Privacy Policy

Last updated: August 4, 2026

TrimPlayer is a podcast player that automatically detects and skips intros, ads, and outros. Auto-trim is powered by a backend service (TrimBrain) that needs to know which episodes you play in order to fingerprint them and serve trim points. This policy explains exactly what data leaves your device, why, who it goes to, and how to get it deleted. It covers the Android app, the web player at app.trimplayer.com, and the trimplayer.com website.

1. TL;DR

2. Data that stays on your device

The following lives only on your device. It never leaves it unless you initiate an OPML export or backup, or you turn on optional cross-device sync (§4), which uploads the items marked below:

3. Data we send to our TrimBrain backend

The TrimBrain backend (hosted at api.trimplayer.com on AWS infrastructure in the United States) needs certain data to perform auto-trim. We send the minimum required:

We do not upload audio from your device. We do not collect your IP-derived location, contacts, photos, or microphone input.

4. Optional account and cross-device sync

TrimPlayer works fully without an account, and nothing in the app is withheld if you never make one. There is exactly one reason to create one: keeping your library in step across devices — the Android app, the web player at app.trimplayer.com, and a linked Garmin watch.

What creating an account involves. You give us an email address and a password, or you sign in with Google, in which case Google gives us the verified email address on that account. We store the email address and a hashed password — never the password itself. We do not ask for your name, and Google sign-in gives us the email address only. We do not send marketing email; the only email we would ever send to that address is a password reset you asked for.

What sync uploads. While you are signed in, the app and the web player exchange a delta of your library with the backend. In full, that is:

That list is exhaustive as of the date at the top of this page. Sync does not include downloaded audio, your Statistics screen, or your app settings.

Linked devices. A Garmin watch is linked with a short code shown on the watch and approved in the app; the link binds that device to your account so it can fetch your queue. You can see your linked devices and unlink any of them from the app, which also deletes that device's link to your account. Unlinking revokes every sign-in session on the account except the one you unlinked from, so your other devices — including ones you are keeping — will ask you to sign in again.

If you never sign in, none of the above happens: no account row exists, we hold no email address for you, and your library never leaves your device except as described in §3.

5. In-app purchases (Google Play Billing)

Every feature in TrimPlayer is free for everyone. If you choose to support the project with a voluntary subscription, the payment is processed by Google Play Billing. We never see your credit card or payment details. Google sends us a purchase token, which we exchange with Google's Play Developer API to confirm and acknowledge the subscription. We store the purchase token alongside your anonymous client identifier so we can show your "thank you for supporting" state on subsequent app launches. Supporting is entirely optional and unlocks nothing. Google's handling of your payment data is governed by the Google Privacy Policy.

6. Connections to podcast hosts

When you stream or download an episode, your device connects directly to the podcast's hosting provider (Megaphone, Libsyn, etc.). These providers will see your IP address and user-agent and may log them according to their own policies. TrimPlayer has no control over what podcast hosts log.

7. Third-party services we use

We do not use Facebook SDK, advertising networks, attribution SDKs, or any analytics provider other than the Google services listed above.

The Android advertising ID. We do not use advertising IDs for anything, we run no ads, and we sell and share nothing. However, honesty about a dependency rather than about our intentions: the Firebase Analytics SDK contributes the com.google.android.gms.permission.AD_ID permission to the app, and it can collect the Android advertising ID by default. The app does not currently ship the setting that switches that collection off. If you want to reset or delete that identifier regardless of any app, Android lets you do so under Settings → Privacy → Ads.

8. Data retention

Database records. Records tied to your client identifier — episode telemetry, skip events, your queue snapshot, support entitlement and the auto-trim usage counter — are retained while your install remains active. Cached audio downloaded for fingerprinting is automatically evicted on a rolling basis (typically within days). If you created an account, your account record — email address, hashed password, and the synced library described in §4 — is retained until you ask us to delete it.

Server request logs. Separately from the database, our API writes one log line for every request it handles, to the server's own log and to AWS CloudWatch. Each line contains the method, the path, the query string, the response status, how long it took, your IP address and your user-agent. This matters more than it sounds: the auto-trim lookup passes the episode URL as a query parameter, so these logs amount to a record of episodes requested against an IP address and a device type. They exist for debugging and abuse investigation. They are not keyed to your client identifier and cannot be searched by it, which also means we cannot pick your entries out of them in response to a deletion request — see §9.

Uninstalling the app does not automatically delete server-side records, because the backend has no way to know an uninstall happened.

9. Your rights (GDPR, CCPA)

If you have never created an account, the only personal data we hold is tied to your anonymous client identifier. If you have created one, we also hold your email address. Either way you have the following rights over that data:

To exercise any of these, email trimplayerapp@gmail.com. If you have an account, write from the address on it. If you don't — which is the normal case — we have no name or email to look you up by, so include the anonymous client identifier, which you can find under Settings → About → Diagnostics.

What a deletion request actually covers, precisely. A vague promise here would be worth nothing, so:

10. App permissions

TrimPlayer requests:

11. Children

TrimPlayer is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has used the app, contact us and we will delete any associated server-side records.

12. Changes to this policy

We may update this policy as the app evolves. Significant changes will be announced in the app's release notes. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For any privacy question or data request: trimplayerapp@gmail.com.