Privacy Policy

Effective September 8, 2026

Sorarr is an iOS companion for self-hosted media services. This policy describes the information handled when you use the app.

Summary

Sorarr has no advertising, third-party analytics, or cross-app tracking. We do not sell personal information. Most app data stays on your device or travels directly between your device and services you choose to connect.

Services you connect

Sorarr communicates with Plex, Plex servers, Sonarr, Radarr, and—when configured—The Movie Database (TMDB) to perform actions you request and display media information. These providers may receive account identifiers, requests, device/network information, or other data under their own privacy policies. Server addresses, API keys, Plex tokens, custom headers, and similar credentials are stored in the iOS Keychain. Non-secret preferences and cached media metadata are stored locally.

Optional iCloud backup

If you enable settings backup, Sorarr stores an encrypted settings backup in your private Apple CloudKit database. The backup may include server configuration and credentials. It is encrypted on your device with AES-256-GCM before upload; its encryption key is kept in Keychain/iCloud Keychain. Apple processes CloudKit data under Apple's terms. Sorarr's developer cannot access your private CloudKit database or decrypt the backup.

Optional push notifications

If you enable hosted push notifications, Sorarr sends an Apple Push Notification service (APNs) device token, a random installation identifier, notification environment, and registration timestamps to the Sorarr relay. Your Sonarr or Radarr server sends selected webhook event content to a secret relay URL so the relay can format and deliver the requested notification through APNs. The relay stores device registration and random enrollment credentials while you remain enrolled; disabling/deregistering notifications removes the device registration. The relay does not receive your Plex, Sonarr, or Radarr API keys.

Diagnostics

Crash reports generated by the app remain on your device unless you choose to share them. Sorarr does not include a remote crash-reporting or analytics SDK.

Data retention and control

Local data can be removed by deleting the app. You may remove the optional CloudKit backup from Sorarr's settings and deregister hosted push notifications at any time. Data retained by connected third-party services is controlled by those services.

Security

Sorarr uses platform security features including iOS Keychain, HTTPS for developer-operated relay traffic, and encrypted CloudKit backup. No system can guarantee absolute security; protect access to your device and self-hosted services.

Children

Sorarr is not directed to children under 13, and we do not knowingly collect personal information from children.

Changes

Material changes will be published on this page with a revised effective date.

Contact

Questions or privacy requests: [email protected]

Sorarr is an independent app and is not affiliated with or endorsed by Plex, Sonarr, Radarr, TMDB, or Apple.