Quven is a self-hosted media server: it runs on hardware you control. Your media files and library folders stay on that hardware. Quven Account handles sign-in, linked servers and household profiles, and it stores profile data such as watchlists, ratings, reviews and resume points so that data survives reinstalls and follows you between servers. This policy explains that split.
1. Who is responsible for your data
The data controller for the Quven cloud services is Quven Technologies S.R.L., a single-member company incorporated in Italy, with registered office at Via Castellana 64, Scala E, Int. 17, 90135 Palermo (PA), Italy, registered with the Palermo and Enna Companies Register under VAT number and tax code 07445020824, REA PA-459244, certified email quventechnologies@pec.it. For any privacy request or question, contact support@quven.tv.
Quven was published by its founder as a natural person until 10 September 2026. Processing carried out before that date remains attributed to him; from that date Quven Technologies S.R.L. is the controller and answers for the personal data described in this policy.
2. Local data and explicit cloud exceptions
Your playable media files stay on your own server and devices. Quven Cloud does not build or host a copy of your media library. The following is local unless you deliberately use one of the cloud features described below:
- your media files, libraries and folder layout;
- local copies of metadata, posters and artwork fetched for your content;
- server settings, library folders and device-specific preferences;
- local cache copies of profile data used while the app is running.
We do not store your media files. When managed remote access is used, media bytes can transit the relay as described in section 5 without being retained. Metadata, subtitle and streaming-availability lookups use your server's configured provider credentials when you supply them. Without local provider credentials, the default managed mode sends the lookup request through Quven Cloud (api.quven.cloud) to the relevant provider. Managed requests can include search titles, years, external identifiers, file hashes, file sizes, language preferences and similar lookup parameters, but not the media file itself. Provider responses can be held in an account-anonymous, content-keyed cache until their expiry so identical lookups do not repeatedly contact the provider. See sections 9 and 11.
When a library holds books, your server also sends the names of the authors its books credit to the creator directory in Quven Cloud. That directory is one shared list of public names. An entry holds a name, the public identifiers found for it and its portrait, and nothing ties it to an account, a server, a library, a title or a file. Quven Cloud looks those names up on Wikidata to find the identifiers and a portrait. When a library holds music, your server asks Quven Cloud for an artist's description and portrait by the MusicBrainz identifier the scan found, and Quven Cloud reads them from Wikidata and Wikipedia. A portrait is a Wikimedia Commons image: Quven Cloud keeps a copy of it and your app loads it from Quven Cloud. Until that copy exists, your app loads it from Wikimedia's servers, which see your device's IP address as they would for any image on the web. See sections 9 and 11.
Quven Cloud keeps no copy of the posters, backdrops and covers a catalogue publishes. Your apps load them from that catalogue's own image server (TMDb, TheTVDB, AniDB, Amazon for the posters OMDb names, Open Library, Google Books, ISBNdb, AniList and Metron), which sees your device's IP address as it would for any image on the web, and your server downloads from the same servers the cover of a book it shelves.
If you use the optional Cloud Backup feature, Quven Cloud stores one replace-in-place compressed snapshot per server. It can include library names, types and absolute folder paths; provider identifiers and path-independent file hashes used to restore match decisions; and the names, descriptions and membership identifiers of collections and playlists. It does not include the media files, posters or descriptive provider metadata. The backup is linked to your account and deleted with it.
3. Quven Account information
Quven Account is required to use the desktop, web and native mobile apps. We process the data needed to operate that account and the household profile model:
- your email address and a securely hashed password;
- if you choose to sign in with Google or Apple, the identifier that provider returns for you (an opaque subject, never your password there), stored so the link is recognised next time. You can remove it from the account portal, which deletes that identifier and leaves the rest of your account untouched;
- session and device-authorisation records, hashed security tokens, multi-factor authentication state and account-recovery records;
- your subscription and entitlement status (tier, Founders status, validity);
- technical identifiers and pairing credentials of the servers you link to your account, used to issue and verify entitlement and to authenticate managed metadata, AI, relay, backup and other cloud requests made for that server;
- household profile metadata such as profile names, avatars and optional PIN hashes;
- per-profile user data such as watchlists, ratings, reviews, resume points, watched state, playback history sessions, playlists and collections;
- basic security and operational logs (such as timestamps and request metadata) needed to keep the service safe.
