Privacy Policy
ChannelSurf is operated by Patrick Walders, owner and operator of ChannelSurf. ChannelSurf ("the app", "we") is a media player that plays streams from a provider you supply. This policy applies to the ChannelSurf apps on all platforms and to this website.
Provider data and media
- Provider details (server URL, username/password, M3U/Xtream playlists, and Stalker portal identity) are stored locally. They are not part of cloud sync and are not uploaded to ChannelSurf in readable form.
- If you explicitly transfer a profile to another device, fresh end-to-end encryption protects the credentials. Supabase relays ciphertext and short-lived public-key material but cannot read the credentials. The receiving device stores the decrypted profile locally.
- Channel logos, posters, EPG data, and streams are fetched directly from your provider, not from us. We do not host, index, supply, or sell any media content.
- Casting sends playback information to the Google Cast, AirPlay, or DLNA device/service you select.
Data collected during normal app startup
After a provider profile opens, the app creates or restores a persistent anonymous Supabase Auth user ID and a random local device UUID. This happens even if you have not enabled cloud sync or linked an email.
We use those identifiers only for app functionality: authentication and authorization, entitlement/promotion lookup, device and sync security, and to make account linking, pairing, Transfer, Watch Party, remote access, and support available. They are linked to related account/device/group records when you use those features. They are not advertising identifiers and are never used to track you across other companies' apps or websites.
An unlinked anonymous backend user is automatically deleted after 180 days without account, device-group, entitlement, checkout, or session activity. The local UUID remains until app/site data is cleared. If you use only an anonymous identity, you can request earlier deletion from Settings → About → Send feedback. Using the app again creates a new anonymous identity.
Data collected when you choose a feature
Offline movies and episodes
When you request an offline copy, your paired home desktop receives the provider media URL and the title's display metadata over the authenticated ChannelSurf connection. It prepares a compatible media file and stores it in your chosen DVR folder or temporarily stages it for transfer. Provider URLs and transfer credentials are not written to the download index. Supported phones and tablets store completed media and its display metadata in profile-scoped, app-private storage; transfer credentials are protected by the device Keychain or Keystore. Completed copies remain until you delete them. Incomplete host staging expires after seven days.
Email account, trial, and Premium
Email linking is optional and passwordless. If you sign in, start a trial, or purchase Premium, Supabase stores your email and OTP/authentication events and links them to your existing user ID. Resend delivers transactional email.
- We store the plan, purchase source/status, renewal/cancellation dates, and customer/subscription/transaction identifiers needed to unlock and support Premium.
- A one-way SHA-256 email hash enforces one free trial per email.
Paddle is the merchant of record for current web purchases. Paddle processes the card, billing address, tax, invoice, and fraud checks under its privacy policy. ChannelSurf receives email, order, and subscription information, but never receives card or bank details. Apple processes iOS in-app purchases and Google processes Android in-app purchases under their respective store terms. ChannelSurf receives and verifies store transaction/subscription identifiers and renewal state, but does not receive payment credentials entered into either store.
Cross-device sync and device features
Cloud data upload begins only after you create or join a sync group. Supabase then processes:
- favorites, watchlist, watched episodes, recent/live activity, resume positions, content/channel identifiers and related display metadata;
- optional recommendation signals consisting of an opaque provider-aware movie/series content key, progress/completion, controlled topic identifiers, normalized genre/category keys, timestamps, “Not interested” feedback, and the personalization setting;
- provider display name/type, accent color, enabled state, and order; hidden channels/groups, provider-group names/order, custom category names and channel memberships, channel order, guide-cleanup choices, DVR state, preferred home-host settings, program-reminder title/channel/time metadata, and portable interface choices such as navigation/Home ordering and visibility, startup destination, quick-action ordering/visibility, and dismissed hints. Provider URLs, usernames, passwords, MAC addresses, playlist/XMLTV URLs, other login data, and notification tokens are not synced; and
- registered device ID, app-provided device name, platform/type, and last-seen time.
