1. Information we collect
- Account details such as your email address, password setup status, and sign-in timestamps.
- Device details such as device identifiers, device name, app version, platform, and linked-device status. For each device signed in to your account we also record the most recent IP address and an approximate location (city/country) derived from it, to enforce the per-account device limit and to detect account sharing.
- Playlist or provider details you choose to store in your account portal or cloud-linked setup.
- Billing details such as plan, customer ID, subscription status, transaction status, and payment-provider references.
- Operational and security data such as rate-limit records, request status, and basic logs needed to keep the service running.
- Account-linked product milestones: the first reported times you finish configuring a TV service with channels, reach active playback (including a playing guide preview or radio), and are shown a plan price in the app. These are three timestamps, not a viewing history. See “Product milestones” below.
- If you opt in, anonymous diagnostic data such as crash and error reports, app version, and device model (see “Diagnostic data” below). This is off by default.
- If you join beta updates in the app, the linked device’s update channel, app build and enrollment time. Beta reports also include the device/build context shown in the report form. Provider credentials, account tokens and full stream URLs are excluded.
- On selected public information pages that carry advertising, Google may process advertising data such as your IP address, browser or device information, consent choices, and ad interactions. Advertising is not shown inside the TV app or on the privacy policy, admin, account, checkout, sign-in, device-pairing, or other non-content utility pages.
2. How we use information
- To create and secure accounts.
- To pair your phone with your TV and link devices to the same account.
- To store playlists or cloud-synced settings that you ask us to keep.
- To process premium billing, confirm entitlements, and prevent fraud or abuse.
- To limit how many devices an account can stream on, and to detect and prevent account sharing.
- To diagnose service problems, improve product reliability, and enforce our terms.
- To understand where account holders encounter difficulties between setup, playback and choosing a plan.
- To operate the opt-in beta programme, publish known issues and match reports to builds.
- To fund the free website and app through advertising on public content pages.
3. Third parties
TiviGlass may use third-party providers to operate core parts of the service, including hosting, authentication, storage, and payment processing. Those providers may process information on our behalf only as needed to deliver the relevant function.
Payment information is handled by the disclosed payment provider at checkout. TiviGlass does not claim to own or license third-party IPTV services, playlists, or streams that you choose to connect.
Google AdSense is our advertising provider on public content pages. Google and the ad technology providers identified in the advertising consent flow may use information to serve, limit, secure, and measure ads according to your choices and location. Learn more about how Google uses information from sites that use its services.
4. Content-source responsibility
If you store playlist or provider details in TiviGlass, you remain responsible for making sure those sources are lawful and authorized. This policy does not change that responsibility, and TiviGlass does not provide or endorse unauthorized content sources.
5. Retention
Different records are kept for different lengths of time. The list below describes what the service actually does, rather than only what we intend.
- Account, device, and playlist records are kept for as long as your account exists. Deleting your account removes your profile, your plan and entitlement record, your device list (including the last IP address and approximate city recorded against each device), your saved playlists and the provider credentials stored with them, your cloud-synced settings and any cloud backup, your saved channel names and other catalogue customisations, and your support tickets.
- Product milestone timestamps are linked to your account and kept while it exists. They are deleted with the account.
- If you have a recurring plan, deleting your account also tells Stripe to cancel it at the end of the period you have already paid for, so you keep the access you bought until it runs out.
- Sign-in tokens are short-lived. Once a token has been replaced by a newer one, a daily cleanup deletes it after 48 hours.
- Remote support sessions expire on their own and cannot be held open indefinitely. A pairing code is valid for one hour, a paired session closes after 20 minutes without operator activity, and no session lasts longer than two hours in total.
- Payment and invoice records are kept after an account is deleted, because tax and accounting law requires us to keep them. We never hold your card details; Stripe processes and stores those.
- A small anti-abuse record of free-trial claims outlives the account that made it. That is deliberate: without it, deleting an account would reset the one-trial-per-person limit. It holds no readable email address or device identifier, only one-way hashes of them, together with the country and IP address the claim came from.
- Crash and error reports, if you switch them on, are not linked to your account, your playlists, or your hardware. They are grouped by a random identifier created on the device, which changes if you reinstall or clear the app's data, and credentials and other sensitive text are removed on the device before anything is sent. We keep them while they remain useful for diagnosing the fault they describe.
Where a record is no longer needed for the purpose it was collected for, we delete it or reduce it to a form that no longer identifies you.
VOD discovery and optional community rankings
Personal watch counts stay on this device within the active profile. They count qualifying playback in the built-in player and are removed locally on account sign-out or profile deletion. Recommendations use recent viewing locally to select a seed title. Discovery requests may send public TMDB IDs, or catalogue title names and years when resolving popularity metadata, through our cached metadata service to TMDB. Provider credentials and stream URLs are not included.
Sharing viewing counts is off by default for each profile on each device. If you enable it under Movies or Shows → Sort → Most watched on TiviGlass, known watched movie or series TMDB IDs are linked to your signed-in account for deduplication. At most one contribution per account/title/day and 30 titles per account/day are accepted. Only aggregate rankings for titles with at least five contributing accounts are displayed. Contributions are kept within a 30-day daily retention window and deleted with your account. Turning sharing off stops future contributions; existing contributions expire on that schedule.
