Privacy Policy
Dysc is a music player operated by Tunahan Ekici ("Dysc", "we", "us", or "our"). This Privacy Policy explains how information is handled when you use the Dysc iOS app, visit the Dysc website, join the beta programme, or contact us.
Dysc is an independent client compatible with Jellyfin. It is not affiliated with, sponsored by, or endorsed by the Jellyfin project or Jellyfin, Inc. Dysc does not provide a Jellyfin server, a music catalogue, or a Dysc user account.
1. Plain-language summary
- Dysc connects directly to a Jellyfin server chosen by you.
- We do not operate an intermediary server for your music or Jellyfin credentials.
- Your password is sent to your chosen server when you sign in and is not saved by Dysc.
- Your server address, username, user ID, and access token are stored on your device using the iOS Keychain.
- Music, artwork, library metadata, preferences, and downloads may be cached or stored locally on your device.
- The current app does not include advertising, cross-app tracking, or developer-operated analytics.
2. Information handled by the app
Server and sign-in information
You provide a Jellyfin server address, username, and password to sign in. Dysc sends these details directly from your device to the server address you selected. The password is used for authentication and is not saved by Dysc. If authentication succeeds, Dysc stores the server address, username, Jellyfin user ID, and access token in the iOS Keychain so that you can remain signed in.
Device identification
Dysc sends the name of your device, an identifier assigned to Dysc by iOS, the Dysc client name, and the app version to your selected server. Jellyfin uses this information to identify and manage the client session. The server operator may be able to see this information in the server's active-device or session records.
Library, playback, and server activity
To provide its features, Dysc requests and displays information from your server, including artists, albums, tracks, playlists, lyrics, artwork, favourites, and related metadata. Dysc may send playback start, progress, pause, and stop events to the server when playback reporting is enabled. Actions such as favouriting an item, creating or editing a playlist, reordering tracks, deleting a playlist, and changing a playlist cover are also sent to the selected server.
Photos selected by you
If you choose a photo as a mixtape or playlist cover, iOS provides the selected image to Dysc. Dysc prepares a JPEG version and uploads it to the selected Jellyfin server. Dysc does not request unrestricted access to your entire photo library for this feature.
Information stored on your device
Depending on the features you use, Dysc may store:
- cached library metadata, playlist information, lyrics, and artwork;
- downloaded music, downloaded artwork, and temporary streaming cache files;
- app, playback, appearance, library, network, and download preferences;
- recent searches, custom radio stations, and other locally created settings; and
- local notification preferences and Album of the Day state.
Notifications
If you enable Album of the Day notifications, Dysc asks iOS for notification permission and schedules notifications locally on your device. Dysc does not use a developer-operated push-notification service for this feature.
Your Jellyfin server and its operator
A server may be operated by you or by someone else. The server operator independently controls its accounts, logs, security, retention, and other processing. If you connect to a server you do not operate, review that operator's privacy information and contact them about server-side data. We cannot access, correct, or delete information held on a server we do not operate.
3. Information received by us
App usage
The current version of Dysc does not send your music library, credentials, playback history, device identifier, or app-usage analytics to us. We do not use this information for advertising and do not sell it.
Beta requests and correspondence
If you email us, request support, report a security issue, or join an active beta mailing list, we receive the information you choose to provide. This can include your email address, name, app and iOS versions, device model, server version, diagnostic information, screenshots, and the content of your message. Please do not send your password, access token, private media, or an unrestricted server account.
The beta form in the current website preview saves an entered email address only in that browser and does not transmit it to Dysc. This policy will be updated before a hosted form or mailing-list provider begins collecting beta registrations.
Apple services
Apple may process information when you download Dysc through the App Store or TestFlight, submit TestFlight feedback, or share diagnostics under your Apple device settings. Apple handles that information under its own agreements and privacy policy.
4. How information is used
Information received directly by us is used only as reasonably necessary to:
- manage beta invitations and communicate about the beta;
- answer support, privacy, and security enquiries;
- investigate crashes, defects, compatibility problems, or abuse;
- improve Dysc using feedback you choose to provide; and
- meet legal, security, accounting, or regulatory obligations.
Where data-protection law requires a legal basis, we rely on steps requested by you, performance of an agreement with you, our legitimate interests in operating and securing Dysc, your consent where requested, or compliance with legal obligations. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
6. Storage and retention
- Keychain credentials remain until you sign out or the retained Keychain item is otherwise erased by iOS or the device owner. Keychain items may persist after the app itself is deleted.
- Caches remain until cleared by you, removed by iOS, replaced by newer data, or removed with the app.
- Downloads remain until you remove them or remove the app.
- Preferences remain until reset or removed with the app.
- Beta-list information is retained until you unsubscribe, ask for deletion, or for no more than 24 months after our last beta-related interaction.
- Ordinary support correspondence is normally retained for no more than 24 months after the last interaction.
- Security reports may be retained for up to 36 months, or longer where reasonably necessary to address an ongoing issue or legal obligation.
Server-side retention is controlled by the operator of the Jellyfin server. Signing out of Dysc does not delete server records, your Jellyfin account, or playlists stored on the server.
7. Your choices and rights
You can:
- disable playback reporting in Dysc settings;
- change notification permission in iOS Settings;
- clear cached library data and artwork;
- remove individual downloads or all downloaded music;
- sign out to remove the saved Jellyfin credential from the Keychain; and
- sign out and then delete the app to remove its locally stored data, subject to normal iOS Keychain and backup behaviour.
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information held by us, or to object to certain use. You may also withdraw consent and complain to your local data-protection authority. Email jellydisc@proton.me to exercise a right. We may need to verify your request.
Account deletion
Dysc does not create or control a Dysc account. Your Jellyfin account belongs to the server you use. To delete that account or its server-side data, contact the server administrator. We cannot perform that deletion unless we operate the relevant server.
8. Security and server connections
Dysc uses the iOS Keychain for stored credentials and relies on iOS protections for local app data. No method of storage or transmission is completely secure.
You should use HTTPS for any server reachable over the internet. If you choose an HTTP connection, credentials, session information, metadata, and media traffic may travel without transport encryption and may be observable or altered by others on the network. You are responsible for the configuration and security of the server and network you use.
9. Children
Dysc is not directed specifically to children and we do not knowingly collect personal information from children through a Dysc-operated service. A parent or guardian who believes a child has sent information directly to us should contact us so that we can review and, where appropriate, delete it.
10. Changes and contact
We may update this policy when Dysc, its providers, or legal requirements change. The effective date above will be revised, and material changes will be communicated in the app or on the website where appropriate.
Privacy enquiries can be sent to jellydisc@proton.me.