Privacy
Mär collects nothing. There are no accounts, no analytics, no tracking, and no crash reporting. There is no server operated by this project that your app talks to.
The app connects only to the servers you configure and to the public directories and catalogues you choose to browse: Podcast Index, Apple's podcast directory, Radio Browser, Jamendo, the Internet Archive, LibriVox, Project Gutenberg, Wikidata and Wikimedia Commons for station logos, MusicBrainz and the Cover Art Archive for album art, and LRCLIB for lyrics. Those services see the requests you make to them, in the same way any website you visit does; what they log is governed by their own policies.
Passwords and access tokens for the servers you configure are kept in the device keychain and stay there. There is one exception, the credentials of private and paid podcast feeds, and where those travel is described below. Listening progress is stored on your own server, or on the device when a source has no server of its own. With Jellyfin the access token rides inside the stream and cover links the app requests, so it appears in the logs of your own Jellyfin server and of any proxy in front of it, and nowhere else. Downloads stay on the device.
If iCloud is enabled on your device and the sync switch in the app is on (it reads "Sync via iCloud", and "Sync across devices" once you have set up a service of your own), the following travels through iCloud in your own account, so that it follows you between your devices (Apple's key-value store and iCloud's own database): listening positions of podcasts, catalogue titles and local files; your playlists and listening statistics; the choices you make in the app, such as radio favourites, recent searches, hidden titles and playback speeds; and the addresses of servers that once worked, so that your other device can offer them under its address field. Podcast subscriptions (feed addresses) travel over iCloud like listening states, when iCloud sync is on. This includes the subscriptions a device pulls from your own gpodder server: they reach your other devices, and unsubscribing on any of them reaches that server as well. Listening positions are not removed by this. The credentials of private and paid podcast feeds travel this way as well, as iCloud keychain items, while the sync switch is on and no Mär sync service of your own is set up. Every other username, password and token never travels over iCloud. That data goes to Apple under your account and Apple's terms.
If you point the app at a Mär sync service you host yourself (Settings, Sync), the podcast positions, the playback claim (which of your devices is playing), the listening statistics, your playlists and your choices travel to that service instead of iCloud. The password you enter is exchanged for a token that stays in the device keychain; the password itself is not stored. That service is yours: this project runs none, and nothing is sent anywhere else.
Usernames and passwords of private and paid feeds travel over exactly one route, never both. With a service of your own set up, they travel to that service, sealed: the app seals them on the device with AES-GCM, under a key derived from a device code through HKDF-SHA256, so the service keeps them without being able to read them. Without such a service they are kept as iCloud keychain items instead, so they travel through Apple while the sync switch is on, as named above. The device code is shown in the app under Settings, Mär Sync, and it reaches a second device by copying it across; the code itself does not travel through iCloud.
Every request to that service travels inside an encrypted session, including over a plain http address. The session uses the Noise protocol in its NK pattern, in the spelling Noise_NK_25519_ChaChaPoly_SHA256. Your device remembers the service's key from the first connection, as a fingerprint held in the device keychain for that address. It stays on this device: it is not in the iCloud keychain, and it does not move to another device through a backup, so a new device meets the service again. If the key changes, signing in stops until both fingerprints have been shown to you. Two things stay outside the session: fetching the service's public key itself, and the question whether the service can be reached.
When you import from Pocket Casts, the app signs in to Pocket Casts once with the e-mail address and password you enter, reads the subscriptions and listening states of your own account, and discards the credentials when the import finishes. Nothing is stored and nothing runs in the background. This uses an interface that Pocket Casts does not document officially. Imports from Apple Podcasts, AntennaPod and OPML files read a file you choose; nothing leaves the device.
Nothing is sent anywhere else.
← maer.fm