← Cathode
Privacy Policy
Last updated: August 2026
Cathode is a media player for iPhone and iPad. It connects to media servers and playlists that you configure. This policy explains what data the app handles, what leaves your device, and what it does not.
The short version: Cathode has no account system and no server of ours that stores your content or credentials. Your server details stay on your device. The only data that leaves the app to us is anonymous, aggregated usage and crash diagnostics, through Google Firebase, to keep the app stable.
1. Your servers and credentials
- When you add a source (Xtream Codes, M3U/XMLTV, Jellyfin or Plex), the server address and your username, password or token are stored in the iOS Keychain on your device.
- Those credentials are never sent to us. Cathode connects directly from your device to the server you entered.
- What you browse, play and download is a conversation between your device and your server. We do not see it, log it, or receive it.
- Backups you export are encrypted with a passphrase you choose. Without that passphrase the backup cannot be read, and we cannot recover it.
2. Analytics & crash reporting (Google Firebase)
Cathode uses Google Firebase Analytics and Firebase Crashlytics to understand how the app is used at an aggregate level and to be alerted when it crashes. This may include:
- Anonymous usage events (for example, that a screen was opened) and general device information such as model, iOS version, language and region.
- Crash reports, including diagnostic logs and the state of the app at the time of a crash.
- An anonymous, app-generated installation identifier.
This data is processed by Google as part of Firebase. It is not used to identify you personally, and it does not include your server addresses, usernames, passwords or the media you watch. See Google's Firebase Privacy and Security and Google Privacy Policy.
3. Optional third-party services
These are used only if you choose to enable them by adding your own token in Settings:
- TMDB (The Movie Database) — if you add a TMDB Read Access Token, Cathode queries TMDB to fetch artwork and metadata for titles you look at. Those search terms are sent to TMDB.
- OpenSubtitles — if you add an OpenSubtitles token, Cathode queries OpenSubtitles to find and download subtitle files for what you are watching.
If you do not add these tokens, these services are never contacted.
4. Media artwork and streams
To show posters, channel logos and video, the app loads images and streams from the servers you configured and from any artwork URLs those servers or playlists provide. These requests go directly from your device to those hosts.
5. What we do not do
- We do not sell your data.
- We do not require an account or ask for personal information.
- We do not collect your server credentials or your viewing history.
- We do not serve third-party advertising.
6. Children
Cathode is not directed at children under 13 and does not knowingly collect personal information from them.
7. Data retention & your choices
Source credentials live only on your device — remove a source, or delete the app, to remove them. Analytics and crash data retention follows Google Firebase's standard retention settings. You can limit some diagnostics sharing through your device's iOS privacy settings.
8. Changes to this policy
If this policy changes, the "last updated" date above will change. Material changes will be noted on this page.
9. Contact
Questions about privacy? Email CONTACT_EMAIL.
Cathode is an independent media player. It is not affiliated with, or endorsed by, Jellyfin, Plex, TMDB, OpenSubtitles, Google, or any content provider. You are responsible for the sources you connect to it.