Privacy Policy
Effective 2026-08-26
1. At a glance
- Your video files and playback history stay on your device by default. They are never sent to our servers.
- If you turn on cross-device resume, your playback history, settings and server list are stored in a private, app-only folder inside your own Google Drive. It does not pass through our servers, and the app never receives your email address or name.
- Passwords for media servers are encrypted on your device and uploaded only as ciphertext. The master password that unlocks them never leaves your device.
- When the app crashes or freezes, a diagnostic report is sent to the developer. You can turn this off in app settings; turning it off also deletes reports that have not been sent yet.
- Google account details and your posts are stored only if you use the message board.
- This website uses Google Analytics to count visits and see which pages are read (section 7).
- The app sends numbers only, once a day, about how much it was used (section 8) — launches, time in use, how often each feature was used. What you watched is never sent: no file names, no paths, no server addresses. Turning it off in settings stops the counting, not just the sending.
- No advertising trackers and no selling of personal data.
- If you want your data deleted, contact us and we will delete it.
2. What the app uses on your device
The app requests the following Android permissions so that it can find, list and play the media already on your device. Neither that list nor the file contents leave your device (see section 3 if you enable sync).
- Read video and audio files — to build the local media library
- Internet and network state — for network playback and notice checks
- Foreground service and notifications — so playback continues with the screen off or while you use another app
The app does not request location, contacts, camera or microphone permissions. It does not read files you have not opened through it.
3. Syncing between devices with your Google account
Turning on Connect Google account in settings lets you resume playback on another device. It is off by default and shows the Google consent screen when you enable it.
Which scope we request
We request access to a single application-private folder in Google Drive (drive.appdata). This scope cannot read or create any other file in your Drive. The folder is hidden from the Drive interface and no other application can open it.
We do not request identity scopes: no name, no email address, no profile photo. The app has no sign-in screen; it keeps a single connected flag on the device. It does not even store the access token, and asks Google for a fresh one when needed.
What is stored there
- Playback history — file name, size, playback position, duration, last played time
- App settings and favourites
- Your saved server list — address and user name (for passwords see section 4)
All of it lives inside your own Google account. It never passes through our servers and we cannot read it.
Turning it off and deleting the data
- Disconnect in settings — that device stops uploading and downloading. Local history is kept.
- Delete all playback history in settings — removes the uploaded data and the history on every connected device. Devices that were offline are cleared the next time they connect.
- You can also revoke access to CoPlayer from your Google account settings at any time.
Limited Use disclosure
CoPlayer use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The data is used solely to provide the sync feature described above. It is not used for advertising, not transferred to third parties, and not read by humans.
4. Passwords for media servers
When you add an SMB or FTP server to the app, the password is encrypted on the device with a key held in Android hardware-backed storage. That key cannot leave the device.
To carry passwords to another device you create a vault with a master password of your own choosing. Only the ciphertext, re-encrypted with a key derived from that master password, is uploaded. The master password and the derived key are never uploaded anywhere. If no vault exists or it is locked, the password field is left empty and only the address travels.
This means that if you forget the master password, we cannot recover it either.
5. Crash reports
When the app crashes or stops responding, it sends a report describing where in the app the failure happened, together with the device model, Android version and app version. The video you were watching and your playback history are not sent, but a file name or address can appear inside the text of an error message.
These reports are delivered through Google Firebase Crashlytics (Google LLC) and are used only to fix defects. We do not attach any account identifier, email address or usage history to them.
Crash reporting is on initially. Turning off Send crash reports in app settings stops all sending from that device and also deletes reports that have not been sent yet.
6. Subtitle translation and notices
- Subtitle translation: language packs are downloaded from Google once, and the translation itself runs on the device. The subtitle text stays on the device. It is sent on to an outside translation service only when you register one yourself.
- Notices and configuration: the app periodically fetches a configuration file from this website to show announcements. No identifying value is sent with that request — every request receives the same file.
