Privacy Policy

JR Player Privacy Policy

Effective date: August 31, 2026 · Applies to JR Player for iPhone, iPad, and Apple TV

The short version

JR Player collects nothing. There is no account to create, no analytics, no advertising, no tracking, and no server of ours that your listening passes through. Your library, your credentials, and your playback history stay on your device and on the JRiver Media Center server you own.

The app does make a small number of outbound connections — to your own server, and to a handful of public catalogue services that supply artist and composer artwork. Every one of them is listed below, along with exactly what it receives.

What stays on your device

All of the following is written into JR Player's own storage on your device and is never transmitted to us:

  • Server connection details — the address, port, and whether HTTPS is used, plus your JRiver username and password or Access Key. Stored in the iOS/tvOS Keychain (see below).
  • App settings — audio quality, storage limit, sort order, browse preferences, and similar choices.
  • Cached music and artwork — audio files downloaded or buffered for playback, album covers, and artist photos, together with a small metadata record per track so the app can manage its own storage.
  • Your playback queue and recently played albums, so the app can resume where you left off and populate the Apple TV Top Shelf.
  • A diagnostics log, described in its own section below.

JR Player also writes your album, artist, playlist, genre, and track names into your device's own Spotlight index, so that iOS search and Siri can find and play them. That index belongs to your device and is not visible to us.

Your server credentials

Your JRiver username, password, and Access Key are stored in the system Keychain, which encrypts them at rest. JR Player also uses the Keychain to hold what it needs to recognise your server on later connections.

If you have iCloud Keychain turned on, saved credentials sync between your iPhone and iPad through Apple's end-to-end encrypted service. Apple cannot read them in transit, and neither can we. Apple TV does not take part in iCloud Keychain — which is why setting one up uses the direct transfer described below.

Credentials are sent only to the JRiver server you configured, in order to authenticate to it. You can change or replace them at any time in Settings → Server.

One thing worth knowing: if you have not enabled HTTPS in JRiver Media Center, the connection between the app and your server is unencrypted, and your credentials and library traffic travel your network in the clear. JR Player shows a warning on the Server screen when this is the case. Enabling HTTPS in JRiver (Tools → Options → Media Network) is strongly recommended, particularly if you connect from outside your home network.

Connections the app makes

Your JRiver Media Center server

Nearly all of JR Player's network activity is a direct connection between your device and the server you configured: browsing, searching, downloading audio and artwork, and writing play counts and last-played dates back to your library so they match what JRiver itself records. That traffic goes to your machine, not ours. We have no access to it and no ability to obtain it.

JRiver's Access Key lookup

If you choose to connect using a JRiver Access Key rather than an address, the app asks JRiver's lookup service (webplay.jriver.com) to translate that key into your server's addresses. The key is the only thing sent. Connecting by address does not use this service, except occasionally to re-verify your server's identity if its security certificate changes. See JRiver's privacy statement.

Artist and composer artwork

To show artist photos and composer portraits that your library does not contain, the app queries three public catalogues. Each receives only what it needs to answer a single lookup, with no identifier for you or your device attached, and none of them is told what you are playing:

  • MusicBrainz — receives an artist or composer name and returns that artist's public catalogue identifier. Privacy policy.
  • fanart.tv — receives that catalogue identifier and returns artist photo URLs. If you choose to enter your own personal fanart.tv API key in Settings → Artist Images, it is stored on your device and sent to fanart.tv with these requests. fanart.tv.
  • Wikidata and Wikimedia Commons — receive a composer name or catalogue identifier and return a public-domain or CC0 portrait. Privacy policy.

Every request JR Player makes identifies itself with the app's name and version, the device family (iPhone, iPad, Mac, or Apple TV), the operating system version, and a contact address for this app — a descriptive identification that Wikimedia's policy requires and MusicBrainz recommends. It contains no identifier for you or your device.

These services are independent third parties with their own privacy practices, linked above. We do not share any information with them beyond the single lookup value described, and we receive nothing back from them about you.

Generated mixes and Apple Intelligence

When you ask JR Player to build a mix — through the Make a Mix option or a spoken request like "play me some summer music" — the app uses Apple's Foundation Models to interpret what you asked for and choose tracks. Depending on your device, that runs on the on-device model or on Apple's Private Cloud Compute. Where Private Cloud Compute is used, what is sent is your request and a list of candidate track titles and artist names drawn from your own library, so the model can pick among them.

