This article describes Seed Truck's data and security behavior at a high level. The external Privacy Policy is the authoritative legal explanation of data processing:
Read the Seed Truck Privacy Policy
Direct Torrent-Client Communication
Seed Truck sends torrent-management requests directly from the app to the Transmission or qBittorrent endpoint you configure. Torrent lists and management commands are not routed through a Bitten Apps relay server.
Requests can include authentication details, custom HTTP headers, torrent lists and statistics, magnet links, .torrent metainfo, labels or tags, speed-limit settings, and transfer commands. Your torrent client, reverse proxy, hosting provider, VPN, network operator, and related services can still process relevant traffic.
Saved Server Records
Seed Truck stores each server record in Apple's data-protection Keychain. A record can include:
- The server name, identifier, and client type
- The configured endpoint
- The optional username and password
- Optional custom HTTP header names and values
These Keychain items are marked as synchronizable. Apple can synchronize them to compatible devices using the same Apple Account when Keychain synchronization is available and enabled. Seed Truck does not control synchronization timing.
Deleting a saved server removes its record from Seed Truck. It does not delete the remote account, torrents, or downloaded files.
Local Preferences
The refresh interval, torrent sort field, and sort direction are stored as device preferences rather than inside the synchronized server record. Seed Truck does not maintain a separate CloudKit torrent library.
Torrent Files and Magnet Links
Quick Look reads a selected .torrent file locally and does not contact a configured server. When you choose Start Download in Seed Truck, the app sends the metainfo or magnet link to each selected torrent client.
The remote client downloads the payload files. Seed Truck does not download torrent payloads to the iPhone, iPad, or Mac as part of these management operations.
HTTP and HTTPS
Seed Truck allows both HTTP and HTTPS endpoints. HTTP does not encrypt authentication details or other traffic and can expose credentials, custom headers, torrent metadata, responses, and commands to parties able to observe or alter the connection.
Use HTTPS with a valid certificate whenever possible. If HTTP is required for a local server, use it only on a network you trust.
Custom Headers and Redirects
Custom headers support servers behind an additional authentication layer. Their values are stored with the server record and sent with authentication and API requests. Treat custom header values like passwords.
When an HTTP redirect crosses to a different origin, Seed Truck removes configured custom headers, authorization data, cookies, and the Transmission session identifier before following the redirect.
Support Requests
When you choose Submit a Support Request, Seed Truck identifies the product as Seed Truck and includes the current Apple platform so support can route the request. It does not include a RevenueCat customer identifier.
Zendesk processes the information you choose to enter in the form. Never submit server passwords, custom-header values, cookies, private magnet links, or private torrent metadata.
Your Controls
- Use HTTPS where available.
- Enter credentials in the authentication fields, not in the endpoint URL.
- Configure only the custom headers required by your server or reverse proxy.
- Delete a saved server when you no longer want its record retained by Seed Truck.
- Choose carefully between removing a torrent while keeping files and removing it while deleting files.
For the complete disclosure, read the Seed Truck Privacy Policy.