Privacy Policy — IPTV Deck
Last updated: July 20, 2026
1. Summary
This Privacy Policy explains how ZS Software ("we", "us") handles your data in the IPTV Deck mobile application ("the App"). By using the App you agree to this policy.
IPTV Deck is a media player. Most of your data — including your channel catalog — stays on your device. We only store data in the cloud when you sign in, and only to sync your setup across your devices. We do not sell your data and we do not show ads.
You control this in Settings → Sync & privacy:
- Choose what syncs — each category (settings, playlists, favorites, watchlist, continue watching, custom groups, hidden items) can be turned off individually. Turning one off deletes it from the cloud on the next sync.
- End-to-end encryption — optional. When enabled, your synced data is encrypted on your device before it is uploaded, and we hold only unreadable bytes. We cannot read it, and we cannot recover it for you.
- Choose where it is stored — on Android you can move your synced data to a private folder in your own Google Drive instead of our cloud.
2. Data we collect
Only when you sign in (optional):
- Account identifiers — the email address and/or name provided by Google or Apple sign-in, and a Firebase user ID.
- Synced app data, stored under your account so it can follow you across devices, limited to the categories you leave enabled:
- playlist metadata, including the server address and username for Xtream-type playlists you add;
- favorites, watch history, and custom groups;
- channel/category visibility settings and app preferences.
- Playlist passwords are not uploaded unless you enable end-to-end encryption. In that case they are encrypted on your device first and are unreadable to us. With encryption off, they never leave your device.
- A small unencrypted record stating which storage you chose and a non-reversible fingerprint of your encryption key. This lets a newly installed app find your data and tell you a recovery code is needed. It contains none of your content and cannot be used to decrypt anything.
Always (on your device):
- Your full channel catalog is stored locally in an on-device database and is not uploaded.
Purchases:
- RevenueCat processes and stores your subscription/purchase status and store receipts, tied to an app-generated identifier, so we can unlock Premium. Payment card details are handled solely by Apple/Google and are never seen by us.
Optional features:
- Subtitle search sends your search query to OpenSubtitles only when you use that feature.
- Diagnostics — if enabled in a build, aggregated crash reports may be collected (Sentry) to help us fix bugs. These do not include your playlist credentials.
We do not collect advertising identifiers and do not track you across other apps or websites.
3. How we use your data
- To authenticate you and sync your playlists, favorites, history, and settings across your devices.
- To provide and restore your Premium entitlement.
- To operate optional features you invoke (e.g. subtitle search).
- To diagnose crashes and improve reliability.
4. Third parties
We share data only with service providers that make the App work:
- Google Firebase (Authentication, Firestore) — account and synced data. See Google's Privacy Policy and the Firebase data-processing terms.
- RevenueCat — subscription status and receipts.
- Apple App Store / Google Play — payment processing.
- OpenSubtitles — only your subtitle search query, only when used.
- Sentry — optional crash diagnostics.
- Google Drive — only if you choose it as your sync storage (Android). Your data is written to a private application folder in your own Drive account, which other apps cannot read. We never receive a copy of it. Removing the app's data from your Google account settings deletes that copy.
We do not sell or rent your personal data to anyone.
5. Storage and retention
Synced data is retained while your account exists. Local data remains on your device until you delete it or uninstall the App. When you delete your account, your cloud data is removed (see below).
6. Your rights and choices
- Delete your account and cloud data at any time from Settings → Account → Delete account. This removes your synced data from Firestore and deletes your authentication record. Local on-device data is removed when you uninstall the App. If you moved your sync to your own Google Drive, delete that copy from your Google account's app-data settings — we have no access to it.
- Stop syncing any category at any time from Settings → Sync & privacy. The category is deleted from the cloud on the next sync while your device keeps its copy.
- Access or correction — contact us to request a copy of, or correction to, your data.
- Depending on your region (e.g. EU/EEA under GDPR), you may have additional rights, including the right to object, restrict processing, or lodge a complaint with a supervisory authority.
7. Children
The App is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
8. Security
Data in transit is encrypted (HTTPS/TLS). Cloud data is protected by per-user security rules so that a signed-in user can access only their own document. No method of transmission or storage is 100% secure.
End-to-end encryption (optional). When you enable it, your synced data is encrypted on your device using XChaCha20-Poly1305 before upload. The key never leaves your device: it is shown to you once as a recovery code and stored in the operating system's secure keystore (Android Keystore / iOS Keychain), marked so that it is not copied to iCloud or any other backup.
This has a consequence we want to state plainly: we cannot reset it and we cannot recover your data. If you lose your recovery code and no longer have a device holding the key, the data stored in the cloud is permanently unreadable — by you and by us. In the App you can start over from a device that still has its local copy.
Your playlist passwords remain in the secure keystore on your device at all times, regardless of these settings.
9. International transfers
Our providers may process data on servers outside your country. Where required, appropriate safeguards are applied.
10. Changes to this policy
We may update this policy from time to time. Material changes are reflected by updating the "Last updated" date.
11. Contact
Privacy questions or data requests:
Email: mistyksu@gmail.com