H HFXHQ

HAMFIN Privacy Policy

HAMFIN is an Android TV client that connects to media services selected by the user. This policy explains what the app handles, where information goes, and the controls available to users.

Effective and last updated: July 30, 2026

In short: HAMFIN contains no advertising SDKs and does not sell personal information. Most information is exchanged directly with the Jellyfin and optional companion services that a user chooses to connect.

1. Scope and operator

This policy applies to the HAMFIN Android TV application, package com.hfxhq.hamfin, operated by HFXHQ. HAMFIN is a client application; it does not provide a media library or streaming subscription. The person or organization operating a connected Jellyfin, Radarr, Sonarr, or other server may have its own privacy practices.

2. Information HAMFIN handles

3. How information is used

HAMFIN uses this information only to provide and maintain app functionality, including:

HAMFIN does not use personal information for advertising, cross-app tracking, or sale to data brokers.

4. Where information may be sent

5. Storage, security, and transmission

HAMFIN stores connection details, tokens, Requests credentials, optional service API keys, settings, and caches in app-private storage on the Android device. Credential databases and preferences are excluded from Android cloud backup and device transfer. App-private storage is protected by Android's application sandbox, but credentials are not separately encrypted by HAMFIN at the application layer.

HAMFIN Requests uses HTTPS. HAMFIN also supports user-configured HTTP addresses so it can reach local media servers. Information sent over HTTP is not encrypted in transit. Users should use HTTPS for any service reached over an untrusted network and should protect server and device access.

6. Retention and user controls

7. Delete a HAMFIN Requests account or data

Users can request deletion of an account created or linked by the HFXHQ-operated HAMFIN Requests service, along with its associated request history and personal information.

Request account and data deletion

In the email, include the Requests/Jellyfin username and the domain of the connected Jellyfin server so the correct account can be identified. Do not send a password, access token, API key, or PIN. Additional verification may be requested to prevent unauthorized deletion. HFXHQ will complete verified deletion requests within 30 days unless limited retention is required for security, fraud prevention, or legal compliance.

This process covers the HFXHQ-operated HAMFIN Requests service. To delete a Jellyfin account or information held by any independently operated server, contact that server's administrator.

8. Children

HAMFIN is a general-audience media client for use with a server configured by an account holder and is not directed to children under 13. A library or navigation section containing children's media does not change the app's intended audience. HFXHQ does not knowingly use the HAMFIN Requests service to collect personal information directly from children. A parent or guardian may contact HFXHQ to request deletion if they believe a child supplied information.

9. Changes and contact

This policy may be updated when HAMFIN's features or privacy practices change. Material changes will be reflected by updating the date at the top of this page.

Privacy questions and deletion requests can be sent to jeffery.hamstra@gmail.com.