Legal

Privacy policy

Effective 2 October 2026

In short

  • Tortuga is a video player and provides no content. The addons you install, and the servers they point to, get your requests directly. Tortuga’s own server is not in that path.
  • With a Tortuga account, Tortuga’s server keeps your sign-in identity, your devices and what you sync. It can read what you sync, and stores it encrypted at rest. There is no end-to-end encryption.
  • Official builds send crash reports, with addon and stream links removed, unless you turn them off.
  • No ads, no analytics, and your data is not sold.

Who is responsible

Tortuga is an open-source project by its developer, edde746 on GitHub, who runs Tortuga’s hosted server at api.usetortuga.app and is responsible (the “controller”) for the data it holds. A server that someone else runs is that operator’s responsibility; see Self-hosted servers.

This website

usetortuga.app is a set of static pages. It sets no cookies and runs no scripts, analytics or ads. The service that hosts it may keep ordinary request logs, as any web server does.

Data on your device

The apps store on your device:

  • your profiles: name, avatar, preferences, and a PIN if you set one, as a salted hash;
  • each profile’s addons and their order. An addon’s link can contain keys for services you set up in that addon;
  • your library, watch progress and watched marks, and the last stream you picked for each video;
  • profile settings, this device’s settings, and recent searches, which stay on this device;
  • a cache of artwork, and, if you use an anime tracker, two public lists that map anime IDs between services. Addon responses are cached in memory only, while the app runs.

Your session with the sync server and your tracker sign-ins are kept in the system’s secure storage: the Keychain on Apple devices, the Android Keystore, Windows Credential Manager, or the Secret Service on Linux.

A profile PIN locks the profile picker. It is a convenience, not strong protection: someone with full access to the device and its data could get around it.

While a video plays, its title, episode and artwork appear in your system’s media controls (Now Playing on Apple devices, the media notification on Android, the media controls on Windows, MPRIS on Linux).

Signing out removes your profiles, addons and library from the device. Uninstalling the app or clearing its data removes the rest. Copies in your device backups follow your backup settings.

Your Tortuga account

Tortuga asks you to sign in the first time you open it. Unless you choose another server, your account lives on Tortuga’s hosted server at api.usetortuga.app.

What the server stores

  • Your sign-in identity. Signing in with Apple or Google, or with a server’s own OpenID Connect provider, gives the server a signed token from the provider. The server keeps the provider, the provider’s identifier for you (its issuer and subject) and your email address if the provider shares a verified one; with Apple’s Hide My Email, that is a relay address. The account is keyed by the identifier, not by the email. A second sign-in method you add in Settings is kept the same way.
  • An Apple token, for deletion. With Sign in with Apple, the hosted server also keeps the refresh token Apple issues, and uses it only to revoke Tortuga’s access with Apple when you delete your account.
  • Your devices. Each signed-in device has its own session. The server keeps the device’s name as your system reports it (such as the name in its settings, or the computer’s name), its platform, when it signed in and when it was last active, to the nearest five minutes. Access and refresh tokens are stored only as hashes.
  • What you sync. Profiles (name, avatar, preferences and PIN hash) and, for each profile, its addons and their order (with their links), library, watch progress and watched marks, the last stream picked for each video, and profile settings. Device settings, recent searches and tracker sign-ins never sync.
  • Bookkeeping. For each synced record, a version number, its size, whether it was deleted and when it last changed; for the account, when it was created and how much it stores.

How it is protected

Everything travels over HTTPS. The server can read what you sync: Tortuga does not use end-to-end encryption, which is why signing in on a new device is all it takes to get your data there.

At rest, the content and identifier of every synced record are encrypted (AES-256-GCM) with a key kept outside the database. A copy of the database or a backup, on its own, therefore reveals none of your addon links, titles or IDs. Sign-in identities, email addresses, Apple tokens and device names are stored as they are, which is why backups are encrypted as a whole as well. The running server, and whoever operates it, can read everything. If you would rather nobody else could, run your own server.

Short-lived records

  • Linking a device by code or QR code. The new device’s name and platform, the code, and a hash of a secret only that device holds. Deleted as soon as the device signs in, or after 10 minutes.
  • Sign in with Apple on Android, Windows and Linux. Apple’s web page returns to a page on api.usetortuga.app. What Apple sends back (its sign-in token, a one-time code and, the first time, the name and email you chose to share) waits there until the app collects it, for at most 10 minutes, and is then deleted.
  • Sign-in checks. Single-use sign-in values and hashes of sign-in tokens already used, kept until they expire and linked to no account.

Server logs

The server logs each request’s method, path, status and duration, a request ID and, for signed-in requests, the account ID. It does not log IP addresses, email addresses, tokens or anything you sync. To limit abuse it counts recent requests per IP address in memory; those counts are never stored. The hosting and network providers in front of the server see your IP address as part of carrying the connection.

Trackers

Trackers are optional. A service you connect gets what you watch with that profile on that device: playback progress, titles you mark watched, and the ratings and list changes you make. Each device connects on its own and keeps the service’s tokens in its secure storage. Tortuga’s server never stores them; for MyAnimeList and AniList they pass once through its sign-in relay, described below.

