Processing on Apple TV
The tvOS app stores server addresses, connection preferences, display caches, and app settings on the device. Central sign-in and NAS credentials are stored in tvOS Keychain. Videos and viewing records are requested directly from your authorized NAS. Signing out of the central account does not revoke the saved NAS connection or delete NAS records.
QR sign-in uses a separate device approval web screen where you sign in with Apple or Google and approve the code shown on your TV. Device requests expire after 10 minutes and a one-time exchange issues a central session to the TV. The web screen processes temporary security cookies and approval information. The QR does not contain NAS credentials or session tokens, and the browser does not relay NAS videos or viewing records.
The tvOS app has no advertising SDK, ad requests, new slab unlocks, or payments. It displays existing slab unlocks stored on the NAS. The current iOS release candidate is also ad-free; processing by earlier test builds is described separately below. On TV, start central account deletion from Profiles and connection → Roux account, or Roux account before connecting to a NAS.
01. Operator and scope
Roux is operated by kyhoon. For privacy inquiries, contact kyhoonx@gmail.com. Original files, databases, and backups on a self-hosted Roux Server are managed by its NAS owner. If you join someone else’s server, ask the owner about their operations, backups, and deletion practices.
Roux is currently preparing for launch and in testing. Available sign-in providers and features may vary by app version and server configuration.
02. Data we process and why
- Social sign-in and central account
- We process account identifiers, display names, email and verification status when provided by Apple or Google, Roux account IDs, device identifiers, names and platforms, sign-in and session times, and authentication information. This supports sign-in verification, session management, and unlinking providers during account deletion. Roux does not receive your social account password.
- Server membership and permissions
- We process account IDs, display names, sign-in providers, server and member identifiers, join and approval status, and permissions. When you request to join, the NAS owner can see your name, provider, and account ID to identify you. Social account emails and original provider account identifiers are not included in NAS membership information.
- NAS library and viewing history
- File paths, metadata, images, subtitles, playback positions, completion status, ratings, short reviews, viewing history, collections, Watch Cards, and slab unlocks are stored on the NAS. They support search, playback, Continue Watching, and personal reviews. Original media is mounted read-only and is not transferred through the central account service.
- Setup guide and device storage
- Setup checkmarks are stored separately on your device and in your browser. They are not synced or sent centrally and can be cleared with Reset. iPhone stores server addresses, connection settings, display caches, and app settings. Sign-in and server credentials are stored in iOS Keychain. A hashed server/card key and reward ID from an unfinished slab reward in an earlier test version may remain on your device. This version can retry saving an existing reward to the NAS without requesting an ad. It does not create new ad rewards or send this data to an advertising SDK. Your website language choice is also stored only in this browser. You can change it with the language link or clear it in browser site settings.
- Website visits and inquiries
- General guide pages have no contact form, first-party analytics, or ads. Processing on the separate TV approval sign-in screen is described in the Apple TV section above. The hosting provider may process IP addresses, request paths and times, browser information, and other access data to deliver and secure pages. If you email us, we receive your sender address and message to resolve issues and handle rights requests.
Sign-in and access information are necessary for those features and security. Reviews, external subtitle searches, and email inquiries are optional. Avoiding an optional feature avoids the processing it requires.
03. External services and information sharing
Roux connects to the services below. Actual transfers depend on your settings and consent when using each feature.
The included Google Sign-In SDK privacy manifest declares phone numbers, approximate location, user and device identifiers, usage information, and other authentication and analytics data in addition to names and email addresses. Roux does not request phone-number input or additional contact permissions and does not store phone numbers in Roux account records. Provider and SDK processing depends on Google’s policies and the account and authentication flow.
- Apple · Google: Social sign-in and unlinking. The provider you choose processes authentication information. Apple Privacy Policy · Google Privacy Policy
- Supabase: Database and API hosting for Roux’s central account service. Processes accounts, sessions and server memberships. The metadata gateway is inactive. Supabase Privacy Policy
- TMDB: Work, cast, and poster lookups. Processes search information such as titles, years, work identifiers, and languages, along with network request information. TMDB Privacy Policy
- OpenSubtitles: When configured and used for external subtitle search or download, processes work identifiers or titles and years, seasons and episodes, languages, and request information. OpenSubtitles Privacy Policy
- When external subtitles are enabled, the NAS owner stores their OpenSubtitles API key, username and password in a protected store on the NAS. The NAS authenticates directly with OpenSubtitles over HTTPS; session tokens stay in server memory. Credentials are not sent to the central Roux account service, guide website, iOS app or invited members. Searches send work IDs or titles, years, seasons, episodes and languages; downloads send the selected subtitle ID. The provider processes the NAS public IP, requests and account usage. Original videos, file paths, viewing history and reviews are not sent. Downloaded subtitles stay on the NAS and remain usable after disconnecting the provider.