- a record of what happens to the account itself: sign-ins and sign-outs, password and two-factor changes, email changes, servers linked, renamed or unlinked, seats offered, taken, revoked or given up, profiles created or deleted, payments settled or refunded, the tier you are entitled to, an allowance running out and a consent you changed. Each entry carries the moment, the surface the request came from, the country the network reported and the name of what it concerns: a server, an invited address or a plan code, and never a media title. You read it in the account portal and we keep it for ninety days;
- the optional packs you asked to be told about, so we can write to you once one of them is sold;
- records of the legal and optional choices you make, including the document version, time and connection IP address used to evidence the choice.
We use this data to authenticate you, to deliver your licence entitlement, to sync your profile data, to authorise relay connections and to manage purchases and billing. First login and periodic token refresh require an internet connection; clients can keep working offline for a limited grace period of about seven days before they must refresh. The legal bases are performance of our agreement with you and our legitimate interest in operating and securing the service. We do not sell your personal data or use it for advertising.
3.1 Purchases
When you buy a plan, we process the data needed to take the payment, deliver what you bought and meet our tax and accounting obligations:
- the order: plan, price, currency, discount, taxes, the language of the order and the consents you give at checkout, with their time and the version of these documents;
- if you ask for an invoice, your Italian tax code or, for a business, its name, VAT number and electronic-invoicing recipient code or certified email address;
- the address you enter on the Stripe payment page, which is used to calculate the tax of your country; nothing is shipped to it;
- the payment method used and, for a card, its brand, last four digits and expiry date, which the billing section of the account portal shows. Full card numbers and security codes are held by Stripe and never reach Quven;
- renewals, refunds and disputes of your purchases.
Payments are processed by Stripe, which also processes payment data for its own fraud prevention and legal obligations under its own privacy policy. The legal bases are the performance of the purchase contract and our obligations under Italian tax law. Order, payment and invoice records are kept for the ten years Italian law requires of accounting records (article 2220 of the Civil Code), including after the account is deleted.
4. Diagnostics and crash reporting (opt-out)
Quven apps send diagnostics to help us fix crashes and performance problems. To keep a self-hosted product sustainable, they are on by default as a security and stability measure, disclosed during installation for desktop and server or through a one-time in-app notice on the web and native mobile clients, which transmit nothing until that notice has been acknowledged and diagnostics remain enabled. You can turn them off at any time in the app settings. When enabled, diagnostics are processed through Sentry (EU region) and are scrubbed to remove personal information and authentication tokens before they leave your device. Typical contents are error and performance traces, the app version and basic device and operating-system information. When an error concerns a film, a book or a search, the report may name the title or the search on which it occurred, because without that detail the error cannot be reproduced and its correction takes considerably longer for the person who met it and for every user who meets it afterwards. The report contains nothing that identifies a person, an organisation or a place: names, email addresses, company names, VAT numbers, IP addresses and locations are removed on the device before anything is sent, so the report that reaches Sentry describes the error alone. The legal basis is our legitimate interest in operating and securing the service.
4.1 Optional account-linked product analytics
Product analytics is off by default. If you enable it in Quven Account settings, a client sends a random installation identifier, client version, operating system and architecture together with a closed catalogue of setup, feature-use, aggregate scan, playback, update and reliability events. Scan events contain bounded totals and technical buckets, such as file-size, container, codec and resolution ranges, never one event per media item. Events are linked to a pseudonymous key derived from your Quven Account so we can understand activation, adoption and Quven-actionable failures across releases. Quven rejects unknown event names and does not accept media titles, identifiers, file paths, library names, search or review text, IP addresses, tokens, exception messages or free-form event properties.
The installation identifier is stored on your device and may also be included in Sentry diagnostics when diagnostics are enabled. This allows a product event and a scrubbed crash to be correlated without sending your email or display name to Sentry. You can withdraw product-analytics consent at any time; unsent events are deleted and subsequent product events are rejected. Linkable technical details expire after 90 days; product events and inactive installation rows expire after 395 days. Small, linkable cohorts are suppressed in internal reporting. Irreversible daily aggregate totals may be retained for up to 1,095 days. Account deletion removes account-linked analytics before the account is deleted. The legal basis is consent.
