Privacy Policy — Media Deck
Last updated: July 17, 2026
1. Summary
This Privacy Policy explains how ZS Software ("we", "us") handles your data in the Media Deck mobile application ("the App"). By using the App you agree to this policy.
Media Deck is an offline-first media player. Most of your data — including your whole library catalog and your source credentials — stays on your device. We only store data in the cloud when you sign in, and only to sync your setup across your devices. We do not sell your data and we do not show ads.
2. Data we collect
Only when you sign in (optional):
- Account identifiers — the email address and/or name provided by Google or Apple sign-in, and a Firebase user ID.
- Synced app data, stored under your account so it can follow you across devices:
- configuration of the sources you add (type, name, server or network-drive address, library settings);
- favorites, watch history, and resume position;
- app preferences.
Credentials for your sources (passwords for Jellyfin, Plex, SMB/NAS shares, or WebDAV) are stored encrypted in the device's secure system storage (Android Keystore / SecureStore) and are not read by us.
Always (on your device):
- Your entire library catalog (titles, metadata, poster cache) is stored locally in an on-device database. If you do not sign in, this data is not uploaded.
Metadata (posters and descriptions):
- For Jellyfin and Plex sources, metadata comes directly from your server — we do not contact any external service for this.
- For SMB/NAS and WebDAV sources, the App sends queries based on file names to The Movie Database (TMDB) to fetch posters and descriptions. Results are cached locally on your device.
Purchases:
- RevenueCat processes and stores your subscription/purchase status and store receipts, tied to an app-generated identifier, so we can unlock Pro. Payment card details are handled solely by Google/Apple and are never seen by us.
Diagnostics (optional):
- If enabled in a build, aggregated crash reports may be collected (Sentry) to help us fix bugs. These do not include your source credentials.
We do not collect advertising identifiers and do not track you across other apps or websites.
3. How we use your data
- To authenticate you and sync your source configuration, favorites, history, and settings across your devices.
- To fetch posters and descriptions for SMB/WebDAV libraries (TMDB).
- To provide and restore your Pro entitlement.
- To diagnose crashes and improve reliability.
4. Third parties
We share data only with service providers that make the App work:
- Your own servers and network drives (Jellyfin, Plex, SMB/NAS, WebDAV) — the App connects to them directly using the addresses and credentials you provide. This is your infrastructure, not ours.
- The Movie Database (TMDB) — file-name-based metadata queries, only for SMB/WebDAV sources.
- Google Firebase (Authentication, Firestore) — account and synced data, only when you sign in. See Google's Privacy Policy and the Firebase data-processing terms.
- RevenueCat — subscription status and receipts.
- Google Play / Apple App Store — payment processing.
- Sentry — optional crash diagnostics.
We do not sell or rent your personal data to anyone. This product uses the TMDB API but is not endorsed or certified by TMDB.
5. Storage and retention
Synced data is retained while your account exists. Local data (library catalog, metadata cache, source credentials) remains on your device until you delete it or uninstall the App. When you delete your account, your cloud data is removed (see below).
6. Your rights and choices
- Delete your account and cloud data at any time from Settings → Account → Delete account. This removes your synced data from Firestore and deletes your authentication record. Local on-device data is removed when you uninstall the App.
- Access or correction — contact us to request a copy of, or correction to, your data.
- Depending on your region (e.g. EU/EEA under GDPR), you may have additional rights, including the right to object, restrict processing, or lodge a complaint with a supervisory authority.
7. Children
The App is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
8. Security
Source credentials are stored in the device's encrypted system storage (Android Keystore / SecureStore). Data in transit is encrypted (HTTPS/TLS) where your server supports it. Cloud data is protected by per-user security rules so that a signed-in user can access only their own document. No method of transmission or storage is 100% secure.
9. International transfers
Our providers may process data on servers outside your country. Where required, appropriate safeguards are applied.
10. Changes to this policy
We may update this policy from time to time. Material changes are reflected by updating the "Last updated" date.
11. Contact
Privacy questions or data requests:
Email: mistyksu@gmail.com