Smart M3U IPTV Player Privacy Policy
PRIVACY POLICY FOR SMART M3U IPTV PLAYER
Effective date: August 28, 2026
Last updated: August 28, 2026
App: Smart M3U IPTV Player (Android package com.m3uplayer.smartiptv)
Developer: Algesoft
Contact: anisrahman.contact@gmail.com
1. SUMMARY
Smart M3U IPTV Player is a media player for playlists you supply yourself. It has no user accounts and no advertising. We operate no server that receives your playlists, your credentials or your viewing activity.
Your playlists stay on your device. Everything you enter into the app - your playlists, credentials, favorites and settings - is stored only in the app's private storage on your device. We never receive its contents, and we do not sell or rent personal information to anyone. We do receive the anonymous counts and diagnostics described in section 5 - for example how many playlists exist, never their names, addresses or contents.
The app does include Google Analytics for Firebase, which collects anonymous, aggregated statistics about how the app is used - how many people open it, which Android versions and countries they use, and how the app performs. The app also records anonymous technical diagnostics - which features are used, and which failures occur - in a Google Firebase Realtime Database that we operate, so that we can find and fix faults. Neither contains your playlists, your credentials, or the names of the channels you watch. Section 5 sets out exactly what is and is not collected.
2. WHO WE ARE
Smart M3U IPTV Player is developed and published by Algesoft ("we", "us"). This policy explains how the app handles information. It applies to the Android application only, and not to any third-party service you choose to connect it to.
3. INFORMATION WE DO NOT COLLECT
We want to be specific rather than vague. The app does not:
- Create an account or profile for you, or ask for your name, email or phone number.
- Send your playlists, Xtream usernames and passwords, playlist passcodes, favorites, or the names of the channels you watch to us or to anyone else.
- Track your location. The app requests no location permission and has no access to GPS; it cannot read your contacts, camera or microphone. The only location-related information that exists is the country-and-region estimate Google derives from your IP address, described in section 5.
- Show advertisements, share data with advertising networks, build advertising profiles, or sell or rent personal information.
- Operate any backend server of ours that receives or stores your playlists or viewing activity.
The exceptions to "we collect nothing" are the anonymous usage measurement and the technical diagnostics described in section 5. Everything else in this policy still applies: your playlist data never leaves your device except to the servers you yourself point it at.
4. INFORMATION STORED ON YOUR DEVICE
The app saves the following locally, in its private application storage, so that it can work between launches.
The contents of this data are never sent to us or to our analytics. A small number of anonymous facts derived from it are, as described in section 5: how many playlists you have and roughly how many channels they contain, as ranges rather than exact figures, and whether you accepted the licence agreement - never a name, address, credential or channel. Otherwise it leaves your device only as described in section 7 (connections you initiate) and section 9 (backups you enable).
Playlists you add
- The playlist name, and the label, color and icon you choose for it.
- The playlist source: a URL, an Xtream Codes server address, or a reference to a file you selected from your device.
- The username and password for Xtream Codes playlists, when you enter them.
- An optional passcode, if you choose to lock a playlist.
- The number of channels found and the date the playlist was added.
Channel data loaded from your playlists
- Channel, movie and series names, their stream URLs, logo image addresses, and group/category names, as provided by your playlist.
- Which items you marked as favorites, and when an item was last played.
App settings
- Your selected interface language.
- Whether you have accepted the in-app license agreement.
5. ANALYTICS AND DIAGNOSTICS
We use Google Analytics for Firebase, a service provided by Google, to understand how the app is used in aggregate. Google acts as our data processor for this purpose.
What is collected automatically
- A randomly generated app instance identifier. It identifies an installation, not a person, and is not connected to your name, email or any account.
- Basic usage events: first launch, app opens and session length, app updates, screens viewed, and engagement time.
- Device and app information: device model and manufacturer, Android version, app version, screen size, device language, and network type.
- Approximate location, limited to country and region, derived from your IP address by Google. We never see your IP address in our analytics reports.
- The Android Advertising ID, where your device provides one - the Firebase Analytics library declares the com.google.android.gms.permission.AD_ID permission. We run no advertising campaigns and do not use this identifier for advertising, profiling or audience targeting.
