Privacy Policy
Effective: 9 October 2026 · Last updated: 9 October 2026
Oxtv is an app that plays your own IPTV playlist, with versions for iPhone, iPad, Apple TV, Mac, Android phone, Android TV, Samsung TV (Tizen) and LG TV (webOS). This text explains what data is processed while you use it, where it lives, who receives it and how to delete it.
1. Controller and contact
The app is published by two individual developers. For every privacy question or request: oxtv@obalabs.app
2. Two ways to use it
- Guest mode (default): no account, no cloud. Playlists, passwords, favourites and resume points stay on that one device. Deleting the app deletes all of it.
- With an account: you sign in with Apple or Google; data within the scope listed below is written to your Firebase account and synced across devices.
3. Data processed
a) Account data
- Sign in with Apple (iPhone, iPad, Apple TV, Mac): the user identifier Apple issues, the email (possibly a private relay address) and the name, which arrives only on the first sign-in. We never see your Apple password.
- Sign in with Google (iPhone, iPad): the email and name Google shares for verification. We never see your Google password. Google's own SDK is not used; Firebase's web flow is.
- Written to the account document (
users/{uid}): user id, display name, email, sign-in provider and update time. The profile photo is not written. - TVs and Android devices do not sign in to the account directly. The device gets an anonymous Firebase identity and shows a code and a QR on screen; Oxtv on your phone approves. Approval creates a device grant in your account: the device's anonymous id, its name (from a three-value list such as Samsung TV, LG TV, Android TV), platform, approval time and a "last seen" time refreshed at most once a day. The phone also writes your email and name into that grant so the TV can show them on its Account screen.
b) Playlist and provider data
- For Xtream Codes: server address, username and password; for M3U: the URL. The playlist name and the subscription expiry date if the provider reports one.
- In guest mode the password stays on the device only: in the Keychain on Apple devices, in the app's local storage on TVs and Android, under a key separate from the playlist. The password is sent only to the playlist's own server.
- With an account the password is written to your account (the
secretfield of theusers/{uid}/playlists/{id}document) so you do not retype it on other devices. The field is stored in Firestore without additional encryption; access is limited by Firestore security rules: only you and the devices you linked by QR can read or write it. When you unlink a TV its access ends. - What that means: a device you link to your account by QR can read and change your playlists and their passwords. The confirmation screen on the phone says so. Link only your own devices.
c) Viewing data
- Favourites (live channels), watchlist (movies and series), your named channel lists, removal records.
- Resume points: which title, which position, when. At most 100 records on the device and 50 in the cloud.
- Profiles (up to five): name, kind (standard or kids), and the settings tied to a profile: language, subtitle appearance, playback rate, hidden categories, home shelves, adult filter.
- Content marked as adult is, by default, kept out of watch history and resume points.
- Recent searches stay on the device only and are never synced.
d) Data that stays on the device
- The parental PIN, its attempt counter and lock. It never goes to the cloud and survives sign-out.
- The catalogue cache (the downloaded playlist, valid for six hours), the TMDB metadata cache, the image cache (up to 512 MB).
- Provider-specific technical settings (such as the live stream format) and device settings (volume, layout).
4. Data not collected
- Advertising identifier, ad networks, third-party trackers
- Analytics or usage telemetry, crash reporting SDKs (Firebase Analytics and Crashlytics are not included)
- Location, contacts, photos, microphone
- A record or the content of what you stream: streams go from your device to your provider and never pass through us
Oxtv does not track you in the App Store's "App Tracking Transparency" sense and does not match your data with other companies' data.
5. Requests that leave the app
The app has no server of its own. Every outgoing request is in the table below; there are no others.
| To | What is sent | Why |
|---|---|---|
| Your provider (the Xtream or M3U server) | Username, password, the requested channel/movie/episode | To download the catalogue and play streams. Most IPTV panels use plain HTTP; the app allows it. |
| TMDB (api.themoviedb.org, image.tmdb.org) | Movie and series titles and years from your playlist; matched ids; interface language | Logo, poster, rating, cast, trailer and recommendation data. Adult content is excluded from searches. |
| skipdb.tv (api.skipdb.tv) | The title's IMDb id, stream duration, season and episode number | Intro, recap and outro timings (the skip button). |
| OpenSubtitles (api.opensubtitles.com) | The title's IMDb id | Subtitle timing used to detect a post-credits scene. Subtitles are not displayed; only timing data is used. |
| Google Firebase (only with an account) | The account and sync data listed in section 3 | Sign-in and cross-device sync. |
| YouTube | Trailer id | The trailer button opens the YouTube app or site; nothing is played inside Oxtv. |
These services have their own privacy policies: TMDB, OpenSubtitles, Firebase. Oxtv uses the TMDB API but is not endorsed or certified by TMDB.
6. Where data is stored
- On your device: everything in 3(b), 3(c) and 3(d), in local files and the device's secure storage.
- In the cloud (only with an account): Google Firebase Authentication and Cloud Firestore. Firestore security rules allow only you and your linked devices to reach the documents under your account. The rules are kept in the app's source code (
firebase/firestore.rules). - Firebase servers may be located outside Turkey (Google data centres); creating an account means your data is transferred abroad.
7. Purpose
- Playing your playlist and showing its catalogue
- Syncing across devices and profiles
- Support, when you ask for it
Your data is not used for advertising, profiling or marketing and is not sold or handed to third parties. It may be shared with authorities where the law requires it.
8. Retention
Cloud data stays until you delete it or close the account. Signing out clears the copy on the device, not the cloud. Deleting the app removes only that device's data. TV pairing codes expire within five minutes and are deleted by the device that created them.
9. Deletion and your rights
You can delete your account from inside the app: in the account section of Settings, as the account owner (not from a TV linked by QR). You are first asked to re-authenticate with the same provider. Then playlists, linked devices, favourites, watchlist, resume points and the users/{uid} document are deleted, followed by the account itself. If you signed in with Apple, the Apple authorization is revoked as well. This cannot be undone.
If you cannot reach the app, write from your account's email to oxtv@obalabs.app; the request is fulfilled within 30 days.
Under Turkish data protection law (KVKK, Law no. 6698) and, where it applies, the GDPR, you have the right to access, rectify, erase, restrict, port and object. Use the same address.
10. Children
Oxtv is not directed at children and does not knowingly collect data from anyone under 13. The kids profile is a content filter within an account; it does not create a separate account or any data belonging to a child.
11. Changes
When this text changes the effective date is updated and material changes are announced inside the app. Earlier versions are available by email.
12. Languages
This policy is published in Turkish and English. In case of conflict the Turkish text prevails.