Legal
Privacy policy
Last updated: 14 August 2026. Multipass is operated by Kamm Creative Solutions LLC, based in New York, United States, which is the controller of the data described here. Questions go to support@kammcs.com.
The short version
Your media lives on your server, not ours. We never collect the names of your movies, shows, or files, or anything about what you watch. We hold an email address and a subscription record for people who buy remote access, plus anonymous diagnostics you can switch off. We sell nothing to anyone and run no advertising or tracking.
What we never collect
The titles in your library, your file names and paths, your watch history, your ratings, and the contents of your media never leave your own server. This is enforced in the software, not left to a setting, and it applies to every report described below. We also collect no location data, no contacts, and no advertising identifiers, and we do not sell or share personal data with anyone for marketing.
Diagnostics the software sends
There are three, and only three, channels back to us.
- Crash reports. On by default, with an off switch you can reach the first time you run a server. A crash report carries the stack trace, your operating system, and the app version. It is identified by a random install id you can reset at any time, never by your account or your server, and it is sent without authentication so nothing on our side can tie it back to a person.
- Usage statistics. Off unless you turn them on. When enabled they carry the app version, the platform, coarse flags for which features are in use, and playback and transcode counters. Same anonymous install id, same rule about titles.
- Connection diagnostics. When a signed-in app loses its connection to your server, it uploads a short log of what happened: request outcomes, reconnection attempts, and the state changes around the drop. This one is authenticated, so it is associated with your account. It never contains request bodies, access tokens, or media URLs. An install that only ever runs on your own network, with no account, never sends one.
Self-hosting a server with everything off is a supported configuration. Turn off crash
reports, leave usage statistics off, and skip the account, and the software makes no
report to us at all. Server operators running headless can set
MULTIPASS_TELEMETRY_OFF to enforce that at the process level.
What your account holds
An account is needed only for remote access, sharing, and downloads. Local use of your own server on your own network needs no account. If you create one, we store your email address, a securely hashed password (never the password itself), when the account was created and verified, which servers you have linked, and your subscription or trial status. If you join the launch list, we store your email address so we can tell you when we launch, in our own database with no third-party mailing tool.
Remote streaming
When you watch away from home, apps first try to reach your server directly. If your network will not allow that, the stream falls back to a relay on our infrastructure. Every leg of that connection is encrypted in transit, and we do not record or store what passes through it. We do count relayed bytes per server, because remote access is metered, but a byte count says nothing about what was watched.
Movie Night
Chat messages and reactions in a Movie Night exist in memory on the host's server for the length of the party and are gone when it ends. They are never written to disk and never reach us. Voice chat is peer to peer between participants; our relay carries only the audio connections that a restrictive network refuses to make directly, and it cannot read them.
Companies that receive data
- Stripe handles payment and is the merchant of record. Card details go to Stripe directly and never touch our systems. We keep a Stripe customer reference so we know what you bought.
- TMDB supplies artwork, cast, and descriptions. Your server asks our metadata service, which passes the request to TMDB. We do not log or store those requests, and poster images are fetched by your server straight from TMDB.
- Apple and Google push services deliver notifications to phones and tablets, for example when a download finishes. The text of a notification passes through them to reach your device. Turn notifications off in your device settings and nothing is sent. The Apple TV app contains no push or analytics component of any kind.
There are no advertising networks, no analytics SDKs, and no third-party trackers in any Multipass app, on the server, or on this website. This website sets no tracking cookies.
How long we keep things
- Crash reports and usage statistics: 180 days, then deleted automatically.
- Connection diagnostics: 30 days, then deleted automatically.
- Account and subscription records: for as long as the account exists.
Your choices
You can switch crash reports off, leave usage statistics off, reset your install id, and turn notifications off, all without losing any feature of the product. To see a copy of what your account holds, correct it, or delete the account entirely, write to support@kammcs.com from the address on the account. Deleting an account removes the account record, its linked servers, and its subscription history. Deletion is handled by us rather than in the apps because the apps contain no account management at all: they sign in to a server and nothing more.
Children
Multipass is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, write to us and we will remove it.
Changes
If this policy changes we will update the date at the top, and we will tell account holders by email before any change that affects what we collect.