Privacy policy
Keelarr is an iOS app for managing media services you host yourself. It is developed by Yurii Zarovnyi, an individual developer ("I", "me"). This page describes what the app does with your information.
The short version
- Keelarr has no account, no sign-up and no server of its own.
- The app talks to the servers you add to it and, unless you switch it off, sends anonymous usage data to TelemetryDeck, an analytics service. That data never includes your server addresses, credentials or media.
- Your server addresses and credentials are stored on your device and are never sent to me. Like other app data, your server addresses can be part of your own device backups.
- The app contains no advertising code and does not track you.
- Apart from that anonymous usage data and what Apple shares with developers, both described below, I only see what you choose to send me.
What the app stores on your device
Keelarr stores the following locally:
- Connection settings for each instance you add: its name, address, port, base path and connection options, and the result and time of its last connection test.
- Credentials such as API keys, usernames, passwords and custom header values. These are kept in the iOS Keychain, readable only while your device is unlocked and bound to that device: they cannot be restored onto a different device, even from a backup.
- Certificate trust decisions you make for servers that use a self-signed or private certificate: the server's host, port and certificate fingerprint.
- Cached data: the app may keep a local copy of what your services return, such as library and queue listings, so screens load quickly. Your services remain the source of truth and the copy can be rebuilt from them at any time.
- App preferences, such as your chosen appearance and whether usage data is shared.
- Usage statistics kept by the analytics SDK: the date of your first session, recent session start times and lengths, and usage signals waiting to be sent. They are described under "Analytics, advertising and tracking" below.
- Diagnostic log lines in the iOS system log on your device, one per network request, to help troubleshoot connection problems. Each line records the server address and path that was requested and the outcome. Request headers, query strings and response contents are never logged, and the app does not send these lines anywhere.
If you back up your device to iCloud or to a computer, connection settings, trust decisions, cached data, preferences and the analytics SDK's usage statistics are included in that backup in the same way as other app data. Those backups are yours and are handled by Apple under your Apple Account; I have no access to them.
Removing your data
- Removing an instance in the app deletes its connection settings and its credentials.
- A certificate trust decision belongs to the server's address and is not deleted with the instance. You can remove it from that instance's screen; do so before removing the instance, because afterwards it stays until you delete the app.
- Deleting the app removes its settings, trust decisions, cache, preferences and the analytics SDK's usage statistics. iOS can keep Keychain items after an app is deleted, so remove your instances in the app first if you want to be certain their credentials are erased.
Where the app sends data
Keelarr makes network requests only to the addresses you configure. Those requests carry the credentials you entered for that service, because that is how the service authenticates you. Nothing from those requests is sent to me or to any third party.
Separately, the app sends anonymous usage data to TelemetryDeck, as described in the next section, unless you switch it off.
When you add an instance and its HTTPS address cannot be reached, the app may check
whether the same server answers over unencrypted HTTP, so that it can suggest that
address to you. That check carries no credentials, but the address itself is sent
unencrypted. Your credentials travel unencrypted only if you enter an
http:// address yourself, or if you accept that suggestion.
What your own services log or retain is governed by those services and by whoever operates them, not by this policy.
Analytics, advertising and tracking
The app includes the TelemetryDeck SDK, an analytics library. It is the only software in the app that sends anything to a third party. The app contains no advertising software and no crash reporting software of its own, and it does not track you across apps or websites.
What the app sends
The app sends one usage signal each time a connection test finishes, whether it passes or fails. A test you cancel, or one that is never attempted, sends nothing. The signal carries two values:
- The service type: Sonarr, Radarr, Prowlarr, SABnzbd or qBittorrent.
- The outcome, from a fixed list: success, unverified, or the kind of failure (name lookup failed, connection refused, untrusted certificate, credentials rejected, wrong address, a web page instead of an API response, unsupported API version, redirect to an insecure address, redirect to a different host, or unclassified).
The signal never carries a server address, port, path, header, credential, instance name, certificate fingerprint or media title. It has no field that could hold one.
What the SDK adds
The SDK attaches the following to every signal:
- Device and system details: device model, platform, operating system and its version, processor architecture, screen resolution, scale and orientation, and time zone.
