Privacy policy
Connection information
When you connect, our server processes the provider address and credentials or playlist link to validate your connection and retrieve metadata. Xtream credentials are stored in an encrypted HttpOnly session cookie, with Secure enabled in production and SameSite Strict. The default session lasts four hours; choosing Remember extends an Xtream session to seven days. Disconnecting clears the active cookie.
Passwords are not stored in localStorage or IndexedDB. Direct playback necessarily gives the browser the stream address, which may include provider credentials and can be visible in network tools. The optional relay uses encrypted session-bound tickets; the server still contacts the provider. Your provider receives requests necessary for connection and playback.
Temporary playlist processing
Uploaded files and fetched playlists are parsed by our server, not entirely offline. Parsed libraries are held temporarily in server memory for the current session and are not saved to a permanent playlist database. Server restarts and session expiration can require reimporting or reconnecting. Playlist files are not sent to a third-party parsing service.
Storage on your device
IndexedDB stores playlist identifiers, limited display metadata, favorites, recent history, and playback progress. Stored history excludes raw stream URLs and remote artwork URLs. Small volume, brightness, fit, and history preferences use localStorage. These settings are device-local and are not automatically synchronized.
Use Settings to clear specific local data or all local data for a playlist. Clearing the browser’s website data also removes local records. Disconnecting clears the current session but does not automatically erase every saved favorite. Other people using the same browser profile may be able to see its local viewing metadata.
Contact messages
The contact form processes your name, email address, subject, and message. When delivery is configured, these fields are sent through the operator’s configured mail adapter to the contact mailbox. If delivery is unavailable, the form reports an error and does not claim that the message was sent. Do not include credentials or private playlist links.
Messages delivered to the contact mailbox may be retained to respond to your request and maintain the related correspondence. Contact us to ask about deletion of correspondence. We cannot remove data held independently by your IPTV provider.
Logs and third parties
The application does not intentionally log provider credentials, playlist contents, or stream URLs, and no analytics is installed by default. Hosting infrastructure may keep ordinary access, security, and error logs, including request times and IP addresses, according to its configuration. Encrypted media tickets can appear in access logs; they are scoped to the active session and expire.
We do not sell user playlist data. Direct media requests reach your provider; relayed requests reach it through this server. Artwork is fetched through the application with size and type restrictions. External content providers have their own privacy practices, which this policy does not control.
Your choices
Only connect on devices you trust, disconnect on shared screens, and clear local history when appropriate. Avoid sharing provider addresses that contain tokens. To ask a privacy question or request deletion of contact correspondence, use the contact page without including passwords. This policy may change as application behavior changes.