1. Scope and operator
This policy applies to the HAMFIN Android TV application, package com.hfxhq.hamfin, operated by HFXHQ. HAMFIN is a client application; it does not provide a media library or streaming subscription. The person or organization operating a connected Jellyfin, Radarr, Sonarr, or other server may have its own privacy practices.
2. Information HAMFIN handles
- Account and connection information: server addresses, usernames, profile and account identifiers, authentication tokens, optional local PINs, and credentials supplied for optional services.
- Media and app activity: library browsing, searches, watch history, playback progress, favorites, selected media, subtitle and playback choices, requests, requested seasons, quality preferences, and request status.
- Device and app information: Android device identifier, device name, manufacturer, model, operating-system version, HAMFIN version, language, display and playback capabilities, and app preferences.
- Optional diagnostics: a user may choose to send a crash report, app logs, or a media report. These reports can include technical device details, server and media identifiers, playback configuration, codec information, recent app events, and diagnostic messages.
- Voice search: when a user invokes voice input, audio is processed by the speech-recognition service configured on the Android device. HAMFIN receives the resulting text and uses it as a search query.
3. How information is used
HAMFIN uses this information only to provide and maintain app functionality, including:
- signing in to and communicating with a selected media server;
- showing and personalizing libraries, home rows, artwork, and recommendations;
- playing media and synchronizing progress, watched state, and favorites;
- submitting and managing optional movie and television requests;
- supporting voice search, Android TV recommendations, and external players; and
- diagnosing failures when a user affirmatively sends a report.
HAMFIN does not use personal information for advertising, cross-app tracking, or sale to data brokers.
4. Where information may be sent
- Your selected Jellyfin server receives authentication, device, browsing, playback, preference, and diagnostic information needed for the features a user invokes. Optional crash reports are sent to the connected Jellyfin server after a user chooses Send.
- HAMFIN Requests at requests.hfxhq.tv receives the Jellyfin credentials entered for Requests only after explicit opt-in. It may create or link a Requests account and processes searches, request selections, quality choices, request history, and status. The service is operated for HFXHQ by using Seerr/Jellyseerr software and Cloudflare infrastructure.
- Optional user-configured services, such as Radarr, Sonarr, or a custom Seerr server, receive the information needed for the selected feature. Server addresses and API keys are stored locally.
- Artwork providers, including TMDb image infrastructure, may receive ordinary network request information when HAMFIN loads provider-hosted artwork.
- Android TV and external players: HAMFIN may provide the Android TV launcher with media titles, descriptions, artwork links, identifiers, and resume positions. If the user chooses an external player, HAMFIN sends that player the media title, playback position, and stream or subtitle links needed to play the selection.
- Device speech provider: voice audio is handled under the privacy terms of the speech-recognition provider selected on the device.
5. Storage, security, and transmission
HAMFIN stores connection details, tokens, Requests credentials, optional service API keys, settings, and caches in app-private storage on the Android device. Credential databases and preferences are excluded from Android cloud backup and device transfer. App-private storage is protected by Android's application sandbox, but credentials are not separately encrypted by HAMFIN at the application layer.
HAMFIN Requests uses HTTPS. HAMFIN also supports user-configured HTTP addresses so it can reach local media servers. Information sent over HTTP is not encrypted in transit. Users should use HTTPS for any service reached over an untrusted network and should protect server and device access.
6. Retention and user controls
- Local information remains until it is removed through available app controls, Android app storage is cleared, or HAMFIN is uninstalled. To remove all locally stored HAMFIN information, use Android Settings to clear HAMFIN's storage or uninstall the app.
- Removing a server or profile in HAMFIN removes its primary local connection record but may leave non-account layout preferences or cached information. Clearing app storage removes those remaining local items.
- Information on a user-operated Jellyfin, Radarr, Sonarr, or custom Seerr server is retained and controlled by that server's operator. Removing it from HAMFIN does not delete the corresponding remote account or server records.
- HAMFIN Requests account information and request history are retained while needed to provide the Requests service or until a verified deletion request is completed. Limited security and operational records may be retained when reasonably necessary to prevent abuse, resolve failures, or meet legal obligations.
7. Delete a HAMFIN Requests account or data
Users can request deletion of an account created or linked by the HFXHQ-operated HAMFIN Requests service, along with its associated request history and personal information.
Request account and data deletionIn the email, include the Requests/Jellyfin username and the domain of the connected Jellyfin server so the correct account can be identified. Do not send a password, access token, API key, or PIN. Additional verification may be requested to prevent unauthorized deletion. HFXHQ will complete verified deletion requests within 30 days unless limited retention is required for security, fraud prevention, or legal compliance.
This process covers the HFXHQ-operated HAMFIN Requests service. To delete a Jellyfin account or information held by any independently operated server, contact that server's administrator.
8. Children
HAMFIN is a general-audience media client for use with a server configured by an account holder and is not directed to children under 13. A library or navigation section containing children's media does not change the app's intended audience. HFXHQ does not knowingly use the HAMFIN Requests service to collect personal information directly from children. A parent or guardian may contact HFXHQ to request deletion if they believe a child supplied information.
9. Changes and contact
This policy may be updated when HAMFIN's features or privacy practices change. Material changes will be reflected by updating the date at the top of this page.
Privacy questions and deletion requests can be sent to [email protected].