Privacy Policy
1. Summary
Yak is a local-first podcast player. Subscriptions, downloads, queue, playback history, and settings are stored on your device (and may be included in your Google/Android Auto Backup when that system feature is on — see §3.1a). We do not run ads, sell personal data, or use third-party analytics or crash-reporting SDKs.
The free app uses the internet for actions you request and for any background refresh or downloads you enable: fetching podcast feeds, artwork, and episode audio; and discovering shows (Podcast Index and/or Apple iTunes Search). We do not currently offer Cloud sync, gpodder sync, or any other remote library sync in the shipped Settings UI — use OPML export or an encrypted on-device backup to move your library. We do not store your library on our servers. If that changes, we will update this policy before that feature is offered.
This policy also covers yakplayer.com, our support email, optional content-report emails, and short-lived edge logs for our discovery Worker and website (§3.6–§3.8).
2. Who we are
| Developer / data controller | TGC Network LLC (“we”, “us”) |
| App | Yak (com.tgcnetwork.yak) |
| Website | https://yakplayer.com |
| Support / privacy contact | support@yakplayer.com |
| Support page | https://yakplayer.com/support |
3. Data we process
3.1 Stored only on your device (not sent to TGC Network LLC)
| Data | Purpose | Storage |
|---|---|---|
| Podcast subscriptions, episode metadata | Library and feed UI | Local database (Room) |
| Playback position, played/finished state, history | Resume and history | Local database |
| Queue order | Playback order | Local database |
| Downloaded episode audio | Offline playback | App-scoped device storage |
| App settings (skin, speed, etc.) | Preferences | Local DataStore / database |
| Optional Save debug logs (beta) | Crash/error logs you may share | App-private files (see §5) |
| Hidden shows/episodes (report/hide) | Keep objectionable content out of your library | Local DataStore only |
None of the above is uploaded to TGC Network LLC servers as part of normal free-app use.
3.1a Android Auto Backup (system feature)
The app allows Android’s Auto Backup / cloud backup for the user’s Google account. Sync credential stores (reserved for future sync features) are excluded from backup. Other on-device library data (subscriptions, history, settings, downloads) may be backed up by Google’s backup service when you have system backup enabled. That copy is controlled by your Google account and Android backup settings — it is not a TGC-hosted Cloud sync product.
Erase data on this device, clearing app data, or uninstalling Yak removes the local copy on this device only. Those actions do not delete the Google Auto Backup copy. If you reinstall Yak, Android may restore app data from that Google backup unless you manage or delete the backup in Android or Google settings.
3.2 Sent to third parties as part of normal app use
Your device’s IP address is visible to each server it contacts (how the internet works). We do not run a separate analytics pipeline on those IPs.
| Destination | What’s sent | When | Why |
|---|---|---|---|
| Podcast / feed hosts (publishers or their CDNs) | HTTP(S) requests for feed URLs, episode audio, artwork you open or download | Subscribe, refresh, play, download, display art | Load shows and media you requested |
| Podcast Index (via our discovery proxy — §3.3) | Search terms; trending/discovery requests | Discover / search | Find shows |
| Apple iTunes Search API | Search terms; trending fallback requests | Discover / search fallback | Find shows when Podcast Index is unavailable |
We do not send advertising IDs, analytics events, or tracking pixels to these parties. gpodder.net is not contacted by the free v1 Settings UI (there is no sync opt-in path).
3.3 Our discovery proxy (not Cloud sync)
Release builds may call a Cloudflare Worker we operate so Podcast Index API credentials are not stored in the app. That Worker:
- Accepts discovery/search/trending requests from the app
- Signs and forwards them to Podcast Index
- Is not a library sync or backup service — it does not store your subscriptions, queue, or playback positions
Standard short-lived operational logs (e.g. Cloudflare edge/Worker logs including IP, request path, status, timestamps) may exist for security, abuse prevention, and reliability. We do not use them to build advertising profiles or a user library archive. See §9 for retention.
3.4 Data you export yourself
- OPML and encrypted
.tgcbbackups (legacy.wspimport still supported) are written to a location you choose. We never receive those files unless you email them to us yourself. - Import (OPML,
.tgcb, compatible backups) is processed on-device.
3.5 What we do not offer today
- No Cloud sync — no TGC-hosted account, opaque sync token, or server-side subscription/progress store.
- No gpodder (or other) sync in Settings — remote sync UI is not shipped in free v1; move libraries with OPML /
.tgcb. - No user accounts with us — no email/password registration with TGC Network LLC.
- No ads, no sale of personal data, no third-party analytics/crash SDKs.
3.6 Website visitors (yakplayer.com)
Our marketing and legal pages are hosted on Cloudflare Pages. When you visit:
| Recipient | What’s processed | Purpose | Retention |
|---|---|---|---|
| Cloudflare | IP address, User-Agent, requested URL, referrer, and similar edge telemetry | Serve pages over HTTPS; security and abuse protection | Short-lived operational logs per Cloudflare defaults — not a Yak user account database |
| Google Fonts (fonts.googleapis.com / fonts.gstatic.com) | IP and User-Agent when the browser loads webfonts used by the site | Display site typography | Per Google’s policies |
We do not run a separate analytics SDK on the site. We do not offer a website newsletter signup and do not collect email addresses through yakplayer.com forms.
