Davvy Privacy Policy
Effective date: 2026-08-21
Davvy is published by Polyphasic Developers Ltd ("we," "us," or "our"), a company registered in the United Kingdom. This Privacy Policy explains how Davvy handles information when you use the Davvy app for iPhone, iPad, Mac and Apple TV.
For the product overview and supported servers, visit the Davvy landing page.
The short version. Davvy is a client for a media server that you control. It has no account system, no backend of ours, no analytics and no tracking, and the first release carries no advertising. Your server details and your watch progress sync through your private iCloud, not through us. The only request Davvy makes to anywhere other than your own server is a title-and-year lookup for poster art, described below.
Summary
- We operate no server that Davvy connects to. Davvy talks to the WebDAV server whose address you enter, and to The Movie Database for artwork. Nothing of ours sits in between.
- There is no Davvy account and no sign-up. We never see your server address, your credentials or what you watch.
- Davvy contains no analytics SDK, no crash-reporting SDK and no advertising SDK. It does not present Apple's App Tracking Transparency prompt, does not access the advertising identifier (IDFA), and does not track you across apps or websites.
- Your server profiles — including the WebDAV username and password — and your continue-watching progress are stored by the app and mirrored to your own private iCloud (CloudKit) database, so an Apple TV can use a server you set up on your phone. This is your iCloud account, not ours; we have no access to it.
- The scanned index of your library (file names, paths and sizes) stays on each device and is never uploaded anywhere.
- To show posters and descriptions, Davvy sends the cleaned-up title and year of items in your library to The Movie Database. No account, device or personal identifier is sent with those lookups.
- Davvy is free at launch, with no subscription and no in-app purchase.
What Davvy Collects
We collect nothing. Davvy has no analytics, no telemetry and no reporting of any kind back to us, and there is no service of ours for it to report to. We receive no information about you, your device, your server or your viewing.
Everything described below either stays on your device, goes to the media server you chose, goes to your own iCloud account, or is an anonymous artwork lookup.
Your Media Server
Davvy is a client, not a streaming service. To use it you supply the address of a WebDAV server that you own or have an account on — a Synology or QNAP NAS, TrueNAS, Nextcloud, rclone serve webdav, Apache, nginx, Caddy or anything else that speaks WebDAV. From then on, Davvy communicates directly with that server to list folders, scan your library and stream files.
That traffic goes from your device to your server. It does not pass through us and we have no visibility of it. What your server records about your activity — access logs, byte ranges served, timestamps — is determined by that server and by whoever operates it. If that is not you, their policies apply to it.
How Davvy Signs In To Your Server
Davvy authenticates to your server with HTTP Basic authentication, using the username and password you entered for that server. Those credentials are sent only to the server addresses you configured, and to nothing else.
There is one exception worth knowing about. When you AirPlay or cast, the receiving device fetches the file itself and cannot see the authorisation header Davvy would normally add, so for those routes Davvy embeds your username and password in the stream URL it hands to the player. That URL stays between your device and your own network or server, but it does mean the credential travels as part of a URL rather than a header on those routes.
Plain HTTP and Local Network Access
Home servers on a LAN, and Tailscale addresses, very often have no TLS certificate, so Davvy permits plain http:// connections. That is a deliberate choice — without it, the most common home setup would simply not work — but on a plain HTTP connection your WebDAV credentials and your media travel unencrypted across whatever network they cross. Use https:// for any address reachable from the internet, and treat untrusted Wi-Fi as untrusted.
If your server is on the same network as your device, iOS and tvOS will ask for permission to find and connect to devices on your local network. Davvy requests this to reach the server address you entered, and on iPhone and iPad to discover Cast devices. Declining it does not affect servers reached over the internet.
What Is Stored, And Where
Davvy keeps three kinds of data, and they are treated differently.
Server Profiles — Stored On Device, Synced Through Your iCloud
A server profile holds the name you gave the server, the media root path, up to three addresses (home, Tailscale and public), your folder include and exclude rules, and your WebDAV username and password. On iPhone, iPad and Apple TV this record is mirrored to the private database of your own iCloud account, so that a server you configure on your phone appears on your Apple TV without you re-typing anything. Apple's iCloud terms apply to that data; Polyphasic Developers has no access to it and no way to read it.
