled, connection details (including the connected account name and email), library metadata and playback state may be stored in your private CloudKit database and synced between your devices. If you initiate Google Drive sign-in for Apple TV, authorization results, including access and refresh tokens, are encrypted for transfer to the paired Apple TV over your local network.

Google user data is used only to provide the connection, browsing, playback, download and device-sync features you choose. We do not sell this data, use it for advertising or credit decisions, or use it to train generalized artificial intelligence or machine-learning models. We do not permit human access to Google user data except with your affirmative consent, when necessary for security, to comply with applicable law, or as otherwise permitted by Google's Limited Use requirements. AllPlayer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google data retention and deletion

AllPlayer retains locally saved account details, tokens, metadata and downloaded media for the features you use until you remove them through the app or device controls. Signing out removes the saved Google authorization tokens for that account on that device. You can also revoke AllPlayer's access in your Google Account connections. Revoking access prevents further authorized access to Google Drive; it does not automatically delete previously downloaded media, cached information or data already synced to iCloud. Remove those copies separately using AllPlayer's media and connection controls and the relevant device or iCloud storage controls. Turning off sync does not itself delete previously synced data. Repeat removal on other devices where copies remain. For help, or to request deletion of information you sent directly to the developer, email playersupport.arco@gmail.com.

iCloud sync and Handoff

On supported devices, iCloud configuration sync is enabled by default and can be turned off in AllPlayer Settings. It uses AllPlayer's private CloudKit database to sync LAN servers, video-stream lists, cloud connections, related connection data, playback progress, favorites, watch-later state, and similar media-library state between your devices. For some services this can include credentials or authorization information saved with a connection; Google Drive tokens are excluded as described above. Apple processes this data under its terms and privacy policy. Handoff uses Apple system services to transfer limited playback context; sensitive signed URLs, local paths, and URLs containing embedded credentials are excluded from Handoff.

Apple TV and Apple Watch

Apple TV QR setup can let an iPhone or iPad send server addresses, usernames, passwords, one-time codes, access tokens, refresh tokens, or similar authorization results over the local network. Where supported, this information is encrypted before transfer and is used for the connection or sign-in you request. The Apple Watch app exchanges browsing, artwork, playback, and control information with its paired iPhone through Apple connectivity services.

TMDB metadata connection fallback

In versions that support this feature, AllPlayer first requests movie and TV metadata directly from TMDB. If the direct connection fails or times out, it can retry the API request through our HTTPS relay at tmdb.allplayer.uk, hosted on Cloudflare Workers. The relay processes the request path, search terms or media identifiers, language and other query options, and the TMDB API credential needed for that request. Cloudflare also processes network information such as the connecting IP address. The relay forwards requests only to TMDB, does not keep an application database or enable Workers request logs, and does not receive video contents, Google Drive credentials, or cloud-drive file listings. Poster and backdrop images continue to load directly from TMDB image servers. Cloudflare may process service and security data under its Privacy Policy.

Third-party services

Depending on the features you choose, AllPlayer may communicate with Apple services; cloud, NAS, or media-server providers; Tailscale; OpenSubtitles; TMDB; video or stream hosts; and other sources you configure. These services receive the network and account information necessary to answer your request, including your IP address in ordinary network communication.

If you start an internet speed test, AllPlayer first uses Cloudflare's public speed-test service and may use Measurement Lab (M-Lab) as a fallback. M-Lab retains and publicly publishes measurement data under its privacy policy for Internet research. A remote-server speed test reads data from the selected server and does not upload a test file to it. See Cloudflare's Privacy Policy and M-Lab's Privacy Policy.

Shared links and web content

When you share or paste a supported link, AllPlayer may contact the original website, its APIs, or its media hosts to identify and retrieve content on your device. Some sites require a browser sign-in session and may use cookies or similar technologies. AllPlayer does not send your media to a developer-operated analysis server. Source availability and privacy practices are controlled by the relevant website or service.

Purchases and diagnostics

App distribution, purchases, refunds, and purchase restoration are handled by Apple. Apple may also provide crash reports and limited diagnostics such as device model, operating-system and app versions, time of an error, configuration, and crash details according to your device settings. We use diagnostic information only for troubleshooting, reliability, and app improvement.

Data sharing and security

We do not sell personal information. We share or enable access only as needed to provide a feature you request, use platform and service providers described in this policy, comply with legal obligations, or protect rights and security. We use reasonable safeguards, but no internet, local-network, or electronic-storage method is completely secure.

Children, rights, and choices

AllPlayer is not directed to children under 18, and we do not knowingly collect personal information from children. Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, request portability, or withdraw consent for information we control. You can revoke system permissions, disconnect services, turn off iCloud sync, or remove local app data through the app and system Settings. Contact us for requests concerning information you sent directly to us.

Changes and contact

We may update this policy as AllPlayer changes. The effective date above identifies the latest published version. For privacy questions or requests, email playersupport.arco@gmail.com.