Privacy Policy - iOS
Effective Date: November 11, 2025
1. Introduction
Welcome to GridStreamr ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our iOS application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the GridStreamr iOS app.
Important: GridStreamr allows you to organize playlists using different formats (including M3U URLs and Xtream Codes), create customized playlists based on existing playlist entries, view EPG (Electronic Program Guide) data, and watch streaming content using our built-in video player. We do not host, provide, or stream any content ourselves—content is streamed directly from your configured sources to your device. You are solely responsible for ensuring you have legal rights to access any content sources you add.
By using our app, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our app.
2. Information We Collect
2.1 Personal Information
When you create an account or sign in, we may collect:
- Email address (for account creation and authentication)
- Username
- Full name
- Phone number (if provided)
- Password (encrypted and securely stored, when using email/password authentication)
Gmail Authentication
When you sign in using Gmail (Google Sign-In), we collect:
- Your Gmail email address
- Your Google account name
- Your Google profile information (if made available by Google)
- Google account ID (used for authentication)
We use Google's OAuth 2.0 authentication service. When you sign in with Google, you authorize us to access this information from your Google account. We do not have access to your Gmail password or other Google account credentials.
2.2 Playlist and Media Information
To provide our core services, we collect:
- Playlist URLs and configurations you add to the app
- Playlist names and custom labels
- Viewing preferences and favorites
- Channel organization and custom categories
2.3 Usage Data
We automatically collect certain information when you use our app:
- Device type and model
- Operating system version
- App version
- Usage statistics (features used, time spent in app)
- Crash reports and diagnostic data
2.4 Data We Do NOT Collect
- We do not collect, store, or transmit the actual media content you view through the app
- We do not host or provide any video or audio content
- We do not collect your precise location data
- We do not collect your contacts or photos
- We do not access your device's microphone or camera without your explicit permission
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Create and manage your account
- Store and sync your playlist configurations and customizations across devices
- Enable playlist organization and custom playlist creation features
- Display EPG (Electronic Program Guide) data for your playlists
- Enable the video player functionality for viewing content from your sources
- Provide customer support and respond to your inquiries
- Send you important service updates and notifications
- Analyze usage patterns to improve app performance
- Debug and fix technical issues
- Ensure the security of our services
Note: We do not use your data for content recommendations, as we do not provide or control the content itself. Content is sourced directly from your configured playlist providers.
4. Tracking and Advertising
4.1 App Tracking Transparency
We respect Apple's App Tracking Transparency (ATT) framework. If our app requests permission to track you across other companies' apps or websites, we will:
- Present you with a clear explanation of why we're requesting permission
- Only track if you grant permission
- Respect your choice if you decline tracking
- Never gate app functionality based on your tracking preference
4.2 Analytics
We use analytics services to understand how our app is used and to improve our services. These analytics:
- Help us identify and fix crashes and bugs
- Show us which features are most popular
- Are aggregated and anonymized where possible
- Comply with Apple's privacy requirements
4.3 Advertising
Currently, we do not display third-party advertisements in our app. If this changes in the future, we will:
- Update this privacy policy
- Request your permission through the ATT framework if required
- Provide you with control over your advertising preferences
5. Third-Party Services
Our app uses the following third-party services:
5.1 Supabase
We use Supabase for authentication and data storage. Your data is stored securely on Supabase's servers. Review Supabase's privacy policy at: https://supabase.com/privacy
Google OAuth Services
When you use Gmail sign-in, we integrate with Google's OAuth 2.0 authentication services. Google processes your authentication request and provides us with limited profile information. Review Google's privacy policy at: https://policies.google.com/privacy
Data Sharing with Google: When you sign in with Gmail, we share your authentication request with Google. Google confirms your identity and shares your profile information (email, name) with us. We do not share your playlist data or viewing activity with Google.
5.2 RevenueCat
We use RevenueCat for in-app subscription management. RevenueCat processes subscription-related data. Review RevenueCat's privacy policy at: https://www.revenuecat.com/privacy
5.3 External Playlist Sources and Content Providers
When you add playlists from external sources (M3U URLs, Xtream Codes providers), the app connects directly to those services to retrieve playlist information and stream content through the built-in video player. We act only as an intermediary for organization purposes:
- We do not host, store, or cache the media content from these sources
- Content streams directly from your configured providers to your device
- We do not control or modify the content from these sources
- We are not responsible for the privacy practices of external content providers
- You should review the privacy policies of your content providers
Your Responsibility: You are responsible for ensuring you have legal rights to access content from any sources you configure in the app. We do not verify, endorse, or take responsibility for the content or services provided by third-party sources.
