Documentation

Privacy and security

Home Stream runs in your house, on your machine, for your household. It is designed so that your library, your history and the rest of your home network stay that way.

What leaves your house

The server only reaches out to the internet to fill in details and pictures, and to check a sign-in with Apple. Here is everything it contacts:

The machine itself also checks the image registry once a day, at the hour you chose, for a newer version of Home Stream.

What never leaves

Your files are never uploaded. Neither are your watch history, your accounts or anything about who lives in your house. There are no analytics. There is no Home Stream account to create, and no email is ever sent. The web interface loads its code only from your own server.

Made for your home network

Home Stream is meant to be reached only from inside your home. It uses plain http rather than https, because the certificates that make https work can't normally be issued for a private address on a home network.

That has one real consequence. Without https, a browser's sign-in can't be marked as secure-only, so someone already on your network could capture it. The page's own scripts still can't read it. Treat your Wi-Fi password as the front door. If you give visitors Wi-Fi, a separate guest network is a good idea.

Watching away from home isn't supported yet. Don't open a port on your router to reach Home Stream from outside. The design notes recommend a VPN into your home network instead. Proper remote access is planned as a switch the administrator controls, off by default.

It answers only to names it knows

A web page on the internet can try to reach devices on your home network through your own browser, by pointing a name of its own at them. To stop this, Home Stream only answers when it is addressed by a name a household would use:

Anything else gets "This server does not answer to that name." If you really do use a full domain name for it at home, add that name to HOMESTREAM_HOSTNAMES. Several names can be separated with commas. Put it in the environment section of compose.yaml, because the server doesn't read it from .env on its own:

    environment:
      TZ: ${TZ:-UTC}
      PUBLISHED_PORT: ${PORT:-8080}
      HOMESTREAM_HOSTNAMES: media.example.com

Then run docker compose up -d from the folder that holds compose.yaml and .env (~/homestream if you used the installer).

Setting up and getting back in, from home only

A brand-new server answers nothing but its setup screen. It can't show your library, your settings or your folders to anyone until it has an administrator. The only exception is a version check, because a version number isn't a secret.

To set it up, you need the setup code. The server prints it to its log and keeps it in a file only the server's user can read. Having the code proves you have access to the machine itself, which is the right test for the person who owns it. Setup is also refused from anywhere except your home network. That way, a server accidentally reachable from the internet can't be taken over by whoever finds it first.

The recovery code that resets a lost password follows the same rules. It is kept in a file beside the database, never written to the log, and replaced as soon as it is used. Recovery only works from your home network. A request that arrives through another server, such as a proxy, is refused for both setup and recovery.

Accounts and signing in

What the server itself is allowed to do

Choosing library folders

Give Home Stream the folders your media is in, and nothing more.

All documentation · Next: Support