Privacy Policy
Krill is a media player. It plays media from the sources that you connect, for example Jellyfin, Emby, fnOS, WebDAV, SMB and local folders. Krill does not require an account. Krill does not sell your data, and it does not use advertising or third-party tracking SDKs.
Data on your device
- Library index: Krill builds an index of titles and matches from your sources. It stays on this device. You can rebuild it in Settings at any time.
- Watch history: playback progress, watched marks, Watchlist, match corrections, per-series player settings and your Home selection.
- Sign-in data: server addresses, user names and passwords are kept in the Apple Keychain. Krill uses them only to connect to your sources and does not send them to Krill's servers.
- Media files: they always stay on your server or device. Krill's servers do not relay or store your media.
iCloud sync
If you are signed in to iCloud, Krill syncs your watch history, source configurations and match corrections between your devices through your iCloud private database. Sign-in data syncs through iCloud Keychain. This data belongs to your Apple Account only; the developer of Krill cannot access it. The Library index does not sync; each device builds its own. Apple operates iCloud under the Apple privacy policy. You can manage or delete this data in your Apple Account settings.
Title information (TMDB)
Titles, posters and descriptions come from The Movie Database (TMDB). Krill sends TMDB requests through its own Cloudflare proxy. A request contains the title identifier or search text, and the metadata language and region that you selected. The proxy limits requests per IP address and caches public title information. Cloudflare and TMDB receive your IP address when they process network requests. Krill does not link these requests to your identity or your watch history.
Anonymous usage statistics
Anonymous usage statistics are on by default so that we can see which features are used. Krill counts four events: a source was saved successfully (source type only), playback was attempted (source type only), the user changed Home (Discover, Library or Source View), and a cold app start. Each event contains only coarse app version, OS major version, platform and language region. Krill does not count unique active devices.
- It does not record titles, file names, source addresses, server details, accounts or any personal information.
- It does not use device, installation, session or event identifiers. Cloudflare processes IP addresses for network delivery and rate limiting. Krill does not write IP addresses into statistics or daily summaries and disables Worker request invocation logs.
- Workers Analytics Engine keeps raw events for about 3 months. D1 keeps only daily counts by the coarse dimensions above, with no automatic expiration period.
- Events wait in a bounded local queue excluded from backups. They are sent in batches only while online, with delayed retries on failure. Sampling or retries can make counts approximate. Offline counts use the date the server receives them.
- You can turn it off at any time in Settings › Privacy. Krill immediately stops collection and new sends, cancels the in-flight request and clears the local queue. Data delivered before opt-out cannot be recalled. Cold starts while off are not replayed after opt-in.
Diagnostic logs
You can export diagnostic logs from the About page and send them to us with the system share sheet. Before export, Krill removes sign-in data, tokens, user information in server addresses and signed URL parameters. Krill does not upload diagnostic logs automatically. If you turn on Apple's Analytics & Improvements setting, Apple can give crash reports to the developer.
Your choices
- Clear the image cache, rebuild the Library or remove sources in Settings.
- Turn off anonymous usage statistics.
- Manage iCloud data in your Apple Account settings.
- When you delete the app, its on-device data is removed. Keychain and iCloud data are kept or removed according to Apple's rules.
Children's privacy
Krill is not directed to children under 13 and does not knowingly collect personal information from children.
Changes to this policy
If this policy changes in an important way, we update this page and its effective date.
Contact
For privacy questions, contact support@kami.asia. Do not include your password or private source addresses in your message.