Privacy

Home Stream collects nothing about you. Your library lives on a server you run, and the sample library you can try first forgets you within a day.

The short version. The apps talk to a server you run, in your own house. Your library, what you have watched, your favourites and your account live there. We cannot see any of it, because it never reaches us — there is no account on our machines and no analytics in the apps. The one thing we run is a small sample library to try the apps with, which never knows who you are.

What the apps store on your device

Signing out removes the token. Deleting the app removes the rest.

The sample library

A new install opens on a small sample library we run, so there is something to look at before you connect your own server. It gives the app an anonymous guest account: no name, no email and no Apple ID.

While you look around, the sample library keeps what any library keeps, so its features work: what you played and where you got to, favourites, your watch list and playlists. None of it is linked to you, none of it is used for anything else, and all of it is erased within 24 hours, or after two hours unused, whichever comes first.

The sample library is reached through Cloudflare, which carries the connection to it. Connecting your own server leaves the sample library for good, and nothing from it comes with you.

What your own server holds

Your server records what you would expect a media library to record: your account and its name, what you have watched and where you got to, favourites, playlists and watch lists. That is data you hold, on hardware you own. We have no access to it, and no way to ask for it.

You can delete your account from inside the apps — Settings on iPhone and iPad, the account screen on Apple TV — which erases your playlists, favourites, watch history and watch list from that server.

Signing in with Apple

Sign in with Apple identifies you to your own server, so a household can keep one person's viewing separate from another's. Apple gives your server an identity token, which it verifies with Apple's public keys. We are not part of that exchange and receive nothing from it.

The two things the apps load from elsewhere

What is not in the apps

Children

A household can give an account a child's age rating, and the server refuses anything above it. That setting lives on your server, like everything else.

Changes

If this ever stops being true, this page changes before the behaviour does.

Getting in touch

Questions about privacy, or anything else, go to support.