legal / 01
Privacy Policy — Silo Apps
Silo is self-hosted software. Your account records, media library, and viewing history live on the Silo server that you choose, not in a central Silo account. Some screens load artwork, avatars, or trailer information from external providers as described below. The apps contain no advertising or tracking SDKs. Optional Silo-managed diagnostics and push delivery use only the limited technical data described below.
1. Scope
This policy covers the first-party Silo client applications: Silo for Android, Silo for Android TV, Silo for iOS, Silo for tvOS, and Silo for macOS (together, "the apps"), published by the Silo project. It also describes the optional Silo-managed diagnostics collector and push relay. Section 4 also describes equivalent external-resource requests made by the first-party web client bundled with a self-hosted Silo server. This policy does not otherwise govern a self-hosted Silo server or a third-party client. The operator of each self-hosted server controls that server and its data.
2. Self-hosted accounts and media activity
The apps connect to the Silo server whose address you configure. Account registration, sign-in credentials, profiles, media-library data, playback progress, search queries, requests, and streaming traffic go to that server. The Silo project does not receive or control this information. Who can access it and how long it is retained are determined by the operator of the self-hosted server.
We recommend serving Silo over HTTPS. Whether the connection to a self-hosted server is encrypted depends on that server's configuration. For instructions on requesting deletion from a server operator, see Delete a Silo account.
3. Data stored on your device
To function, the apps may keep the following data locally:
- the addresses of the Silo servers you add;
- sign-in tokens issued by those servers;
- cached library metadata and artwork;
- playback positions and other user preferences;
- media you explicitly download for offline use; and
- pending diagnostic reports and redacted diagnostic breadcrumbs.
You can remove locally retained diagnostics in the app. Signing out, removing a server, clearing the app's data, or uninstalling the app removes the applicable local data. Removing local data does not by itself delete an account or data held by a self-hosted server.
4. Third-party artwork, avatars, and trailers
The apps and the first-party web client may cause external providers to be contacted, either directly or through your self-hosted server, to provide the following resources. These requests do not pass through the Silo-managed diagnostics collector or push relay.
- TMDB request discovery and artwork. When Silo's Requests
feature is enabled, request searches and discovery use the self-hosted
server's built-in TMDB integration. This integration operates independently
of metadata plugins, so the server may send search text and request or
discovery queries to TMDB even when no TMDB metadata plugin is installed
or enabled. The client sends those queries to your self-hosted server, not
directly to TMDB, and does not send TMDB your Silo credentials. Posters and
backdrops returned for request search, discovery, or detail screens may
then load directly from
image.tmdb.org. The separate image request includes the requested image path and size. - DiceBear avatars. Generated avatar previews and saved
preset avatars may load directly from
api.dicebear.comwhile an avatar picker, profile-selection screen, or other profile display is rendered. The request includes the selected style, seed, image format, size, and other image options. Most presets use generated word-pair seeds. The current Apple and Android TV initials-avatar flows instead use the profile name as the DiceBear seed; after that choice is saved, another Silo client may request the same name-based seed when it displays the profile. Silo does not send DiceBear a Silo password, sign-in token, email address, or self-hosted server address as part of an avatar-image request. - YouTube trailers. The Apple apps and first-party web
client may load a trailer thumbnail directly from
i.ytimg.combefore you select the trailer. The request includes the YouTube video identifier. Selecting a trailer in an Apple app attempts to open the installed YouTube app with that identifier. In the web client, selecting a trailer loads a player fromyoutube-nocookie.com. YouTube then handles the playback interaction. Silo does not download, proxy, or restream YouTube videos.
A self-hosted server may also return an absolute artwork or avatar URL. If a Silo client displays that resource, the device contacts the URL's host directly. The self-hosted server operator controls whether it supplies such URLs and is responsible for its own provider choices and disclosures.
Each direct request necessarily reveals the connection IP address, request time, requested URL, and standard app, browser, device, and transport metadata to the provider and its delivery infrastructure. An artwork or video identifier may reveal the media title or trailer being displayed; an avatar seed identifies the generated avatar and, in the initials-avatar cases described above, may contain the profile name. Resources may be cached on the device or by the browser, which can avoid some repeat requests.
Silo does not control these providers' logs, uses, retention, or deletion practices. See the privacy information published by TMDB, DiceBear, and Google. Their practices and retention periods may differ, and their public policies do not provide a resource-request-specific retention period for every item listed above.
5. Optional diagnostics
The Silo apps can create diagnostic reports for crashes, hangs, application-not-responding events, playback, networking, focus, casting, downloads, browsing, and app lifecycle problems. Availability varies by app version and platform. Reports remain on the device for review until you choose what to do with them. A report is not sent to the Silo-managed collector unless you explicitly select Send. Hosted diagnostics are not available to child profiles and are never uploaded automatically.
