Your library stays yours
Privacy policy
Effective 4 October 2026
Up Next connects directly to the Jellyfin server you choose. We do not operate a media service, collect your viewing history on our servers, or include advertising or analytics SDKs in the app.
Your Jellyfin connection
The app sends your login information to your selected Jellyfin server to authenticate. Your password is not stored by Up Next. The returned access token is stored in Apple’s Keychain on your Apple TV. Your server address, username, user identifier, an app-generated device identifier and preferences are stored locally so you can reconnect without entering everything again.
Your selected server receives requests for your library and images, searches, playback negotiation, selected audio and subtitle streams, playback position, watched state and session updates. Its operator can see network information such as your IP address and apply their own retention and privacy practices. If someone else operates that server, ask them how your information is handled.
Local caches and the Apple TV home screen
Up Next caches media metadata, episode information, viewing progress and artwork on your Apple TV to make browsing quicker. A small local snapshot of Continue Watching titles and images is shared with the app’s Top Shelf extension to show them on the Apple TV home screen. The extension does not receive your password or access token.
Personal collections and preferences
Your collections, collection rules and exclusions, watch-chooser preferences, hidden Continue Watching titles, language preferences and last browsing position are stored locally for the selected server and user on this Apple TV. Discovery and the watch chooser use Jellyfin library metadata and viewing state; they do not send your library to an external AI or recommendation service. Collections and these preferences are not synchronised to other devices. Signing out disconnects the account but its local preferences and collections can remain for a later sign-in.
Diagnostics
The app uses Apple’s local system logging for connection status, response codes, cache behaviour and playback diagnostics. Technical logs can contain server hostnames, media identifiers and error information. Passwords and authentication tokens are not intentionally logged. We do not automatically upload these logs to our servers.
Tracking and advertising
Up Next does not use advertising identifiers, behavioural advertising, cross-app tracking or third-party analytics SDKs. We do not sell your personal data. The app does not request access to your contacts, location, photos, camera or microphone.
Your choices and retention
Sign Out removes the saved access token and connection, the current library snapshot and the Top Shelf snapshot. Artwork and other local caches may remain until evicted by the app or operating system. Removing the app removes its local app data; shared-container data can remain while another installed component uses it. You can revoke the app’s session on your Jellyfin server. Watched state and history already sent to the server are controlled by that server, not erased by signing out of Up Next.
HTTPS is preferred when you enter a server without a scheme. HTTP is supported for servers that require it. HTTP does not encrypt login or playback traffic, so use HTTPS when your connection requires transport protection.
Support email
If you email [email protected], we receive your email address and whatever you choose to send. We use that information to respond and handle the support request. Please do not email your Jellyfin password or access token. For access, correction or deletion requests concerning support correspondence, contact the same address.
This website
This site is hosted on Cloudflare Pages. We do not add analytics scripts, advertising, forms or tracking cookies. Cloudflare processes request information such as IP addresses and browser details to deliver and protect the site under its privacy policy. Your email application handles mail links.
Children and media
The app does not provide a catalogue or collect children’s profiles for us. Media availability and user restrictions are determined by the selected Jellyfin server. Its administrator should configure appropriate permissions for each user.
Changes and contact
We may update this policy when the app or its data handling changes. The current policy and its effective date will be published here. For privacy questions, contact the Up Next developer at [email protected].
Up Next