RSPLAYER
Docs GitHub Install

Privacy Policy

Last updated: 2026-09-28

Overview

This policy covers:

  • The RSPlayer applications: the Android app (de.rsplayer.app), the desktop app and the server, including their web interface.
  • The RSPlayer websites: rsplayer.de, docs.rsplayer.de, stats.rsplayer.de and the live demo at demo.rsplayer.de.

RSPlayer is free, open source software (https://github.com/ljufa/rsplayer), run as a private, non-commercial project from Germany.

In short: the applications send no data to the developer. There are no accounts, no ads, no analytics and no crash reporting. What the applications store stays on your device or on your own RSPlayer server. Some features fetch information from public third-party services, listed under Network connections. The websites count visits anonymously with a self-hosted, cookie-free statistics tool and keep no server logs.

Controller

The controller (Verantwortlicher) under the General Data Protection Regulation (GDPR / DSGVO) is:

Dragan Ljubojevic
Postal address: see the Legal notice
Email: support@rsplayer.de

For the applications, the developer receives no data. When you run RSPlayer, you control your own installation and the data in it.

RSPlayer applications

Data stored on your device

The applications store the following locally, and only so they can work:

  • Settings: audio output selection, DSP/equalizer settings, UI preferences, and similar configuration.
  • Music library index: metadata (title, artist, album, cover art) read from the audio files you make available to the app.
  • Playback state: queue, playlists, favorites, play history, and podcast subscriptions and progress.
  • Network share credentials: if you configure an SMB/NFS share, its address and credentials are stored in the app's private storage and used only to connect to that share.
  • Browser storage: the web interface keeps two entries in your browser's local storage: the latest release version from the update check with the time it was checked, and the version whose update notice you dismissed. No cookies are used.

This data is never uploaded to the developer. Uninstalling the app or clearing its data (or your browser's site data) deletes it.

Android permissions

Permission Purpose
Internet, network state, Wi-Fi state Connect to your local network, internet radio, podcasts and the app's web interface
Multicast state Discover other RSPlayer devices on your local network (multiroom)
Read media audio / images (or read external storage on older Android) Read your music files and cover art to build the library
Foreground service (media playback), wake lock Keep music playing with the screen off
Notifications Show the playback notification and controls
Ignore battery optimizations Prevent Android from stopping playback in the background

The app does not access your contacts, location, camera, microphone, calendar, SMS or call logs.

Network connections

The applications only contact the network when you use a feature that needs it:

  • Internet radio and podcasts: the app connects to the stream and feed URLs you choose to play or subscribe to. Those servers will see your IP address and standard request information, as with any media player or browser.
  • Podcast search and artwork lookup: search terms you enter may be sent to public directory services such as the Podcast Index (api.podcastindex.org) or Apple's iTunes Search API (itunes.apple.com).
  • Radio metadata: for some stations the app may fetch now-playing information from the station's metadata provider (for example api.streamabc.net).
  • Internet radio directory: browsing and searching stations in the Radio library, and loading details of your favorite stations, queries the public Radio Browser API (de2.api.radio-browser.info). The country, language, tag or search text you choose is sent with the request. Station logos are loaded directly from the addresses listed in that directory.
  • Album cover lookup: when a playing track has no embedded or folder cover art, the app sends its artist and album name to the Last.fm API (ws.audioscrobbler.com) to find a cover image, which is then loaded from Last.fm's image servers.
  • Lyrics: when you open the lyrics panel, the artist, title, album and duration of the current track are sent to LRCLIB (lrclib.net).
  • Update check: when the web interface loads, it asks the GitHub API (api.github.com) for the latest RSPlayer release to show an update notice, at most once a day per browser. Only the release number is requested; nothing about your installation is sent. The Android app skips this check.
  • Multiroom sync: when you group devices, audio and control data travel directly between your own devices, encrypted, using the iroh/QUIC peer-to-peer library. If a direct connection is not possible, traffic may pass through an iroh relay server, which only forwards encrypted data and cannot read it.
  • Your own server: if you connect the app to an RSPlayer server on your network, data flows between the two devices you control.

The album cover, lyrics, radio directory and update requests are made directly by the web interface in your browser (or in the app's built-in web view), so those services see the IP address of the device you are using and standard browser request information. No account or identifier is sent, and the address of your RSPlayer server is not sent as a referrer. The privacy policies of these services apply to their processing.