6. Data Storage and Security
We take data security seriously and implement appropriate technical and organizational measures to protect your information:
- All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS
- Your password is encrypted using bcrypt hashing
- We store data in secure, SOC 2 Type II certified data centers
- We implement access controls to limit who can access user data
- We regularly review and update our security practices
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.
7. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (e.g., hosting, analytics, payment processing)
- Legal Requirements: When required by law, court order, or government regulation
- Safety and Rights: To protect our rights, privacy, safety, or property, and that of our users or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified)
8. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this privacy policy. Specifically:
- Account information (email, name, username, phone) is retained until you delete your account
- Google sign-in data is retained for authentication purposes while you have an active account
- Playlist data is retained while you have an active account
- Usage analytics may be retained for up to 2 years for service improvement purposes
- Crash logs and diagnostic data are typically retained for 90 days
When you delete your account, we delete all personal information including your email, name, phone number, and Google account association within 30 days, except where we are required to retain certain information for legal or regulatory compliance.
9. Your Rights and Choices
You have the following rights regarding your personal information:
9.1 Access and Portability
You can access your personal information and playlist configurations at any time through the app. You can export your playlist organization data and customizations in standard formats. Note that we only store your organizational preferences and configurations, not the actual media content from your sources.
9.2 Correction
You can update your account information (email, name, username, phone number) and playlist details directly in the app. If you signed in with Gmail and want to update your Google account information, you must do so through your Google account settings.
9.3 Deletion
You can delete your account and all associated data through the app settings. Once deleted, your data cannot be recovered. This includes:
- Your personal information (email, name, username, phone)
- Your Google sign-in association (if applicable)
- All playlist configurations and customizations
- Favorites and preferences
To delete your account:
- Open the GridStreamr app
- Navigate to Settings → Account
- Select "Delete Account"
- Confirm your decision
Note: Deleting your GridStreamr account does not delete your Google account. If you want to revoke GridStreamr's access to your Google account, visit Google's security settings at: https://myaccount.google.com/permissions
9.4 Tracking Preferences
You can control tracking permissions through:
- iOS Settings → Privacy & Security → Tracking
- iOS Settings → Privacy & Security → Apple Advertising → Personalized Ads
9.5 Marketing Communications
You can opt out of promotional emails by clicking the unsubscribe link in any marketing email or by adjusting your notification preferences in the app.
10. Children's Privacy
Our app is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.
11. International Data Transfers
Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. By using our app, you consent to such transfers.
12. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, and disclose
- Right to request deletion of your personal information
- Right to opt-out of the sale of personal information (Note: we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us using the information below.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
14. Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:
- Posting the new privacy policy in the app
- Updating the "Effective Date" at the top of this policy
- Sending you an email notification (for significant changes)
- Displaying an in-app notification
Your continued use of the app after changes are made constitutes acceptance of those changes.
15. Contact Us
If you have questions, concerns, or requests regarding this privacy policy or our privacy practices, please contact us:
Email: gridstreamr@gmail.com
Website: https://gridstreamr.com
Response Time: We aim to respond to all privacy inquiries within 30 days
16. Data Protection Officer
For privacy-related inquiries specific to GDPR compliance, you can contact our Data Protection Officer at:
Email: gridstreamr@gmail.com
17. Apple App Store Privacy Information
In accordance with Apple's App Store requirements, here is a summary of our data collection practices:
Data Used to Track You
We do not use your data to track you across apps and websites owned by other companies unless you grant permission through the App Tracking Transparency framework.
Data Linked to You
- Contact Info: Email address, name, phone number (if provided), Gmail account details (if using Google Sign-In)
- User Content: Playlists, favorites, viewing preferences, username
- Identifiers: User ID, Google account ID (if using Gmail sign-in)
- Usage Data: Product interaction, crash data
Data Not Linked to You
- Diagnostics: Crash logs, performance data
This privacy policy was last updated on November 11, 2025