Privacy Policy
Effective date: September 11, 2026
Nestrr is an independent client application for media servers managed by you or your server administrator. Nestrr does not provide, host, sell, or include any media. A Seerr server connected to Jellyfin or Plex, or a compatible Jellyseerr server connected to Jellyfin, is required to use the app.
Information used by the app
Depending on the features you use, Nestrr processes:
- Connection and authentication information for the Seerr/Jellyseerr and Jellyfin or Plex servers you choose to connect, including server addresses, credentials, session cookies, and tokens.
- When you connect Plex, the browser authorization code, Plex account identifier and username, Nestrr client identifier, accessible server names and addresses, account authorization token, and server access tokens. You sign in on Plex in your browser; Nestrr does not receive your Plex password.
- Library, request, playback progress, watchlist, favorite, and profile information from those servers and from Trakt when you connect a Trakt account.
- When notifications are configured, the Nestrr notification service processes the public, non-authenticating Seerr
plexClientIdentifierlocator, your push subscription identifier, pairing and delivery status, the numeric Seerr account identifier claimed by your device, and bounded device metadata to help an administrator confirm the exact matching account. Pairing status is limited to pending, approved, rejected, expired, cancelled, or revoked. The device-to-administrator code contains no account identity and does not authorize the device by itself. - After a pairing request is approved, aliases from the exact matching Seerr account are stored as tenant-specific keyed hashes (HMACs). These values are pseudonymous rather than anonymous, and are isolated so the service cannot use one server's stored alias to correlate the same person across other servers.
- On Android and iOS, when a OneSignal App ID is configured, the OneSignal SDK initializes when Nestrr launches and may create a push subscription identifier before notification permission or delivery opt-in. OneSignal, Apple, and Google process that identifier, the media title, localized request-status text, an optional validated TMDB poster URL, and, only for availability navigation, the public media type and TMDB identifier, plus related device, network, app, and interaction information needed to prepare and deliver notifications. Pushes never include the requester's identity, pairing codes, credentials, internal identifiers, or administrator actions.
- Cast interaction, device, and app information processed by the Google Cast SDK.
- Crash reports and selected technical failure diagnostics processed by Sentry on Android and iOS, including stack traces, a code-defined operation category, HTTP status when available, and device, app, and operating-system information. These diagnostics exclude server addresses, request and response content, credentials, account details, and media or notification identifiers.
Nestrr does not sell personal information and does not use personal information for advertising or cross-app tracking.
Local network and notification permission
Local network access is used to connect to your Seerr, Jellyfin, or Plex server and to discover and control compatible casting devices. Creating a pairing request or bootstrapping an administrator device is not notification consent and does not display the operating-system permission prompt. OneSignal initialization and creation of the push subscription identifier may happen before consent so the device can be associated securely, but notification permission and delivery opt-in are requested separately only after you choose to authorize notifications on that device. Until then, Nestrr receives no push notifications.
Where information is sent
Nestrr sends requests directly to the servers and services needed for the features you use:
- Your Seerr/Jellyseerr and Jellyfin or Plex servers.
- Plex account services when you authorize Nestrr and retrieve your account and accessible servers. For Plex sign-in to Seerr, Nestrr sends the Plex account authorization token to the Seerr server you entered. That server can retain it under its own account and retention policies.
- Your selected Plex server for library access, streaming, downloads, and playback progress. Server access tokens also accompany media URLs handed to an external player or casting receiver you choose. Plex account and server tokens are not sent to the Nestrr notification or image proxies.
- OneSignal at mobile app launch when its App ID is configured, including before notification permission or delivery opt-in as described above.
- Trakt, when you choose to connect a Trakt account.
- TMDB image endpoints and the Nestrr Cloudflare image proxy used to display artwork selected by media identifiers and the app language.
- The Nestrr Cloudflare notification service when an administrator configures the integration, when a device requests or completes pairing, and when Seerr sends a notification webhook. The service uses a Cloudflare Worker, D1, Queues, and a dead-letter queue for exhausted delivery attempts. OneSignal then delivers the privacy-limited push through Apple or Google.
- Google Cast services and compatible Cast devices when casting is used.
- Sentry, when the Android or iOS app encounters a crash, an unhandled error, or a selected handled technical failure.
The notification Worker does not fetch a Seerr address supplied by a client and does not receive the user's Seerr session token for pairing. The app reads the public plexClientIdentifier locator and current profile directly from Seerr. The locator is discoverable and grants no authority. The account number and device metadata sent by the app are claimed information that a modified client could falsify; they are not independently attested by Seerr.
