ChannelSurf
Legal

Privacy Policy

Last updated: August 27, 2026

ChannelSurf is operated by Patrick Walders, owner and operator of ChannelSurf. ChannelSurf ("the app", "we") is a media player that plays streams from a provider you supply. This policy applies to the ChannelSurf apps on all platforms and to this website.

Provider data and media

Data collected during normal app startup

After a provider profile opens, the app creates or restores a persistent anonymous Supabase Auth user ID and a random local device UUID. This happens even if you have not enabled cloud sync or linked an email.

We use those identifiers only for app functionality: authentication and authorization, entitlement/promotion lookup, device and sync security, and to make account linking, pairing, Transfer, Watch Party, remote access, and support available. They are linked to related account/device/group records when you use those features. They are not advertising identifiers and are never used to track you across other companies' apps or websites.

An unlinked anonymous backend user is automatically deleted after 180 days without account, device-group, entitlement, checkout, or session activity. The local UUID remains until app/site data is cleared. If you use only an anonymous identity, you can request earlier deletion from Settings → About → Send feedback. Using the app again creates a new anonymous identity.

Data collected when you choose a feature

Offline movies and episodes

When you request an offline copy, your paired home desktop receives the provider media URL and the title's display metadata over the authenticated ChannelSurf connection. It prepares a compatible media file and stores it in your chosen DVR folder or temporarily stages it for transfer. Provider URLs and transfer credentials are not written to the download index. Supported phones and tablets store completed media and its display metadata in profile-scoped, app-private storage; transfer credentials are protected by the device Keychain or Keystore. Completed copies remain until you delete them. Incomplete host staging expires after seven days.

Email account, trial, and Premium

Email linking is optional and passwordless. If you sign in, start a trial, or purchase Premium, Supabase stores your email and OTP/authentication events and links them to your existing user ID. Resend delivers transactional email.

Paddle is the merchant of record for current web purchases. Paddle processes the card, billing address, tax, invoice, and fraud checks under its privacy policy. ChannelSurf receives email, order, and subscription information, but never receives card or bank details. Apple processes iOS in-app purchases and Google processes Android in-app purchases under their respective store terms. ChannelSurf receives and verifies store transaction/subscription identifiers and renewal state, but does not receive payment credentials entered into either store.

Cross-device sync and device features

Cloud data upload begins only after you create or join a sync group. Supabase then processes:

Pair codes expire after 10 minutes; TV/account link codes expire after 15 minutes and are single-use. Expired code rows are automatically deleted after one day.

If you enable Watch from Anywhere, Supabase stores the group/host/device IDs, generated hostname, public IP, port, reachability/transport, and heartbeat or certificate times needed to reach your home host. Cloudflare provides DNS/relay/network protection and Let's Encrypt provides certificates. The relay carries TLS traffic without decrypting the application or media stream. Disabling the local server does not immediately delete the published endpoint; group/account deletion or a support request does, and endpoints without an update for 30 days are automatically deleted.

Transfer/remote command records contain device IDs, content/channel identity, position, status, and public-key material—not readable provider credentials. Rows older than 10 minutes are swept when a later command is sent, and every command row is automatically deleted after one day.

Watch Party optionally processes a nickname, random session member ID, presence, playback state, chat, and reactions through Supabase Realtime. ChannelSurf does not write that live-room content to its database; it lasts for the session.

Personalized movie and series recommendations

When Personalized recommendations is enabled, qualifying movie and episode viewing updates a compact preference signal. Live TV, catch-up, and DVR do not contribute. Recommendations are ranked on your device against that device's available catalog; ChannelSurf does not send your recommendation profile to an LLM or advertising service.

If the profile uses Cloud Sync, Supabase stores and relays the compact signals listed above so paired devices can produce consistent results. Titles, synopses, artwork, stream URLs, provider endpoints, usernames, passwords, and raw playback-event logs are not included. You can disable personalization or use Reset Recommendations in Settings. Viewing signals expire after 180 days and the retained set is capped at 500 rows, with explicit feedback retained ahead of ordinary viewing rows within that cap.

