Privacy
Synctuary for iPhone, iPad, Mac, Apple Watch and Apple TV. Last updated October 2, 2026
Synctuary collects no personal data. It plays from a Plex server you run yourself and manages the software around it. Your library, what you watch and your credentials stay between your devices and your own servers. There is no Synctuary account, no analytics, no advertising and no tracking.
What the app stores, and where
- Your services and settings: the servers you add, your theme, your layout choices. They are stored on your device. The list itself, never a key, a password or a token, is also mirrored to your private iCloud key-value store, so a second device signed into the same iCloud account finds your services without retyping them. That store is visible to you and to Apple, never to us. On Apple TV, which has no persistent file storage, it lives in system preferences.
- Keys, passwords and tokens live in the device's keychain: the API keys for your services, the token Plex issues when you sign in, Trakt's tokens if you connect Trakt, and the keys a phone and an Apple TV make when they pair. Each is sent only to the service it belongs to, and never to us.
- Offline downloads (iPhone, iPad and Mac) are kept on the device until you remove them from the Offline screen or delete the app.
- Artwork and your library's lists are kept on the device, so posters and titles appear at once rather than being fetched again on every visit. Settings → Library shows how much space they take and clears them; on Apple TV the system may also clear them when storage runs low.
- Search and Siri (iPhone and iPad): the titles in your library are indexed on the device so the phone's own Search and Siri can find them. The index never leaves the device. What you say to Siri is handled by Apple under Apple's Siri privacy terms.
- Apple Watch: the phone sends the watch what is playing on your server, including which member of your household is watching, what is downloading, and the week ahead. It travels over Apple's Watch Connectivity between your own two devices and nowhere else.
- Widgets and the Apple TV top shelf read what the app last saw, from a container shared with the app on the same device, and fetch from your servers with the same keys the app uses.
- Nothing is uploaded to any Synctuary service. There is no account to create and no profile to build.
Permissions
- Local Network: required to reach servers on your own network, such as Plex, Sonarr or Radarr. It is also how a phone and an Apple TV running Synctuary find each other, through Apple's Bonjour, for Send to TV and for Transfer Setup.
- Notifications (iPhone and iPad): optional, and off until you turn them on. See below.
Between your own devices
Three features move something from one of your devices to another. None of them goes through the internet or through us.
- Transfer Setup copies your services and their keys from a device that is set up to one that is not, over your local network. The bundle is sealed with a short code that one device shows and the other types; the code is the key it is sealed with, so a device that connects uninvited collects nothing it can read. The bundle exists only for the transfer.
- Send to TV pairs a phone with an Apple TV once, with a four-digit code shown on the television, over your local network. Each device keeps a key in its keychain from then on. A command names only the title to play, is signed with that key, and is stamped with the moment it was sent so it cannot be replayed.
- Watch Together: if you watch with others on a FaceTime call, your play, pause, seek and position go to the people on the call through Apple's SharePlay, along with which title it is so their app can open it. Nothing else about your library is shared, and Apple's SharePlay terms govern the call itself.
Push notifications
Notifications are optional, on iPhone and iPad; Apple TV and Mac do not receive them. If you never enable them, nothing in this section applies and no data leaves your device for this purpose.
If you do enable them, Synctuary registers webhooks with your own media services pointing at a relay we operate. So that one webhook reaches every iPhone and iPad in your home, the relay keeps a short list for your household: a random household number, a one-way hash of the household's key, and each device's push token, which is an anonymous identifier Apple or Google issues to the installation, with when it was last seen. That is all it keeps: no name, no account, no server addresses, no media and no notification contents.
When one of your services reports an event, the relay turns it into a notification, typically a title name such as which episode finished downloading, hands it to Apple's or Google's push service, and keeps nothing of it. A device's entry is removed once it has not been refreshed for 30 days, or as soon as Apple or Google reports that its push token is no longer valid, as happens after the app is deleted. Request logging is disabled.
If you would rather not use our relay, you can deploy your own copy and point Synctuary at it in Settings. Turning notifications off stops your services' events from reaching it.
