Purpose
iPlay is developed and operated by Loma Studio. It is a media player and media-library tool for Apple devices. You choose the local folders, network servers, or cloud accounts to connect. iPlay uses that access to browse directories, identify films and episodes, display their information, play media, and download files when you request a download.
Information iPlay accesses
For connected sources, iPlay reads folder and file names, identifiers, paths, file sizes, modification dates, media formats, and video, audio, and subtitle track information. Playback and downloads require reading the media file itself. The app stores library records, matching results, favorites, search history, playback positions, and preferences on your device. Local and network media are accessed through the source you select, such as Files, WebDAV, SMB, Emby, or Jellyfin.
Google Drive and Microsoft OneDrive
Google Drive authorization requests https://www.googleapis.com/auth/drive.readonly, openid, and email. The Drive permission allows iPlay to list folders, scan selected directories, read file metadata, and stream or download media. It permits read access to all Drive files, although the media library is built from folders you select. openid and email identify the signed-in account and display its email in the connection screen. iPlay does not request permission to edit, upload, or delete your Google Drive files.
Microsoft OneDrive authorization requests Files.Read, User.Read, openid, email, and offline_access. These permissions allow reading the signed-in user's files, displaying the account, and renewing access without repeated sign-in. iPlay does not request file-writing permissions. Google and Microsoft process the sign-in; iPlay does not receive your account password.
Access tokens, refresh tokens, their expiry times, and the displayed account email are stored in the device Keychain. Tokens are sent only to the relevant provider for authorized API access or renewal. Cloud file requests run directly between your device and Google or Microsoft; this integration does not use a Loma Studio proxy to collect your media files or OAuth tokens.
Sharing and third parties
To identify media and retrieve artwork, iPlay sends cleaned film or series titles derived from file or folder names, years, season and episode numbers, or media identifiers to TMDB. It stores the returned metadata and images locally. Google and Microsoft access tokens, account email, full cloud paths, and video or audio contents are not sent to TMDB.
Online subtitle searches send the search text or detected media title, media identifiers, year, episode information, and language preferences to OpenSubtitles.com. When available, automatic matching can also send a media-file hash and file size. Depending on the enabled subtitle service, searches may use SubDL or ASSRT. The selected provider receives the query and download requests, not your cloud account tokens. Subtitle synchronization analyzes audio and subtitle timing on the device; the current synchronization algorithm does not upload audio for speech recognition.
Apple processes iPlay Pro purchases through StoreKit. iPlay reads verified transaction and entitlement information to unlock purchased features; it does not receive your payment-card details. Network service providers receive the IP address and request information needed to deliver their services, and their privacy policies apply. If you email support, we use the information you supply to answer your request; do not include passwords, tokens, or private media in a support message.
iPlay does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Human access to Google user data is not part of normal app operation. We do not transfer cloud account credentials or media contents to unrelated services.
Retention and deletion
Library records and preferences remain on your device until you remove them or the app's data. Media downloaded by you and downloaded subtitles remain until you delete them; removing a cloud connection does not delete the original cloud files and may leave separately downloaded local files. Artwork and metadata caches can remain between sessions; use Clear Image Cache in Settings to remove cached images.
In Files, open the cloud-account connection screen and delete the added Google Drive or OneDrive account. This removes its locally stored authorization credentials and associated source and library records. To revoke the provider's grant as well, visit Google's third-party connections page or Microsoft's application-permissions page linked below. Removing the app does not necessarily remove Keychain entries or revoke provider authorization. Remove the connection and revoke access before uninstalling if you want to end access.
Manage Google account connections · Manage Microsoft account permissions
Security
Google and Microsoft connections use HTTPS and OAuth Authorization Code with PKCE. Account passwords stay with the provider. iPlay protects stored cloud authorization tokens with the system Keychain and validates authorization callbacks. Use a device passcode and connect only to media sources you trust. For user-configured network sources, transport protection depends on the protocol and server address you choose.
Google API Limited Use
iPlay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services User Data Policy
Contact
For privacy questions, deletion requests concerning information you sent to support, or questions about your permissions, contact Loma Studio at [email protected]. You can also visit our Support page. We update this policy when our data practices change and show the revised date here.
