1. Information we collect
- Account details such as your email address, password setup status, and sign-in timestamps.
- Device details such as device identifiers, device name, app version, platform, and linked-device status. For each device signed in to your account we also record the most recent IP address and an approximate location (city/country) derived from it, to enforce the per-account device limit and to detect account sharing.
- Playlist or provider details you choose to store in your account portal or cloud-linked setup. When cloud sync or cloud backup is enabled, this also includes saved favourites, viewing history, reminders, profile settings and catalogue customisations. The Google Play version supports these features too; the limits on remote service checks below do not disable the cloud features you choose to use.
- Billing details such as plan, customer ID, subscription status, transaction status, and payment-provider references.
- Operational and security data such as rate-limit records, request status, and basic logs needed to keep the service running.
- Account linked product milestones: the first reported times you finish configuring a TV service with channels, reach active playback (including a playing guide preview or radio), are shown a plan price in the app, open a checkout link for your account, and continue from that page to payment, plus the app version you were using during your free trial. Newer versions of the app also record when your free trial ended and the first time you see your trial countdown or a notice that your trial has ended. These are single first time records, not a viewing history. See “Product milestones” below.
- If you opt in, anonymous diagnostic data such as crash and error reports, app version, and device model (see “Diagnostic data” below). This is off by default.
- If you join beta updates in the app, the linked device’s update channel, app build and enrollment time. Beta reports also include the device/build context shown in the report form. Provider credentials, account tokens and full stream URLs are excluded.
- On selected public information pages that carry advertising, Google may process advertising data such as your IP address, browser or device information, consent choices, and ad interactions. Advertising is not shown inside the TV app or on the privacy policy, admin, account, checkout, sign-in, device-pairing, or other non-content utility pages.
2. How we use information
- To create and secure accounts.
- To pair your phone with your TV and link devices to the same account.
- To store playlists or cloud-synced settings that you ask us to keep.
- To process premium billing, confirm entitlements, and prevent fraud or abuse.
- To limit how many devices an account can stream on, and to detect and prevent account sharing.
- To diagnose service problems, improve product reliability, and enforce our terms.
- To understand where account holders encounter difficulties between setup, playback and choosing a plan.
- To operate the opt-in beta programme, publish known issues and match reports to builds.
- To fund the free website and app through advertising on public content pages.
3. Third parties
TiviGlass may use third-party providers to operate core parts of the service, including hosting, authentication, storage, and payment processing. Those providers may process information on our behalf only as needed to deliver the relevant function.
Payment information is handled by the disclosed payment provider at checkout. TiviGlass does not claim to own or license third-party IPTV services, playlists, or streams that you choose to connect.
When our account creation, password reset or TV sign-in pages check that you are a person, they use Cloudflare Turnstile. It runs a short automatic check in your browser and sends Cloudflare technical signals such as your IP address, browser details and the address of our website. It does not read what you type. Cloudflare processes this for us to stop automated abuse, and may also use it to improve Turnstile, as described in the Turnstile Privacy Addendum.
Google AdSense is our advertising provider on public content pages. Google and the ad technology providers identified in the advertising consent flow may use information to serve, limit, secure, and measure ads according to your choices and location. Learn more about how Google uses information from sites that use its services.
4. Content-source responsibility
If you store playlist or provider details in TiviGlass, you remain responsible for making sure those sources are lawful and authorized. This policy does not change that responsibility, and TiviGlass does not provide or endorse unauthorized content sources.
5. Retention
Different records are kept for different lengths of time. The list below describes what the service actually does, rather than only what we intend.
- Account, device, and playlist records are kept for as long as your account exists. Deleting your account removes your profile, your plan and entitlement record, your device list (including the last IP address and approximate city recorded against each device), your saved playlists and the provider credentials stored with them, your cloud-synced settings and any cloud backup, your saved channel names and other catalogue customisations, and your support tickets.
- Product milestone records, including the app version you used during your free trial, are linked to your account and kept while it exists. They are deleted with the account.
- For a recurring plan purchased directly through Stripe, account deletion requests cancellation of that Stripe subscription. For a subscription purchased through Google Play, manage cancellation in Google Play before deleting your TiviGlass account; account deletion must not be treated as confirmation that Google Play billing has stopped.
- Sign-in tokens are short-lived. Once a token has been replaced by a newer one, a daily cleanup deletes it after 48 hours.
