Legal
Privacy policy
Last updated 12 August 2026
Castaway Media collects no personal data. There are no analytics, no tracking, no advertising identifiers, and no servers operated by the developer. There is nothing to collect data with.
What we collect
Nothing. The app has no account system, no telemetry, no crash reporting service and no analytics SDK of any kind. No information about you or your usage is transmitted to the developer, because there is no developer-operated server for it to be transmitted to.
How the app works
Castaway Media is a client for servers you run yourself. It connects to an Audiobookshelf server you specify for podcasts, audiobooks and ebooks, and optionally to a Plex server for music. All content, progress and library data lives on those servers, under your control.
The app ships with no content and provides no access to content you don't already have.
What's stored on your device
- Server addresses and credentials — held in the iOS Keychain, the system's encrypted credential store. Sent only to the servers you entered them for.
- Downloaded media — episodes, audiobooks and ebook files you chose to download.
- Cover art — cached so the app works offline and doesn't refetch images repeatedly.
- Preferences — playback speed, theme, swipe actions, per-podcast overrides and similar settings.
- Positions and bookmarks — kept locally and synchronised with your own server.
Deleting the app removes all of it.
iCloud
Some preferences and queue state sync through your own iCloud account so they carry between your devices. This is Apple's own key-value storage, it stays within your Apple Account, and the developer has no access to it. Turning off iCloud for the app in iOS Settings stops this.
Who the app talks to
- Your Audiobookshelf server — the address you entered, and nowhere else.
- Your Plex server — if you connect one, along with Plex's own sign-in service for authentication.
- Apple's iTunes directory — a public API, used to search for podcasts and to show charts. Queries carry your search terms and no identifying information.
- LRCLIB — a public, non-commercial lyrics database, queried by track and artist name when lyrics are shown. Nothing about you is sent.
- Last.fm — only if you supply your own API key, and only to look up how widely an artist's tracks are played so the app can mark the well-known ones. The request carries the artist's name and your key; it carries nothing about you, and no key means no request.
Optional integrations
If you choose to connect Lidarr, the app communicates with that server at the address you provide, using credentials you supply, to request albums. This is entirely optional, off unless configured, and involves only your own infrastructure.
Notifications
New episode and new content alerts are generated on your device by comparing what your server reports against what the app last saw. They are local notifications. No push service is involved and nothing leaves the device to produce them.
Children
The app is not directed at children and collects no data from anyone, including children. Content shown is whatever is on the servers you connect.
Data sharing and sale
No data is collected, so none is shared, sold, rented or disclosed to anyone. There are no third-party advertising or analytics partners.
Your rights
Regulations such as GDPR and CCPA grant rights to access, correct and delete personal data held about you. No personal data about you is held, so there is nothing to request. Data on your own servers is governed by whatever policies you apply to them.
Changes to this policy
If this policy changes, the revised version will be posted here with an updated date. Material changes affecting how the app handles data will also be noted in the app's release notes.
Contact
Questions about this policy or the app: support@castawaymedia.app