The short version

PearCinema collects no personal data. Your films never leave the machine they already live on, except to play on a device that has been let in. There is no PearCinema account and no PearCinema server holding anything about you.

Where your data actually sits

There are two places, and PeerLoom runs neither of them.

On the machine holding the films, which is yours or a friend's. That machine keeps the video files themselves, an index of them so the app can browse quickly, the list of which devices are allowed in, the names people chose for themselves and their devices, and per-person viewing history such as favourites, what has been watched and where you got to in a film.

On your phone. Your device's own identity key, which is what a library recognises you by, anything you have downloaded to watch offline, and your app preferences.

Nothing is copied anywhere else. If you stop using PearCinema, deleting the app removes everything on the phone, and whoever runs the library can remove your access and your history from their dashboard.

How your phone reaches the library

Your phone connects straight to the machine holding the films, over the peer to peer network built on the Hypercore Protocol. There is no PearCinema server in between, and no copy of your library in a cloud anywhere.

Every connection is encrypted end to end and authenticated in both directions, so the library knows exactly which device is asking and your phone knows it is talking to the right library. There are no passwords or tokens involved: your device's identity key is the whole credential, it is generated on the phone and it never leaves it.

Because that key is what a library recognises, access is a decision the library owner makes and can undo. Removing a device from the dashboard cuts it off immediately, including a device that is playing a film at that moment.

When a direct connection cannot be made

Nearly all of the time your phone and the library connect to each other directly. On a small number of networks that direct connection cannot be made at all, and mobile networks are the common case. When that happens PearCinema can fall back to a relay that PeerLoom runs, which passes the encrypted traffic between the two ends.

The relay cannot read what passes through it. Your films, your browsing and your viewing history stay encrypted end to end and PeerLoom holds no key to them. What a relay unavoidably handles is the fact that two ends are talking, identified by random public keys rather than names or email addresses, along with the timing and the amount of data. The relay keeps no record of it and stores nothing.

The relay is a last resort and never the first choice. It is offered only after a direct connection has actually been attempted and failed, or where the network makes one impossible from the start. While a film is coming through the relay its quality is capped, so that watching away from home does not quietly consume a mobile data plan. Full detail: The PeerLoom relay.

If you would rather not use ours, you can paste in the details of a relay you run yourself, and yours is used instead.

Looking up film descriptions and posters

A video file usually carries a filename and nothing else, so a library of plain folders needs somewhere to get titles, descriptions and posters from. PearCinema takes them from the disk first: the description and artwork files that Kodi, Sonarr or Radarr may already have left beside your films, which needs no internet at all.

Beyond that, the person running the library can switch on lookups from The Movie Database. This is off unless they turn it on, and turning it on means supplying their own key from that service. When it is on, the machine holding the films sends film and episode titles to that service in order to get descriptions and artwork back. Your phone never contacts it; only the library machine does, and only about titles, never about who is watching or what they watched.

If the library is connected to a Jellyfin or Emby server instead, PearCinema simply uses what that server already knows and looks nothing up.

Playing on a television

PearCinema can send a film to a television on the same network, such as a Roku or a Samsung set. To do that, the machine holding the films offers the video to that television over your own local network, and your phone acts as the remote control.

Two things worth being plain about. The television is on your network, not ours, and nothing about the film goes outside it. And the television is a device the library owner has not personally let in the way a phone is, so if access is revoked, PearCinema stops the television as well rather than leaving it playing.

Permissions

  • Camera: Used to scan the pairing code shown by a library's dashboard. Nothing is recorded or stored.
  • Network access: Used to reach the library directly, and for the relay fallback described above. No readable data is sent to any server.
  • Local network: Used to reach a library on the same network as your phone, so a film travels across your own home rather than out to the internet and back. On iPhone this is the permission the system asks about the first time.
  • Notifications: Used to show the controls for a film playing on a television, and to tell you when a download has finished.
  • Keeping the screen awake: Used so the picture does not switch itself off while you are watching.

Films you download to watch offline are kept in the app's own private storage, which needs no permission at all and which nothing else on the phone can read. Deleting the app removes them.

PearCinema asks for no location, no contacts, no microphone and no access to your photos or your files.

No tracking or analytics

PearCinema contains no analytics, no advertising SDKs, no crash reporting services and no third-party trackers of any kind. Nobody at PeerLoom can see what you watch, because nothing about it is ever sent to us.

No accounts

PearCinema does not require you to create an account or provide an email address. Your device's identity is a cryptographic key pair generated on the phone itself. The name you choose is shown to whoever runs the library you pair with, so they can tell whose device it is, and to nobody else.

PearCinema hosts nothing and indexes nothing

Worth stating plainly, because it is the question a video app invites. PearCinema is a player for files you already have on a machine you already own. It has no catalogue of its own, offers nothing to search for or download, and provides no way to obtain a film. It cannot see what is in anybody's library, and there is no central list of libraries anywhere.

If the library belongs to someone else

Worth being plain about, because it is the one thing PearCinema cannot decide for you. When you are let into a friend's library, that friend's machine sees which of their films you play, and can see the name you gave yourself. That is how viewing history and resume points work at all, and it is the same information they would have if they lent you a hard drive and watched you use it.

PeerLoom never sees any of it. It stays between you and the person whose library you asked to join, and either of you can end that at any time.

Open source

PearCinema is fully open source, both the app and the server software. You can inspect the complete source code at github.com/peerloomllc/pearcinema.

Contact

Questions about this privacy policy? Reach out at peerloomllc@proton.me.

Effective date: August 25, 2026