- App and build details: app version and build number, whether the build is a debug, simulator, TestFlight or App Store build, and the SDK's own name and version.
- Locale and display settings: language, locale and region, text direction, light or dark appearance, text size, and accessibility settings (reduce motion, bold text, invert colours, darker system colours, reduce transparency, differentiate without colour).
- Usage statistics the SDK keeps on your device: the date of your first session, the number of sessions, the average and previous session length, and the number of days you used the app (in total and in the last month); plus calendar fields for the moment of the signal (hour of day, day, week, month, quarter and whether it is a weekend).
- A session identifier: a random value that changes every session.
- A per-install identifier: a salted hash of the identifier iOS gives each app vendor on your device. It is never the advertising identifier.
The SDK also sends two signals of its own: one when a session starts, and one the first time the app runs after it is installed. They carry the same details.
How this data is treated
The data is de-identified before it leaves your device: the per-install identifier is hashed on the device, and nothing in the data names you or your servers. It is not linked to your identity, and it is not used for tracking or advertising. I use it only to see which connection problems happen and how often, so I can improve the app.
Switching it off
In Keelarr's Settings, under Privacy, the switch "Share anonymous usage data" is on by default.
- If it is off when the app starts, the app sends nothing.
- If you switch it off while the app is running, sending stops at once, though signals already queued may still go out.
- If you switch it back on, it takes effect the next time the app starts.
TelemetryDeck
TelemetryDeck GmbH, based in Germany, receives and stores this data for me. As TelemetryDeck publishes in its privacy FAQ:
- its servers are in the EU: Microsoft Azure in Amsterdam, Amazon Web Services in Frankfurt, and Hetzner in Falkenstein and Nürnberg;
- IP addresses are never stored, in its database, its log files or anywhere else;
- it hashes the per-install identifier again with its own salt when a signal arrives, as its anonymization article describes;
- it has no schedule to delete stored signals and expects to delete them after 7 to 10 years, without guaranteeing that.
TelemetryDeck's own privacy policy covers its handling of the data. TelemetryDeck provides the same or equal protection of this data as this policy describes.
What Apple may share with me
Keelarr is distributed through Apple's App Store and TestFlight.
- App Store versions. If "Share With App Developers" is on in your device's Settings, under Privacy & Security, Analytics & Improvements, Apple provides me with crash data and usage statistics. Apple shares these only in aggregated form or in a form that does not identify you.
- TestFlight beta versions. For each tester, Apple shows me the device model, operating system and platform, the build installed, and how many sessions and crashes it had. If I invited you by email, I also see the name and email address I invited you with. If you joined through a public link, you appear as "Anonymous" and I do not see your name or email address.
- TestFlight feedback. If you send feedback or a crash report through TestFlight, I receive your comments, any screenshot and crash report, and details of your device at that moment: app version and uptime, device model, iOS version, battery level, carrier, time zone, processor architecture, connection type, free disk space and screen resolution. Public-link testers stay anonymous unless they add their email address to the feedback.
Apple's handling of this information is covered by Apple's privacy policy.
When you contact support
If you email me, I receive your email address and whatever you include in the message. I use it only to answer you and to fix the problem you report, and I do not share it with anyone. Please do not send API keys, passwords or other credentials; I will never ask for them.
Support email is kept for as long as it is useful for resolving the issue. Ask me at any time and I will delete your messages.
Your rights
The only personal information I hold is support correspondence and, for beta testers, what Apple shares as described above. You can ask for a copy of it, ask me to correct it or ask me to delete it by writing to the address below. Usage data is not linked to you, so I cannot pick out yours; to stop sending it, switch off "Share anonymous usage data" in the app's Settings. If you are in the EU, the EEA or the UK you also have the right to complain to your local data protection authority.
Children
Keelarr is not directed at children, and I do not knowingly collect personal information from children.
Changes to this policy
If a future version of the app changes what is collected, for example by adding crash reporting or push notifications, this page will be updated before that version is released, and the date at the top will change.
Contact
Questions about this policy: keelarrsupport@gmail.com