Privacy Policy

Headroom is developed and published by Posh Industries (“Headroom,” “we,” or “us”). We do not host or proxy your media library, operate an advertising service, or require a separate Headroom account.

Scope and who is responsible

This policy covers the Headroom app, headroommusic.app, beta signups, support messages, and optional services described below. Posh Industries is responsible for personal information sent directly to Headroom, such as a beta signup or support request. Your media server and any third-party service you choose have their own operators, practices, and policies.

Information stored on your device

Headroom stores server URLs and names, account names and server-issued user identifiers, preferences, library indexes, artwork caches, diagnostics, playback state, and downloaded media on your device. Passwords are used to authenticate and are not saved by Headroom. Server-issued access and refresh tokens, and Plex cloud tokens when applicable, are stored using the operating system's secure credential storage where available.

Removing an account or server deletes the related app-managed data and credentials. Uninstalling Headroom removes app-managed local data, subject to your operating system's backup, restore, and retention behavior. Data held by your media server or another provider must be managed with that service.

Your media servers

When you connect Jellyfin, Emby, Plex, an OpenSubsonic-compatible server, or Audiobookshelf, Headroom sends the credentials and requests required to authenticate, browse, stream, download, and update playback state. Those requests go to the server URL you supplied. The server operator controls its logs and retention. Plex sign-in also contacts Plex's cloud authentication service when you choose its PIN flow.

Headroom supports plain HTTP because some personal servers run only on a trusted local network. HTTP does not encrypt credentials, tokens, or media. Use HTTP only on a trusted LAN or through a VPN, and use HTTPS for remote access.

The Headroom website

The website is delivered through Cloudflare Pages and its content delivery and security network. Cloudflare may process connection data such as your IP address, browser and device details, requested URL, time, and security signals to deliver and protect the site. Headroom does not use website advertising or behavioral analytics.

Optional and task-specific services

Why we process information

We process information to provide app functions and transactions you request; respond to beta signups, privacy requests, and support; prevent abuse and protect our services; comply with legal obligations; and, only when you affirmatively enable them, provide optional crash reporting or recommendation features. Depending on where you live, the legal basis may be performance of a contract or steps you request, consent, compliance with law, or our legitimate interest in operating a secure and reliable service. You may withdraw consent for optional processing at any time without affecting earlier lawful processing.

Sharing and international processing

Headroom does not sell personal information. We disclose information only to the services described in this policy, to a server or receiver you select, when required by law, or when necessary to protect rights and security. We limit information sent to each provider to the disclosed purpose. Providers may process information in countries other than yours and are responsible for safeguards required under their terms and applicable law.

Retention and deletion

Local data remains until you remove the related account or server, clear the data, or uninstall the app. We periodically review beta signups and support correspondence and delete them when they are no longer needed; ordinarily that is within 12 months after recruitment or the last correspondence, unless a longer period is reasonably needed for security, dispute, or legal purposes. FormSubmit states that it may retain submissions for up to 30 days for delivery and recovery.

Cloudflare, Apple, Google, RevenueCat, Sentry, your media-server operator, and other selected services retain their records according to their own settings, policies, and legal obligations. Disabling an optional service stops new disclosures from Headroom but does not automatically erase records that provider already holds.

Your choices and rights

You can remove accounts, servers, downloads, and other local data in the app, disable optional crash reporting and recommendation services, and stop using Headroom. Depending on where you live, you may also have the right to request access, correction, deletion, portability, restriction, or objection regarding information Headroom controls, and to complain to your local data-protection authority. Email privacy@headroommusic.app. We may need enough information to verify and fulfill your request.

Children

Headroom is not directed to children under 13, and children under 13 should not submit a beta application or support request. If you believe a child sent personal information to Headroom, contact us so we can delete it.

Changes and contact

We may update this policy as Headroom changes. Material changes will be dated here and, when appropriate, disclosed in the app or release notes. Email privacy@headroommusic.app with privacy questions. The support page explains how to get help with app-managed data.

External policies: Cloudflare, FormSubmit, RevenueCat, Sentry, ListenBrainz, Last.fm, MetaBrainz/MusicBrainz, Apple, and Google.