Apple states that Private Cloud Compute uses this data only to fulfil the request, does not retain it, and does not make it available to Apple. It is not sent to us and we never see it. See Apple's Privacy Policy.

This only ever happens when you actively ask for a mix — ordinary browsing and playback never involve a model. If Apple Intelligence is unavailable on your device, the app falls back to a built-in, non-AI method that sends nothing anywhere. Generated mixes are queued for playback only; nothing is written back into your JRiver library.

Setting up Apple TV

Pairing JR Player on Apple TV with your iPhone sends your server settings — including your username and password — directly from the phone to the Apple TV over your local network, using Bonjour. It does not travel over the internet and does not pass through us. The QR code shown on the TV carries a one-time value that the phone echoes back, so the settings can only be delivered to the device you are looking at.

This is why JR Player asks for Local Network access. The same permission is what lets the app reach your JRiver server in the first place.

Siri, Shortcuts, and Spotlight

JR Player supports voice control and system search. Album, artist, playlist, genre, and track names from your library are provided to iOS so that Siri, Shortcuts, and Spotlight can act on them. This is handled by the system on your device; the app does not send your library to us or to any third party for this purpose. Apple's own handling of Siri requests is governed by Apple's Privacy Policy.

The diagnostics log

The app keeps a rolling technical log on the device to make problems diagnosable. It records playback, caching, and network events, and it does include the names of tracks, albums, artists, and playlists, because a log without them is not useful for troubleshooting.

It deliberately does not record your server's hostname, IP address, or port, your username or password, your Access Key, or session tokens. Those are stripped out before anything is written. The log is capped in size, overwrites itself as it fills, and stays on the device.

Nothing sends it anywhere automatically. It leaves your device only if you choose to share it — from the log viewer in Settings → Diagnostics, or by attaching it to a support email as described below.

Contacting support

Settings → Help & Feedback composes an email that you review and send yourself, from your own mail account. It always includes the app version, build, device model, and OS version, because those are the first questions of any support conversation. Details about your server, and the diagnostics log, are attached only if you opt in on that screen. Your password and Access Key are never included — there is no code path that can put them there.

If you email us, we hold that correspondence for as long as it takes to resolve the issue and for a reasonable period afterwards for reference. We do not use it for anything else and do not share it.

No analytics, tracking, or advertising

The App Store build of JR Player contains no analytics SDK, no crash-reporting service, no advertising, and no third-party tracking code of any kind. The app does not read the advertising identifier or the vendor identifier, does not build a profile of you, and does not link anything to data from other companies. It will never present an App Tracking Transparency prompt, because there is nothing to ask about.

Separately, if you have opted in to sharing analytics and crash reports with developers in your device's own settings, Apple may provide us with aggregated crash and usage statistics. That is Apple's mechanism, is controlled entirely by you in Settings → Privacy & Security → Analytics & Improvements, and gives us no way to identify you.

Permissions the app requests

  • Local Network — to reach your JRiver server and to set up JR Player on Apple TV.
  • Siri — to allow hands-free playback control.

JR Player requests no other permissions. It does not access your photos, contacts, calendar, location, microphone, camera, health data, or your Apple Music library.

Retention and deletion

Because nothing is collected, there is no account to close and no data of yours for us to delete on request. Everything the app stores is under your control on your device:

  • Cached music and artwork — clear it at any time from Settings → Offline Music. The app also removes cached audio on its own to stay within the storage limit you set.
  • Server details — change or replace them in Settings → Server.
  • The diagnostics log — clear it from the log viewer in Settings → Diagnostics; it also overwrites itself as it fills.
  • Everything else — deleting the app removes its settings, caches, and stored library data. Keychain items saved to iCloud Keychain are managed by Apple; you can remove saved passwords through your device's iCloud Keychain settings.

Play counts and last-played dates that JR Player wrote to your JRiver library live in that library, on your own machine, and are yours to edit or remove in JRiver Media Center.

Children's privacy

JR Player is not directed to children and collects no personal information from anyone, including children under 13.

Changes to this policy

If JR Player's handling of data changes, this page will be updated and the effective date above revised. Should the app ever begin collecting anything, that change would be described here before it ships, and the app's App Store privacy details would be updated to match.

Contact

For questions about this policy, or to exercise any privacy right available to you under laws such as the GDPR or CCPA, contact jtmckee@gmail.com. Note that since we hold no personal data about you, a request to access, correct, or delete it will generally be answered by confirming that there is nothing to act on.