6. Security
We use reasonable technical and organizational measures to protect service data, but no system is perfectly secure. You should also protect your device, account password, and access to email inboxes used for sign-in.
7. Your choices
- You can stop using the service at any time.
- You can remove playlists from the account portal that you no longer want stored there.
- You can manage payment methods and cancel an auto-renewing plan through Stripe.
- You can turn anonymous diagnostic reporting on or off at any time in the app under Settings, Privacy.
- Where advertising choices apply, you can accept, reject, or manage purposes and vendors in the privacy message shown on an ad-supported page, and reopen those choices from its privacy options control. Browser controls can also remove stored advertising data.
8. Website advertising
TiviGlass uses Google AdSense only in clearly labelled spaces within public content. We do not use pop-up, interstitial, sticky, autoplay, or full-screen ads, and we keep advertising away from admin, sign-in, account management, checkout, device pairing, non-content utility flows, and this policy.
Ads may be contextual or personalized, depending on your region and the choices you make. For visitors in the UK, EEA, and Switzerland, advertising choices are collected through Google’s certified consent platform before they are used for personalized advertising. Declining personalization does not necessarily remove every ad: a contextual or limited ad may still be shown where permitted.
9. Diagnostic data (opt-in)
In the TiviGlass app you can choose to help improve the product by sending anonymous diagnostic reports. This is off by default and only happens if you turn it on, either at first launch or in Settings, Privacy.
When enabled, a report may include:
- Crash information — the technical error and where it occurred in the app.
- App error events such as playback or network failures.
- Your app version and build, device model and manufacturer, and Android/OS version.
- How much data the app is storing on this device — the size of its own database, how many playlists are saved, and how many channels, movies, shows and guide entries are cached. These are sizes and counts only: no playlist, provider, channel or title is named.
- A random, app-generated identifier used only to group reports from the same install.
Reports are redacted on your device before they are sent: they do not include your account, your playlists or provider details, usernames, passwords, stream URLs, or what you watch. The random identifier is not linked to your account and resets if you clear the app’s data or reinstall. You can turn diagnostics off at any time in Settings, Privacy.
10. Remote service checks
Separately from the opt-in reporting above, we may run technical health checks on a device signed in to your TiviGlass account, to find and fix faults across the devices we support. These checks are run by our staff and are recorded against the staff member who started them. This is done on the basis of our legitimate interest in keeping the service working.
A check reads the same technical information the app already holds about itself, such as:
- App version and build, device model, OS version, and available memory and storage.
- Whether your TV guide, channel list and recordings look healthy, and how many of each you have.
- Recent playback, network and app errors, and which video and audio formats your device can decode.
- Whether your provider connection is reachable, and how fast it responded.
These checks only read information — they never change a setting, alter your playlists, or control what is on screen. They are designed so you cannot tell one is happening: nothing is displayed, and any check that could interrupt what you are watching is postponed until the device is idle. The results are redacted on your device before they are sent and never include your provider username or password, your account password, your stream addresses, or a record of what you watch.
Checks only run while the app is open and signed in. If you would prefer your devices were excluded, contact us at admin@tiviglass.com.
11. Approximate location
UK broadcasters produce regional versions of some channels — your local BBC One or ITV1, with your own news and opt-outs. So that the app can offer you the right one rather than another part of the country's, it asks our servers for an approximate location. This is done on the basis of our legitimate interest in showing you the correct regional channel.
The approximate location comes from your internet connection's IP address, which every website you visit can already see. Our network provider turns it into a rough country, region and city — never a street, an address or a precise position. The app does not use your device's GPS and does not ask for location permission.
The app can ask for microphone access on some TVs, and only when you press Speak to search or Speak a setting. Your voice goes to your TV's own speech service (for example Google's on Google TV) to be turned into text, the same way it would from the TV's remote; TiviGlass keeps no recording and no transcript, and never listens unless you press the microphone.
We do not store it. The location is worked out when your device asks and is not written to your account or kept as a history; your device remembers only which TV region it settled on, and that stays on the device. If your connection appears to be outside the UK — which is what happens on a VPN — the app simply applies no regional preference.
12. Product milestones
When you are signed in, the app reports three first-occurrence timestamps with its normal account check-in: usable service setup, active playback, and a displayed plan price. We combine these with account trial and purchase records to understand which parts of getting started need improvement. We do not use them to decide your price or access to the service.
These measurements do not include programme titles, channel names, provider details, playlist contents, viewing duration or a log of repeated activity. Activity while signed out is not attributed to the next account that signs in. A later report from another device can correct a timestamp to an earlier occurrence; it does not create an activity history.
Our lawful basis is our legitimate interest in understanding and improving setup, playback and plan selection. This account-linked measurement is separate from optional anonymous diagnostic reports and does not use that diagnostic toggle. You can object to this use of your information by contacting us through Help and support.
13. Changes to this policy
We may update this policy as the service changes. The effective date at the top of this page identifies the current published version.