Bandit is a media player for the servers and shares you already own. It has no account, no analytics, and no servers of ours in the middle. This page describes exactly what the app does with your data — which is almost nothing.
Effective: 25 July 2026 · Applies to: Bandit for iPhone & iPad, version 1.0
There is no Bandit account and nothing to sign up for. The app contains no analytics, advertising, or tracking of any kind. Your source logins are kept in the iOS Keychain, marked so they never leave the device. Everything the app caches — your libraries, artwork, watch progress — stays on your device. Every network connection goes straight from your device to the servers you configure; none of your data passes through, or is stored on, any server operated by us. We have nothing of yours to sell, share, or lose.
Bandit is an independently developed app (bundle identifier dreadmclaren.Bandit). In this policy, “we” and “us” mean its developer. The best way to reach us about privacy is banditmpapp@gmail.com.
To be exact, the app contains no code that does any of the following:
The only third-party code bundled in Bandit is the open-source VLCKit media framework, used on your device for playback. It is not an analytics or advertising component.
To reach a source — Plex, Jellyfin, Emby, an IPTV portal (M3U or Xtream), a WebDAV or SMB share, or a Stremio-style add-on — Bandit needs its address and sign-in details. You provide those, and they are used only to talk to that service. Depending on the source that means an access token, a username and password, an API key, or a playlist URL.
Each service you connect to has its own privacy practices, governed by that provider’s policy — not this one.
So it can be fast and work offline, Bandit keeps the following only on your device:
None of this is transmitted to us. It is created on your device and stays there until you clear it or delete the app.
Bandit talks directly from your device to the servers you set up. There is no Bandit server in the path, so your traffic, credentials and library contents never reach us.
Artwork, descriptions and ratings shown in Bandit come from the servers you connect — Plex, Jellyfin and Emby supply their own. A rating may be labelled by its origin (for example “TMDB 7.2”) because your server tagged it that way; Bandit itself does not contact TMDB or any external metadata service. Add-on catalogues you choose to install are third-party services — when you use one, your request goes to that provider under its own terms, not ours.
Bandit Pro is sold through the Apple App Store using Apple’s in-app purchase system (StoreKit). Payment is handled entirely by Apple — we never see or receive your card or billing details — and the app learns only whether a valid purchase or subscription exists, which is what unlocks Pro. Apple’s handling of purchase data is covered by Apple’s Privacy Policy. Bandit uses no third-party payment or subscription-analytics service (such as RevenueCat); entitlements are checked on your device with StoreKit.
You are always in control. Remove an individual source to delete its stored credentials, clear Bandit’s cached catalogue and downloads from the app’s settings, or delete the app to remove everything it created on your device. Because nothing is stored on our side and nothing syncs to a cloud account, deleting locally deletes it everywhere.
Bandit is not directed at children and we do not knowingly collect personal information from anyone. Because the app collects no personal data at all, it builds no profile of any user, of any age. The content you reach through Bandit comes from your own sources and is your responsibility to manage.
Some regions grant rights to access, correct, export, or delete personal data a company holds about you — for example under the GDPR (EU/UK) or CCPA/CPRA (California). Because we operate no server and hold no personal data about you, there is in practice nothing for us to retrieve or erase; all data the app creates lives on your device, under your control. If you believe we hold data about you, email us and we will respond promptly.
If this policy changes, the “Effective” date above will change with it, and the current version will always be at this address. Continued use after an update means you accept the revised policy.
Questions about your privacy: banditmpapp@gmail.com.