4.2 Optional viewing insights
Your servers already send us your resume points and playback history so a profile finds its place on another device. That sync is what makes the household model work and it happens whatever you decide here. What this consent adds is a reading of it: hours watched, films and episodes finished, how many titles and series were played, the screens they were played on and the hours of the day you watch, for each profile and for the whole account. While the consent is off, the section does not appear in the portal and we build none of those figures.
While it is on, we also read the same sessions in aggregate to understand how Quven is used across accounts: how long a viewing session runs, which kinds of title are finished, which clients play them. What leaves that reading is a total, never a row, and a count small enough to point at one household is suppressed. A title reaches these figures as a catalogue id, not as anything you typed. Withdraw the consent and the portal section closes at the next read and your sessions stop entering our aggregates; the ones already folded into a daily total stay there, because a total cannot be split back into the sessions it came from. The legal basis is consent.
4.3 Error reports you choose to send
When a Quven app meets an unexpected error, it offers to send us a report of it. Nothing can be sent until you tick the consent box and press Send, and that consent covers the one report alone. The report holds the complete error, the app version, the operating system and its architecture, the server version, how the app was connected and whether a session was open (never an access token), the app preferences, and the app and server logs of the day of the error and the day before. The web app keeps no log files, so the console messages and the pages visited in its tab take their place.
Before the report leaves your device, the app removes email addresses, IP addresses, the names of people, devices and servers, the name of the user folder and every credential, and the library database is never part of it. We store the compressed report on Hetzner in the European Union, linked to no Quven Account, read it only to find and fix the cause of the error, and delete it after 90 days. The dialog shows the report's reference, which you may quote to support to have the report deleted sooner. The legal basis is consent.
5. Remote access relay
If you enable the managed relay to reach your server from outside your network, connection-setup metadata transits our signaling service. A connection may use the Quven media relay and, where necessary, a third-party TURN relay (Cloudflare). Media requests and response bytes are then proxied transiently between your device and server. We meter aggregate bytes against your account and billing period, but do not store the media or inspect the contents for profiling or advertising. Reaching your server by your own means instead (port forwarding, reverse proxy, VPN) does not involve our relay at all.
6. Optional AI features
Managed AI matching is off by default and can be enabled or disabled in server settings on an entitled plan. When enabled and a deterministic match needs AI help, Quven sends the parsed title, year, runtime, original file name and candidate metadata through Quven Cloud to a third-party large-language-model provider. Quota records contain technical request identifiers, status, counts and a request fingerprint, not the submitted title or file name. If you configure your own compatible AI provider key instead, the server contacts that provider directly.
When you explicitly request AI subtitle translation, the subtitle text to be translated is sent through our cloud service to a third-party large-language-model provider, which returns the translation. The translated result is cached on your own server as a subtitle asset. To make retries safe, account-linked translated results can be held for up to seven days. A completed translation can also be stored in an account-anonymous cache keyed by a one-way hash of the source content, language, format and provider model for up to 90 days. We use managed providers on terms intended to prevent submitted content from being used to train their models. Both features run only when you choose their relevant control or action.
7. The Quven websites
The marketing site, the account portal and the payments site set no advertising or cross-site tracking cookies. Our network provider (Cloudflare) delivers and protects the sites and provides aggregate Web Analytics. Its injected beacon measures page views, visits and performance without cookies or local storage; it also processes limited connection metadata such as IP address. If you send a support request from the site, we store the name, email address, plan, platform, reason, subject, message and app version you submit so we can reply, and send the request through Brevo. Support requests are removed after no more than 395 days.
Every page of the marketing site also measures how it is used. The measurement covers every visitor and identifies no one. When a page is shown, used or left, it sends the Quven Cloud the page address without its query string, the page language, the referring site and any campaign parameters present on arrival, the window and screen size, the colour scheme and reduced-motion preference, the time zone, the languages the browser prefers and the connection type it reports, how long the page was in active use, how far it was scrolled, which sections came into view, which buttons, plans, questions and external links were chosen, video progress, page load times and script errors. The Cloud adds the country our network provider derives from the connection, the preferred language and the user agent, from which it reads the browser, the device type and the operating system. No cookie is set and nothing is written to the browser: each page load carries a random identifier that exists only while that page is open, so separate visits cannot be connected, and the IP address is not stored. When the browser tab already carries a campaign journey token, as described below, the events are linked to that journey. The registration, sign-in, email verification and checkout pages of the account portal and the payments site record in the same way which of their steps were reached and how each ended, without the email address or any account identifier. These events are used only for aggregate statistics about the Quven sites and are retained for no more than 395 days. The legal basis is our legitimate interest in understanding and improving the sites; the measurement stays within the limits the Italian Data Protection Authority set in its guidelines on cookies and other tracking tools of 10 June 2021 for analytics that require no consent.
