What we access
With your consent, Leaf Player uses Google’s drive.file permission so you can choose Drive files for playback. The app can see and play only the Drive content you select or otherwise authorize for the app. Leaf Player does not modify, create, share, or delete anything in your Drive.
When you connect other supported sources, Leaf Player accesses the folders, files, server, or account content you explicitly make available under that provider’s permission flow. Remote file sources are used read-only.
What we store, and where
Everything stays on your device. Leaf Player has no developer-run media server.
The optional Wi-Fi transfer feature runs a receiver on your iPhone or iPad itself, only while the transfer screen is open. It accepts supported media files from your computer and never uses data from your connected remote sources.
Stored locally on your device may include your source and folder library, playback positions, favorites, media copied for offline use, playback cache, thumbnails, artwork, local transfer files, settings, and source credentials or tokens in the iOS Keychain where applicable. We do not transmit, store, or process your Google user data on developer infrastructure. We do not collect analytics, telemetry, advertising identifiers, or behavioral profiles.
Remote playback
Authenticated remote playback uses an app-owned localhost proxy on your device. This keeps provider bearer tokens and source-private credentials behind the source integration rather than handing them to a playback engine or a developer-operated relay.
Sharing
We do not share, sell, or transfer your Google user data or personal media activity to advertisers or data brokers. No third-party analytics SDK receives your media history.
Limited Use disclosure
Leaf Player’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Support information
Support is handled by email. If you contact support, the email and any text or attachments you choose to send are processed to answer your request. Leaf Player does not upload diagnostics continuously; screenshots and prepared redacted diagnostics are optional and user-initiated. Do not send passwords, access tokens, or private server credentials.
Revoking access and deleting local data
You can disconnect a source inside the app. For Google Drive, you can also revoke Leaf Player’s access at myaccount.google.com/permissions. Deleting the app removes its locally stored app data, including caches and locally held tokens, subject to ordinary iOS and backup behavior.
Contact
Changes to this policy will be posted at this URL.