Effective August 12, 2026

Privacy is a boundary, not a slogan.

Rin has no advertising identity, analytics SDK, or Rin cloud account. It connects only to services you configure and keeps its durable app data on your device.

What stays on your device

Server profile names and endpoints, playback preferences, local watch history, feed caches, hidden channels and discussion authors, and bounded operational diagnostics live in Rin's app container. Materialious session material and Invidious tokens are stored in the device-only Keychain. Rin does not upload this data to a Rin-operated analytics or account service.

A profile export contains only its name and HTTPS endpoints. It never includes credentials, tokens, history, diagnostics, or personal settings.

The servers you choose

Your configured Invidious server receives discovery, video, channel, subscription, and playback requests. If enabled, Materialious receives encrypted history and progress operations, a live resolver receives the selected video identifier, and SponsorBlock receives a four-character hash prefix used to look up community segments. Those operators have their own privacy and retention practices; Rin cannot control them.

Video and artwork delivery can also contact media hosts identified by the configured service. Discussion links can open YouTube or Reddit in your browser. Rin does not sign you into a Google or Reddit account.

Diagnostics and support

Rin's local diagnostic journal records bounded timings, status codes, error classifications, and device conditions. It excludes full URLs, searches, titles, account names, credentials, video IDs, and history identifiers. Nothing leaves the device unless you explicitly prepare and share a diagnostic report.

If you email support, the mail provider receives your address, message, and attachments. Support mail is retained only as needed to answer the request, investigate a reported problem, or satisfy legal obligations. Ask for deletion at support@rinplayer.com.

Apple review environment

Rin may maintain isolated, non-public accounts and servers solely so Apple can review the app. They contain synthetic subscriptions and viewing state, not customer or developer household data. Ordinary users are not routed through that environment.

Your controls

  • Disconnect either account from Settings to remove its device credential.
  • Delete a server profile to remove its credentials, cache, and local history from Rin.
  • Clear diagnostics at any time and choose whether to export them.
  • Hide channels and discussion authors locally, or report content at its original source.

Questions or deletion requests: support@rinplayer.com.