Tonarr / Privacy

Your music stays yours.

Tonarr is a client for music you already control. It has no advertising network, no cross-app tracking, and no Pragmatic-hosted listening profile.

Last updated: August 31, 2026

Pragmatic Media Pass

Access uses a Pragmatic Media Pass account. Pragmatic receives the email address used to sign in, an opaque account identifier, opaque device-link identifiers, the app and platform linked, entitlement status, and store transaction references needed to validate, restore, refund, and support purchases. It does not receive your media-server password, library, searches, listening history, playlists, likes, lyrics, or playback URLs.

Monthly and annual subscriptions may be purchased through supported app stores or independently on the Pragmatic website. Apple, Google, Amazon, Stripe, and other payment providers process payment details under their own policies; Pragmatic retains entitlement and transaction-reference data, not full card numbers.

What Tonarr accesses

Tonarr connects only to services you choose, such as Plex, Jellyfin, or OpenSubsonic/Navidrome. Those services may return account identity, library metadata, artwork, lyrics, playback URLs, playlists, ratings, and play history needed for features you use.

When you start content-label verification, Tonarr sends the selected tracks' artist, song, album, duration, and available public recording identifiers directly to Apple and Deezer so their public catalogues can return advisory clean or explicit metadata. Tonarr does not send audio, file paths, server addresses, credentials, listening history, account or device identifiers, or advertising identifiers with those lookups.

Builds submitted through public app stores do not expose or perform music-request or acquisition actions; those capabilities and controls are disabled or omitted at build time rather than remotely hidden. Separate internal or privately distributed owner builds may optionally connect directly to an owner-controlled DroppedNeedle server. Legacy private builds may also support an older Tonarr Connector or a direct Lidarr connection.

Where data goes

Media-server sign-in, library, playback, download, search, rating, and playlist traffic goes directly from your device to the service you selected. The content-label lookup described above goes directly to Apple and Deezer. Pragmatic Developments does not proxy that traffic and does not receive your server credentials, listening history, library, searches, or content-label queries.

In a private build with DroppedNeedle enabled, you sign in directly to the private server with the account its owner created. Tonarr stores the server-issued revocable session in secure storage on that device and does not retain the entered password. The server owner controls account roles, approvals, limits, automation, availability, and request history. DroppedNeedle remains separate from Plex, Jellyfin, or OpenSubsonic/Navidrome, which continues to be the source for library browsing and playback. Pragmatic does not receive those request credentials or requests.

Legacy private connector or Lidarr tools likewise communicate only with the endpoint the owner configures. They are not part of builds submitted through public app stores.

Storage and synchronization

Server credentials are stored in Apple Keychain or Android Keystore-backed encrypted storage. Downloads, library caches, preferences, likes, content-label results, and optional listening history remain on your devices.

On Apple platforms, optional Device Harmony uses your private iCloud/CloudKit database to synchronize encrypted credentials and selected playback state across devices signed in to your Apple Account. Apple states that private CloudKit records are not visible to the developer through its portal. Android does not upload Tonarr app-continuity data to a Pragmatic-operated or owner-hosted relay.

Permissions and platform services

Local-network access is requested when connecting to a server on your network. Notifications, media controls, widgets, Spotlight/App Shortcuts, CarPlay, Android Auto, Cast, and Wear features are used only when their related feature is enabled. Apple and Android system media surfaces receive the now-playing information Tonarr publishes for playback controls. Tonarr does not sell data or use advertising identifiers.

On Android, Google's Cast Sender SDK automatically sends encrypted, anonymous app-activity and device diagnostics to Google so Google can improve Cast reliability and performance. Google says this SDK telemetry does not contain user or content metadata, is not used to model an individual user, and cannot be disabled or deleted by Tonarr or Pragmatic Developments.

Retention and deletion

Media Pass account, device-link, and entitlement records remain while the account is active and as needed for fraud prevention, refunds, tax, accounting, and legal obligations. Sign in at pragmatic.onl/media/activate to remove linked screens or permanently delete the Pragmatic account. Account deletion cancels an active Stripe Media Pass subscription immediately; subscriptions bought from Apple, Google, or Amazon must also be cancelled in that store account.

Disconnecting a media server removes its saved credential from that device; on Apple platforms, “everywhere” actions also remove the app-managed private CloudKit record. Listening history can be cleared in Settings, downloads can be removed in the app, and uninstalling removes local app data according to the operating system's rules. Data held by your own media services must be managed with those services.

In a private build, disconnecting DroppedNeedle asks that server to end the saved session before Tonarr removes it locally. If server-side revocation cannot be confirmed, the session may remain valid until you retry or the server owner revokes it. Requests and history retained by DroppedNeedle, a legacy connector, or Lidarr must be deleted under that private service's controls and policy.

Security and transport

Public servers must use HTTPS. Plain HTTP is permitted only for listener-selected loopback, local-DNS, private-address, or Tailnet hosts. Credentials are never accepted inside a server URL.

Contact

For Tonarr privacy, support, accessibility, or deletion requests, contact Pragmatic Developments Inc.

[email protected]