Quven is a self-hosted media server: it runs on hardware you control. Your media files and library folders stay on that hardware. Quven Account handles sign-in, linked servers and household profiles, and it stores profile data such as watchlists, ratings, reviews and resume points so that data survives reinstalls and follows you between servers. This policy explains that split.
1. Who is responsible for your data
The data controller for the Quven cloud services is Domenico Aiello, the independent operator of Quven, based in Italy. For any privacy request or question, contactsupport@quven.tv.
2. Local data and explicit cloud exceptions
Your playable media files stay on your own server and devices. Quven Cloud does not build or host a copy of your media library. The following is local unless you deliberately use one of the cloud features described below:
- your media files, libraries and folder layout;
- local copies of metadata, posters and artwork fetched for your content;
- server settings, library folders and device-specific preferences;
- local cache copies of profile data used while the app is running.
We do not store your media files. When managed remote access is used, media bytes can transit the relay as described in section 5 without being retained. Metadata, subtitle and streaming-availability lookups use your server's configured provider credentials when you supply them. Without local provider credentials, the default managed mode sends the lookup request through Quven Cloud (api.quven.cloud) to the relevant provider. Managed requests can include search titles, years, external identifiers, file hashes, file sizes, language preferences and similar lookup parameters, but not the media file itself. Provider responses can be held in an account-anonymous, content-keyed cache until their expiry so identical lookups do not repeatedly contact the provider. See sections 9 and 11.
If you use the optional Cloud Backup feature, Quven Cloud stores one replace-in-place compressed snapshot per server. It can include library names, types and absolute folder paths; provider identifiers and path-independent file hashes used to restore match decisions; and the names, descriptions and membership identifiers of collections and playlists. It does not include the media files, posters or descriptive provider metadata. The backup is linked to your account and deleted with it.
3. Quven Account information
Quven Account is required to use the desktop, web and native mobile apps. We process the data needed to operate that account and the household profile model:
- your email address and a securely hashed password;
- session and device-authorisation records, hashed security tokens, multi-factor authentication state and account-recovery records;
- your subscription and entitlement status (tier, Founders status, validity);
- technical identifiers and pairing credentials of the servers you link to your account, used to issue and verify entitlement and to authenticate managed metadata, AI, relay, backup and other cloud requests made for that server;
- household profile metadata such as profile names, avatars and optional PIN hashes;
- per-profile user data such as watchlists, ratings, reviews, resume points, watched state, playback history sessions, playlists and collections;
- basic security and operational logs (such as timestamps and request metadata) needed to keep the service safe.
- records of the legal and optional choices you make, including the document version, time and connection IP address used to evidence the choice.
We use this data to authenticate you, to deliver your licence entitlement, to sync your profile data, to authorise relay connections and — when paid plans launch — to manage billing. First login and periodic token refresh require an internet connection; clients can keep working offline for a limited grace period of about seven days before they must refresh. The legal bases are performance of our agreement with you and our legitimate interest in operating and securing the service. We do not sell your personal data or use it for advertising.
4. Diagnostics and crash reporting (opt-out)
The Quven apps send diagnostics to help us fix crashes and performance problems. To keep a self-hosted product maintainable, this is on by default as a security and stability measure. It is disclosed during installation (desktop and server) or through a one-time in-app notice (web and native mobile clients). Native mobile clients do not transmit diagnostics until that notice has been acknowledged and the user keeps diagnostics enabled. You can turn it off at any time in the app settings. When enabled, diagnostics are processed through Sentry (EU region) and are scrubbed to remove personal information and authentication tokens before they leave your device. Typical contents are error and performance traces, the app version and basic device / operating-system information — not your media or your library. The legal basis is our legitimate interest in operating and securing the service.
