الخصوصية
Privacy
Leyla is software you run at home. Your films, your household’s accounts and what everyone watches stay on that server. This page says exactly what goes anywhere else.
In effect from 9 October 2026
In short
- A Leyla server runs on a machine you or your household own. Its operator (whoever set it up) holds everything on it. We, the makers of Leyla, never receive your library, your accounts or your watch history.
- The Leyla apps talk to the server you sign in to, and to nothing else of ours.
- There are no ads, no analytics, no crash reports, no tracking and no update checks, in the server or in any app.
- Your server asks our services for two things: a licence, and details and artwork for titles. Those requests carry the server’s random id and title names or ids, never who is watching.
- We hold a little data of our own: your email if you asked for a beta seat, your Leyla account and purchases if you linked a server or bought a plan, and a GitHub name if you publish plugins.
“Leyla”, “we” and “us” here mean the makers of Leyla, tropicalthink. “Your server” means the Leyla server you or your household run.
On your server
The server keeps its data in its own database, on the machine it runs on. Its operator controls it, and is responsible for it towards everyone in the household. For each account it keeps:
- The account: a username, whether it is an administrator, and when it was made. A password is kept only as a one-way hash, and a profile PIN the same way. There is no email address, phone number or photo.
- Signed-in devices: a name for each device (worked out from the app or browser, such as “Chrome on Windows”), when it signed in and when it was last seen. The app, its version and the operating system are kept to choose what each screen can play.
- Watching: where you stopped in each film or episode, what you have watched and how often, your saved titles, favourites and playlists, titles you hid from Continue watching, and the audio and subtitle choices you made.
- Playback history: each time something played, which file, how it was sent and whether the device was at home or away. The server keeps this for a year, and the detailed events inside it for 180 days.
- Requests and notifications: titles you asked for and the notes you added, and the notifications the server showed you.
- Recommendations: the signals the server uses to suggest titles, worked out on the server from what was watched. They never leave it.
- Security: failed sign-ins for 30 days, and a change log of what administrators changed, with their username, for a year.
The server does not store IP addresses. It records only whether a device connected from the same machine, the home network or the internet.
The operator can back it up and delete it. Deleting an account deletes everything above that belongs to it; see Deleting an account.
What leaves your server
Our licence service
To start a trial and keep its licence current, the server talks to licence.leyla.media. It sends a random id made for that server when it was installed, and, when you link it to your Leyla account, the server name you chose. It asks about once a day. No usernames, titles or viewing are sent.
Details and artwork
To name your titles and find posters, the server looks them up. Unless the operator gives it their own keys, it asks our gateway at providers.leyla.media, which asks TMDB, OMDb and fanart.tv with our keys. A lookup carries a title, a year or an id such as an IMDb number, and, when someone searches for a title to request, the words they typed. Each request also carries the server’s licence, which says which Leyla account and server it is for, so the shared keys are used fairly.
The gateway makes its own request to those services: they see our gateway, not your server’s address or anything about you. It keeps the answers so the next server asking for the same title gets them faster. Those copies hold the answer only, not who asked.
Some lookups go from your server straight to the service:
- With the operator’s own TMDB or OMDb key, lookups go to TMDB or OMDb directly.
- Posters and pictures download from the sites that host them, such as
image.tmdb.organd fanart.tv. - With TMDB turned on, the server downloads TMDB’s public list of title ids once a week.
- The TVmaze plugin asks
api.tvmaze.comfor show and episode details.
Those services see your server’s internet address, as any website you visit does.
Plugins
The server downloads the list of plugins, and the plugins you choose, from index.leyla.media, without sending anything about the server. A plugin can reach only the sites it declares, and the server lists them on the plugin’s page. A plugin from another source is the operator’s choice, and its maker’s responsibility.
Only when the operator turns it on
- Webhooks send events, such as “playback started” with the username and title, to an address the operator types in (for example a Discord or ntfy channel).
- Sonarr and Radarr receive the titles in your library from the server they are set up on.
- A directory server (LDAP) checks sign-ins against the operator’s own directory.
- Direct remote access asks Let’s Encrypt for a certificate for the server’s address.