Pair codes expire after 10 minutes; TV/account link codes expire after 15 minutes and are single-use. Expired code rows are automatically deleted after one day.
If you enable Watch from Anywhere, Supabase stores the group/host/device IDs, generated hostname, public IP, port, reachability/transport, and heartbeat or certificate times needed to reach your home host. Cloudflare provides DNS/relay/network protection and Let's Encrypt provides certificates. The relay carries TLS traffic without decrypting the application or media stream. Disabling the local server does not immediately delete the published endpoint; group/account deletion or a support request does, and endpoints without an update for 30 days are automatically deleted.
Transfer/remote command records contain device IDs, content/channel identity, position, status, and public-key material—not readable provider credentials. Rows older than 10 minutes are swept when a later command is sent, and every command row is automatically deleted after one day.
Watch Party optionally processes a nickname, random session member ID, presence, playback state, chat, and reactions through Supabase Realtime. ChannelSurf does not write that live-room content to its database; it lasts for the session.
Personalized movie and series recommendations
When Personalized recommendations is enabled, qualifying movie and episode viewing updates a compact preference signal. Live TV, catch-up, and DVR do not contribute. Recommendations are ranked on your device against that device's available catalog; ChannelSurf does not send your recommendation profile to an LLM or advertising service.
If the profile uses Cloud Sync, Supabase stores and relays the compact signals listed above so paired devices can produce consistent results. Titles, synopses, artwork, stream URLs, provider endpoints, usernames, passwords, and raw playback-event logs are not included. You can disable personalization or use Reset Recommendations in Settings. Viewing signals expire after 180 days and the retained set is capped at 500 rows, with explicit feedback retained ahead of ordinary viewing rows within that cap.
Movie and series topic enrichment
When you open a specific movie or series category, ChannelSurf may use TheTVDB to improve topic filters. Through an authenticated Supabase Edge Function, we send only a cleaned title, release year, movie/series type, and any validated TheTVDB, IMDb, or TMDB identifier already supplied with the provider metadata. We do not send provider credentials or URLs, stream IDs, profile IDs, viewing history, original uncleaned titles, or synopses.
Supabase stores a shared lookup cache containing a one-way lookup hash, content type, TheTVDB record ID, match status, returned genres/tags, confidence, and expiry—never the title, user, profile, provider, or stream. Successful matches expire after 30 days and misses after 7 days. A separate daily quota row contains only the Supabase user ID, UTC date, and uncached lookup count. Expired cache rows and prior-day quota rows are deleted by a daily database job; account deletion also removes that user's quota rows. TheTVDB processes lookup requests under its privacy policy. Local topic filtering remains available if enrichment is unavailable.
Bug reports and diagnostics
Reports are never sent automatically. If you press Send on a bug report or suggestion, we collect your report text/category and optional reply email. The app automatically attaches app version, platform/device model, user agent/WebView, relevant settings, sync state, feature/codec probes, recent JavaScript errors, and error context.
The attachment is scrubbed for known provider usernames, passwords, URLs and tokens, Stalker MAC identity, and parental PIN before upload. Supabase stores the report; Resend may deliver a copy to the ChannelSurf support mailbox. Database reports survive account deletion but are automatically deleted after 365 days. A delivered support-mailbox copy follows the same 365-day support procedure. You may request earlier deletion from support.
There is no automatic analytics or crash-reporting SDK. Ordinary local playback and LAN diagnostics stay on the device/home host unless you submit a report.
Website availability list and previous beta applications
If you join the availability list, or previously applied through the beta form, we store the email, form source, and a SHA-256 hash of the request IP for product-availability and testing communication, abuse prevention, and rate limiting. The current testing page uses official Apple, Google, and desktop download links. When you follow one, ChannelSurf increments a daily aggregate counter for the app platform and website page. The counter does not store an IP address, user agent, referrer, account identity, or other individual event data. The testing page does not collect an email, provider credentials, playlist URLs, or device details. If you email support for enrollment help, that message is treated as beta/support correspondence and deleted after 365 days.