We want to be explicit about this because it is the part people most often assume works differently: the password is part of that synced record, not held separately in the iOS Keychain. Apple TV cannot reliably read iCloud Keychain items, which left the TV unable to connect, so the credential travels with the profile in your private CloudKit database instead. Earlier versions of Davvy stored credentials in the Keychain, and any credential found there is migrated onto the profile once and then used from there.
In the current macOS build this data is kept locally on the Mac and does not sync.
Watch Progress — Stored On Device, Synced Through Your iCloud
For each item you play, Davvy records the file path on your server, which server profile it belongs to, your position and the item's duration, when you last watched it, and whether you finished it. This is what powers continue watching, and on Apple TV the Top Shelf row on the Home Screen. It syncs the same way as your server profiles, through your own private iCloud database, and it is never sent to us.
Your Library Index — Device Only
When Davvy scans your server it builds an index of what it found: file names, paths and sizes. That index stays on the device that built it and is deliberately excluded from iCloud sync — it can be thousands of rows, it churns on every rescan, and it can always be rebuilt by scanning again. It is never uploaded anywhere.
Settings
Your TMDb API key, if you choose to enter one, is stored in the app's preferences and mirrored through iCloud key-value storage so your other devices can use it. Playback preferences, such as the per-route audio sync offset, are stored on the device.
Deleting the app removes the local copies from that device. Data held in your private iCloud database is removed by deleting the servers within the app, or through Apple's own iCloud storage controls.
Artwork and The Movie Database
To turn a folder of files into a browsable library, Davvy looks up poster art, descriptions, ratings, runtimes, genres and episode details from The Movie Database (TMDb), a service operated independently of us.
Davvy cleans up the file or folder name to work out a title and a year, and sends only that title and year to api.themoviedb.org. Once an item is matched, follow-up requests for episode lists or runtimes use TMDb's own numeric identifier for that title. Artwork images are then loaded from image.tmdb.org.
These requests contain no account, device or advertising identifier, nothing about your server, and nothing that identifies you. As with any internet request, TMDb will see the IP address the request came from, and its own operators determine what they log and retain. TMDb's privacy policy is at themoviedb.org/privacy-policy.
Davvy ships with an application-level TMDb key so that artwork works without you signing up for anything, which means these lookups happen by default as your library is browsed. You may enter your own free TMDb API key in Settings, in which case that key is used instead. Davvy still browses and plays your library using filenames if TMDb is unreachable.
This product uses the TMDB API but is not endorsed or certified by TMDB.
AirPlay, Chromecast and Casting
Davvy can send playback to an Apple TV over AirPlay, and on iPhone and iPad to a Chromecast.
Some files are in containers a receiver cannot play directly. In that case Davvy prepares the stream on your own device: it remuxes the file locally, writes short-lived segments into the app's temporary directory, and runs a small HTTP server on the device's Wi-Fi address so the receiver can pull those segments over your local network. Nothing is uploaded to us or to any third party in this process — the media goes from your server, through your phone, to your TV.
Two practical notes. That local server is unauthenticated for the duration of the casting session, so another device on the same network could in principle fetch the segments while you are casting; use it on networks you trust. And the temporary segment files are deleted when the casting session ends.
On iPhone and iPad, Chromecast support uses Google's Cast SDK, which discovers Cast devices on your local network and over Bluetooth. That is why Davvy asks for local network and Bluetooth permission on those devices. Google's handling of anything the Cast SDK collects is governed by Google's privacy policy. The Mac and Apple TV builds do not include the Cast SDK.
Advertising, Analytics and Tracking
Davvy contains no analytics SDK, no crash-reporting SDK and no telemetry. Nothing measures which screens you open, what you play or how long you use the app.
The first release of Davvy contains no advertising: there is no ad SDK linked into the app, no ads are displayed anywhere in it, and no advertising data is collected from your device. Davvy does not present Apple's App Tracking Transparency prompt, does not request the Identifier for Advertisers (IDFA), and does not track you across other apps or websites.
Davvy is free at launch, with no subscription and no in-app purchase. If a future version introduces advertising or a paid tier, this policy and the App Store privacy details will be updated before that version ships, and any advertising would be limited to iPhone and iPad — the Mac and Apple TV builds cannot show ads.
