Privacy claims are useful only when they identify each data boundary. Quven keeps media files and library folders on the self-hosted server, while Quven Account stores identity, linked servers and selected profile data needed to follow a person across devices and reinstalls.
Local media and cloud profile data are different classes
The server reads the folders you choose and serves those files to authorised clients. Quven’s cloud does not become the storage location for the library. Account identity, linked-server records, household profiles, watchlists, ratings, reviews and resume positions are cloud-backed so they survive reinstallations and remain consistent between clients.
Metadata and optional AI create explicit outbound requests
Matching a title can call configured metadata providers with title-like evidence needed to find the work. Optional AI disambiguation is a fallback for ambiguous matching and can be left disabled. It is not required for library storage or playback, and a configured provider should be evaluated under its own privacy terms.
Diagnostics need both minimisation and control
Crash and playback diagnostics are designed to remove file paths, addresses and email before transmission. The product presents the diagnostic boundary and allows opt-out. Product analytics remains separately consent-gated: enabling collection capability in a build never grants consent on behalf of the person using it.
The managed relay is a separate boundary too. In the current MVP it terminates transport encryption and can see forwarded media while operating the connection; it is constrained as a forwarding service and does not log that media. Use a self-managed route if that trust boundary does not fit your threat model.
Read the complete policy. This guide explains the architecture in practical terms, but the current Privacy Policy remains the authoritative description of purposes, providers, retention and rights.