Privacy Policy
One policy across Nexosa.
This policy covers the Nexosa website, the Windows, macOS and Linux desktop app, the Android app, the downloadable server, and the account services a server operator chooses to connect. It explains what each part processes and who is responsible.
Effective and last updated: 8 September 2026.
The short version
- The website has no account, advertising, analytics, tracking, cookies or browser storage.
- The publisher controls the project reference service, but does not receive account or library data from independently operated servers.
- The operator of the server you use controls its accounts and viewing data. Their identity must be shown before sign-up.
- Local media stays on your device. It is read only after you enable the feature and grant the device permission.
- You can export your server data, clear viewing history, sign out, and delete your account inside the apps.
1. Scope and responsibility
"Nexosa" in this policy means the website, desktop app, Android app and server software together. The website and software publisher is Victor Guminski. The publisher also operates the HTTPS reference service selected by a fresh Android install and is the controller for accounts created on that service. The publisher's address and electronic contact are on About this site.
Every other Nexosa server is operated independently. The person or organization running that server is the controller for accounts, access lists, viewing data and server logs connected with that server. Their name, postal address and electronic contact must appear in the privacy notice shown by the app before account creation. Do not create an account if those details are missing.
A server used only for a purely personal or household activity may fall outside GDPR under Article 2(2)(c). An operator serving anyone beyond that setting must meet the controller duties described here and any other duties that apply to their operation.
2. What is processed
Website delivery
The website host may receive the IP address, request time, requested page, browser information and security events needed to deliver and protect the site. Nexosa does not add an identifier or build a visitor profile.
Downloads
When you press a download button, the download host receives the connection data needed to deliver the file. The website sends no account or profile data with that request and uses a no-referrer policy.
Desktop, Android and iOS devices
The apps store the settings you choose, sign-in tokens and the profiles used on that device. Separately distributed desktop and Android builds may temporarily store an update package only when you request an update. The Google Play build does not download executable updates because Google Play owns its installation and updates. Windows protects the session for the operating-system user. Linux restricts it to that user. Android uses secure, Keystore-backed storage and disables app backups. iOS keeps the settings and the sign-in in the Keychain, on that device only, excluded from iCloud and from backups. The iOS build downloads no update package at all: it is installed and updated by AltStore or SideStore, which sign it with your own Apple ID on the phone, and it only tells you when a newer version exists.
If you enable local media, the Android and desktop apps read the device media index after the operating system permission prompt. On iOS the app reads only its own folder in the Files app, which needs no permission, and cannot read the Music app's library. File names, library contents and local playback stay on the device and are not sent to a Nexosa server.
Accounts and server use
A server may process your display name, email address, Supabase account identifier, playback positions, watched marks and favorites. Invite-only servers also compare your email with an operator-managed allow list. Passwords travel directly to Supabase over an encrypted connection. The Nexosa server does not receive the password and Supabase stores a password hash.
Nexosa Premium
If you buy Nexosa Premium, the payment happens on Buy Me a Coffee under its own privacy policy. The publisher learns from it that a membership exists, which is what grants the Discord role, and never sees your card details. When you link a device, the Nexosa website asks Discord, with your consent on Discord's own sign-in page, for your Discord user id and your roles in the Nexosa server. It keeps neither: the sign-in is revoked as soon as the roles have been read, and the short code that ties the browser to the device is deleted within ten minutes.
The device receives a signed entitlement that carries your Discord user id, the plan and two dates, and stores it beside its other settings. A household server you hand it to stores it the same way. When an app renews, it sends the entitlement back to the website, which asks Discord through the project's bot whether the account still holds the role, and answers with a new entitlement or a refusal. Nothing about what you play is involved in any of this.
Remote access without router setup goes through a relay run by the publisher. Your household's server dials the relay and presents its entitlement, so the relay learns the Discord user id inside it and the name the server chose, and keeps both only while the connection is open, plus a week for the name so that nobody else can take it in the meantime. A connection from your device to the relay carries only the name it is for in the clear; everything else is encrypted between the device and your own server with a key the relay does not have, so the relay cannot read what you watch, who you are, or what you sign in with. It sees the addresses connections come from, as any machine on the internet does, and keeps no record of them beyond ordinary connection logs.
