Privacy Policy
Updated October 3, 2026
How data is handled
ddPlayer browses and plays local, WebDAV, and authorized Baidu Netdisk and OneDrive files that you provide. The app does not automatically upload your media, server addresses, usernames, passwords, or viewing history to the developer. It contains no advertising or cross-app tracking functionality.
Storage on your device
Server configurations, preferences, recent items, and playback progress are stored on your device. Passwords are stored in the system Keychain without iCloud Keychain synchronization. Recent items are limited to 80 entries. Playback progress is cached for up to 30 days, subject to limits of 500 entries and 512 KiB. File and image caches support browsing and playback and can be cleared in Settings. You manage files that you explicitly download.
Servers you choose
When you connect to WebDAV, browse, play, download, upload, move, or delete files, the app sends the requests needed for that action to the server you choose. The server receives your IP address and the account information, paths, or file data needed to authenticate and fulfill the request. Direct media links may access addresses returned by that service. Those services process requests under their own privacy policies. HTTP connections are not encrypted; HTTPS connections use transport encryption. Local network permission is used to reach local servers you add.
OneDrive authorization
When you choose to connect OneDrive, you sign in and consent to file read access on Microsoft’s official website; ddPlayer does not read your Microsoft password. The app uses the authorization code flow with PKCE, without a developer-operated authorization server. Access and refresh tokens are stored in this device’s system Keychain to maintain the connection. The device requests file listings directly from Microsoft Graph and reads media directly from temporary download addresses provided by Microsoft, without routing media through the developer’s server. Selecting a folder sets the browsing entry point in the app and does not narrow Microsoft’s read authorization. Removing a source clears the corresponding authorization stored on the device without deleting cloud files. You may also revoke access in your Microsoft account’s app authorization settings.
Baidu Netdisk authorization
When you choose to connect Baidu Netdisk, you sign in and consent on Baidu’s official website; ddPlayer does not read your Baidu password. The developer-operated authorization service at auth.ddplayer.app is hosted by Cloudflare. It receives the authorization code and stores encrypted access tokens, refresh tokens, and authorization scope to maintain the connection. The service and hosting provider also receive connection information such as your IP address needed to process HTTPS requests. The device stores its session credential only in the system Keychain; access tokens are used in memory. The device requests directory listings and media directly from Baidu and its media services, without routing them through the authorization server. Removing a Baidu source requests deletion of its server session; if offline, cleanup is retried on a later launch. Incomplete authorization sessions are kept for at most 10 minutes. Connected sessions are cleared after 90 consecutive days of inactivity. You may also revoke app authorization in Baidu Netdisk’s authorization management. Removing a source in ddPlayer is separate from revoking the grant at Baidu.
Subscriptions and payments
Apple's App Store processes subscriptions. ddPlayer uses StoreKit to verify transactions on the device and determine available features. The app does not receive your payment card details or send subscription transactions to a developer-operated server. Restore Purchases requests updated transaction information from Apple. Apple processes purchase and related information under its own privacy policy.
Your choices
You can remove server configurations, manage local files, clear caches, and change local network permission in system settings. Manage or cancel a subscription through your Apple Account. Deleting the app does not cancel a subscription. Please do not include server passwords or unrelated sensitive information when contacting support.
Support and policy updates
If you email support, the developer receives the email address, description, and attachments you choose to send, and uses them to respond and resolve your request. You can use the address below for privacy questions or to request deletion of support correspondence, subject to legally required retention. We will update this policy and its date when the app's functionality or data practices change.