Movie and series topic enrichment

When you open a specific movie or series category, ChannelSurf may use TheTVDB to improve topic filters. Through an authenticated Supabase Edge Function, we send only a cleaned title, release year, movie/series type, and any validated TheTVDB, IMDb, or TMDB identifier already supplied with the provider metadata. We do not send provider credentials or URLs, stream IDs, profile IDs, viewing history, original uncleaned titles, or synopses.

Supabase stores a shared lookup cache containing a one-way lookup hash, content type, TheTVDB record ID, match status, returned genres/tags, confidence, and expiry—never the title, user, profile, provider, or stream. Successful matches expire after 30 days and misses after 7 days. A separate daily quota row contains only the Supabase user ID, UTC date, and uncached lookup count. Expired cache rows and prior-day quota rows are deleted by a daily database job; account deletion also removes that user's quota rows. TheTVDB processes lookup requests under its privacy policy. Local topic filtering remains available if enrichment is unavailable.

Bug reports and diagnostics

Reports are never sent automatically. If you press Send on a bug report or suggestion, we collect your report text/category and optional reply email. The app automatically attaches app version, platform/device model, user agent/WebView, relevant settings, sync state, feature/codec probes, recent JavaScript errors, and error context.

The attachment is scrubbed for known provider usernames, passwords, URLs and tokens, Stalker MAC identity, and parental PIN before upload. Supabase stores the report; Resend may deliver a copy to the ChannelSurf support mailbox. Database reports survive account deletion but are automatically deleted after 365 days. A delivered support-mailbox copy follows the same 365-day support procedure. You may request earlier deletion from support.

There is no automatic analytics or crash-reporting SDK. Ordinary local playback and LAN diagnostics stay on the device/home host unless you submit a report.

Website availability list and previous beta applications

If you join the availability list, or previously applied through the beta form, we store the email, form source, and a SHA-256 hash of the request IP for product-availability and testing communication, abuse prevention, and rate limiting. The current testing page uses official Apple, Google, and desktop download links. When you follow one, ChannelSurf increments a daily aggregate counter for the app platform and website page. The counter does not store an IP address, user agent, referrer, account identity, or other individual event data. The testing page does not collect an email, provider credentials, playlist URLs, or device details. If you email support for enrollment help, that message is treated as beta/support correspondence and deleted after 365 days.

The raw IP is used transiently by the form function and is not stored in the waitlist table. Waitlist email/IP-hash rows are automatically deleted after 365 days; unsubscribe or contact us for earlier deletion.

Cloudflare hosts and protects the website and processes ordinary request metadata such as IP address, user agent, time, and URL. Relevant pages request fonts from Google Fonts, release/download information from GitHub, and public promotion information from Supabase. Those providers may keep their own request logs. ChannelSurf does not install advertising or cross-site behavioral analytics trackers.

Purposes, linking, and service providers

We use data for app functionality, account management, customer support, developer communications you request, purchase fulfillment, security/fraud prevention, and legal/financial compliance.

Supabase provides Auth, database, Realtime, and Edge Functions. Resend delivers transactional/support email. Paddle processes web purchases; Apple and Google process purchases initiated in their native stores. Cloudflare hosts the website and supports optional remote access. TheTVDB supplies optional movie and series metadata for topic filters. Google Fonts and GitHub serve website resources. Your IPTV provider and casting platform are independent recipients you select.

Data associated with persistent user, device, group, purchase, waitlist, or report records is treated as linked. We do not sell personal data, use it for third-party advertising, or track you across other companies' apps or websites.

Retention and deletion

See Delete Account and Delete Your Data. If you cannot use in-app account deletion, email the address below from your linked account address; verifiable requests are processed within seven days.

Your rights

Depending on where you live (e.g., GDPR in the EU/UK, CCPA in California), you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us at the address below and we will honor applicable requests.

Device permissions

Children

The app is not directed to children and does not knowingly collect data from children.

Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

Contact

Patrick Walders — support@channelsurfplayer.com