Internet radio
Both apps can play internet radio, and none of it passes through a Nexosa server. Asking for stations sends a request from your device to an open directory called Radio Browser, carrying the address your device connects from, what you searched for, and the app name and version its guidelines ask a client to send. Playing a station connects your device straight to that broadcaster, so the broadcaster sees a listener at your address, exactly as if you had opened the stream in a browser. The desktop app opens a second short connection to the same station to read the line saying what is playing, then closes it.
Neither app records, saves, converts or re-transmits a station. The stations you keep are stored in that app's own settings on the device and never on a server. Neither the publisher nor a server operator is the controller for what the directory or a broadcaster does with a request your device made to them.
Requests and reports
If you contact the publisher or a server operator, they process the contact details and message needed to answer a privacy request, security report or illegal-content report. A Digital Services Act notice may also include the reported item's exact location, an explanation of alleged illegality and a good-faith statement. Do not include unrelated personal or sensitive information.
Nexosa has no advertising identifiers, telemetry, crash reporting, profiling or automated decisions with legal or similarly significant effects.
3. Purposes and legal bases
- Service and account features, GDPR Article 6(1)(b): authentication, password recovery, playback progress, favorites, data export, updates and the functions you request.
- Nexosa Premium, Article 6(1)(b): checking that a device or a household server belongs to a paying member, and renewing that check while the membership lasts.
- Device-media consent, Article 6(1)(a): local media access is off by default and can be withdrawn in Nexosa settings and the operating-system settings.
- Security, Article 6(1)(f): website security logs, fraud and abuse prevention, an invite-only email allow list, and protection of accounts and media. The relevant controller must balance this interest against your rights.
- Legal duties, Article 6(1)(c): responding where law requires it, including data-protection requests, security incidents and valid illegal-content notices or authority orders.
A name and email are required only when you choose to create a server account. Local media can be used without giving the Nexosa project an account.
4. Recipients and external connections
- Cloudflare: hosts the static website and may process ordinary connection and security data for the website controller.
- Public download host: receives ordinary connection data when you choose a website download. Separately distributed clients ask the connected Nexosa server for update metadata and files; private project repository addresses and credentials are not sent to the app. The Google Play build does not perform self-updates.
- Google Play: provides the Android store package, updates, integrity and related store services under your Google account. Nexosa does not receive your Google account details from Play.
- Buy Me a Coffee: takes Nexosa Premium payments under its own terms and privacy policy, and tells Discord to grant or remove the membership role.
- Discord: receives your sign-in when you link a device and answers, to the Nexosa website, with your user id and your roles in the Nexosa server; later renewals ask the same question through the project's bot.
- The Nexosa relay: a machine run by the publisher that carries connections between the apps and a Nexosa Premium household's own server when they are away from home. It sees the household's chosen name, the Discord user id in the entitlement the server presents, and the addresses connections come from; the content of every connection is encrypted end to end with a key only the household's server holds.
- Supabase: provides authentication and, when selected by the server operator, the profile database. It acts under the server operator's instructions for that processing.
- Radio Browser and radio broadcasters: receive a request directly from your device when you use the radio part of either app, and only then. The directory is not run by the publisher, and a broadcaster is not run by anybody connected with Nexosa.
- The server host: carries server traffic when the operator uses a cloud host. A server running only on a home machine has no cloud server host.
Nexosa does not sell personal data and does not share it for advertising. External providers may process data outside the EEA. The responsible controller must use an EEA region where available and put an Article 28 processing agreement and a valid Chapter V transfer mechanism in place where required.
5. Retention
- Website and download connection records follow the security and retention settings of the relevant host.
- Device settings remain until you change them or remove the app data.
- Device sessions remain until sign-out, profile removal, account deletion or token expiry.
- A Nexosa Premium link code lives for ten minutes at most. The entitlement stays on the device, and on a server it was handed to, until you unlink it, remove the app data, or it lapses and is not renewed.
- The relay keeps a household's name and the Discord user id that brought it while the server is connected and for one week after, in memory only, and nothing about the connections it carried beyond ordinary connection logs.
- Playback progress and favorites remain until you clear them or delete the account.
- Account name and email remain until account deletion, subject to any legal retention duty.
- After account deletion, a random account identifier with no name or email may remain for up to seven days to reject old tokens, then it is removed.
- The Android data-export file in the Nexosa cache is removed after the save or share sheet closes. A copy you save is under your control.
- Requests and reports are kept only as long as needed to answer, document and defend the decision, then deleted or anonymized.
