Privacy Policy
Headroom is developed and published by Posh Industries (“Headroom,” “we,” or “us”). This policy explains what the app stores on your device, what optional services receive, and what we receive through the website and support.
Scope and who is responsible
This policy covers the Headroom app, headroommusic.app, beta distribution, support messages, and optional services described below. Posh Industries is responsible for personal information sent directly to Headroom, such as a support request. Your media server and any third-party service you choose have their own operators, practices, and policies.
Information stored on your device
Headroom stores server URLs and names, account names and server-issued user identifiers, preferences, library indexes, artwork caches, diagnostics, playback state, and downloaded media on your device. Passwords are used to authenticate and are not saved by Headroom. Server-issued access and refresh tokens, and Plex cloud tokens when applicable, are stored using the operating system's secure credential storage where available.
Headroom may also keep a local storefront diagnostic ledger with aggregate counters for storefront views, entitlement checks, purchase attempts and results, and restore results. It contains no library contents, server URLs, account names, media titles, or playback history. These counters are never uploaded in the background. They leave your device only if you explicitly review and share a diagnostic export that includes them.
Removing an account or server deletes the related app-managed data and credentials. Uninstalling Headroom removes app-managed local data, subject to your operating system's backup, restore, and retention behavior. Data held by your media server or another provider must be managed with that service.
Your media servers
When you connect Jellyfin, Emby, Plex, an OpenSubsonic-compatible server, or Audiobookshelf, Headroom sends the credentials and requests required to authenticate, browse, stream, download, and update playback state. Those requests go to the server URL you supplied. The server operator controls its logs and retention. Plex sign-in also contacts Plex's cloud authentication service when you choose its PIN flow.
Headroom supports plain HTTP because some personal servers run only on a trusted local network. HTTP does not encrypt credentials, tokens, or media. Use HTTP only on a trusted LAN or through a VPN, and use HTTPS for remote access.
The Headroom website
The website is hosted on an IONOS server and routed through a self-managed Pangolin reverse proxy. IONOS may process connection and server data needed to provide and secure the infrastructure. If Cloudflare proxy or security services are enabled for the domain, Cloudflare may also process connection data such as your IP address, browser and device details, requested URL, time, and security signals. Headroom does not use website advertising, behavioral analytics, tracking pixels, or cross-site tracking cookies.
If you request beta or launch updates, Headroom stores your email address, the update topics you selected, consent and confirmation timestamps, subscription status, and limited campaign codes and landing page path present in the URL when you submit the form. We send a confirmation link before activating the subscription. If you submit the website feedback form, Headroom stores the report, the platform, provider and category you selected, and an email address only if you choose to provide one. Do not put credentials, access tokens, private server addresses, diagnostic files, or personal media information in that form.
To prevent automated abuse, the website temporarily stores a keyed, one-way representation of the request address or submitted email. The website database does not retain the raw connection IP for this purpose. Our SMTP or mailbox provider processes the addressing and delivery data needed to send confirmations, updates, and feedback notifications.
The Headroom community
Public discussions can be read without an account. To post, Headroom stores your email address, the public display name you choose, account status and role, sign-in timestamps, and a one-way hash of each active session token. Your email address is not displayed publicly. A private, one-time sign-in link is sent to that address so the community does not need to store a password.
Thread titles, posts, public display names, dates, categories, and moderation status are public. Reports to moderators are private and include the reporter, reason, and referenced post. Do not publish credentials, access tokens, private server addresses, diagnostic files, personal media information, or anything you do not want indexed and quoted by others.
Optional and task-specific services
- Beta distribution: joining the beta through TestFlight on iOS or Google Play testing on Android is handled by Apple or Google under its own policies. The optional Headroom email form is separate from enrollment and is used only for the update topics you request. Apple or Google may provide Headroom with beta activity, crash, and feedback information through their developer consoles.