No data is sent to the developer.

Security

Data is kept in the app's private storage on your device. Connections to third-party services use HTTPS wherever the service supports it. Some internet radio stations only offer plain HTTP streams, which is outside the app's control.

Websites

Hosting and server logs

The websites run on a rented virtual server. The hosting provider processes data only on RSPlayer's behalf, as a processor under Art. 28 GDPR.

When you open a page, your browser sends your IP address and standard request information (date and time, requested page, browser, referring page) to the server. This is technically necessary to deliver the page. The web servers keep no access logs, so this information is not stored.

Everything the pages need (scripts, styles, fonts, images) is served from these servers, so your browser does not contact third-party services such as CDNs or font providers. The one exception is the live demo: it is a full RSPlayer web interface, so the lookups described under Network connections (album covers, lyrics, radio directory, update check) happen there too.

Cookies and browser storage

The websites use no cookies, no tracking pixels and no third-party analytics (such as Google Analytics).

The documentation search on docs.rsplayer.de keeps a copy of the search index in your browser's local storage so searching is fast, and refreshes it once a day. It contains only the documentation text and never leaves your browser. The live demo stores the same update-check entries as any RSPlayer web interface (see Data stored on your device).

Visit statistics

rsplayer.de and docs.rsplayer.de count visits with GoatCounter, self-hosted at stats.rsplayer.de. No data goes to a third party.

  • Your IP address is never written to disk. To tell a new visit from a page reload, GoatCounter keeps IP address and browser only in memory, under a random ID, for up to 8 hours.
  • Counted per visit: the page, the referring site, browser and operating system, and the country derived from the IP address. Screen size and language are not collected: the pages remove screen size before the request is sent, and GoatCounter is configured not to store either. Clicks on some buttons (for example "Try the live demo" or an install tab) are counted the same way.
  • Only totals are stored (for example, page views per page per day). Individual page views are not kept.
  • The stored totals cannot be linked to you. They are kept as long as the statistics are useful and are never sold or shared.

The live demo and the RSPlayer applications do not use analytics.

Legal basis

Delivering the websites and counting visits are based on legitimate interest (Art. 6(1)(f) GDPR). Delivering a page requires processing your IP address. Anonymous statistics show which pages, features and install methods are used, so the project can focus its limited time; they are collected in a way that stores nothing that identifies you.

The documentation search index is stored in your browser because it is strictly necessary for the search function you use (§ 25(2) no. 2 TDDDG).

Data sharing and retention

The developer collects no personal data through the applications, so none is shared, sold or retained. Data on your device remains until you delete it.

On the websites, no personal data is stored: there are no server logs, and the visit statistics keep only anonymous totals. Nothing is shared with third parties apart from the hosting provider acting as processor.

Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): to ask what personal data about you is stored.
  • Right to rectification (Art. 16 GDPR): to have inaccurate data corrected.
  • Right to erasure (Art. 17 GDPR): to have your data deleted.
  • Right to restriction of processing (Art. 18 GDPR): to limit how your data is processed.
  • Right to object (Art. 21 GDPR): to object to processing based on legitimate interest.
  • Right to lodge a complaint (Art. 77 GDPR): with a data protection supervisory authority (Datenschutzaufsichtsbehörde), in particular in the EU member state where you live or work.

Because no data that identifies you is stored, a request usually cannot be matched to you (Art. 11 GDPR). You can still ask at support@rsplayer.de.

Children

RSPlayer does not knowingly collect any information from anyone, including children under 16.

Changes to this policy

Changes will be published on this page and the "Last updated" date will be revised. Significant changes will also be noted in the release notes.

Contact

Questions or requests: support@rsplayer.de, or open an issue at https://github.com/ljufa/rsplayer/issues

The software is provided "as is", under the MIT License. See the Disclaimer.

RSPLAYER
Open source under the MIT license.
Visits are counted with self-hosted GoatCounter: no cookies, no IP addresses stored. Privacy · Legal notice
UseLive demoDocumentationRelease notes
ProjectGitHubReport an issueHome AssistantFirmwareHardware
Contactinfo@rsplayer.de