KoalaPaw Privacy Policy
The short version
KoalaPaw is designed to collect as little as possible. The only data that ever leaves your television for us is an optional crash report. Everything else stays on your device or goes only to your own Jellyfin server.
Who we are
KoalaPaw is an Android TV app published by Koala Software Ltd. It is a client for Jellyfin, a self-hosted media server: it plays media from a server that you (or your household) operate. KoalaPaw is not affiliated with or endorsed by the Jellyfin project.
What we collect
Crash reports (optional)
If the app crashes, it may send a crash report to our server (an endpoint operated by Koala Software Ltd, hosted in the EU). This is on by default, and you can turn it off at any time in Settings → Account → Send crash reports (the change takes effect the next time the app starts). When it is off, nothing is captured and nothing is sent.
A crash report contains:
- the error’s stack trace;
- the app version and Android version;
- the device model, brand, and build information;
- memory, display, and locale configuration at the time of the crash.
Crash reports do not contain your passwords, access tokens, server credentials, media files, usage history, or any device or installation identifier. One honest caveat: a stack trace can incidentally include a short piece of text from the moment of the crash, such as your server’s hostname or a media title. We use crash reports only to find and fix bugs.
Crash reports are kept for at most the 500 most recent reports and never for more than 90 days — older ones are deleted automatically — and are readable only by the developer, behind authentication. Your device’s IP address is used transiently to rate-limit the reporting endpoint and is never stored with a report.
If you turn crash reporting off, no new reports are sent. To ask for a specific report to be deleted, contact us.
What we don’t collect
We do not collect or receive:
- account information (we don’t offer accounts);
- analytics, usage statistics, or advertising identifiers;
- your media, media titles, or watch history;
- your Jellyfin username, password, or access tokens;
- precise or approximate location;
- microphone, camera, contacts, or files.
Your Jellyfin server
When you use KoalaPaw, the app talks directly to the Jellyfin server you configure: signing in (via Quick Connect or a passwordless profile), browsing your libraries, searching, tracking playback progress, and streaming media and images. All of that data stays between your TV and your server — we never see it. Whether that traffic is encrypted depends on how your server is configured; plain HTTP on a home network is common.
Your Jellyfin credentials (server address, username, and access token) are stored only on your TV, encrypted with a key held in the device’s hardware-backed Android Keystore. They are never sent anywhere except to your own server.
Data stored on your device
KoalaPaw stores settings and preferences locally on your TV: screen-time limits and usage, babysitter sessions, playback preferences (speed, buffer size, subtitle appearance), search history, home-screen customisations, and language. This data never leaves the device and is excluded from Android backups. It is deleted when you clear the app’s data or uninstall it.
Children
KoalaPaw is designed to be used by children, with parental controls (screen-time limits, quiet hours, a kid mode, and a parental PIN). The app collects no personal data from children — or from anyone else — beyond the optional crash reports described above, which contain no account identifiers.
Third-party services
The only endpoint the app contacts on our behalf is our own crash-report receiver. The app contains no advertising, analytics, or tracking SDKs. Media and images are loaded only from your own Jellyfin server. The app is built with open-source libraries (including Media3, Coil, ACRA, and libass-android); of these, only ACRA performs network activity of its own, and only to our server as described above.
Data sharing and sale
We do not share, sell, rent, or trade any data with anyone.
Security
Credentials are encrypted at rest with hardware-backed keys. Crash reports travel over HTTPS and are stored on a server administered by Koala Software Ltd, readable only behind authentication.
Retention
Crash reports: at most the 500 most recent, and never longer than 90 days. On-device data: until you delete it or uninstall the app.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to complain to the ICO. Since the only data we hold is crash reports with no account identifiers, the practical route for any of these is to contact us and we will help.
International transfers
Our crash-report server is hosted in the EU (Finland). The UK has an adequacy arrangement with the EU, so no additional transfer safeguards are required.
Changes
If this policy changes, the effective date above will be updated and the in-app copy refreshed.
Contact
Koala Software Ltd — ryan@koalasoftware.com