7. Website and message board
Signing in with Google is required to post on the message board. This sign-in is unrelated to the app sync — the app does not use it, and the website never accesses your Google Drive.
| What we receive | Why | Kept until |
|---|---|---|
| Email address and account identifier | To attribute posts and let you delete your own | You delete the post or request deletion |
| Text and timestamp of your posts and comments | To display the board | You delete the post or request deletion |
| A session cookie | To keep you signed in | You sign out or the session expires |
Analytics cookies (those beginning with _ga) and what is logged with them — page address, time of visit, referring source, browser and device type, approximate region | To see which pages are read and what needs fixing, and to count one person's several page views as a single visit | Cookies last up to 2 years (or until you clear them) |
During sign-in Google also passes basic profile information such as your name and profile photo alongside the email address and account identifier, and those values are retained in the account record of our authentication provider. The board itself uses only the email address and the account identifier; the name and photo are never displayed. Email addresses are shown partially masked. No other information — contacts, calendar, files — is requested.
Posts and comments are publicly visible. Please do not write personal details or contact information in them.
Visit statistics are collected with Google Analytics. Nothing that identifies you personally — name, email address — is sent, and what we see are aggregate numbers: how many people read a page yesterday, not who they were. IP addresses are used only to derive the approximate region and are not stored in the reports. Google deletes the individual records after 2 months for events and 14 months for user identifiers; only aggregate figures remain after that. None of it is used for advertising.
If you would rather not send it, use your browser's tracking protection or Google's opt-out add-on. The site works exactly the same either way.
8. App usage statistics
To decide what to fix, we need to know which features are actually used. Once a day the app sends numbers only.
| What we receive | Why | Kept until |
|---|---|---|
| Launch count · time the app was on screen · playback time and count · how often each feature was used (split view, remote servers, subtitle translation, playback speed, and so on) | To see which features are used and which are not | 400 days |
| App version · Android version · form factor (phone, foldable, tablet) · language | To know which environments to fix first | 400 days |
| An install number — a random value created by the app | To group one device's daily numbers into a single row | Until you uninstall the app or turn statistics off |
What is never sent: file names, file paths, server addresses, accounts, what you watched, search terms. There is no field that could carry them — only the numbers above and a fixed set of words leave the device.
The install number is unrelated to your account, your device identifiers and any advertising identifier. The app generates it on first run and it disappears when the app is removed.
What is sent passes through this website and is stored in Supabase (section 9). IP addresses are not stored. Individual daily records are deleted after 400 days.
How to turn it off: Settings → About → “Send usage statistics”. Turning it off stops the counting, not just the sending, and deletes what was stored on the device along with the install number. Turning it back on starts from zero — nothing from the off period is kept.
9. Where data is stored
- Your own Google Drive — playback history and settings, if sync is enabled. We cannot read it.
- Supabase (Supabase, Inc.) — board posts, comments, the sign-in account record, and app usage statistics (section 8). The statistics table is locked and cannot be read from a browser.
- Vercel (Vercel, Inc.) — hosting for this website. Access logs such as request path and time may be retained briefly by the provider.
- Google LLC — crash reports sent by the app, and this website's visit statistics (Google Analytics, section 7).
10. What we do not do
- No advertising. The app contains no advertising SDK.
- What you watched is never sent anywhere. The app's usage statistics count how often features were used; there is no field that could carry a file name, a path or a server address (section 8). Neither the app nor the website contains any advertising tracker.
- We do not sell or rent personal data.
- We do not share data with third parties other than the service providers listed in section 9, except where required by law.
- We do not knowingly collect data from children under 14.
11. Deleting your data
- Board: sign in and use Delete on your own post or comment. It is removed immediately.
- App: on-device history can be cleared in app settings and is removed when you uninstall the app. Data uploaded to Drive is removed with Delete all playback history in settings (section 3).
- By request: to have the account record deleted as well, contact us through the channels listed on the support page. After verifying your identity we delete it without undue delay and confirm the result.
12. Your rights
You may request access to, correction of, deletion of, or a halt to the processing of your information. Use the route given in the contact section below and we will act on it. If a request is refused, we will explain why.
13. How we protect data
- We never receive a password of yours. Sign-in is delegated to Google.
- Permission to edit or delete a post is enforced on the server, not in the browser.
- All traffic uses encrypted connections (HTTPS).
- Server passwords are encrypted before they leave the device (section 4).
14. Changes to this policy
Updates are published on this page with a new effective date. Significant changes are also announced on the message board.
15. Contact
For privacy enquiries and requests, use the channels listed on the support page. We verify your identity, act on the request and confirm the result. Please do not post personal requests on the message board, which is publicly visible.