Promotional and installer links can pass through a first-party Quven Cloud endpoint that issues a random journey token; only its SHA-256 hash is stored. A download event can contain the release, platform and architecture selected; a fixed campaign-source label when the link carries one; country and language; user agent and referrer; the Cloudflare request identifier; and a daily rotating hash derived from the connection IP address. The analytics row does not store the raw IP address, email address, media titles, file names or library data. If the journey token is later presented during account registration, the journey and related download can be linked to that account's internal identifier; otherwise it remains unclaimed and expires. The source label is selected by Quven from a fixed list and is not user-provided text. Raw request metadata and claim tokens are removed after seven days; linked attribution is retained for no more than 395 days. This measurement uses no cookie or persistent local storage. The clear token is held only in the current browser tab's session storage, removed from the visible landing URL and discarded when that tab session ends. The legal basis is our legitimate interest in understanding and improving product distribution with minimal data.
8. Email
We send transactional email related to your account, such as email verification, password resets, order confirmations and billing notices. We send product news, including offers on Quven plans, only if you chose to receive it when you created your account or later in its settings. Every such email says why you receive it and carries a link to stop it, and you can turn it off at any time in the Communications section of the account portal. Both kinds are delivered through our email provider (Brevo).
For each product-news email we keep a record linked to your account: the campaign and the version of the message, the address it went to, its language, your plan, whether you belong to the Founders programme, the country last seen on your account when it was sent, and any promotion code it carried. Brevo reports back whether the email was delivered or bounced, when it was first opened and clicked and how many times, and whether you unsubscribed or reported it as spam. An open is detected by an image in the email that loads when you display it, and a click by a link that passes through Brevo. Some mail apps load images in advance, so an open can be recorded that you did not make. When you buy the plan an email offered, we note the order it led to with its amount and currency, and a whole refund removes that note. Unsubscribing through the link, or reporting the email as spam, also withdraws your product-news choice in the account. We keep these records while your account exists and delete them with it, and we do not sell them or use them for advertising. The legal basis for sending product news is your consent; for the record and its measurement, it is our legitimate interest in knowing whether our communications reach and interest you, which you may object to through the contact in section 1.
8.1 Public article comments
If you comment on a Quven article, we process your public display name,
plain-text comment body, article and parent-comment identity,
timestamps, moderation state and any report or moderation reason. For an
account comment, we also process the account identifier. For a guest
comment, we record the guest_blog_comment identifier, the public
IP address, User-Agent, platform and architecture hints supplied by the browser,
the Cloudflare request identifier when available, and the version and timestamp
of the accepted comment rules. We do not request additional browser fingerprinting
signals. Approved comments show your public display name, body and timestamps
to anyone who reads the article. Public readers do not receive your email
address or account identifier. Authorised moderators can see the linked account
identifier and email address, or the limited guest network and device record,
together with reports and moderation history where needed to review abuse,
respond to a valid authority request and enforce the Terms.
Active comments and any account relationship remain while the comment and account exist, unless moderation or a deletion request removes them. The guest network/device record and rules-acceptance evidence are removed automatically after 395 days, unless a legal obligation requires a narrower case-specific hold. Rejected or hidden material, reports and moderation records are retained only as needed to operate and defend the community feature. Account deletion removes the author relationship and comment body. A minimal, content-free deletion marker may remain when an existing reply needs the conversation structure or a retained moderation record requires referential integrity; it is public only when needed for a published reply. Comment bodies, identifiers, moderation reasons and named participation are never product-analytics events. The legal bases are performance of our agreement for account comments and our legitimate interest in providing and protecting public discussions, preventing abuse and establishing, exercising or defending legal claims. You may object to processing based on legitimate interests through the contact in section 1.
9. Third-party services and where data goes
Depending on the features you use, data is processed by the following categories of providers, each under its own privacy terms:
- TMDb and OMDb: used to fetch movie and TV metadata, either directly with credentials you configure or through the managed Quven Cloud proxy.
