Cinemarr / Privacy

A private screening room.

Cinemarr connects your Seerr account to video libraries you control. Pragmatic Developments does not operate a public catalogue, sell viewing data, or use advertising trackers.

Last updated: August 31, 2026

Pragmatic Media Pass

Access uses a Pragmatic Media Pass account. Pragmatic receives the email address used to sign in, an opaque account identifier, opaque device-link identifiers, the app and platform linked, entitlement status, and store transaction references needed to validate, restore, refund, and support purchases. It does not receive your media-server or Seerr password, library, searches, viewing history, watchlists, requests, votes, issues, or playback URLs through Media Pass.

Monthly and annual subscriptions may be purchased through supported app stores or independently on the Pragmatic website. Apple, Google, Amazon, Stripe, and other payment providers process payment details under their own policies; Pragmatic retains entitlement and transaction-reference data, not full card numbers.

What Cinemarr accesses

Cinemarr accesses only the Seerr, Plex, Jellyfin, and Emby services you choose. Depending on the feature, those services provide account identity and permissions, requests, watchlists, title metadata, artwork, library availability, playback URLs, watch state, and issues.

Where data goes

Sign-in, library, playback, download, discovery, request, watchlist, issue, profile, and administration traffic goes directly from your device to the service you selected. Pragmatic Developments does not proxy that traffic and does not receive your credentials, viewing history, library, searches, votes, or requests through those direct connections.

On Android, only when you enable Android Continuity, Cinemarr seals household continuity state with AES-GCM authenticated encryption before sending it to the CinemaRelay endpoint you choose. The encrypted payload can include media-service credentials, playback progress, profiles, quality and playback preferences, Movie Night state, notification read state, and a recent playback handoff. CinemaRelay receives authenticated ciphertext, a randomized continuity-domain identifier, an access proof, revision information, and an update time. It stores the ciphertext, domain identifier, revision and update metadata, and a one-way hash of the access verifier. It does not receive the recovery secret or encryption key and cannot decrypt the payload or use the enclosed media-service credentials.

A CinemaRelay endpoint may be operated by your server owner or by Pragmatic Developments. Either operator can see network and relay-record metadata available to that endpoint, but not the encrypted household state. The continuity domain is not linked to your Media Pass account by Cinemarr.

Storage and synchronization

Credentials are stored in Apple Keychain or Android Keystore-backed encrypted storage. Downloads, household profiles, movie-night votes, playback preferences, and cached metadata otherwise remain on your device.

On Apple platforms, optional continuity uses your private iCloud/CloudKit database. Apple states that private CloudKit records are not visible to the developer through its portal. Apple continuity does not use CinemaRelay.

Android Continuity is off until you create or restore it. Participating Android devices keep the recovery secret in Keystore-backed encrypted storage; you can also copy the displayed recovery key to another device. Anyone with that recovery key and the relay address can access and decrypt the continuity domain, so it should be protected like a password. Sync occurs with the selected relay while the feature remains enabled.

Notifications and consent

After you enable alerts and grant system permission, Cinemarr may schedule local notifications based on direct checks of the services you configured. The release does not use Firebase Cloud Messaging, Apple Push Notification service message routing, CinemaRelay push routing, or a Pragmatic-operated notification-routing service. Android Continuity uses CinemaRelay only for the encrypted synchronization described above.

Cast diagnostics

On Android, Google's Cast Sender SDK automatically sends encrypted, anonymous app-activity and device diagnostics to Google so Google can improve Cast reliability and performance. Google says this SDK telemetry does not contain user or content metadata, is not used to model an individual user, and cannot be disabled or deleted by Cinemarr or Pragmatic Developments.

Retention and deletion

Media Pass account, device-link, and entitlement records remain while the account is active and as needed for fraud prevention, refunds, tax, accounting, and legal obligations. Sign in at pragmatic.onl/media/activate to remove linked screens or permanently delete the Pragmatic account. Account deletion cancels an active Stripe Media Pass subscription immediately; subscriptions bought from Apple, Google, or Amazon must also be cancelled in that store account.

Disconnecting removes the selected media-service credential from that device; on Apple platforms, remove-everywhere actions also remove the app-managed private CloudKit record. Disable alerts to stop local notification checks, remove downloads in the app, and uninstall to remove local data under the operating system's rules. Data owned by Seerr or your media server must be deleted there.

A CinemaRelay continuity record is retained at the selected relay until a device successfully revokes that domain. Choosing Disable Android Continuity sends an authenticated deletion request; after the relay confirms deletion, Cinemarr removes the local recovery secret and relay address. If the relay is unreachable or refuses the request, Cinemarr keeps the local continuity configuration and tells you to retry rather than claiming deletion succeeded.

Uninstalling Cinemarr does not contact CinemaRelay and does not by itself revoke the relay domain. Deleting a Media Pass account also does not delete that domain because the two are not linked. Disable Android Continuity successfully before uninstalling or deleting the account; otherwise the encrypted relay record remains until it is revoked using its recovery key or removed by that relay's operator.

Security and transport

Public servers must use HTTPS. Plain HTTP is permitted only for user-selected loopback, local-DNS, private-address, or Tailnet hosts. Credentials are not accepted inside server URLs.

Contact

For Cinemarr privacy, support, accessibility, or deletion requests, contact Pragmatic Developments Inc.

[email protected]