- Vercel: Provides hosting, security, and access processing for this guide website. Vercel Privacy Policy
Inquiry emails are received through Google’s Gmail. External providers may process information outside South Korea, under their infrastructure, processing locations, and retention policies. Reading this policy alone does not constitute consent to international transfers or personalized ads. Features requiring separate notices or consent follow those procedures.
Roux does not provide NAS videos or viewing history and reviews to advertisers for ad targeting. Information may be disclosed to the extent necessary in response to lawful legal requests.
04. Ad-free launch version
iOS version 1.0 build 76 is ad-free. It does not include the Google Mobile Ads or UMP SDK, request ads, show ad consent screens, or offer new slabs in exchange for ads. It does not request IDFA tracking permission.
Watch Cards are earned by watching media. Playback and personal reviews remain available, and existing cards, slabs and viewing records are preserved.
Build 75 and earlier test versions included optional ads. Those versions may process IP addresses, device and app identifiers, ad interactions and diagnostics through Google’s SDK for ad delivery, measurement and fraud prevention. Advertising SDK data information for earlier versions. Advertising will return only after applicable usage terms are confirmed and through a separate app update with updated privacy notices.
05. Retention and deletion
- Central account information: Retained while the account exists. Once account deletion is completed, the central account, linked provider information, stored credentials, sessions, and membership records are removed from the operational database. Signing out or token expiration does not delete all account data.
- Optional metadata connection: The NAS owner stores a personal TMDB API Read Access Token in a protected store on their own NAS. The NAS sends search titles, years, languages and work IDs directly to TMDB; images are fetched from its image CDN and cached on the NAS. TMDB receives network request information including the NAS public IP address. Original videos, original filenames, file paths, viewing history and reviews are not sent. The token is not sent to the Roux account service, guide website, iOS app or invited members. Invited members see metadata through their authorized NAS library. File browsing and playback work without this optional connection. Roux’s central metadata gateway is inactive; this setup does not send searches or gateway authentication records to it.
- NAS data: Retained while records remain on that server. Leaving or being removed from a server does not automatically delete viewing history, reviews, or cards. The NAS owner manages deletion and backups. Deleting your central account or iPhone app does not erase remote NAS data.
- Previous pending rewards on your device: Data remaining from an earlier test version is used only to retry saving that existing reward to the NAS and is deleted after the NAS confirms the save. It is not used to request new ads. Uninstalling the app may lose this information. Keychain credentials are cleaned up by the app’s sign-out and disconnect procedures; uninstalling alone does not guarantee removal of all Keychain entries.
- Inquiry information: Retained as needed to handle inquiries and rights requests, then deleted when the purpose is fulfilled or a deletion request is processed. If legal obligations or an ongoing dispute require further retention, we explain the scope and reason.
- Hosting logs and backups: May remain separately from operational data and expire according to the hosting provider’s retention and backup policies and configuration. Deleting operational data does not mean every backup is deleted immediately. Contact us about the scope and status of deletion.
Electronic information managed by Roux is deleted or made inaccessible. Roux’s central service does not arbitrarily delete files or backups on user-owned NAS devices.
06. Access, correction, deletion, and choices
To request access, correction, deletion, restrictions on processing, or withdrawal of consent, contact kyhoonx@gmail.com. We verify the minimum information needed to identify you and explain the outcome or any limitations. Do not send passwords, authentication tokens, or NAS administrator passwords.
- Delete your central Roux account: In the app, open Settings → Roux account to start account deletion. Leave joined servers and complete ownership transfer or recovery for servers you own. The app will first guide you through any pending membership or access cleanup. Central service or sign-in provider outages may require a retry.
- Delete NAS records: Use the app’s editing features or ask the NAS owner to delete records. The owner manages data and backups. Some records have no individual deletion control in the app, so leaving a server does not mean all records are erased.
- Change access or consent: Change Local Network access in iOS Settings or unlink Roux in your social account’s connected-app settings. Unlinking alone does not delete your central Roux account.
07. Safeguards and children’s information
Roux uses purpose-specific access controls, per-account server permissions, Keychain credential storage, encryption for provider credentials stored centrally, HTTPS for remote connections, and diagnostics without sensitive information. NAS owners are responsible for security updates, administrator access, and backup protection on their servers.
Managed profiles do not offer social sign-in. Children under 14 should ask a guardian instead of creating their own central account or sending inquiries containing personal information. If you learn that a child’s information was submitted without guardian verification, contact us so we can investigate and delete it.
08. Changes and contact
When data, purposes, providers, or features change, we update this page and its effective date. Material changes to your rights or those requiring additional consent will be announced separately in the app or on the website.
Operator: kyhoon
kyhoonx@gmail.comInclude your app version and request type when contacting us. You do not need to attach server secrets or original videos.