Privacy Policy
Last Updated: August 8, 2026
Introduction
Alflix (formerly Vibe Stream; "we", "our", or "the app") is a third-party client for Plex, Jellyfin, and Emby that lets you browse and stream content from your own media server. This privacy policy explains how the app handles your information on every platform it ships on.
The short version: we run no accounts, no ads, no analytics, and no tracking. Your media and your viewing habits stay between your device and your server. The handful of narrow cases where anything reaches a service we operate are each listed below.
Information the App Handles
Authentication Information
When you sign in to your media server through Alflix, the app collects and processes:
- Plex, Jellyfin, or Emby authentication tokens
- Your media server account username
- Media server connection information
Local Network Information
To connect to a media server on your local network, the app may access:
- Local network device discovery information
- IP addresses of media servers on your network
Usage Information
The app stores locally on your device:
- Your authentication session
- App preferences and settings
- Recently accessed content and playback progress
- Content you download for offline viewing
On TV platforms, the app may also publish Continue Watching and trending titles, progress, and artwork to the system home screen (for example the Apple TV Top Shelf), where the operating system displays them.
How This Information Is Used
The information above is used solely to:
- Authenticate you with your Plex, Jellyfin, or Emby server
- Connect to and communicate with your media server
- Display your library and stream or download content
- Maintain your session and preferences
Data Storage and Security
- Authentication tokens are stored locally on your device. The Apple TV app keeps them in the system Keychain; on other platforms they live in the app's private storage, inside the operating system's app sandbox
- Preferences, history, and downloads are stored locally on your device
- Media streaming happens directly between your device and your media server; it never passes through us
Services We Operate
We run a small number of self-hosted services that support specific features. None of them are third-party clouds, none see your media, and none build profiles.
Crash Reporting
If the app crashes or hits an internal error, a crash report is sent to our self-hosted error-reporting service. Crash reporting is on by default and you can switch it off at any time in the app's settings; when it is off, nothing is sent.
Reports contain a stack trace, the app version, and basic device information (model and OS version). Before a report leaves your device, known credentials, authentication tokens, server addresses, and IP addresses are automatically scrubbed from it. Reports contain no account names and no information about what you watch. Session tracking and performance tracing are disabled. Crash reports are retained for 90 days and then deleted automatically.
Diagnostic Logs
The app never uploads logs on its own. If you choose to share diagnostics from the app's log screen, the log text you see is sent to our server so we can troubleshoot your issue. Authentication tokens, server addresses, and IP addresses are scrubbed from logs before they are displayed or uploaded; redaction is automatic and best-effort, so a log may still contain details the patterns did not catch. An uploaded log can be retrieved by anyone with its retrieval ID while it is available, and is deleted automatically after three days.
Watch Together
When you start or join a Watch Together session, our relay server exchanges room, participant, server, and media identifiers plus playback timing (play, pause, and position) so participants stay in sync. The relay never carries the media stream or your media-server credentials. Rooms expire within 24 hours and inactive rooms are removed within minutes. When you're not in a session, nothing is relayed.
Discord Rich Presence (optional)
If you enable Discord Rich Presence, the poster image of what you're playing is uploaded to our server so Discord can display it in your status. The image is served from a temporary public URL and deleted automatically within three hours. This only happens while the feature is switched on.
Sign-in Relay for Optional Integrations
If you connect an optional tracking service (such as Trakt, Simkl, MyAnimeList, or AniList), the sign-in handshake passes through our relay to complete the authorization. We do not store your credentials for these services.
Operational Logs
The services above keep limited operational logs (such as request errors and rate-limit events) for security and reliability.
Third-Party Services
Any service the app talks to also receives ordinary network information, such as your IP address and user agent, and handles data under its own privacy terms.
Plex, Jellyfin, and Emby
Alflix talks to the media server you configure. Authentication and streaming happen between your device and your server (and, for Plex, plex.tv sign-in). Their privacy policies apply to their services: plex.tv/about/privacy-legal and jellyfin.org (for your own Jellyfin or Emby server, its operator's practices apply). We do not control and are not responsible for their data practices.
Seerr Request Servers
If you connect an Overseerr or Jellyfin Seerr server, your searches and media requests are sent to that server, which is operated by whoever runs it (usually you or your server admin).
Metadata and Artwork
To show richer artwork, logos, ratings, and trending information, the app may query public metadata services such as The Movie Database (TMDB) and OMDb, artwork hosts those services point to, and community-maintained mapping lists served from the jsDelivr CDN. These requests contain identifiers of the title being looked up, never your identity or account details.
Update Checks
On platforms without a store-managed update channel, the app checks GitHub and its update feed on the jsDelivr CDN for new releases. This can be turned off in the app's settings.
External Players
If you choose to open a title in an external player app, that app receives the media URL, which may contain a server access credential, together with playback details. The external player handles that data under its own terms.
Local Network
Server discovery and the Companion Remote feature can send discovery traffic on your local network to find your media server and paired devices. This traffic stays on your network.
Optional Tracking Integrations
If you connect Trakt, Simkl, MyAnimeList, AniList, or a similar service, the watch activity you choose to sync is shared with that service under its own privacy policy. These integrations are off unless you connect them, and you can disconnect them at any time.
What We Never Do
- Sell your personal information
- Show ads or share data with advertisers
- Run analytics or track your viewing habits
- Require an account with us
Your Rights and Choices
You can:
- Sign out at any time to remove your authentication session from the device
- Uninstall the app to remove all locally stored data, including downloads
- Turn crash reporting or automatic update checks off in the app's settings
- Disconnect any optional integration from the app's settings
- Email us to ask that crash reports or uploaded diagnostics be deleted
Children's Privacy
Alflix does not knowingly collect personal information from children under 13. The app relies on your media server's authentication, and users must comply with Plex's or their server operator's terms of service and age requirements.
Data Retention
- Authentication tokens, preferences, and downloads remain on your device until you sign out or uninstall the app
- Crash reports are deleted automatically after 90 days
- Diagnostic logs you chose to upload are deleted after three days; Discord poster images after three hours
- Watch Together sync data is transient: rooms expire within 24 hours and inactive rooms are removed within minutes
Changes to This Privacy Policy
We may update this privacy policy from time to time and will reflect material changes by updating the "Last Updated" date at the top of this page.
Contact
Questions about this policy or your data? Email [email protected].
Your Consent
By using Alflix, you consent to this privacy policy and the processing of your information as described here.