Privacy Policy
Last Updated: April 7, 2026
1. Introduction
Llamafin ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Llamafin music player application ("the App").
Our core principle: Your music, your data, your server. Llamafin is designed to minimise data collection and maximise your control over your information.
2. Information We Do NOT Collect
Llamafin is designed with privacy-first principles. We do NOT collect:
- Personal identifiers (name, email, phone number, address)
- Usage analytics or behavioral tracking data
- Advertising identifiers or tracking cookies
- Music listening history on any central server
- Location data or GPS coordinates
- Contact lists or social graph data
- Biometric or health data
- Financial information or payment details (the App is free)
3. Information Processed Locally
The following information is processed and stored locally on your device onlyand is never transmitted to our servers:
- Authentication Credentials: Your Jellyfin server URL, username, and authentication token are stored securely on your device for session management.
- User Hash: A SHA-256 hash of your Jellyfin User ID is computed locally for P2P device pairing. The original User ID is never transmitted or stored outside your device.
- Playback History: Your listening history, queue data, and play statistics are stored locally in IndexedDB.
- Settings & Preferences: All app settings (EQ presets, themes, playback preferences, etc.) are stored locally.
- Downloaded Content: Music files downloaded through the App are stored in your device's local storage or external SD card.
- Search History: Search queries are stored locally for suggestion purposes.
- Network Speed Data: Historical network speed test results (up to 10,000 entries) are stored locally for smart download optimisation.
- Device Metrics: CPU, memory, and network performance data is collected and stored locally for debugging and optimisation purposes.
4. Information Transmitted to Your Jellyfin Server
When you use Llamafin, the following information is communicated only to your own Jellyfin server (which you control):
- Authentication: Username and password (or Quick Connect code) during login
- Streaming Requests: Requests to stream, download, or transcode music files
- Playback Reporting: Play/pause/stop events and playback progress for library statistics
- Library Queries: Requests to browse albums, artists, songs, playlists, etc.
- Search Queries: Online search requests to your Jellyfin server
We do not operate, access, or monitor your Jellyfin server. All communication is directly between your device and your server.
5. P2P Communication (Llamafin Connect)
When using Llamafin Connect for peer-to-peer device control:
- Device Discovery: Devices on the same local network are discovered via mDNS/Bonjour protocol. No external servers are involved.
- Encryption: All P2P connections use ECDH (Elliptic Curve Diffie-Hellman) key exchange and AES-256-GCM encryption.
- Identity: Devices are identified by hashed user identities (SHA-256), not by personal information.
- Network: P2P communication occurs over your local network or direct peer connections. We do not relay or store P2P data.
- Ownership Model: A single-owner model ensures only you can control playback on connected devices.
6. WebSocket Communication
Llamafin maintains a WebSocket connection to your Jellyfin server for real-time events (playback state changes, library updates, notifications). This connection is:
- Encrypted when using HTTPS/WSS
- Managed entirely between your device and your server
- Automatically reconnected on failure with no data loss
7. Third-Party Services
Llamafin integrates with the following third-party services:
8. Data Security
We implement industry-standard security measures to protect locally stored data:
- Authentication Tokens: Stored with expiration dates; automatically invalidated on authentication failure
- Passwords: Never stored locally; always authenticated directly with your server
- Secure Logout: Invalid tokens trigger immediate secure session termination
- HTTPS Support: All communication can be encrypted in transit
- P2P Encryption: ECDH + AES-256-GCM for all peer-to-peer connections
9. Children's Privacy
Llamafin does not knowingly collect personal information from children under 13. The App is designed for general audiences. Parents and guardians can manage access through their Jellyfin server's user management features.
10. Data Retention
Since we do not collect or store data on central servers, there is no central data to retain or delete. All data is stored locally on your device and can be deleted at any time by:
- Clearing app data in your device settings
- Uninstalling the application
- Using in-app data clearing options (Settings → Advanced)
11. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data, including:
- Access: Request access to data we hold about you (none held centrally)
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (delete locally via app settings)
- Portability: Receive your data in a machine-readable format (export locally stored data)
- Objection: Object to processing of your data (all processing is local and under your control)
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on this website with a new "Last Updated" date. We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us through the official Llamafin support channels.