4.1 Optional account-linked product analytics
Product analytics is off by default. If you enable it in Quven Account settings, a client sends a random installation identifier, client version, operating system and architecture together with a closed catalogue of setup, feature-use, aggregate scan, playback, update and reliability events. Scan events contain bounded totals and technical buckets, such as file-size, container, codec and resolution ranges, never one event per media item. Events are linked to a pseudonymous key derived from your Quven Account so we can understand activation, adoption and Quven-actionable failures across releases. Quven rejects unknown event names and does not accept media titles, identifiers, file paths, library names, search or review text, IP addresses, tokens, exception messages or free-form event properties.
The installation identifier is stored on your device and may also be included in Sentry diagnostics when diagnostics are enabled. This allows a product event and a scrubbed crash to be correlated without sending your email or display name to Sentry. You can withdraw product-analytics consent at any time; unsent events are deleted and subsequent product events are rejected. Linkable technical details expire after 90 days; product events and inactive installation rows expire after 395 days. Small, linkable cohorts are suppressed in internal reporting. Irreversible daily aggregate totals may be retained for up to 1,095 days. Account deletion removes account-linked analytics before the account is deleted. The legal basis is consent.
5. Remote access relay
If you enable the managed relay to reach your server from outside your network, connection-setup metadata transits our signaling service. A connection may use the Quven media relay and, where necessary, a third-party TURN relay (Cloudflare). Media requests and response bytes are then proxied transiently between your device and server. We meter aggregate bytes against your account and billing period, but do not store the media or inspect the contents for profiling or advertising. Reaching your server by your own means instead (port forwarding, reverse proxy, VPN) does not involve our relay at all.
6. Optional AI features
Managed AI matching is off by default and can be enabled or disabled in server settings on an entitled plan. When enabled and a deterministic match needs AI help, Quven sends the parsed title, year, runtime, original file name and candidate metadata through Quven Cloud to a third-party large-language-model provider. Quota records contain technical request identifiers, status, counts and a request fingerprint, not the submitted title or file name. If you configure your own compatible AI provider key instead, the server contacts that provider directly.
When you explicitly request AI subtitle translation, the subtitle text to be translated is sent through our cloud service to a third-party large-language-model provider, which returns the translation. The translated result is cached on your own server as a subtitle asset. To make retries safe, account-linked translated results can be held for up to seven days. A completed translation can also be stored in an account-anonymous cache keyed by a one-way hash of the source content, language, format and provider model for up to 90 days. We use managed providers on terms intended to prevent submitted content from being used to train their models. Both features run only when you choose their relevant control or action.
7. The Quven websites
The marketing site and account portal set no advertising or cross-site tracking cookies. Our network provider (Cloudflare) delivers and protects the sites and provides aggregate Web Analytics. Its injected beacon measures page views, visits and performance without cookies or local storage; it also processes limited connection metadata such as IP address. If you send a support request from the site, we store the name, email address, plan, platform, reason, subject, message and app version you submit so we can reply, and send the request through Brevo. Support requests are removed after no more than 395 days.
Promotional and installer links can pass through a first-party Quven Cloud endpoint that issues a random journey token; only its SHA-256 hash is stored. A download event can contain the release, platform and architecture selected; a fixed campaign-source label when the link carries one; country and language; user agent and referrer; the Cloudflare request identifier; and a daily rotating hash derived from the connection IP address. The analytics row does not store the raw IP address, email address, media titles, file names or library data. If the journey token is later presented during account registration, the journey and related download can be linked to that account's internal identifier; otherwise it remains unclaimed and expires. The source label is selected by Quven from a fixed list and is not user-provided text. Raw request metadata and claim tokens are removed after seven days; linked attribution is retained for no more than 395 days. This measurement uses no cookie or persistent local storage. The clear token is held only in the current browser tab's session storage, removed from the visible landing URL and discarded when that tab session ends. The legal basis is our legitimate interest in understanding and improving product distribution with minimal data.
8. Email
We send only transactional email related to your account — for example email verification, password resets and, in future, billing notices. These are delivered through our email provider (Brevo). We do not send marketing email unless you have separately asked to receive it.