- A recommendation pack address, off by default, downloads a pack and sends nothing about the library.
Nothing else leaves the server: no usage statistics, no crash reports and no update checks.
The apps
The Leyla apps for Android phones, Android TV and Google TV, the web app, the LG and Samsung TV apps, Roku and Kodi all talk to the server you sign in to. They contain no analytics, advertising, crash reporting or push messaging. The LG and Samsung apps open your server’s own web app.
- Finding your server: the Android app can look for Leyla servers on your home network. Nothing about this leaves your network.
- Casting: when you cast, the app finds Chromecasts on your home network and asks the Chromecast to play the film from your server. The Chromecast runs Google’s standard player for this, which loads from Google. In Chrome, the web app loads Google’s cast script only when you press Cast.
- Network library: on Android, artwork from your server loads through Cronet, the Chrome network library that Google Play services provides.
- Camera: the Android app uses the camera only to scan the QR code on an invitation. Nothing is recorded or sent.
- Notifications: the Android app shows a notification while it downloads a film for offline watching. Android asks you first.
On the device, the apps keep your server’s address, your sign-in (in the Android Keystore on Android), your playback settings, recent searches, artwork they have already shown, and the films you downloaded. Signing out removes your sign-in; uninstalling the app removes the rest.
What we hold
A beta seat
When you save a seat on this site, we keep the email you gave, the film you said you’d watch first if you named one, and the date. We use them to invite you to the beta and write to you about it, and for nothing else.
Your Leyla account
You need a Leyla account to link a server for the longer trial or to buy a plan. You sign in to it at licence.leyla.media with your email: we send a one-time link, and there is no password. We keep:
- your email, and when your trial ends;
- each server you linked: its random id, the name you gave it, when it was linked, when it last asked for a licence, and when it was moved to another machine;
- your plan and payments: the plan, its status and dates, refunds, and Polar’s numbers for the subscription and each order.
A server that hasn’t been linked to an account gets its five-day trial with only its random id, and we know nothing else about it. When you’re signed in, the account pages set one cookie to keep you signed in. This site sets no cookies.
Plugin publishers
If you publish plugins on plugins.leyla.media, you sign in with GitHub, and we keep your GitHub id, username and the display name you choose, alongside the plugins you upload and a record of review decisions. We count downloads per plugin per day, without recording who downloaded them.
Internet addresses
To stop abuse, our services limit how often the same address can save a seat, start a trial or sign in to the plugin store. The address is used for that count and is not stored.
Who else is involved
We don’t sell or rent personal data, and we don’t share it for advertising. These companies handle it for us, each under its own privacy policy:
| Who | What for | What they get |
|---|---|---|
| Cloudflare | Runs this site and every Leyla service, and stores their data. | Every request to them |
| Polar | Takes payment when you buy a plan. | Your email and account id |
| Amazon Web Services | Sends the sign-in email for your Leyla account (from the EU). | Your email |
| GitHub | Signs plugin publishers in. | Your GitHub sign-in |
| TMDB, OMDb, fanart.tv | Answer title lookups from our gateway. | Titles and ids |
Your card details go to Polar and never reach us. Polar tells us which plan you bought, its status and its dates.
How long
| What | Where | Kept |
|---|---|---|
| Accounts, watching, requests | Your server | Until deleted |
| Playback history | Your server | 1 year |
| Detailed playback events | Your server | 180 days |
| Failed sign-ins | Your server | 30 days |
| Change log | Your server | 1 year |
| Beta seat | Leyla | Until you ask |
| Leyla account, linked servers | Leyla | Until you ask |
| Sign-in links | Leyla | 1 day after use |
| Payment records | Leyla, Polar | As tax law requires |
| Plugin publisher | Leyla | Until you ask |
Your choices
For anything on a Leyla server, ask its operator: they can see, export, correct and delete it, and we can’t. For what we hold, write to us and we will tell you what we have, correct it, or delete it. Wherever you live, you can also complain to your data protection authority.
Leyla is not made for children to sign up to on their own. A household’s operator decides who gets an account on their server.
Changes and contact
When this policy changes, the new version goes here with a new date.
Write to hi@tropicalthink.com about anything on this page.