6. Cookies and device storage
The website sets no cookies and uses no local storage, session storage or IndexedDB. It therefore needs no tracking-consent banner. App files are limited to storage that is necessary for a feature you explicitly request, such as staying signed in, remembering settings, keeping the radio stations you chose to keep or, outside the Google Play build, installing an update you requested. This reflects the strictly necessary exception in section 3-15 of the Norwegian Electronic Communications Act. Nothing an app stores is read by the publisher, and none of it is used to recognise a device anywhere else.
7. Your rights
Where GDPR applies, you may request access, correction, deletion, restriction, portability and, where relevant, object to processing or withdraw consent. You also have the right to complain to a supervisory authority.
- Access and portability: use "export my data" in the desktop tasks screen or Android Profile tab to receive the server data as JSON.
- Correction: ask the server operator to correct your name or email in Supabase.
- Erasure: clear watch history, remove favorites or delete the account inside either app. Public instructions and an outside-the-app request path are on the account deletion page. Ask the operator to remove your email from an invite-only allow list.
- Restriction, Article 18: "remember where I got to", in each app's settings and on by default, is what sends a playback position and a watched mark to your server so a film can be resumed on another screen. Switch it off and that device stops sending either from its next report onwards, including mid-playback; nothing already stored is touched, and the entries above clear or export it. It is per device, because it is the device that reports. Beyond that, contact the controller identified for the server or processing concerned.
- Objection: contact the controller identified for the server or processing concerned. Separately distributed builds provide a version-check switch. The Google Play build does not perform the external version check.
- Withdraw local-media consent: switch local media off and revoke the operating-system permission at any time.
- Report something in a library (Digital Services Act, Article 16): both apps carry a notice form on a server item, and one on the Android Profile tab and the desktop tasks screen for a concern about a server rather than one of its files. It asks what the item is, why you believe it is unlawful, and for your confirmation that what you have said is accurate, and will not send without all three; your account already identifies you to that server. An item notice is stored by that server for its operator. A concern about the server itself, where there is no item to point at, is handed to your device's own mail program addressed to the contact the server publishes. Nothing about either reaches the Nexosa project.
- Find out what was decided, and disagree with it (Articles 17 and 20): the decision on a notice appears in the app you reported from, under "what you reported", written out as what was done, on what ground, the operator's reason, whether anything was automated, and what you can do next. Nothing is automated: a Nexosa server has no automated detection, so a person reads every report. You can say the decision is wrong, once, free, for six months from it, and it goes back to the same operator to look at again. Article 19 exempts a qualifying micro or small online platform from most of Section 3. The location of a server in a home does not decide whether the operator is an enterprise or whether the service is an online platform, so each operator must assess the service it actually provides. Going to a court where you live is unaffected either way.
The controller normally answers a verified request within one month. In Norway you may complain to Datatilsynet, P.O. Box 458 Sentrum, NO-0105 Oslo.
8. Children
Nexosa is not directed to children under 13 and is not enrolled in Google Play's Designed for Families program. In Norway, a child aged 13 or older may give their own consent where an information-society service relies on consent. A parent or guardian must approve and supervise any use by a younger child on a private household server. Operators must not expose children to unlawful or age-inappropriate media.
9. Security and incidents
Nexosa uses authenticated profiles, validated access tokens, per-profile authorization, short-lived single-item stream tickets, secure mobile token storage and data minimization. The Google Play build accepts only HTTPS server addresses and disables cleartext traffic. Separately distributed builds can use plain HTTP on a trusted home network, but that traffic is not encrypted between the device and server.
No system is completely secure. Where GDPR applies, the responsible controller must assess a personal-data breach, notify the supervisory authority within 72 hours when required by Article 33, and inform affected people when Article 34 requires it.
10. Changes and contact
Material changes receive a new effective date and should be presented before they take effect for an account. The version shown by an independently operated server may add its controller details, providers, retention periods and local choices. It may not remove rights given by mandatory law.
Contact the server operator for account, library and server requests. Contact the Nexosa project maintainer for the website or published app itself. Include enough information to identify the relevant server or request, but never send your password or access token.
This policy is intended to provide the information required by GDPR Articles 12 to 14 and to describe the product's privacy controls. Compliance also depends on each server operator completing the controller details, processor agreements, regional settings, access controls, retention choices and security duties that cannot be completed by the software publisher.