  • Trakt, Simkl and MDBList sign in with a code on the service’s own website, between your device and the service.
  • MyAnimeList and AniList sign in through Tortuga’s sign-in relay on api.usetortuga.app, which holds Tortuga’s credentials for those services. The relay hands the service’s tokens to your device once and keeps nothing: a sign-in in progress is held in memory for at most 10 minutes, only a hash of your device’s one-time secret is kept, tokens are never logged, and nothing is written to the database. The apps use this relay even when you sync with your own server.
  • For anime trackers, the apps download two public ID lists (Fribb’s anime-lists and Anime-Lists) from jsDelivr the first time an anime tracker needs them, and check them for updates weekly.

Crash reports

Official builds of Tortuga send crash reports to Sentry. The Sentry server is self-hosted at bugs.plezy.app, the instance that also serves Plezy, a sister project by the same developer; it is not Sentry’s cloud service.

Crash reports are on by default. Turn them off in Settings, under This device, with “Send crash reports”. The switch applies to that device only.

A report contains what went wrong and where in the code, the app version, the device model and system version, and recent log lines. Before a report leaves the device, every link is cut down to its scheme and host and anything shaped like a key or token is removed, so reports never contain your addon or stream links. Reports are kept for up to 90 days. Like any server, the crash-report server sees the IP address a report comes from. Builds you make yourself from the source send no crash reports.

Services the apps talk to

Your device talks to these services directly, without Tortuga’s server in between. Each sees your IP address, as any service you connect to does, and handles your data under its own privacy policy.

  • Your addons. Each addon you install receives the requests for what it offers: the catalogs you browse, what you search for, and the IDs of what you open. Subtitle addons also receive the video’s file name, size and a fingerprint (the OpenSubtitles hash, computed from the start and end of the file). New profiles start with Cinemeta and OpenSubtitles v3, which Stremio runs; Cinemeta can’t be removed.
  • Stream and image servers. The servers your addons point to. The apps request a stream only when you pick it, and load posters, backgrounds and logos from wherever the addon says they are.
  • Sign-in providers. Apple, Google, or the OpenID Connect provider of a server you choose. On TVs, Google sign-in uses Google’s device code page.
  • Trackers you connect, and jsDelivr for the anime lists (see Trackers).
  • YouTube and your browser. Trailers open in YouTube or the browser, as do addons’ web links and configuration pages.
  • Updates. The Mac app downloaded as a disk image checks GitHub for updates with Sparkle. Versions from an app store update through that store.

Self-hosted servers

You can sign in to a server you or someone else runs instead of Tortuga’s. Its operator, not Tortuga, decides how your data is handled there, and this policy does not cover it. The server software can read what you sync on any server.

A few things still go through api.usetortuga.app: Sign in with Apple on Android, Windows and Linux returns through its page, and tracker sign-in for MyAnimeList and AniList uses its relay. A self-hosted server can’t revoke Sign in with Apple when you delete your account, because only the hosted server holds Tortuga’s Apple key; it deletes your data and asks you to remove Tortuga from your Apple Account’s sign-in settings yourself. With the server’s own OpenID Connect provider, Apple and Google aren’t involved at all.

Keeping and deleting data

  • Delete your account at any time in Settings, under Account, with “Delete account”. It immediately deletes the account and everything under it from the server (sign-in identities, devices, synced data and device links) and signs out every device. On the hosted server it also revokes Sign in with Apple.
  • Sign out a single device in Settings, under Account and Devices. A device that hasn’t been used for 180 days is signed out automatically, and its session deleted.
  • Removing something that syncs, such as an addon or a library item, removes it from your devices. The server keeps a small deletion marker with the item’s ID, encrypted like the rest, until the account is deleted, so devices that were offline remove it too.
  • Backups. The hosted server’s database is backed up daily. Each backup is encrypted before it is uploaded to S3-compatible storage and deleted after 30 days, so a deleted account is gone from the backups within 30 days.
  • Otherwise, your account stays until you delete it. Crash reports are kept for up to 90 days, and the short-lived sign-in records above for minutes.

Your rights

Wherever you live, you can:

  • see and change what you sync in the app, and delete it there;
  • delete your account and everything the server holds for it, at any time, in the app;
  • ask for a copy of the data the hosted server holds about you, ask for it to be corrected or deleted, or object to how it is used (see contact).

In the EU, the EEA and the UK, the GDPR gives you these rights, and you can complain to your data protection authority. The hosted server processes your data to provide the account and sync you asked for, and to keep the service secure and working, which includes crash reports; you can object to the latter, and switch crash reports off at any time.

Children

Tortuga is not directed at children. An account belongs to the person who signs in. Profiles for others in the household, children included, are part of that account and collect nothing extra.

Security

The apps talk to the server over HTTPS. The server keeps session tokens only as hashes, encrypts synced data at rest and encrypts backups before they leave it, and the apps keep secrets in the system’s secure storage. No system is perfectly secure. If you find a security problem, report it through the GitHub project, and ask for a private channel rather than posting details publicly.

Changes and contact

Changes to this policy are posted on this page with a new effective date. For privacy questions or requests, contact the developer through the Tortuga GitHub project. GitHub activity is public, so don’t include addon links, tokens or other sensitive details there.