RewindMate · Privacy

Your films. Your privacy.

How personal data is processed in RewindMate for Apple TV.

1. At a glance

  • No advertising, and no analytics or tracking services operated by RewindMate.
  • Your Jellyfin library is loaded directly from the server you choose.
  • Sign-in tokens and API keys are stored in your Apple TV’s Keychain. Your Jellyfin password is not saved.
  • Your membership card, virtual rentals and settings are stored locally.
  • The optional streaming catalogue connects to Movie of the Night. Film images may also be loaded from TMDB.

2. What this policy covers

This policy covers RewindMate for Apple TV: the local demo video store, your own Jellyfin library, the optional streaming catalogue, a voluntary Seerr connection and local PIN protection.

The demo works without signing in or requesting film data from external services. For Jellyfin, you use your existing server account; for the streaming catalogue, you provide your own API key. You do not need a separate RewindMate account.

3. A direct connection to Jellyfin

When you connect Jellyfin, the app sends your username and password directly to the server at the address you entered to sign you in. The password is not retained. RewindMate uses the access token issued by the server for subsequent requests.

The server also receives your IP address, the app name and version, the device label ‘Apple TV’ and a randomly generated device identifier. It provides film titles, descriptions, posters, video data and saved playback positions.

During film playback, RewindMate reports playback start, progress and stop events to Jellyfin, including film and session identifiers, playback position and playback status. The silent film previews on the video store’s monitors do not change your personal playback position.

How data is stored and processed on the server depends on its operator and configuration. RewindMate also allows HTTP addresses for your own servers. Use HTTPS for an encrypted connection, especially outside your home network.

4. Optional streaming catalogue

After you save an API key and select services, the app automatically loads or refreshes shelf offers through Movie of the Night’s Streaming Availability API. It also sends requests when you search or load more titles. Requests include your API key, selected country, search term or selected services, and pagination identifiers where needed. The provider also receives your IP address as part of the connection.

The suggested country comes from your device’s region settings; RewindMate does not request GPS location. Search results are held in memory. Shelf offers and pagination progress are also stored locally across app restarts and used for up to 24 hours, or less when offers expire sooner. Changing the key, country or services, or removing access, clears the shelf cache.

Film images and provider links

When streaming films are displayed, posters may be loaded directly from cdn.movieofthenight.com or image.tmdb.org. The image provider receives your IP address and the technical image request. RewindMate stores compressed covers in a limited local image cache; see section 5.

Opening an offer link takes you to the relevant streaming provider. Alternatively, RewindMate displays the link as a QR code for another device. Sign-in, playback and further data processing take place with that provider under its own privacy policy.

Movie of the Night’s privacy policy and TMDB’s privacy policy also apply to these external services. RewindMate does not guarantee that data is processed exclusively within the EU.

5. What stays on your Apple TV

Credentials in the Keychain

Your Jellyfin server address, access token, user identifier and username, along with your Movie of the Night API key, are stored in the local tvOS Keychain using a device-bound protection class. The app does not sync these Keychain entries through iCloud.

Settings and the video-store experience

The app locally stores the last server address you entered, a random device identifier, demo playback positions, your country and your selected streaming services. It also stores the name and number on your virtual membership card, your film bag and your rentals, including film title, release year, identifier and rental date. The film bag and virtual rentals are stored separately for the demo and for each Jellyfin server account.

Virtual rentals are part of the video-store experience. They do not trigger a payment or a real rental transaction. RewindMate does not send this local membership-card or rental data to the developer.

Your local history retains the last 30 rental events per library, including film identifier, title, year, rental time, return time where applicable, and whether a title belongs to the protected area. Returning a film keeps its history entry.

PIN protection

The optional four-digit PIN is stored in a separate device-bound Keychain entry. Its enabled state, failed-attempt counter and temporary lockout deadline are stored locally. The PIN is not sent to the developer. Disabling it with the current PIN removes its Keychain entry; there is currently no PIN recovery function.

Local caches

Library responses and search results are processed in memory. The app also stores streaming shelf offers locally as described in section 4. Compressed cover images are stored in the tvOS caches directory and can be reused after app restarts. Cache filenames are hashes; account names and authenticated image URLs are not written to those files. The cache is limited and may be cleared by tvOS; older covers may remain available offline.

Optional Seerr connection

When you choose to sign in, your Jellyfin username and password are sent directly to the Seerr server address you enter. That server also receives technical connection data, including your IP address. The password is not retained. The Seerr server address, username, session cookie and any expiry date are stored in the device-bound Keychain. The last successfully used Seerr address and username are also stored in local settings. The app currently supports sign-in and session checks; it does not yet browse a Seerr catalogue or submit media requests.

6. Data sharing and tracking

RewindMate includes no advertising, analytics or tracking services and has no crash-reporting service of its own. It does not send usage statistics to a developer-operated server. The app does not include its own cloud synchronisation service.

The app connects to your Jellyfin server, your Seerr server if configured, and the services listed above when you use the streaming catalogue. Their own logging and Apple’s system services are governed by their respective settings and privacy policies. The app cannot determine these providers’ data retention periods.

7. Purposes and legal bases

Where the controller processes personal data to provide the app features you request, this processing is necessary for the performance of a contract under Article 6(1)(b) GDPR. Other enquiries are handled on the basis of the legitimate interest in responding to them under Article 6(1)(f) GDPR.

Where processing requires consent, Article 6(1)(a) GDPR is the legal basis. You can withdraw your consent with effect for the future. Your server operator or an external provider relies on its own applicable legal basis for any processing it carries out independently.

8. Disconnecting and deleting data

Disconnect Jellyfin

Select ‘Disconnect and open demo’ (‘Trennen und Demo öffnen’) to remove your saved Jellyfin sign-in from the Keychain. This does not delete data on your Jellyfin server or revoke tokens already issued by that server. If needed, also revoke the device’s access in Jellyfin.

Remove streaming access

Select ‘Remove access’ (‘Zugang entfernen’) to delete your saved API key, in-memory catalogue results and locally saved shelf offers. Your country and service selections remain stored locally. You can also revoke an API key with the provider.

Disconnect Seerr

In the Seerr settings, select Trennen to remove the locally saved Keychain session. The last server address and username remain in local settings. This action does not perform a server-side logout; revoke the session with your server operator if needed.

Local data

You can remove films from your bag, return virtual rentals and clear a membership-card name you chose in demo mode. Returns keep the rental history. Disconnecting does not automatically delete other settings, membership-card data, rental history, image caches or demo playback positions. These remain until changed, removed with the local app data or, for caches, cleared by cache management.

Before deleting the app, use the functions above to remove saved credentials. Uninstalling alone does not guarantee that Keychain entries are deleted. There is currently no single button to reset all app data.

9. Your rights

Subject to the applicable legal requirements, you can request access, rectification, erasure, restriction of processing and data portability. You can object to processing based on legitimate interests on grounds relating to your particular situation. You can also lodge a complaint with a data protection supervisory authority.

For enquiries about the app, contact the controller at privacy@mate.build. For data held exclusively on your Jellyfin server or by an external service, also contact the relevant operator. The developer has no direct access to that data or to the data stored locally on your Apple TV.

Read the General Data Protection Regulation

10. Policy date and changes

This policy describes RewindMate’s features as of 8 September 2026. It will be updated to reflect changes to features or data processing.

11. Data controller

Controller
Fabian Vocke
Am Autobahnzubringer 1
76709 Kronau
Germany

Email
privacy@mate.build