Bug reports and feature requests
Reporting a bug is optional and happens only when you fill in the form under Setup & Help in Settings and press Send. If you never use it, nothing in this section applies.
What is sent is what the form shows you: which area of the app, how often it happens, your summary and description, the steps if you gave any, and, only if you leave the toggle on, the app version, your device model and system version, which kinds of service you have configured, and whether you were on your home network. The full text of those details is displayed in the form before you send, so you can read exactly what would go. Server addresses, API keys, passwords and media titles are never included.
The report travels through the same relay as notifications, which forwards it to info@synctuary.ca and keeps nothing. There is no database and no logging, and the report's contents are never written down anywhere on the way through.
Requesting a feature works the same way, from Request a Feature beside it. A request sends the part of the app you chose, your idea, and which version of the app and which kind of device you have, and nothing about your device beyond that.
Reports and requests are one-way and anonymous. There is no field for your email address and none is collected, so nobody will reply: say everything you want to say in the report itself. Nothing in a report is linked to you or to any identifier.
Purchases
Synctuary PRO is bought through Apple's App Store, as a subscription or a one-time purchase. Apple handles the payment. The app learns only whether you own PRO, from Apple; no payment details, no receipt and no identity reach us. Subscriptions are managed and cancelled in your Apple ID settings, not in the app.
Other services the app contacts
Besides your own servers, Synctuary talks to a small number of outside addresses, and only when a feature needs them:
- Apple Push Notification service and Firebase Cloud Messaging: to deliver notifications, if you enable them.
- plex.tv: only if you choose to sign in to Plex. Synctuary uses Plex's own PIN flow, so your Plex password is never seen or handled by the app; Plex returns a token scoped to this device. While you are signed in, the app also reaches your Plex account for the things that live there rather than on your server: the profiles in your Plex Home, your watchlist, servers a friend has shared with you, Plex's own catalogue to look a title up, reviews on Plex Community, which you can read, post and react to under your Plex name, and the notifications Plex keeps for your account, such as a reaction to one of your reviews. A rating you give a title is written to your own server, which passes it to your account. Signing out in Settings ends all of it.
- Trakt (api.trakt.tv): only if you connect a Trakt account in Settings. While it is connected, the app tells Trakt what you play, at start, pause and stop: which film or episode, by its public TMDB, TVDB or IMDb number, and how far through you are. A title's page reads back your Trakt rating and history. Disconnecting in Settings → Trakt stops it and removes the tokens.
- TheIntroDB (api.theintrodb.org): when your server has no intro or credits marker for an episode, the app asks this community database for one, by the show's TMDB number, season and episode. There is no account and nothing about you in the request beyond the app's name and version, and, as with any website, your IP address.
- image.tmdb.org: to load poster artwork for titles discovered through Overseerr or Jellyseerr. These are ordinary image requests; TMDB will see your device's IP address, as any website would.
Your own servers talk to services of their own, on their own account: Plex to its metadata agents and to OpenSubtitles when you ask it to find subtitles, Tautulli to a location lookup for the Stream Map. Synctuary reads what your server already worked out; it does not make those requests itself.
Each of these is governed by its own provider's privacy policy.
Children
Synctuary is not directed at children and collects no personal data from anyone, including children. A Plex profile that Plex marks as restricted sees only the watching screens in Synctuary; that is Plex's setting, read as it is.
Your choices
- Settings → Setup & Help → Reset erases everything the app stored, keychain entries included, and returns it to a fresh install. Deleting the app does the same.
- Signing out of Plex, or disconnecting Trakt, in Settings ends the app's contact with that account and removes its token.
- Turning notifications off stops your services' events reaching our relay.
- Removing a service in Settings deletes its address and its stored credential.
- The relay holds nothing that identifies you, only the anonymous push tokens described above, which expire on their own. If you would like a device's entry removed sooner, or any of this confirmed in writing, use the contact address below.
Changes to this policy
If this policy changes in a way that affects what the app does with your information, the updated version will be published here with a new date, and a release note will say what changed.
Contact
Questions about this policy or the app: info@synctuary.ca