- Remote support sessions expire on their own and cannot be held open indefinitely. A pairing code is valid for one hour, a paired session closes after 20 minutes without operator activity, and no session lasts longer than two hours in total.
- Payment and invoice records are kept after an account is deleted, because tax and accounting law requires us to keep them. TiviGlass does not store your full payment card details; payments are handled by Stripe for direct purchases or Google Play for Play purchases.
- A small anti-abuse record of free-trial claims outlives the account that made it. That is deliberate: without it, deleting an account would reset the one-trial-per-person limit. It holds no readable email address or device identifier, only one-way hashes of them, together with the country and IP address the claim came from.
- Crash and error reports, if you switch them on, are not linked to your account, your playlists, or your hardware. They are grouped by a random identifier created on the device, which changes if you reinstall or clear the app's data, and credentials and other sensitive text are removed on the device before anything is sent. We keep them while they remain useful for diagnosing the fault they describe.
Where a record is no longer needed for the purpose it was collected for, we delete it or reduce it to a form that no longer identifies you.
VOD discovery and optional community rankings
Personal watch counts stay on this device within the active profile. They count qualifying playback in the built-in player and are removed locally on account sign-out or profile deletion. Recommendations use recent viewing locally to select a seed title. Discovery requests may send public TMDB IDs, or catalogue title names and years when resolving popularity metadata, through our cached metadata service to TMDB. Provider credentials and stream URLs are not included.
Sharing viewing counts is off by default for each profile on each device. If you enable it under Movies or Shows → Sort → Most watched on TiviGlass, known watched movie or series TMDB IDs are linked to your signed-in account for deduplication. At most one contribution per account/title/day and 30 titles per account/day are accepted. Only aggregate rankings for titles with at least five contributing accounts are displayed. Contributions are kept within a 30-day daily retention window and deleted with your account. Turning sharing off stops future contributions; existing contributions expire on that schedule.
6. Security
We use reasonable technical and organizational measures to protect service data, but no system is perfectly secure. You should also protect your device, account password, and access to email inboxes used for sign-in.
7. Your choices
- You can stop using the service at any time.
- You can remove playlists from the account portal that you no longer want stored there.
- You can manage direct purchases through Stripe, and Google Play purchases through Google Play. Use the payment provider through which you bought your plan to cancel an auto-renewing subscription.
- You can delete your TiviGlass account in the app using Delete your TiviGlass account in the account settings, or sign in at tiviglass.com/account and use its account deletion control. If you cannot access your account, contact admin@tiviglass.com for help requesting deletion. The retention section above explains which records are retained.
- You can turn anonymous diagnostic reporting on or off at any time in the app under Settings, Privacy.
- Where advertising choices apply, you can accept, reject, or manage purposes and vendors in the privacy message shown on an ad-supported page, and reopen those choices from its privacy options control. Browser controls can also remove stored advertising data.
8. Website advertising
TiviGlass uses Google AdSense only in clearly labelled spaces within public content. We do not use pop-up, interstitial, sticky, autoplay, or full-screen ads, and we keep advertising away from admin, sign-in, account management, checkout, device pairing, non-content utility flows, and this policy.
Ads may be contextual or personalized, depending on your region and the choices you make. For visitors in the UK, EEA, and Switzerland, advertising choices are collected through Google’s certified consent platform before they are used for personalized advertising. Declining personalization does not necessarily remove every ad: a contextual or limited ad may still be shown where permitted.
9. Diagnostic data (opt-in)
In the TiviGlass app you can choose to help improve the product by sending anonymous diagnostic reports. This is off by default and only happens if you turn it on, either at first launch or in Settings, Privacy.
When enabled, a report may include:
- Crash information — the technical error and where it occurred in the app.
- App error events such as playback or network failures.
- A playback smoothness summary, sent at most once a week and only if at least 10 minutes of video has been watched since the last one. It is numbers only: how many times playback started and how long the picture took to appear, how long video played, how often it failed to start or stopped to buffer, how many video frames were shown or dropped, how long the picture ran below its expected frame rate, how much of the viewing overlapped with the app updating in the background, and which type of decoder and player was in use. It is sent with the device and app details listed below, including counts of how the app last closed (for example a crash or the app stopping responding), memory use, and which video types the app has switched to software decoding. It names no channel, programme, title or provider, and it carries no error events. It is sent only while diagnostics are switched on.