8.1 Public article comments
If you comment on a Quven article, we process your account identifier, public display name, plain-text comment body, article and parent-comment identity, timestamps, moderation state and any report or moderation reason. Approved comments show your public display name, body and timestamps to anyone who reads the article. Public readers do not receive your email address or account identifier. Authorised moderators can see the linked account identifier and email address, reports and moderation history where needed to review abuse and enforce the Terms.
Active comments and their account relationship remain while the comment and account exist, unless moderation or a deletion request removes them. Rejected or hidden material, reports and moderation records are retained only as needed to operate and defend the community feature. Account deletion removes the author relationship and comment body. A minimal, content-free deletion marker may remain when an existing reply needs the conversation structure or a retained moderation record requires referential integrity; it is public only when needed for a published reply. Comment bodies, identifiers, moderation reasons and named participation are never product-analytics events. The legal bases are performance of our agreement and our legitimate interest in providing and protecting public discussions.
9. Third-party services and where data goes
Depending on the features you use, data is processed by the following categories of providers, each under its own privacy terms:
- TMDb and OMDb — used to fetch movie and TV metadata, either directly with credentials you configure or through the managed Quven Cloud proxy.
- OpenSubtitles — used to search and fetch subtitles, either directly with credentials you configure or through the managed Quven Cloud proxy.
- JustWatch (via TMDb) — source of streaming availability shown in the app.
- Sentry — diagnostics and crash reporting (EU region, opt-out).
- Cloudflare — content delivery and protection, aggregate Web Analytics, the managed TURN relay, DNS and inbound email routing.
- Hetzner — European hosting for Quven Cloud databases, account avatars, server-backup snapshots and shared content caches.
- Brevo — transactional account and support email.
- A large-language-model provider — optional managed AI matching and on-demand AI subtitle translation.
- Stripe — payment processing, only once paid plans launch.
10. Where your data is processed
Our cloud services run on infrastructure located in theEuropean Union. Some third-party providers may process data outside the EU; where they do, appropriate safeguards (such as the European Commission's Standard Contractual Clauses) apply. We select providers and configure or contract with them to provide protection consistent with this policy and applicable law.
11. Data retention
We keep account, profile, linked-server, relay-usage, consent and the latest optional server-backup data while your Quven Account exists, subject to shorter technical-token lifetimes and any limited retention required for legal, accounting or security obligations. Expired device-authorisation rows are removed within 24 hours. Support requests are removed after 395 days. Account-linked AI translation results are minimized after seven days, and account-anonymous translated-subtitle cache entries are removed after 90 days. Managed metadata cache entries are removed when their provider-specific expiry passes. Diagnostics are kept for no more than 90 days. Optional product analytics and linked marketing attribution are retained for no more than 395 days, with raw attribution metadata removed after seven days. When you delete your account, we delete account-linked personal data and uploaded avatars, except where retention is legally required; irreversible aggregate statistics can no longer be connected to the account.
12. Your rights
Under the EU General Data Protection Regulation and applicable law, you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You may exercise these rights by contactingsupport@quven.tv. You can withdraw optional account consents in Quven Account settings or by contacting us. Account deletion is available in each native app underSettings → Account → Delete account and in the account portal. You also have the right to lodge a complaint with your local data-protection authority (in Italy, the Garante per la protezione dei dati personali).
13. Children's privacy
Quven is not directed to children, and a Quven Account is not intended for use by children below the age of digital consent in their country. We do not knowingly collect personal data from such children.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and reflect the changes on this page. When a material mandatory change affects the account services, the apps require affirmative acceptance of the new document version.
15. Contact
For any privacy question or request, contactsupport@quven.tv or use theSupport page. See also ourTerms & Conditions.
The short version: your media files stay on your own server. Account, linked-server and profile data live in Quven Account; optional cloud backup, managed metadata, transient relay, diagnostics and optional AI are limited to what each feature needs. Managed AI matching is off by default and user-controlled, subtitle translation runs on request, and diagnostics remain controllable on every surface.