Privacy policy
BufferedTV Studio collects nothing.
BufferedTV Studio is an independent app for running PeerTube channels on iPhone, iPad and Mac. This is exactly what it keeps, what it sends, and to whom.
Last updated 5 October 2026
The short version
This app collects nothing. There is no analytics, no tracking, no advertising, no crash reporting and no third-party code of any kind. Nothing is sent to the developer, because there is no server belonging to the developer to send it to.
Everything the app does, it does directly between your device and the PeerTube instances you sign in to. Subtitles it writes, and translations it makes, are made on your device.
What stays on your device
| Data | Where it is kept | Why |
|---|---|---|
| Your sign-in tokens for each account | The device’s keychain, on this device only: they are left out of backups and never move to another device | So you stay signed in |
| The accounts you have signed in to: username, instance address, display name, the address of your avatar and the instance’s name, and which account is open | App preferences on the device | So the app can list your accounts and reopen the one you were using |
| Videos on their way up: the app’s own copy of each file, the details you gave it, its thumbnail, and any subtitles and translations written for it | The app’s own storage on the device, left out of backups | So an upload interrupted by a lost connection or a restart can carry on. Each is deleted once it is on your instance, or when you cancel it |
Your instance password, and a two-factor code if your account has one, are used once, to get a sign-in token from that instance, and are never stored.
Deleting the app removes its preferences and its storage. The keychain is looked after by the system, which may keep its items after the app has gone; signing out of each account deletes them.
What is sent, and to whom
The app talks to three kinds of server, and to nothing else.
1. The PeerTube instances you sign in to
When you sign in, your username and password (and a two-factor code, if asked for) are sent to that instance, and only that instance, to get a token. Before that, the app asks the address you typed for its public settings, to check it is a PeerTube server.
After that, everything you do in the app is a request to the instance the account belongs to, sent with that account’s token: listing and editing your videos, uploading them, adding subtitles and chapters, reading and answering comments, moderating, managing channels, playlists, live streams and imports, reading your notifications, and reading the statistics your instance keeps about your videos. The app only reads those statistics; it adds nothing to them.
Uploads. A video, its thumbnail and the details you gave it go to the instance you are uploading to. Subtitles written on the device go to the same place, once the video is up.
Comments. A reply you write is sent to your instance under your account, and it is public: your instance shares it with the rest of the network, like any PeerTube comment. The app keeps no copy.
Imports. When you import a video from a web address or a magnet link, or sync a channel from another site, you send that address to your instance, and your instance fetches the video itself.
2. Wherever your instance keeps its files
Thumbnails, avatars, banners, video files and subtitle files are loaded from the addresses your instance gives for them. Usually that is the instance itself; some instances keep files with a storage service instead. To write subtitles for a video that is already published, the app downloads the smallest copy of it with the sound in, listens to it, and deletes it; to translate a subtitle track, it downloads the track. Those servers see your IP address and the usual details any web request carries, as they would if you visited them in a browser.
3. Apple, for speech and language support
Subtitles are written with Apple’s on-device speech recognition, and translated with Apple’s on-device translation. The first time you write subtitles in a language, or translate into one, your device downloads what it needs for that language from Apple, as part of the system, and may ask you first. The app sends Apple no sound, no text and nothing about your videos: listening and translating both happen on your device.
If your device asks whether BufferedTV Studio may use speech recognition, this is what it is for: writing subtitles from your videos’ sound, on the device.
Each of these services has its own privacy policy, which the app has no control over.
What the app does not do
- It does not collect, transmit or sell personal data.
- It does not contain analytics, telemetry, advertising or tracking of any kind.
- It does not use third-party code or SDKs.
- It does not track you across apps or websites, and requests no tracking permission.
- It does not send your videos’ sound or subtitles anywhere but your instance.
- It has no developer-operated backend. There is nowhere for your data to go.
The app’s privacy manifest says the same to Apple: no data collected, no tracking, and the two system features it uses and why. It reads and writes its own preferences, to remember your accounts, and it checks when its own upload files were last changed, to tidy away any left behind.
Children
BufferedTV Studio is a tool for people who publish videos, and it needs an account on a PeerTube instance, each of which sets its own rules, including on age. It is not designed for children.
Your control
- Sign out of an account in Settings ▸ Accounts. This revokes its token with the instance, deletes it from the device and forgets the account. Your videos and channels stay where they are.
- Cancel an upload, or clear finished ones, from the list of uploads, which deletes the app’s copies.
- Delete any subtitle track from a video’s Subtitles page.
- Deleting the app removes its preferences and storage. Sign out of each account first to empty the keychain too.
Contact
Questions about this policy: ric@squarecows.com
Help and support: studio.buffered.tv/#support