Legal

Privacy Policy

Last updated: August 3, 2026 · Policy version 2026-08-03

Controller

My TV Player is operated by Quansight Consulting. Privacy and data-protection inquiries: .

Data we collect

  • Account: email, display name, hashed password, OAuth identifiers if you use social sign-in.
  • Playlists: M3U URLs, uploaded files, Xtream credentials (encrypted), parsed channel metadata, EPG URLs.
  • Usage: favorites, group layout, device list, optional continue-watching positions per profile (opt-in).
  • Devices: platform label, hashed device fingerprint, masked IP and coarse location (city/country) for security alerts.
  • Billing: Paddle customer ID, plan tier, invoice history, we never store full card numbers.
  • Technical: app version, OS, crash and error reports (sent by default; opt out in the app under Settings > Privacy).

Data we do not collect

  • We do not log what you watch unless you enable continue watching in Settings > Privacy.
  • We do not sell or rent personal data, there are no ads.
  • We do not use third-party tracking pixels on the web console.
  • We do not host or transcode your video streams on our servers by default.

Crash reports and telemetry

The native apps send crash and error telemetry so we can find and fix stability problems. Telemetry is enabled by default.

  • What is sent: crash reports, error diagnostics, app version and OS information, session counts, and sampled performance timings.
  • Why: to keep the apps stable and improve quality. Telemetry is never used for advertising or profiling.
  • Where it goes: Sentry, our error monitoring processor, using EU-hosted ingestion.
  • Never included: playlists, viewing activity, credentials, or other personal content.
  • Retention: reports are kept under Sentry's standard retention policy, then deleted.

You can opt out at any time in the app under Settings > Privacy > Send crash reports.

Legal bases (GDPR)

  • Contract providing the service you signed up for.
  • Legitimate interest fraud prevention, abuse detection, product security, and crash/error telemetry (enabled by default with an in-app opt-out).
  • Consent optional continue watching and marketing emails (off by default).

Where data lives

Application data is stored in our PostgreSQL cluster in EU-West (Frankfurt) when deployed to our EU production stack. Object storage (avatars, channel logos) uses S3-compatible storage in the same region. Backups are encrypted at rest and retained 30 days.

Retention

Active account data is kept while your account exists. Deleted accounts are purged within 30 days after the grace period, except billing records retained up to 7 years for tax law. Continue-watching rows delete with the profile or when you clear history or opt out.

Cookies & local storage

Strictly necessary cookies only, HttpOnly refresh token and CSRF protection for sign-in. No analytics cookies. Theme preference uses localStorage key mtp.theme. Web settings cache uses mtp.webSettings.v1; privacy toggles sync to your account server-side.

Processors

  • Paddle, merchant of record: payment processing, invoicing, and VAT/sales-tax compliance (PCI DSS).
  • Sentry, crash and error monitoring for the native apps (EU-hosted ingestion).
  • Transactional email provider, account verification and receipts.
  • Cloud host, EU infrastructure under DPA.
  • Google and Microsoft, optional sign-in (limited profile data).
  • Telegram, only if you link the optional notification bot; reminder text is delivered through Telegram.

Your rights

Access, rectify, export, or delete your data from Account > Data & privacy or by emailing . Update your display name on Account anytime. To change your sign-in email, use Account > Change email, we verify the new address before swapping it. We respond within 30 days. You may lodge a complaint with your local supervisory authority.

Children

The service is not directed at children under 16. Kid profiles are controlled by the account owner with parental PINs, we do not knowingly collect data from minors without guardian consent.

International transfers

Primary storage is in the EU. Crash and error telemetry goes to Sentry with EU data residency. Some processors (sign-in providers, Paddle) may process data in the United States under Standard Contractual Clauses and their DPAs.

Changes

We will post material changes here and email account owners 14 days before they take effect.