Norrsaga is an audiobook and podcast player for Audiobookshelf, made by Koeda Studio in Sweden for Android Automotive OS and (in beta) iOS. It is a client for a server you choose and control. There is no Norrsaga account, no analytics, no advertising and no crash reporting. Koeda Studio is the data controller for the little processing described here.

What stays on your device

  • Server connection details — the server address, your username, and the tokens your server issues at sign-in. Your password is sent to your server once and never kept. Tokens are encrypted with the Android Keystore, or stored in the Keychain on Apple devices.
  • Playback state and settings — the last played item and position, playback speed, and your other preferences.
  • Caches and downloads — library listings and artwork, plus the files you download for offline listening on Apple devices.
  • Diagnostics — a short log of recent errors, shown under Settings → Diagnostics in the car. Server addresses, URL query strings and titles are stripped before anything is written. The log never leaves the device on its own.

Signing out deletes your credentials; downloads and the log can be cleared in the app. On Android the app opts out of cloud backups. On Apple devices settings and downloads may be included in a backup, but credentials never are. Uninstalling removes everything, though a Keychain entry can linger unless you sign out first.

What goes to your server

The app talks only to the Audiobookshelf server you configure: sign-in, browsing, search, streaming, playback progress, and reading-position and queue updates. Your server also sees ordinary request details such as your IP address and app version. Android release builds require HTTPS; Apple builds also allow plain http for servers on your home network. What your server operator logs is up to them — if it is not your server, ask them.

If you set up the optional narrator server, the app hands it your Audiobookshelf token together with the item and reading position, so it can fetch the ebook and write progress back with your permissions. Only point Norrsaga at a narrator you run or trust.

Sharing a problem report

The Diagnostics screen can show a QR code. The car uploads nothing: the log is packed into the link itself, in the part after # that browsers never send to a server, and norrsaga.app/report decodes it on your phone. It holds the app version, car model, Android version and the latest log lines. It reaches Koeda Studio only if you submit the pre-filled GitHub issue, under GitHub’s privacy policy. Issues are public, so read it first and never paste passwords or tokens.

Optional episode alerts on iOS

If you turn on new-episode alerts, Norrsaga registers your device in your Audiobookshelf server’s notification settings (this needs an admin account). When an episode arrives, your server pings a small relay Koeda Studio runs on Cloudflare Workers, which forwards it to Apple’s push service. The relay sees your push token, the podcast and episode titles and episode identifiers — nothing more, and never your Audiobookshelf password or token. It has no database, but operational logs are on: a shortened push token, episode identifier, delivery status and errors, kept for three days (Cloudflare’s Workers Logs retention on the plan the relay runs on) even after you disable alerts. Cloudflare also processes request metadata such as the sending server’s IP address.

Turn alerts off in the app, or remove the registration on your server, to stop them. Apple and Cloudflare act under their own policies (Apple, Cloudflare).

In the car

Android Automotive OS shows titles, authors, artwork and playback state in its media controls; it never gets your credentials. Voice requests are transcribed by the car’s own assistant, which hands Norrsaga the text (say, “play Dune”) to search your server. The app never hears the recording and does not keep the text.

App stores and permissions

Installing goes through Google Play, the App Store or TestFlight, under Google’s and Apple’s policies. If you have opted in to share diagnostics with developers, they may forward crash reports or TestFlight feedback to Koeda Studio, used only to fix bugs.

The apps ask for network access, background audio, local network access where needed, and notifications if you enable them. Never location, contacts, microphone, camera or photos.

This website

norrsaga.app is a static site with no cookies, analytics, third-party fonts or embeds. Cloudflare hosts it and processes standard request metadata to serve and protect it. Koeda Studio keeps no visitor logs.

  • Why: connecting to your server and playing your library is needed to provide the app (contract). Episode alerts and problem reports happen only with your consent, which you withdraw by turning them off. The short-lived relay and website logs rest on our legitimate interest in keeping the services running and safe.
  • Where: the relay and this website run on Cloudflare, and alerts pass through Apple. Both may process data outside the EEA, including in the United States, under the EU-US Data Privacy Framework and standard contractual clauses. Everything else lives on your device or your server.
  • Your rights: you may ask to access, correct, delete or receive a copy of your personal data, and to object to or restrict its processing. Contact Koeda Studio for the relay and website, and your server operator for their server. You can also complain to the Swedish Authority for Privacy Protection, IMY, or the authority where you live.
  • Children: Norrsaga is not directed at children.

Changes and contact

Changes are published on this page with a new effective date and noted in the changelog. Privacy questions go to privacy@koeda.studio; everything else to the issue tracker.

← Back to Norrsaga