1. Scope and who operates Libra
This Privacy Policy applies to the Libra Media Player iOS application, including later updates unless a replacement policy is provided, and this website. Libra Media Player is referred to in this policy as “Libra” and is provided by Seven, referred to as “we” or “us.”
Libra is an Apple-native media player for personal media libraries. Libra does not provide or host movies, television programs, or other media. You choose the servers and third-party services that the app contacts.
2. Information stored on your device
Libra stores information needed to remember your setup and provide playback. Depending on the features you use, this may include:
- Emby server profiles, server addresses, account identifiers, display names, selected routes, and library presentation settings.
- Emby access tokens and certain service credentials in Apple Keychain. Passwords used during sign-in are not retained by Libra.
- App preferences, search history, playback history, progress, Favorites, Watchlist, and Tracking state.
- Danmaku service addresses, matching preferences, and confirmed episode bindings that you configure.
- Metadata, artwork, interface caches, and optional reusable media bytes used to improve performance and playback continuity.
- Privacy-bounded diagnostic records, Apple MetricKit reports made available to the app, and diagnostic packages you explicitly create.
3. Optional iCloud synchronization
iCloud Sync is optional. When you enable it, Apple processes synchronized data through services associated with your Apple Account.
Depending on your settings, Libra can synchronize Emby profile configuration through your private iCloud key-value store, compatible Emby access tokens through iCloud Keychain, configured danmaku service profiles, and Libra-owned viewing, Favorite, Watchlist, and Tracking state through a private CloudKit database.
The personal-media CloudKit records exclude raw credentials, server endpoints, provider delivery records, downloads, media bytes, artwork caches, and diagnostic archives. Emby profile synchronization is separate and may include configured server routes and a synchronized Keychain token when you enable that profile for a device family.
Turning synchronization off stops synchronization on that device but does not itself erase retained local or cloud copies. Profile deletion, device-family targeting, app deletion, and the iCloud controls provided by Apple may affect which copies remain.
4. Services Libra contacts
Libra sends requests only as needed to provide features you use. Those requests may include network identifiers such as your IP address and technical request information that is ordinarily visible to an internet service.
- Your Emby servers: authentication, library browsing, metadata, images, playback information, media delivery, progress, and supported library actions.
- TMDB: discovery, metadata, artwork, people, collections, and related-media information. The default configuration can access TMDB through the Libra gateway; you may instead configure a compatible custom TMDB service.
- Trakt: optional schedule and episode-airing information.
- Danmaku services: optional search, matching, and timed comments through the service address you configure.
- Apple services: App Attest, iCloud, CloudKit, iCloud Keychain, push-notification infrastructure, and TestFlight or App Store services where applicable.
- Infrastructure and security providers: delivery and protection of this website and the Libra gateway.
5. Libra gateway and App Attest
The default TMDB connection uses a controlled Libra gateway so that application credentials do not need to be exposed directly in the app. Apple App Attest helps the gateway determine whether a request comes from a genuine instance of Libra. The app sends an App Attest registration or assertion and receives a time-limited installation authorization token for supported gateway requests.
The gateway is designed not to require your name, email address, Emby password, Emby access token, media files, or complete personal library. The infrastructure and security providers used by the website and gateway may process IP addresses, request timing, user-agent information, security signals, and bounded operational logs to deliver, secure, and troubleshoot requests.
6. Photos, files, and exports
Libra asks for permission to add to your Photos library only when a feature needs to save a captured video frame. Libra does not need permission to browse your full photo library for this purpose.
Personal-media import uses Apple’s system file picker. Libra validates and imports the selected archive and does not retain the selected import file as an app-owned copy. Export creates a fresh archive only when you invoke sharing. Diagnostic packages are also created and shared only when you request them.
Files or diagnostics you choose to share are handled by the destination you select and become subject to that destination’s privacy practices.
7. Diagnostics, analytics, and tracking
Libra does not use advertising SDKs and does not track you across apps or websites for advertising. This website does not set first-party analytics cookies and does not include third-party analytics scripts.
The app keeps bounded operational diagnostics on your device. Sensitive values such as credentials, authorization headers, full URLs, request bodies, media files, and ordinary media identities are excluded from normal logs. Libra does not automatically upload its local diagnostic package; you decide whether and where to share an exported copy.
8. Retention and your choices
Different records have different lifetimes. Caches may expire, be evicted by the operating system, or be cleared from Libra. Account profiles and personal-media state remain until changed or deleted because they are needed to preserve your choices. Some negative state, such as an explicit removal or “stop watching” decision, may be retained to prevent deleted items from reappearing.
- You can remove configured services and Emby profiles from the app.
- You can clear supported caches without deleting your durable personal-media state.
- You can disable iCloud Sync; disabling alone does not erase existing synchronized data.
- You can delete Libra from your device and use Apple’s iCloud storage controls for data associated with your Apple Account.
9. Security
Libra separates credentials from ordinary preferences and caches, uses Apple Keychain for supported secrets, uses encrypted CloudKit fields for personal-media payloads, and limits diagnostic contents. No storage or transmission system can be guaranteed completely secure, especially when you connect to a server or service operated by someone else.
Libra supports user-managed Emby servers that may use local HTTP connections. A non-HTTPS connection is not protected by TLS. Use HTTPS and a trusted network whenever your server supports it.
10. Children
Libra is not directed to children under the minimum age required to consent to data processing in their jurisdiction. Libra does not offer a separate Libra account or intentionally collect a child’s name or email address. Parents and guardians are responsible for the media libraries and third-party services they make available to a child.
11. Changes and contact
We may update this policy when Libra’s features, providers, or legal obligations change. The current effective date will remain visible at the top of this page. Material changes should be reviewed before a new app release.
For privacy questions or requests, contact libraplayer@163.com.
