In short: we keep the minimum needed to run your device — its MAC address, the playlist link you gave us, and a log of playback. We do not sell your data, and we never see your card number.
[company name], [registered address], is the controller of the personal data described here. For any privacy question or request, write to [contact email].
Device data. When a device is registered — by you, by a reseller, or through the upload page — we store its MAC address, the name given to it, its registration and expiry dates, and the M3U playlist link. We need these to know which device is entitled to work and what to load on it.
Your playlist link contains your provider credentials. An Xtream link normally carries your username and password in the address itself. We store it as you gave it to us, because the application needs the exact link to fetch your list. Treat it as a secret: anyone who obtains the link can use your subscription. We restrict access to it to your reseller and to our administrator.
TV account. For Samsung/Tizen televisions we create a login. We store the username, and the password only as a cryptographic hash — we cannot read it back.
Playback log. Each time a stream is opened, we record the device's MAC address, the name of the stream, the IP address, and the time. This is what lets us count connections, spot a shared or abused account, and support you when playback fails. It means we can see what was played and from where — we tell you this plainly rather than hide it in a clause.
Reseller accounts. Business name, login username, hashed password, credit balance, and a ledger of every credit movement, including purchases. We keep the ledger because it is our accounting record.
Orders. Order reference, quantity, price, payment method, status, and the reference returned by the bank. We do not store card numbers, expiry dates, or CVV — those are entered on the payment provider's page and never reach our servers.
Website and abuse prevention. Our server and rate limiter process IP addresses of requests, to block abuse of the public registration and payment pages.
We do not sell your data, and we do not share it for advertising.
We use one session cookie, and only for the panel: it keeps a reseller or administrator logged in. There are no advertising or analytics cookies, and no third-party trackers. The payment provider may set its own cookies on its own page during checkout.
The site is served over HTTPS. Panel passwords are stored hashed. Access to the database is limited to our administrator. No system is perfectly secure, so please keep your own login and your playlist link to yourself.
You can ask us to show you the data we hold about your device or account, correct it, delete it, or send it to you in a portable form. You can also object to our use of playback logs. Write to [contact email] from the address you registered with, or ask through your reseller. We answer within 30 days. Deleting a device's data means the device stops working.
If you believe we mishandled your data, you may complain to the data protection authority of [country] or of the country where you live.
The service is not directed at children under 16, and we do not knowingly register them. The application includes a parental lock that you can enable with a PIN.
If we change what we collect, we change this page and the date at the top.
See also our terms of use.