Privacy Policy
Last updated 28 September 2026
Basalt is built so that your files, your library and your viewing stay in your home. Refora Technologies runs no Basalt server, has no Basalt accounts, and receives no data from the apps: no telemetry, no analytics, no crash reports. This page sets out exactly what the apps keep, where, and the few things that ever leave your network.
1. What this covers
This policy covers the three Basalt apps published by Refora Technologies: Basalt Host and
Basalt for Windows, and Basalt for Android. It also covers this website,
basalt.reforatech.com, in section 8.
The apps are free software under the GPLv3, and their source code is public.
2. The short version
- Your files are read and sent only between your own devices, on your own network, encrypted with TLS 1.3.
- Everything the apps remember is kept on your own devices, mostly on the host PC.
- The only requests the apps make beyond your network are a check for updates, to GitHub, and, only if you switch it on, looking up posters for your films and series.
- This website counts visits with Google Analytics, which you can opt out of. See section 8.
3. What stays on your devices
On the host PC
Basalt Host keeps its data in %APPDATA%\Basalt\ in your Windows user profile. None of it is sent
anywhere.
| What | Why |
|---|---|
| Settings | The drive you chose to share, the host’s name, and the switches in its settings. |
| The host’s identity | A private key and certificate, made on the PC, that devices use to recognise this host. |
| Paired devices | Each device’s name, its device identifier (see section 4), its key fingerprint, whether it is read-only, and when it was last seen. |
| Profiles | Each profile’s name and colour, and its PIN in hashed form, never the PIN itself. |
| Watch history and stars | How far through each video you are, and your starred files, per profile or per device. |
| The media index | What is on the drive, sorted into films, series, photos, music and videos, with each video’s picture size. |
| Thumbnails and posters | Pictures made from your photos and videos on the PC, and posters, if you switched posters on. |
| A log | What the host did, such as devices connecting and anything that went wrong. It can include file and folder names from the drive. It is replaced each time the host starts. |
On other Windows PCs
Basalt for Windows keeps which host it is paired with, that host’s key fingerprint and last address, the token the
host gave it at pairing, a remembered profile sign-in if you asked for one, and your settings, in
%APPDATA%\Basalt\. The tokens that keep it paired and signed in are encrypted with
Windows’ own per-user protection, so a copy of the file is of no use on another account or computer.
On Android
Basalt for Android keeps the same things in its own private storage, which other apps cannot read. That storage is
left out of phone backups, so a pairing never travels to another phone. Files you download are saved to the
Download/Basalt folder, where you and your other apps can see them.
4. What travels over your network
Announcements. So that devices can list it, the host announces itself on your local network every three seconds. The announcement carries the host’s key fingerprint, the PC’s name, the drive’s name, a port number, and whether pairing asks for a PIN. Any device on the same network can see it, as with a network printer. It carries no files and nothing about who uses Basalt.
Connections. Everything else between a device and the host, including file lists, the files themselves, video streams and profile sign-ins, is encrypted. Each device remembers the host’s key when it pairs and checks it each time it connects.
Recognising your devices. So that a phone or PC is recognised as the same device after Basalt is reinstalled, each app sends the host a device identifier. It is made from an identifier your phone or PC already provides to apps, scrambled one way before it leaves the device, so the original cannot be worked out from it. It is sent only to your own host, never anywhere else, and it is used only to keep one entry per device. It does not let a device connect: only pairing with the host does that.
What the host sees. The host knows which paired devices are connected, what each is transferring, and which profile is signed in on each. It shows that in its own window, to whoever uses the host PC, and keeps watch history as described above. It does not send any of it anywhere.
5. What leaves your network
The apps make requests beyond your network for two purposes only.
Updates
Each app asks api.github.com whether a newer release exists, and, if you choose to install one,
downloads it from GitHub and checks its SHA-256 checksum before installing. The request carries nothing about you
beyond what any web request carries, which is your IP address. It is handled by GitHub under
GitHub’s privacy statement.
Posters, only if you switch them on
Download posters in Basalt Host is off until you turn it on. When it is on, the host sends the title and year of each film and series it recognised to third-party poster services, including The Movie Database (TMDb) if you add your own key, and saves the pictures it gets back. Those services receive the titles and your IP address, under their own privacy policies. Switching posters off stops the lookups.
Recognising films in the first place happens on the PC, against a catalogue shipped inside the host. It needs no connection and sends nothing.
Play in your player on Android hands a film to another app you choose, such as VLC, over a link that only exists on the phone itself. What that app does is covered by its own policy.
6. Profiles and PINs
Profiles are optional. A profile is a name, a colour and a PIN of 4 to 8 digits, kept on the host. The PIN is stored only in hashed form, and repeated wrong PINs lock the profile for a while. The host’s window never shows PINs. Resetting a PIN or removing a profile on the host signs that profile out of every device at once, and removing it also deletes its history and stars.
7. Android permissions
Basalt for Android asks for the following, each for one reason.
| Permission | What it is used for |
|---|---|
| Internet, and network state | To reach the host on your home network, and to check for updates. |
| Local network, Wi-Fi state and multicast | To hear hosts announcing themselves on the Wi-Fi, so you can pick one from a list. |
| Change network state | To keep the connection on the Wi-Fi when that network has no internet access, instead of Android moving it to mobile data. |
| Foreground service and wake lock | To let a transfer or a song carry on while the screen is off. A notification says so while it happens. |
| Notifications | For that notification, and for transfer progress. |
| Install packages | To hand an update you chose to install to Android’s own installer. Android asks you before allowing it. |
| Storage (older versions of Android) | To save downloads to the Download folder on versions of Android that need it. |
The app reads photos, videos and files on the phone only when you choose them to upload, through Android’s own picker, or when you share them to Basalt from another app.
8. This website
- Analytics. This website uses Google Analytics to count visits and see which pages are read. It sets cookies in your browser and receives details such as your IP address, browser, device type and the pages you visit, which Google processes under its privacy policy. It is not used for advertising. To opt out, choose Cookies at the foot of any page, then Don’t count me; your choice is remembered in your browser. Browser add-ons that block analytics work too.
- No advertising. This site shows no ads and loads no advertising or social media trackers.
-
The version number. To show the latest version and file sizes, your browser asks
api.github.comonce per visit. GitHub sees your IP address, as with any request. The answer is kept in your browser’s session storage until you close the tab, and is not a cookie. - Downloads. The download buttons fetch the apps from GitHub’s release pages, under GitHub’s privacy statement.
- Email. If you write to us, we use your message and address only to reply, and keep them no longer than needed for that.
9. Your choices and rights
Because the apps keep your data on your own devices, it is entirely under your control. You can delete any of it:
remove a profile or a device from the host, delete files in %APPDATA%\Basalt\, clear the Android
app’s storage, or uninstall the apps. Refora Technologies holds no data about you from the apps, so there is none
for us to access, correct, export or delete. If you have written to us by email and want that correspondence
deleted, ask and we will.
10. Children
Basalt collects nothing from anyone, so there is nothing to handle differently for children. Parents may want to give children their own profile, or a read-only device.
11. Changes to this policy
If this policy changes, the new version appears on this page with a new date at the top.
12. Contact
Questions about this policy, or about anything Basalt does, are welcome.
- Email reforatech@gmail.com
- Open an issue on GitHub
- reforatech.com
See also the Terms of Use, which cover the licence, your content, and the open-source components Basalt is built on.