Privacy
Nothing to collect.
Last updated: 11 August 2026
JAVP is a player, not a service. There is no JAVP account, no JAVP media library, and no JAVP server that stores what you watch. The app runs on your device and talks to the sources you configure. This page describes exactly what that means.
What JAVP collects about you
Nothing from the open-source / sideload build: no analytics, crash-reporting, attribution, or advertising SDK.
Google Play builds may show advertising and offer an optional subscription to remove ads and unlock extras. When an ads SDK is enabled, that vendor’s own privacy terms apply to ad delivery; JAVP still does not build a JAVP account or usage analytics product. In the EEA/UK and other regions that require it, the Play build gathers consent (Google’s User Messaging Platform) before initializing AdMob or using an Advertising ID. You can revisit ad privacy choices from Settings → Premium when the form is available. Sideload builds from updater.javp.app stay ad-free.
What is stored, and where
All of the following stays on your device unless you deliberately turn on sync.
| Data | Where it lives |
|---|---|
| Watch history and playback progress | Local device storage, per profile |
| Your sources, watchlist, favourites, collections and playlists | Local device storage, per profile |
| Integration tokens and keys (SIMKL, TMDB, Trakt) and proxy settings | Encrypted secure storage backed by the Android keystore |
| Sync credentials (WebDAV password, Google Drive tokens) | Encrypted secure storage backed by the Android keystore |
| IPTV source credentials (playlist URLs, Xtream username and password) | Stored alongside the source definition in app storage — and included in the sync snapshot if you enable sync, since they are needed to rebuild the source on another device |
| Posters, metadata and channel caches | Local caches, rebuilt from your sources; never synced |
Network connections the app makes
Always
- Your sources. Whatever you added — your media server, your playlist provider, the host of a link you pasted. JAVP connects to them directly, with no relay in between.
-
Update check (sideload builds only). APKs installed from
updater.javp.app periodically request
https://updater.javp.app/latest.jsonto see whether a newer APK exists. It is a plain file request; no identifier about you is attached. Standard web server logs on that host may record the request IP, as with any HTTP request. Builds from Google Play do not perform this check — updates come through the Play Store instead.
Only if you set them up
- SIMKL — scrobbles what you watch to your SIMKL account, after you sign in. Optional; local history is kept either way.
- TMDB — metadata enrichment using an API key you supply yourself.
- Trakt — metadata enrichment only; no watch tracking is sent.
- plex.tv — only if you choose Plex account sign-in rather than entering a server URL.
- Google Drive — only if you pick it as a sync target. JAVP uses the app-private data area, so it is not visible in your My Drive and JAVP cannot see the rest of your Drive.
- WebDAV or a synced folder — only if you configure profile sync. The destination is yours.
- Discord Rich Presence (desktop only). On Windows, Linux and macOS, when Discord is running on the same machine and the toggle is on (Settings → General → Integrations), JAVP can show a “watching / listening” status on your Discord profile via local IPC. That status may include the title you are playing unless you enable Hide the title. Artwork is always the static JAVP portal asset — never a poster URL from your media server (those often embed tokens). Presence is machine-local and is not included in profile sync. Mobile and TV builds do not use Discord.
Poster and artwork images are fetched from whatever URLs your sources or metadata providers return, which means those hosts see a request from your device — the same as any app that displays remote images.
Local network
On Android TV, Add with phone starts a temporary web server on your local network so a phone browser can submit a source. It is protected by a short-lived token, is only reachable on your LAN, and stops when you leave the pairing screen. Nothing is routed through the internet.
This website
javp.app sets no cookies, runs no analytics, and embeds nothing belonging to
another company. Fonts, images, styles and scripts are all served from this
domain, so reading these pages does not hand your address to a font host or a
CDN. The only outbound request any page makes is the version lookup to
updater.javp.app that fills in the version number next to the
download button, and that is skipped entirely with JavaScript turned off.
Third-party components
The app's interface uses Google Fonts for typography, which may be fetched at runtime by the underlying font package. Chromecast support, when you use it, relies on Google's Cast framework and sends the stream URL and its metadata to the receiver device you selected.
Content
JAVP hosts, indexes, bundles and recommends no media whatsoever. Every title, channel and file you see comes from a source you added. What you connect to and whether you have the rights to it is your responsibility.
Children
JAVP is not directed at children and collects no personal data from anyone. Since the content comes entirely from your own sources, parental judgement about those sources is yours to apply — profiles can help keep a shared TV tidy.
Changes
If this policy changes it will be updated here with a new date. If a future version of JAVP ever collects something, this page will say so before that version ships — not after.
Contact
Questions or corrections: join the Discord or email [email protected].