- Your app version and build, device model and manufacturer, and Android/OS version.
- How much data the app is storing on this device — the size of its own database, how many playlists are saved, and how many channels, movies, shows and guide entries are cached. These are sizes and counts only: no playlist, provider, channel or title is named.
- A random, app-generated identifier used only to group reports from the same install.
Reports are redacted on your device before they are sent: they do not include your account, your playlists or provider details, usernames, passwords, stream URLs, or what you watch. The random identifier is not linked to your account and resets if you clear the app’s data or reinstall. You can turn diagnostics off at any time in Settings, Privacy.
One thing to be clear about, because “anonymous” can be read more strongly than we mean it: like every request the app makes to us, a diagnostic report is sent with your device’s Android device identifier. That is how we tell one TV from another and how we can act on a device when something is wrong with it, and it is sent whether or not diagnostics are switched on. It is not part of the report itself and it is not used to build a profile of you.
10. Remote service checks
Separately from the opt-in reporting above, we may run technical health checks on a device signed in to your TiviGlass account, to find and fix faults across the devices we support. These checks are run by our staff and are recorded against the staff member who started them. This is done on the basis of our legitimate interest in keeping the service working.
A check reads the same technical information the app already holds about itself, such as:
- App version and build, device model, OS version, and available memory and storage.
- Whether your TV guide, channel list and recordings look healthy, and how many of each you have.
- Recent playback, network and app errors, and which video and audio formats your device can decode.
- Whether your provider connection is reachable, and how fast it responded.
These checks only read information — they never change a setting, alter your playlists, or control what is on screen. They are designed so you cannot tell one is happening: nothing is displayed, and any check that could interrupt what you are watching is postponed until the device is idle. The results are redacted on your device before they are sent and never include your provider username or password, your account password, your stream addresses, or a record of what you watch.
Checks only run while the app is open and signed in. If you would prefer your devices were excluded, contact us at admin@tiviglass.com.
On the Google Play version of the app, these checks read less: the ones that would return your watch history, your saved and reminder lists, or your channel and on-demand line-ups are switched off entirely, leaving only the device and connection checks above. A support session you start yourself is unaffected on every version, because you are present and have agreed to it.
11. Approximate location
UK broadcasters produce regional versions of some channels — your local BBC One or ITV1, with your own news and opt-outs. So that the app can offer you the right one rather than another part of the country's, it asks our servers for an approximate location. This is done on the basis of our legitimate interest in showing you the correct regional channel.
The approximate location comes from your internet connection's IP address, which every website you visit can already see. Our network provider turns it into a rough country, region and city — never a street, an address or a precise position. The app does not use your device's GPS and does not ask for location permission.
The app can ask for microphone access on some TVs, and only when you press Speak to search or Speak a setting. Your voice goes to your TV's own speech service (for example Google's on Google TV) to be turned into text, the same way it would from the TV's remote; TiviGlass keeps no recording and no transcript, and never listens unless you press the microphone.
We do not store it. The location is worked out when your device asks and is not written to your account or kept as a history; your device remembers only which TV region it settled on, and that stays on the device. If your connection appears to be outside the UK — which is what happens on a VPN — the app simply applies no regional preference.
12. Product milestones
When you are signed in, we record single first time product milestones for your account: the first reported times you finish configuring a TV service with channels, reach active playback (including a playing guide preview or radio), are shown a plan price in the app, open a checkout link for your account, and continue from that page to payment, plus the app version you used while on a free trial. Newer versions of the app also record when your free trial ended and the first time you see your trial countdown or a notice that your trial has ended. The app reports its own milestones with its normal account check in, and the checkout steps are recorded by our website when you open and use a checkout link. We combine these with account trial and purchase records to understand which parts of getting started need improvement. We do not use them to decide your price or access to the service.
These measurements do not include programme titles, channel names, provider details, playlist contents, viewing duration or a log of repeated activity. Activity while signed out is not attributed to the next account that signs in. A later report from another device can correct a timestamp to an earlier occurrence; it does not create an activity history.
Our lawful basis is our legitimate interest in understanding and improving setup, playback and plan selection. This account-linked measurement is separate from optional anonymous diagnostic reports and does not use that diagnostic toggle. You can object to this use of your information by contacting us through Help and support.
13. Changes to this policy
We may update this policy as the service changes. The effective date at the top of this page identifies the current published version.