Notification setup depends on your Seerr server exposing its public locator and webhook settings, and on Cloudflare D1 and Queues, OneSignal, Apple Push Notification service or Firebase Cloud Messaging, and your network being available. Durable outbox processing, bounded retries, the dead-letter queue, and authenticated operator redrive reduce loss and duplication, but they cannot prove that a device displayed a notification.
Public server addresses must use HTTPS. If you explicitly connect to a local or private server over HTTP, traffic between your device and that server is not encrypted. Your server administrator is responsible for the operation, security, and privacy practices of the Seerr/Jellyseerr, Jellyfin, and Plex servers you access. Third-party services process information under their own terms and privacy policies.
Notification pairing and administrator approval
A user gives a short-lived code generated by their device to a server administrator. The code only locates a pending request. It does not prove the user's identity, reveal the private device credential, or grant access. The administrator signs in to Seerr, reloads the exact account identifier attached to the request, confirms that matching account without any account selector, and approves or rejects that device. This approval is the authorization decision.
The first administrator bootstrap uses trust on first use for the public locator. The app generates a cryptographically random webhook secret independently from the Seerr API key, keeps it only in the encrypted in-progress bootstrap draft, and installs the webhook after the Worker confirms the administrator membership. Once the app reads the exact configuration back from Seerr, it deletes that local draft instead of retaining the root webhook secret with the everyday device credential. The per-device administrator credential expires after 90 days and requires rebootstrap. Bootstrap never requests operating-system notification permission.
A strong, completely interaction-free association is not possible while Seerr does not provide the notification service with a signed identity assertion or another independently verifiable session proof. Initial server setup, sharing the device code, administrator approval, and the later operating-system permission prompt therefore remain explicit steps.
Retention, deletion, and your choices
Nestrr stores authentication secrets in the device credential store on native platforms and removes its local session credentials when you sign out or unlink the corresponding service. Uninstalling the app may leave credentials in the Apple Keychain; sign out or unlink the service before uninstalling to remove Nestrr's local session. Cached media metadata and preferences may remain until you clear the app's data or uninstall it. Information stored by your server administrator or a third-party service is retained according to that party's policies.
When you save media for offline playback on Android or iOS, media files and selected subtitles are stored on your device. Locally saved playback progress is sent to the linked media server when it becomes reachable. You can remove downloads from within Nestrr.
Unlinking Plex removes the local Plex session. It does not delete your Plex account or revoke authorizations and tokens retained by Plex or Seerr. Manage Plex authorizations through your Plex account and contact your Seerr administrator about credentials retained by that server.
Full pairing requests, device codes, claimed account numbers and device metadata, and administrator claim-replay data are deleted no later than 48 hours after creation. Minimal authenticated approval or rejection receipts containing no code or claimed account/device data may remain for up to 30 days so a device or administrator can safely recover a lost response. Delivery attempts stop no later than 7 days after collection. Successfully completed delivery payloads are then retained for up to 7 days; failed payloads are retained for diagnostics for up to 14 days after failure (therefore no more than 21 days after collection), and pseudonymous delivery audit metadata for up to 30 days. Authenticated operator-redrive receipts may remain for up to 90 days to prevent duplicate incident actions. Minimal pseudonymous OneSignal unsubscribe receipts may remain for up to 30 days. An unsubscribe event only starts a 30-day quarantine: the service rechecks the current provider status so a voluntary notification opt-out never unlinks the device, and an authenticated app refresh cancels cleanup. Approved membership aliases, credential hashes, and the push subscription identifier remain while the device is linked; administrator credentials expire after 90 days, and revoked server-side credentials and cleanup records are retained for up to 30 days. When sign-out or unlink happens offline, an encrypted local cleanup instruction containing the membership identifier and its device credential remains on that device until the service confirms deletion, or until you clear the app's data or uninstall it; discarding it earlier could leave the remote membership active. Recovery backups may retain a deleted copy for up to 30 additional days.
You may disable notifications, unlink the current notification device, unlink Trakt, unlink Jellyfin or Plex, and sign out from within the app. Disabling notifications stops local delivery; unlinking or administrator revocation stops server-side targeting and schedules deletion of the membership, push subscription identifier, and tenant-specific aliases under the periods above. Nestrr does not create or manage your Seerr/Jellyseerr, Jellyfin, or Plex account. Contact your server administrator about deletion of server-side accounts and data, and manage your Plex account directly with Plex. To request deletion of notification identifiers controlled for Nestrr, email nestrr95@gmail.com.
Children
Nestrr is not directed to children. Server administrators control which users can access their servers and which media is available to those users.
Changes
This policy may be updated when Nestrr's features or service providers change. The effective date above identifies the current version.
Contact
Privacy and deletion requests: nestrr95@gmail.com