# Loft Privacy Policy
Effective date: 21 September 2026 Publisher: Eduards Abisevs Contact: loft@abishevs.dev
## The short version
Loft does not collect your data. We have no servers that Loft talks to, no accounts, no analytics and no advertising. What you put into Loft stays on your device, and the only place Loft connects to is the service you add to it yourself — unless you switch on iCloud sync, which keeps your devices in step through your own iCloud account, end-to-end encrypted so that neither Apple nor we can read it.
## What Loft is
Loft is a media player. You add your own media service to it — with the address, username and password that service gave you — and Loft lets you browse and play what that service offers. Loft does not provide, sell or recommend any content or service, and we have no relationship with the service you choose.
## What stays on your device
| What | Where it is kept | |---|---| | Your service's username and password | The system Keychain, protected by your device. They stay on this device — unless you switch on iCloud sync, when iCloud Keychain carries them to your other devices, end-to-end encrypted. | | Your service's address, and the name you gave it | A database inside Loft's own storage on your device. | | The catalogue your service offers (titles, categories, artwork addresses, descriptions) | The same database. | | Your library: favorites, watchlist, what you have watched and how far | The same database. | | Artwork | A cache in Loft's own storage, which you can clear in Settings. | | A random identifier for this installation | Loft's own settings on your device. It is used only to label changes to your library, is not linked to you or your device's hardware, and is not sent anywhere. |
Loft's database is excluded from iCloud and device backups, because the catalogue can be rebuilt from your service at any time. This means your library is not backed up automatically — use Settings → Export Library to keep a copy. The export contains your favorites, watchlist, progress and history with their titles, and no login details or service addresses.
Nothing on this list is sent to us. We cannot see it.
## iCloud sync (optional, off unless you switch it on)
Settings → iCloud → Sync with iCloud keeps your devices signed in to the same Apple Account in step. When it is on:
| What | How it travels | |---|---| | Your services' addresses, usernames and passwords | iCloud Keychain, Apple's end-to-end-encrypted password sync. | | Which services you added and the names you gave them; your favorites, watchlist, lists, what you have watched and how far, with the title, year and poster of each; when you cleared history | Your private iCloud database, in fields that are end-to-end encrypted with keys only your devices hold. | | The catalogue your service offers, artwork and search history | Not synced. Each device fetches its own copy. |
This data is stored in your iCloud account under Apple's privacy policy, and counts towards your iCloud storage. End-to-end encrypted means that Apple cannot read it, and neither can we: we have no access to your iCloud account at all.
Switching sync off stops it straight away and leaves everything on your device. Logins already in iCloud Keychain stay there, because removing them would also remove them from your other devices; delete a service in Loft to remove its login everywhere. To delete Loft's data from iCloud, use your device's iCloud settings (on iPhone: Settings → your name → iCloud → Manage Storage → Loft).
## Who Loft connects to
- The service you added. Loft connects directly from your device to the address you
entered, to sign in, fetch the catalogue, fetch details when you open an item, and play video. Your username and password are sent to that service, because it requires them. If you add an address beginning with http:// rather than https://, that connection is not encrypted — Loft warns you about this before you save it. What that service does with the information it receives is governed by its own terms and privacy policy, not this one.
- Hosts that serve artwork. Posters, channel logos and similar images come from
addresses your service provides, which may belong to other companies. When Loft shows an image, your device requests it from that address, which — as with any web request — can see your IP address.
- Links you choose to open. Where your service names a trailer, Loft shows a link to
YouTube. Nothing is sent to YouTube unless you tap it, and it then opens outside Loft.
Loft also runs a small web server that is reachable only from inside your device (on the loopback address 127.0.0.1). It exists to hand converted video to the system's player and cannot be reached from your network or the internet.
- Apple's iCloud, only if you switch on iCloud sync — see above.
Loft makes no other network requests. In particular, it contacts no server run by us.
## What we collect
Nothing. Loft contains no analytics, no advertising or tracking code, no crash-reporting service of its own, and no account system. We do not track you across apps or websites.
If you have chosen to share analytics with app developers in your device's settings, Apple may provide us with crash reports and aggregate usage statistics. These come from Apple under Apple's privacy policy, are anonymous, and are used only to fix problems. Loft's own logs are kept on your device by the operating system and are written so that they never contain your password, username or your service's full address.
## Your controls
In Loft you can:
- remove a service, which deletes its saved password from the Keychain and its catalogue
from your device;
- clear your watch history, or clear Continue Watching, without affecting your favorites;
- clear cached artwork;
- export your library as a file.
Deleting Loft removes everything it stored on your device. Its Keychain entries are removed when you remove each service; to be certain nothing remains, remove your services in Loft before deleting the app.
## Children
Loft is not directed at children and collects no information from anyone, including children.
## Future changes: sync
Loft does not offer syncing between devices today, and none of the following exists yet.
We may later offer an optional, paid feature to keep your library in step across your devices. If we do, it will change this policy, and we will update this page and ask you before anything is sent. As designed, it would store on our servers only what is needed to sync your library: an account identifier (from Sign in with Apple), the devices you register, and your favorites, progress, watchlist and history — recorded against random identifiers rather than titles. It would not send your service's address, username, password, catalogue or the titles of what you watch. Loft would remain fully usable without it, and you would be able to delete your account and all data held for it from within the app.
## Changes to this policy
If this policy changes, we will publish the new version at this address with a new effective date. If a change means Loft starts sending any of your information off your device, the app will tell you first.
## Contact
Questions about this policy or your privacy: loft@abishevs.dev.