- TVDB and AniDB: additional catalogues searched when you match a title or a series. Both are reached only through the managed Quven Cloud proxy, never directly from your server.
- Wikidata, Wikipedia and Wikimedia Commons: public reference data and portraits for book authors and music artists. Quven Cloud sends them names, public identifiers and a language, never your account, server or library. Quven Cloud keeps a copy of each portrait for your apps to load; until that copy exists, your app loads it from Wikimedia directly.
- MusicBrainz, Open Library, BookBrainz, Google Books, ISBNdb, AniList and Metron: music and book catalogues searched when a scan or a match needs them, with titles, names, ISBNs and identifiers. They are reached only through the managed Quven Cloud proxy; their cover images are loaded as section 2 describes.
- OpenSubtitles: used to search and fetch subtitles, either directly with credentials you configure or through the managed Quven Cloud proxy.
- JustWatch (via TMDb): source of streaming availability shown in the app.
- Google and Apple: sign-in providers, and only if you link one yourself. They tell us the identifier of the account you signed in with, and they learn that you signed in to Quven. Nothing else about you is sent to them, and no link exists until you make one.
- Sentry: diagnostics and crash reporting (EU region, opt-out).
- Cloudflare: content delivery and protection, aggregate Web Analytics, the managed TURN relay, DNS and inbound email routing.
- Hetzner: European hosting for Quven Cloud databases, account avatars, the portraits it keeps, the error reports you choose to send, server-backup snapshots and shared content caches.
- Brevo: transactional account and support email, and the product news you choose to receive, with the measurement of its delivery and engagement.
- A large-language-model provider: optional managed AI matching and on-demand AI subtitle translation.
- Stripe: payment processing for purchases, including the tax calculation and the address it asks for (see section 3.1).
10. Where your data is processed
Our cloud services run on infrastructure located in the European Union. Some third-party providers may process data outside the EU; where they do, appropriate safeguards (such as the European Commission's Standard Contractual Clauses) apply. We select providers and configure or contract with them to provide protection consistent with this policy and applicable law.
11. Data retention
We keep account, profile, linked-server, relay-usage, consent and the latest optional server-backup data while your Quven Account exists, subject to shorter technical-token lifetimes and any limited retention required for legal, accounting or security obligations. Expired device-authorisation rows are removed within 24 hours. Support requests are removed after 395 days. Account-linked AI translation results are minimized after seven days, and account-anonymous translated-subtitle cache entries are removed after 90 days. Managed metadata cache entries are removed when their provider-specific expiry passes. Creator directory entries and the portraits Quven Cloud keeps carry only public names, public reference data and public images, linked to no account, and are kept with no fixed expiry so every server shelving the same person reads the same entry. Diagnostics are kept for no more than 90 days, and so are the error reports you choose to send. Optional product analytics and linked marketing attribution are retained for no more than 395 days, with raw attribution metadata removed after seven days. Product-news email records are kept while your account exists and deleted with it. Order, payment and invoice records are kept for ten years, as section 3.1 describes. When you delete your account, we delete account-linked personal data and uploaded avatars, except where retention is legally required; irreversible aggregate statistics can no longer be connected to the account.
12. Your rights
Under the EU General Data Protection Regulation and applicable law, you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You may exercise these rights by contacting support@quven.tv. You can withdraw optional account consents in Quven Account settings or by contacting us. Account deletion is available in each native app under Settings → Account → Delete account and in the account portal. You also have the right to lodge a complaint with your local data-protection authority (in Italy, the Garante per la protezione dei dati personali).
13. Children's privacy
Quven is not directed to children, and a Quven Account is not intended for use by children below the age of digital consent in their country. We do not knowingly collect personal data from such children.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we revise the "Last updated" date above and publish the new version on this page. A revision does not ask you to accept the policy again. Processing that relies on your consent, such as product analytics and viewing insights, is asked for separately and can be withdrawn at any time.
15. Contact
For any privacy question or request, contact support@quven.tv or use the Support page. See also our Terms & Conditions.
The short version: your media files stay on your own server. Account, linked-server and profile data live in Quven Account; optional cloud backup, managed metadata, transient relay, diagnostics, the error reports you choose to send and optional AI are limited to what each feature needs. Managed AI matching is off by default and user-controlled, subtitle translation runs on request, and diagnostics remain controllable on every surface.