JellyMold is a media player and client for Jellyfin servers that you host and control. This policy covers both the app and this website.
The short version: the app sends us nothing. What it keeps — your servers, your settings, your place in a programme, and any crash reports iOS hands it — stays on your device. This website collects what you type into one of its forms, and counts visits to its pages without cookies and without identifying anyone.
Who we are
JellyMold is published by Virtue Apps (“we”, “us”), the developer. We make the app. We do not operate any Jellyfin server it connects to, and we have no access to yours.
For anything below, contact us through the contact form.
Part one — the app
What stays on your device
To connect to your servers and play your media, JellyMold stores the following on your device only:
- Server details — each server’s name and network addresses, and the username you signed in with.
- A sign-in token — issued by your server when you sign in, kept in the device Keychain so you need not sign in every time. Your password is never stored.
- Your preferences and playback settings — gestures, subtitles, audio and playback options, playback speed, and which programmes you have adjusted.
- Your play positions — kept on the device so a programme resumes correctly even when the server is unreachable.
- Downloaded media — any files you choose to download, kept in the app’s Application Support directory until you delete them.
- Crash diagnostics — described in its own section below.
None of this is sent to Virtue Apps. The app contains no analytics, no advertising, and no third-party tracking SDKs of any kind. We cannot see your servers, your library, what you watch, or your settings. (The website is a separate matter and has its own section below.)
Crash diagnostics, which stay on the device
When the app crashes, hangs, or misbehaves badly enough for iOS to notice, iOS writes a diagnostic report and hands it to the app on the next launch. JellyMold saves that report — the call stack included — into its own storage on your device, alongside a log of what playback was doing at the time.
It is written to the device and nowhere else. The app has no code that uploads it, and we deliberately did not use a third-party crash reporting service, because those upload by default and that would have made everything above untrue.
The only way a report reaches us is if you decide to send it: it takes a USB cable and a deliberate act on your part, and you can read the file first. If we ever ask for one while helping with a problem, that is a request you are free to refuse.
Deleting the app deletes the reports with it.
What Apple may send separately
Independently of any of this, Apple may share crash reports and usage statistics from App Store apps with their developers — but only if you have turned that on. It is controlled by iOS, not by us, under Settings ▸ Privacy & Security ▸ Analytics & Improvements. What we would receive there is aggregated and comes from Apple, not from JellyMold. To stop it, switch off Share With App Developers.
Information that goes to your own server
When you play something, the app talks directly to your Jellyfin server and, as any Jellyfin client does, reports ordinary playback information to it — what you are watching and how far through you are — so that features like Continue Watching work.
That information is handled by your server and whoever operates it, under their rules, not ours. If the server is not yours, ask its operator how they handle your data.
Your server, your content, your decisions
JellyMold is a client. It shows you what is already on a server you chose to connect to, and it puts nothing there.
Everything about that content is yours to decide and yours to answer for: where you obtained it, whether you have the right to hold it, whether it is appropriate, and who you give access to it. If you share your server with other people, that is your decision and your responsibility, as is what they can reach once you have.
We are not involved in any of it. We do not host, index, supply or moderate your media, we have no access to your server, and we could not see what is on it even if we wanted to. What the app displays is whatever your server returns.
Section 3 of the terms of use says the same thing in the language of an agreement.
iCloud sync
If you are signed in to iCloud, JellyMold syncs your settings and your list of servers across your own devices using Apple’s iCloud key-value storage. This lives in your private iCloud account. It is not shared with us and we have no access to it. Your sign-in tokens are not synced. Signing the device out of iCloud stops this.
Local network access
So that servers on your network can be offered without you typing an address, JellyMold looks for Jellyfin servers on the local network you are connected to. iOS asks your permission the first time. This happens entirely on your device; nothing about your network reaches us.
Other apps
Where you have them installed, a title’s page can hand off to Callsheet or IMDb for cast and crew. Doing so opens that app with the title’s public identifier — nothing about you, your server or your library is included. Both are off unless you turn them on, and what those apps then do is covered by their own policies.
Subscriptions and payments
JellyMold offers an optional subscription, purchased and managed by Apple through the App Store. Apple processes the payment; we never see your payment details. We receive only Apple’s standard sales and subscription reports, which are aggregated and do not identify you. Manage or cancel a subscription in your Apple account settings.
Part two — this website
What we collect, and only if you send it
This site has two forms, and it counts its visitors. It sets no cookies, carries no advertising, and builds no profile of you.
| Form | What it collects | Why |
|---|---|---|
| TestFlight request | Your email address | To consider you for a TestFlight place and to tell you when JellyMold is released |
| Contact | Your name, email address, chosen reason, and message | To read your message and reply to it |
That information is emailed to us and kept in our mailbox. It is not added to a marketing list, sold, or shared with anyone beyond the processors below.
Visitor statistics
We use Cloudflare Web Analytics to see how many people visit and which pages they read. It tells us whether anyone is finding the site; it does not tell us anything about you.
It is measurement rather than tracking, and the difference is not marketing language:
- it sets no cookies and stores nothing in your browser;
- it does not fingerprint your device;
- it cannot follow you to any other website, because it has no identifier that persists beyond the page you are on;
- it is not sold, shared, or used for advertising.
What it records is the page address, the referring page, and general technical details a browser sends anyway — device type, browser, and the country your request came from. We see totals. We cannot pick you out of them, and neither can Cloudflare.
If you would rather not be counted at all, any content blocker or a browser sending Do Not Track will stop the script loading, and nothing on the site breaks without it.
Who processes it on our behalf
- Cloudflare — hosts this site, runs the form endpoints, and provides the visitor statistics described above. Cloudflare processes request metadata, including your IP address, for delivery and security. We also use Cloudflare’s Turnstile to keep bots off the forms; it checks that a submission comes from a real browser and does not track you across sites.
- Resend — delivers form submissions to our mailbox as email.
Both act as processors under our instructions.
Lawful basis and how long we keep it
For anything you send us through a form, we rely on your consent, given by submitting it. You can withdraw that at any time.
For the visitor statistics we rely on legitimate interests — knowing whether anyone reads the site. There is no cookie and no personal data to consent to, which is why you are not asked. You can still opt out by blocking the script.
TestFlight requests are kept until the app has launched and we have told you, and then deleted. Contact messages are kept for as long as needed to deal with the matter and for a reasonable period afterwards, then deleted. Visitor statistics are aggregated by Cloudflare and retained by them; we keep no copy.
Your rights
If you are in the UK or the EU you have the right to ask for a copy of what we hold about you, to have it corrected or deleted, to object to or restrict its use, and to complain to a supervisory authority — in the UK, the Information Commissioner’s Office. Ask through the contact form, choosing Privacy or a data request, and we will deal with it within one month.
Children
JellyMold is not directed at children. The app collects no information from anyone regardless of age, because it collects none at all.
Data retention and deletion
App data lives on your device and, for synced items, in your iCloud. To remove it: sign out of a server in the app, delete the app, or sign the device out of iCloud. Because we hold none of it, there is nothing for us to delete or return.
For anything you sent through a form on this site, ask us and we will delete it.
Changes to this policy
If this policy changes we will update the date at the top and post the new version at this address.
Contact
Questions about this policy or your privacy in JellyMold: use the contact form and choose Privacy or a data request.