Navarre Privacy Policy
The short version
Navarre is built so that your media never touches our servers. Your movies, shows, library contents, and viewing history stay on your own Jellyfin server and stream directly from it to your own devices. We operate a small "control plane" that handles only three things: signing you in, recording your one-time purchase, and brokering the handshake that pairs your devices. We never see what you watch.
If you turn on remote access: Navarre publishes your Jellyfin server on the internet at a public HTTPS web address, using your own Tailscale account. The connection to it is encrypted, and we do not advertise the address anywhere - but the address is not a secret either (addresses like it appear in the public certificate logs that cover every HTTPS site), so anyone who has it reaches your server's sign-in page. The passwords on your Jellyfin accounts are what control who gets in, which is why Navarre refuses to turn remote access on while any enabled account on your server has no password.
Information we collect
- Your email address. Used to sign you in (we email a one-time code - we do not use passwords) and to send receipts and essential service notices.
- Purchase and entitlement records. When you buy the one-time unlock, our payment processor (Stripe, or Google Play) confirms a valid purchase and gives us a reference id and your entitlement status. We do not receive or store your full payment card number.
- Home-server registration. A label you choose for your server, its local network address, and - only if you turn on remote access - the public hostname your own Tailscale account publishes it at.
- A scoped access credential. So a paired device can reach your server from away, we store a limited Jellyfin access token and a scoped-user credential, encrypted at rest. It is scoped to only the libraries you choose to share.
- Device information. A label and platform for each device you pair (for example, "Pixel phone" or "Windows PC"), plus session tokens that keep you signed in.
- Limited technical data. Your IP address is processed transiently to protect the service from abuse (rate limiting). We do not build an advertising or tracking profile.
- Email-list signups (separate from your account). If you enter your email address on our home page to get release news, we store that address, the date you entered it, the two-letter country code your connection reported, and the website you arrived from. Nothing else, and it is not linked to a Navarre account. You can remove it yourself, without an account, at navarre.tv/delete - or email support@navarre.tv. Deleting a Navarre account does not clear this list, and leaving this list does not affect an account.
- Campaign tags. When you arrive from a link we published somewhere (a forum post, a directory listing), that link carries our own campaign name in its web address. We count arrivals per campaign - the campaign name and the date, nothing about you - and your browser remembers the campaign name for up to 30 days so that a purchase can be credited to the link that introduced you. No cookie, no advertising network, and nothing that identifies you.
- Crash reports. If a Navarre app crashes, we receive a technical report (the error, stack trace, app version, device model, and operating system version) through our crash-reporting provider so we can find and fix the bug. Crash reports are not used for advertising or profiling, and they do not include your media, watch history, or email address.
Information we do NOT collect
- Your media files, library contents, watch history, or search queries. Streaming is direct from your server to your device and does not pass through Navarre.
- Your Jellyfin administrator password, or your full payment card details.
Service providers we share with
We share the limited data above only with providers that help us run the service, and only as needed:
- Stripe - payments made on our website or in the Windows app.
- Google Play Billing - purchases made in the Android apps.
- Microsoft Azure (United States) - hosts our control plane. Neon - our database.
- Azure Communication Services - delivers your one-time sign-in code by email.
- Sentry (United States) - receives crash reports from the apps so we can diagnose and fix failures.
- Tailscale - the encrypted transport that publishes your server for remote access runs on your own Tailscale account; Navarre does not operate it and does not see your streaming traffic.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
How long we keep it
We keep your account data while your account is active. Sign-in sessions expire after 90 days. When you delete your account, we delete your account and its associated records (see below). Email-list signups are deleted automatically two years after signup, or as soon as you remove yourself at navarre.tv/delete. Campaign counts are deleted after 400 days, and the campaign name your browser remembers expires after 30 days.
Your rights and choices
- Delete your account and data at any time from the app's Settings, or on the web at navarre.tv/delete. Deletion removes your account, entitlement, stored credentials, and paired-device records.
- Access or correct your information by emailing support@navarre.tv.
- Because remote access and streaming run on hardware and networks you own, much of your data already stays under your direct control.
If you are a California resident, you have the right to know, delete, and correct your personal information, and not to be discriminated against for exercising those rights; the controls above satisfy these requests.
Children
Navarre is not directed to children under 13, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy. We will post the revised effective date here and, for material changes, provide notice.
Contact
Navarre Enterprises LLC · 8987 E Tanque Verde Rd, Ste 309-1017, Tucson, AZ 85749-9399 · support@navarre.tv
Navarre is not affiliated with, endorsed by, or sponsored by the Jellyfin project or the Jellyfin contributors. "Jellyfin" is used only to describe compatibility.