Legal

Privacy Policy

Bandit is a media player for the servers and shares you already own. It has no account, no analytics, and no servers of ours in the middle. This page describes exactly what the app does with your data — which is almost nothing.

Effective: 25 July 2026  ·  Applies to: Bandit for iPhone & iPad, version 1.0

The short version

There is no Bandit account and nothing to sign up for. The app contains no analytics, advertising, or tracking of any kind. Your source logins are kept in the iOS Keychain, marked so they never leave the device. Everything the app caches — your libraries, artwork, watch progress — stays on your device. Every network connection goes straight from your device to the servers you configure; none of your data passes through, or is stored on, any server operated by us. We have nothing of yours to sell, share, or lose.

Who makes Bandit

Bandit is an independently developed app (bundle identifier dreadmclaren.Bandit). In this policy, “we” and “us” mean its developer. The best way to reach us about privacy is [email protected].

What Bandit does not do

To be exact, the app contains no code that does any of the following:

The only third-party code bundled in Bandit is the open-source VLCKit media framework, used on your device for playback. It is not an analytics or advertising component.

Your server credentials

To reach a source — Plex, Jellyfin, Emby, an IPTV portal (M3U or Xtream), a WebDAV or SMB share, or a Stremio-style add-on — Bandit needs its address and sign-in details. You provide those, and they are used only to talk to that service. Depending on the source that means an access token, a username and password, an API key, or a playlist URL.

Each service you connect to has its own privacy practices, governed by that provider’s policy — not this one.

What Bandit stores on your device

So it can be fast and work offline, Bandit keeps the following only on your device:

None of this is transmitted to us. It is created on your device and stays there until you clear it or delete the app.

How Bandit connects

Bandit talks directly from your device to the servers you set up. There is no Bandit server in the path, so your traffic, credentials and library contents never reach us.

Artwork & ratings

Artwork, descriptions and ratings shown in Bandit come from the servers you connect — Plex, Jellyfin and Emby supply their own. A rating may be labelled by its origin (for example “TMDB 7.2”) because your server tagged it that way; Bandit itself does not contact TMDB or any external metadata service. Add-on catalogues you choose to install are third-party services — when you use one, your request goes to that provider under its own terms, not ours.

Purchases

Bandit Pro is sold through the Apple App Store using Apple’s in-app purchase system (StoreKit). Payment is handled entirely by Apple — we never see or receive your card or billing details — and the app learns only whether a valid purchase or subscription exists, which is what unlocks Pro. Apple’s handling of purchase data is covered by Apple’s Privacy Policy. Bandit uses no third-party payment or subscription-analytics service (such as RevenueCat); entitlements are checked on your device with StoreKit.

Deleting your data

You are always in control. Remove an individual source to delete its stored credentials, clear Bandit’s cached catalogue and downloads from the app’s settings, or delete the app to remove everything it created on your device. Because nothing is stored on our side and nothing syncs to a cloud account, deleting locally deletes it everywhere.

Children

Bandit is not directed at children and we do not knowingly collect personal information from anyone. Because the app collects no personal data at all, it builds no profile of any user, of any age. The content you reach through Bandit comes from your own sources and is your responsibility to manage.

Your rights

Some regions grant rights to access, correct, export, or delete personal data a company holds about you — for example under the GDPR (EU/UK) or CCPA/CPRA (California). Because we operate no server and hold no personal data about you, there is in practice nothing for us to retrieve or erase; all data the app creates lives on your device, under your control. If you believe we hold data about you, email us and we will respond promptly.

Changes & contact

If this policy changes, the “Effective” date above will change with it, and the current version will always be at this address. Continued use after an update means you accept the revised policy.

Questions about your privacy: [email protected].