- RevenueCat: the beta build does not offer purchases. If a future release requests storefront information or purchase status, RevenueCat may receive an app-scoped pseudonymous identifier, product and transaction information, platform information needed to verify the purchase, and the IP address required to deliver the request. Headroom does not send media-server credentials or your library to RevenueCat.
- Sentry: crash reporting is off until you opt in. Headroom's configuration sends sanitized JavaScript error categories, app version, code location, and an anonymous grouping value. It excludes raw error messages, breadcrumbs, account, device, library, server, screenshot, replay, performance, and native crash payloads. Sentry receives the connection IP while accepting a report, but Headroom asks it not to attach that IP to the event.
- ListenBrainz: if enabled, Headroom sends the recording or release identifiers needed to request recommendations. ListenBrainz also receives the connection IP.
- Last.fm: if you supply an API key, Headroom sends the key and artist or track names needed for matching. Last.fm also receives the connection IP.
- MusicBrainz: Headroom may send metadata identifiers, artist names, or recording names when resolving metadata or radio matches. MusicBrainz also receives the connection IP.
- AirPlay, Google Cast, CarPlay, and Android Auto: when used, playback metadata and, where required, a media URL are shared with the receiver or vehicle system you selected.
- Stores and test distribution: Apple and Google may independently process store, TestFlight or Play testing, purchase, device, and crash information under their own privacy policies.
- Support: Headroom receives the email, message, and diagnostics or attachments you choose to send. Diagnostic exports redact known credentials and server-sensitive fields, but you should review a file before sending it. A short report sent through the website feedback form is stored on the Headroom website server and may also be forwarded to the Headroom support mailbox.
Why we process information
We process information to provide app functions and transactions you request; respond to privacy requests, beta feedback, and support; prevent abuse and protect our services; comply with legal obligations; and, only when you affirmatively enable them, provide optional crash reporting or recommendation features. Depending on where you live, the legal basis may be performance of a contract or steps you request, consent, compliance with law, or our legitimate interest in operating a secure and reliable service. You may withdraw consent for optional processing at any time without affecting earlier lawful processing.
Sharing and international processing
Headroom does not sell personal information. We disclose information only to the services described in this policy, to a server or receiver you select, when required by law, or when necessary to protect rights and security. We limit information sent to each provider to the disclosed purpose. Providers may process information in countries other than yours and are responsible for safeguards required under their terms and applicable law.
Retention and deletion
Local data remains until you remove the related account or server, clear the data, or uninstall the app. Unconfirmed website subscriptions are deleted after 14 days. Confirmed subscriptions remain until you unsubscribe; the unsubscribed record is retained for up to 30 days and then deleted. Website feedback and support correspondence are ordinarily deleted within 12 months. Temporary website rate-limit records are deleted within 24 hours. Community sign-in requests expire after 30 minutes and sessions expire after 30 days. Public posts remain until removed by their author through a support request or by a moderator; moderation records may be retained as needed to prevent abuse. We may retain a record longer when reasonably required for security, dispute, or legal purposes.
IONOS, Cloudflare when enabled, Apple, Google, RevenueCat, Sentry, our email provider, your media-server operator, and other selected services retain their records according to their own settings, policies, and legal obligations. Disabling an optional service stops new disclosures from Headroom but does not automatically erase records that provider already holds.
Your choices and rights
You can remove accounts, servers, downloads, and other local data in the app, disable optional crash reporting and recommendation services, and stop using Headroom. Every update email includes an unsubscribe link. Depending on where you live, you may also have the right to request access, correction, deletion, portability, restriction, or objection regarding information Headroom controls, and to complain to your local data-protection authority. Email privacy@headroommusic.app. We may need enough information to verify and fulfill your request.
Children
Headroom is not directed to children under 13, and children under 13 should not join an email list or submit a support request. If you believe a child sent personal information to Headroom, contact us so we can delete it.
Changes and contact
We may update this policy as Headroom changes. Material changes will be dated here and, when appropriate, disclosed in the app or release notes. Email privacy@headroommusic.app with privacy questions. The support page explains how to get help with app-managed data.