Silo-managed diagnostics
A hosted diagnostic report may contain:
- the exact app version and build number;
- operating-system version, device manufacturer, model, and form factor;
- display, audio-route, video-codec, and network-type capabilities;
- crash or exit type, summary, stack excerpt, and timestamps; and
- bounded technical logs and breadcrumbs describing redacted app events and performance conditions.
The collector uses a random installation credential to authenticate uploads, enforce quotas, and associate retries. It is not linked to an account or profile on any self-hosted Silo server, but it can correlate reports sent from the same app installation. Hosted diagnostics are therefore pseudonymous, not fully anonymous.
The apps remove account and profile identifiers, usernames, email addresses, credentials, authentication tokens, self-hosted server IP addresses and hostnames, media identifiers, and playback-session identifiers from hosted reports. Client-side filtering and collector-side validation are designed to reject these values before a report is retained. Because free-form crash stacks and logs can be unpredictable, we do not describe this filtering as a mathematical guarantee of anonymity.
Silo-authorized operators may inspect retained reports solely to diagnose and fix application problems. Reports and their approved extracted artifacts are encrypted in transit, stored in private Cloudflare services, and deleted within 30 days. You may request earlier deletion by emailing [email protected] with the report reference shown by the app. Minimal audit records may retain the report reference, action, actor, and time after the report contents are erased.
The collector and Cloudflare necessarily receive the connection IP address. Silo uses it for registration and abuse rate limiting and does not place it in the diagnostic report or collector database. Cloudflare may process standard edge, security, and request metadata under its own policies.
Diagnostics sent to your own server
You may instead choose the diagnostics endpoint on your active self-hosted Silo server. Those reports go to that server, not to the Silo-managed collector. Access, security, retention, and deletion are controlled by the server operator.
6. Push notifications
Notifications for playback controls and download progress are generated locally. Remote push is optional and off unless the user and server administrator enable it. When enabled, the self-hosted server sends a content-free request to Silo's Cloudflare Worker push relay for delivery through Apple Push Notification service or Firebase Cloud Messaging.
The relay does not receive notification titles, message bodies, media names, usernames, profile names, or the self-hosted server URL. It transiently processes a device push token, platform environment and app topic, opaque device and delivery identifiers, and request timing and status. Its durable storage contains opaque deployment status, quota, credential-rotation, retry, and idempotency state, one-way request hashes, and redacted delivery results—not notification content or clear device tokens.
Cloudflare handles the source IP and standard Worker request metadata for operations and abuse control. Apple or Google may process standard push delivery metadata under their own policies. More detail is available in the notification privacy documentation.
7. Analytics, advertising, and sale of data
The apps contain no advertising or cross-app tracking SDKs. Silo does not sell personal data. Optional diagnostics are used only for application support, reliability, security, and bug diagnosis; the push relay is used only for delivery, reliability, and abuse prevention.
8. App permissions
The Android apps request permissions needed for app functionality:
- Internet and network state — to reach your server and, when you choose, Silo-managed services;
- Foreground services and wake lock — to keep playback and downloads running with the screen off;
- Notifications — to show playback controls, download progress, and enabled remote notifications; and
- TV channel/EPG access on Android TV — to publish library rows and channels to the Android TV home screen.
The apps do not request location, contacts, camera, or microphone access for diagnostics.
9. External providers and app stores
Cloudflare hosts the optional diagnostics collector and push relay as a service provider to Silo. The apps are distributed through Google Play and the Apple App Store, which may independently collect install, crash, and diagnostics information under their own policies. Apple and Google also operate the platform push services described above. TMDB, DiceBear, and Google/YouTube receive the direct resource requests described in Section 4 under their own policies; Silo does not describe them as acting solely on Silo's instructions.
10. Children
The apps are general-audience tools for accessing a media server and are not directed at children. Hosted diagnostic capture and upload are disabled for child profiles. Silo does not use data from any user for advertising or tracking.
11. This website
siloserver.org is a static site hosted on GitHub Pages and runs no Silo analytics. GitHub may log standard access data, such as IP addresses, as the host. The site also loads web fonts from Google Fonts, which causes a request to Google's servers.
12. Changes to this policy
We will update this page and its effective date when the apps' data practices materially change. We intend to keep private account and media data on the user's selected server and limit Silo-managed services to the technical data necessary for their stated purposes.
13. Contact
For privacy questions, open an issue on GitHub or email [email protected]. Silo cannot access or delete an account on a self-hosted server; use the account-deletion instructions to contact that server's operator.