The raw IP is used transiently by the form function and is not stored in the waitlist table. Waitlist email/IP-hash rows are automatically deleted after 365 days; unsubscribe or contact us for earlier deletion.
Cloudflare hosts and protects the website and processes ordinary request metadata such as IP address, user agent, time, and URL. Relevant pages request fonts from Google Fonts, release/download information from GitHub, and public promotion information from Supabase. Those providers may keep their own request logs. ChannelSurf does not install advertising or cross-site behavioral analytics trackers.
Purposes, linking, and service providers
We use data for app functionality, account management, customer support, developer communications you request, purchase fulfillment, security/fraud prevention, and legal/financial compliance.
Supabase provides Auth, database, Realtime, and Edge Functions. Resend delivers transactional/support email. Paddle processes web purchases; Apple and Google process purchases initiated in their native stores. Cloudflare hosts the website and supports optional remote access. TheTVDB supplies optional movie and series metadata for topic filters. Google Fonts and GitHub serve website resources. Your IPTV provider and casting platform are independent recipients you select.
Data associated with persistent user, device, group, purchase, waitlist, or report records is treated as linked. We do not sell personal data, use it for third-party advertising, or track you across other companies' apps or websites.
Retention and deletion
- Synced data: kept while its sync group exists. Individual changes update or delete cloud items. Settings → Sync & Pairing → Clear synced data deletes the group's synced app data, recommendation signals, and resume rows, while leaving the account, entitlement, paired devices, and local copies. Disconnect removes only the current device.
- Account: Settings → Subscription → Delete account deletes the email-linked Auth user, entitlement, device-link codes, and that user's device memberships. A group and its synced data are deleted only if no other member remains; shared group data stays for remaining members. The app then creates a fresh anonymous identity. Deleting the account does not cancel an active Paddle subscription, and it also does not cancel an App Store or Google Play subscription. Cancel through Manage subscription and the billing provider.
- Records kept after account deletion: the irreversible trial-claim hash, detached processor-subscription ledger rows, and verified billing/audit events are automatically deleted after seven years. Database copies of submitted bug reports and any reply email/diagnostics are automatically deleted after 365 days; delivered support-mailbox copies follow the same 365-day support procedure. Payment processors may keep legally required records under their own policies.
- Other automatic limits: inactive, unlinked anonymous Auth users are deleted after 180 days; waitlist rows/IP hashes after 365 days; stale remote endpoint/public-IP rows after 30 days; expired TheTVDB cache records according to their 30-day/7-day expiry and prior-day topic lookup counters daily; device commands after one day; and expired pairing/link/checkout-token rows after one day.
- Local data: cloud deletion does not erase provider credentials, DVR files, offline media, or app data stored on a device or home desktop. Delete downloads from DVR & Downloads; delete the local profile, clear app data, or uninstall to remove other device copies.
See Delete Account and Delete Your Data. If you cannot use in-app account deletion, email the address below from your linked account address; verifiable requests are processed within seven days.
Your rights
Depending on where you live (e.g., GDPR in the EU/UK, CCPA in California), you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us at the address below and we will honor applicable requests.
Device permissions
- Camera — scans a pairing or upgrade QR code. Images are not retained or uploaded.
- Local network — discovers and streams to/from devices on your network for casting, handoff, Watch Party/Mirror, DVR, offline-download preparation, and home streaming.
- Notifications — shows locally scheduled program reminders and native playback/remote controls you enable. Program alerts are scheduled by the phone after reminder metadata syncs; ChannelSurf does not upload a push token.
Children
The app is not directed to children and does not knowingly collect data from children.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date above.
Contact
Patrick Walders — support@channelsurfplayer.com