The app does include third-party media components — a VLC playback engine for containers Apple cannot decode, and on iPhone and iPad Google's Cast SDK — but no third-party component that measures or reports your use of the app.
Apple
Davvy is distributed through the App Store. Your download, and any App Store account activity around it, is handled by Apple under Apple's own privacy policy, and we receive only Apple's aggregate, non-identifying sales and download reporting.
Davvy uses Apple's iCloud (CloudKit private database and iCloud key-value storage) to sync your own data between your own devices, as described above, and receives silent push notifications from Apple solely to know when that sync has new data. Your iCloud data is governed by your agreement with Apple.
If you have turned on Apple's own diagnostics and usage sharing, your device may send Apple crash and usage data for apps including Davvy. That is a setting between you and Apple, found under Settings › Privacy & Security › Analytics & Improvements. We do not receive individual crash reports or diagnostic data from it, and Davvy contains no crash-reporting service of its own.
Playback information Davvy publishes to the system — the title and artwork shown on the Lock Screen, in Control Center and on the Apple TV Home Screen's Top Shelf row — is handled on your device so that those standard controls work. On Apple TV the Top Shelf list is shared with Davvy's own Top Shelf extension through a private app group on that device.
Content and Responsibility
Davvy does not provide, host, sell or index films, television or any other media, and it includes no catalogue of its own. It plays only what is on the server you connect it to. You are responsible for the content available through your server and for having the right to access it.
Legal Bases for Processing (UK and EU users)
Where UK GDPR or EU GDPR applies: we do not collect or process personal data through Davvy, so in the ordinary course there is no processing by us for which a legal basis is required.
Where you operate your own media server, you determine what that server records about your use of it. Data synced through iCloud is processed by Apple under your agreement with Apple. Where an artwork lookup is made to The Movie Database, the operators of that service determine how they handle the request they receive.
Data Retention
We hold no data from Davvy, so there is nothing for us to retain or delete.
Data stored by Davvy on your device is kept until you delete the server, delete the app, or clear it through iCloud. Data in your private iCloud database is retained by Apple under your iCloud settings. Retention on your own media server is governed by that server's configuration.
Your Rights and Choices
You can:
- Delete a server in the app, which removes its profile and stored credentials from your devices and from your iCloud database
- Restrict scanning to specific folders, or exclude folders entirely, so that paths you would rather keep private are never listed or indexed
- Enter your own TMDb API key in Settings so artwork lookups use your key rather than the app's
- Sign out of iCloud, or turn iCloud off for Davvy, in which case the app keeps its data locally on that device
- Decline local network or Bluetooth access in Settings if you do not need LAN servers or Cast devices
- Delete the app to remove all locally stored data, and review app permissions at any time under Settings › Davvy
Depending on where you live, you may also have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to lodge a complaint with a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). Because we hold no personal data from Davvy, there is generally nothing for us to disclose or erase, but you are welcome to contact us and we will confirm that and help where we can.
If you are a California resident: we do not collect, sell or share your personal information as those terms are defined under the CCPA/CPRA.
Children
Davvy is not directed to children under 13 and we do not knowingly collect personal information from children. The app collects no personal information from any user. The media available through it is determined entirely by the server you connect to, and is the responsibility of whoever operates that server.
Security
Your server credentials are held in the app's own storage and, on iPhone, iPad and Apple TV, in the private database of your iCloud account, which is protected by your Apple Account and encrypted by Apple in transit and at rest. They are sent only to the server addresses you configured.
Connections to your server use whatever transport your server provides. Davvy permits plain http:// because home and Tailscale addresses commonly have no certificate; where a server is reachable from the internet we strongly recommend serving it over HTTPS, since plain HTTP exposes both your credentials and your media to any network they cross. Requests to The Movie Database are made over an encrypted connection.
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
International Transfers
We transfer no personal data, because we collect none. Traffic between Davvy and your own server goes wherever you host that server. Apple and The Movie Database operate their own infrastructure and their own policies govern any transfers they make.
Changes to This Policy
We may update this Privacy Policy from time to time, particularly if a future version of Davvy changes how the app handles data. If we make material changes we will update the effective date above and, where appropriate, provide additional notice in the app or on this page.
This policy describes Davvy as submitted for its first App Store release.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact [email protected], or see our support page.
Polyphasic Developers Ltd, Lincoln, United Kingdom.