3.7 Support email, UGC reports, and shared diagnostics
| Channel | What we receive | When | Purpose | Retention / rights |
|---|---|---|---|---|
| support@yakplayer.com | Your email address, subject, message body, and any attachments you include | You write to support or privacy | Support, privacy/DSR requests, product feedback | Kept in ordinary business email until the matter is resolved and as needed for records; you may ask us to erase mailbox copies we control |
| UGC report (mailto from the app) | Show/episode metadata and reason pre-filled by the app — only if you send the message from your mail app | You choose Report | Review objectionable-content reports | Same as support email. Hide lists stay on your device |
| Account / data deletion request | Whatever you send via https://yakplayer.com/delete-account | You request deletion | Process deletion / confirm free-tier has no server library | Same as support email |
| Diagnostics you share | Opt-in crash/error text you copy, share, or attach | You manually share from Settings | Debug a problem you reported | Same as support email; on-device reports remain under your control until you clear them |
We do not automatically upload diagnostics. We only see report or support content after you send it.
3.8 Edge / Worker operational logs
Discovery Worker and website CDN logs (IP, path, status, time) are processed for security and reliability only. Recipients: Cloudflare as infrastructure provider; TGC Network LLC as operator. They are not used for advertising and are not a substitute for a user library. Contact support@yakplayer.com for access or erasure requests relating to logs we can reasonably identify.
4. Permissions
| Permission | Why |
|---|---|
INTERNET |
Feeds, artwork, audio, discovery |
FOREGROUND_SERVICE / FOREGROUND_SERVICE_MEDIA_PLAYBACK |
Reliable background playback + media notification |
POST_NOTIFICATIONS |
Playback controls and optional new-episode alerts |
WAKE_LOCK |
Avoid sleep mid-playback |
We do not declare Play Billing in the free-v1 merged manifest. We do not request location, contacts, camera, microphone, SMS, or broad storage permissions. Downloads use app-scoped storage and the system file picker for import/export.
5. Analytics, advertising, diagnostics
- No Firebase Analytics, Crashlytics, ads, or similar SDKs.
- Optional on-device diagnostics (off by default): if you enable Save debug logs (beta) in Settings, sanitized crash/error details stay on your device. Nothing uploads automatically; you may copy/share or clear reports. Disabling the setting deletes stored reports.
- Report or hide (Play UGC): you can hide shows/episodes on this device, and optionally email a report to support@yakplayer.com via your mail app. Hide lists stay on-device; we only receive a report if you send the email.
6. Security
- Local data sits in Android’s app sandbox.
- Encrypted
.tgcbbackups use on-device encryption before write. - We use HTTPS/TLS for our website and discovery services. User-chosen podcast feed, artwork, and media URLs may use HTTP; those connections are not encrypted.
- Future sync credentials (if sync UI ships later) are designed for Keystore-backed encrypted preferences and are excluded from Auto Backup.
7. Your choices and rights
- No account required for the free app.
- Export (portability): Settings → Privacy → Export my data (encrypted
.tgcbbackup or OPML), or Settings → Import / export. - Erase: Settings → Privacy → Erase data on this device (library, downloads, hide lists, diagnostic logs). Uninstall / clear app data also removes the local device copy only (see §3.1a).
- Web deletion request (no login): https://yakplayer.com/delete-account — email path for account/data deletion requests (works without reinstalling the app). Free v1 has no TGC server library to delete.
- Website / email / logs: contact us to exercise access or erasure for support emails or identifiable edge logs we control.
- EU/UK (GDPR): to the extent IP addresses or discovery requests constitute personal data processed via our Worker, site CDN, or visible to publishers, processing is for providing the service you requested (or legitimate interests in securing the site/Worker). Use in-app export/erase for data on your device; contact us for requests related to data we control.
- California (CCPA/CPRA): we do not sell or share personal information as those laws define “sale”/“share” for advertising.
8. Children’s privacy
Yak is not directed at children. We do not knowingly collect personal data from children under 13 (or the applicable age of digital consent). Contact us if you believe otherwise.
9. Retention
| Data | Retention |
|---|---|
| On-device library, downloads, settings, history | Until you delete it or uninstall the app |
| Opt-in diagnostics files (on device) | Until you clear them or turn diagnostics off |
| Support / UGC report / deletion emails | Ordinary mailbox retention until resolved + needed records |
| Discovery proxy / Pages / CDN operational logs | Short-lived security/ops logs only — not a user library archive |
| Google Fonts requests | Per Google |
| TGC Cloud / gpodder sync server data | N/A — not offered in free v1 Settings |
10. Third-party content
Feeds, audio, and artwork are hosted by independent publishers. Your device connects to them directly. Their privacy practices are their own. Website webfonts are loaded from Google Fonts under Google’s terms.
11. Changes
We may update this policy when the app or site changes. The Effective date / Last updated line will change. If we launch Cloud sync, gpodder Settings sync, or another product that stores data on our servers or contacts new sync providers, we will revise this policy before that feature is offered and describe the new data, lawful basis, and retention.
12. Contact
Privacy questions and requests: support@yakplayer.com · https://yakplayer.com/support · Account/data deletion: https://yakplayer.com/delete-account