Diagnostic data we collect directly
Separately from the analytics above, the app sends technical diagnostic data to a Google Firebase Realtime Database that we operate. We use it to find out which parts of the app are failing, and why people stop using it.
- A random installation identifier, created on your device by Firebase Authentication's anonymous sign-in. It identifies an installation, not a person, and is not linked to your name, email or any account. No account is created, and you are never asked to sign in.
- Device model and manufacturer, Android version, app version, device language, and whether the device is a television.
- Records of which features you use - for example that you opened the player, used search, marked a favourite, changed the playback speed, or entered a playlist passcode. We record only that a feature was used, and whether it succeeded; never what it was used on.
- Which screens you open inside the app.
- Whether a stream you played was a live channel, a film or a series episode, and roughly how long it played, as a range. Never its name, its address, or any list of what you have watched.
- Records of failures: why a playlist import failed, the HTTP status a server returned, and the error code when a stream will not play.
- Counts as ranges rather than exact figures - for example how many playlists you have and roughly how many channels they contain.
- The time of your most recent use of the app.
We keep only the 40 most recent events for each installation; older ones are overwritten.
What is never collected
- Playlist names, URLs, Xtream host addresses, usernames, passwords or passcodes.
- Channel names, stream URLs, search terms, or which particular channels you watch or mark as a favorite.
- Any file from your device, and any content of your playlists.
Why we collect it. To count how many people use the app, to see which Android versions and screen sizes we must support, to find and fix crashes, failed playlist imports and streams that will not play, and to decide which features to work on. Under the GDPR our lawful basis is our legitimate interest in maintaining and improving the app, or your consent where consent is required in your jurisdiction.
Where it goes. The data is processed by Google under Google's Privacy Policy (https://policies.google.com/privacy) and the Firebase data processing terms, and may be stored and processed on Google servers in countries outside your own, including the United States. See also how Google uses data from apps that use its services (https://policies.google.com/technologies/partner-sites).
How long it is kept. Analytics data is retained for the period set in our Firebase project settings, subject to Google's own limits - by default two months for device-level data and up to fourteen months for aggregate event data. Diagnostic data is retained until we remove it; the stored event history for each installation is limited to its 40 most recent events by design.
Your choices. The app does not currently offer an in-app switch to turn analytics or diagnostics off. You can limit what is collected by deleting or resetting your Advertising ID in Settings > Privacy > Ads (the exact path varies by device), and by turning off Usage & diagnostics in your Android settings. Clearing the app's storage or uninstalling the app resets both identifiers and stops further collection. Because this data is pseudonymous, and the installation identifiers are not shown to you and are not linked to any account, we have no way to match a request to the records belonging to a particular person or device, so we cannot delete an individual's analytics or diagnostic history on request.
6. PERMISSIONS THE APP REQUESTS, AND WHY
- INTERNET: To download playlists from a URL or Xtream server, to play streams, and to send anonymous analytics and diagnostics.
- ACCESS_NETWORK_STATE: To detect whether a network connection is available before loading or playing.
- WAKE_LOCK: To keep the network connection alive while a stream is buffering, so playback is not interrupted when the screen dims.
- com.google.android.gms.permission.AD_ID: Declared by the Firebase Analytics library so that it can read the Android Advertising ID. See section 5.
The app declares no storage or media permissions at all. Files are opened only through the system file picker, after you select them yourself. That grants the app temporary access to the one file you chose, and requires no storage or media permission on any Android version. The app cannot scan, index or browse your storage.
The app requests no location, contacts, camera, microphone or phone permissions.
7. CONNECTIONS TO THIRD-PARTY SERVERS
Smart M3U IPTV Player is a player, not a content service. When you add a playlist or play a channel, the app connects directly from your device to the server address you provided. We are not a party to that connection and cannot see it.
In the course of those connections, the operator of the server you chose may receive - as with any internet request - your IP address, the request time, the requested URL, and the app's user-agent string. Specifically:
- Playlist and Xtream servers receive requests for your playlist. For Xtream Codes playlists, the username and password you entered are sent to that server as part of the request, because that is how the Xtream protocol authenticates.
- Streaming servers receive requests for the media you play.
- Logo and artwork hosts receive requests for the channel images referenced by your playlist, so those images can be displayed.
These servers are operated by your provider or by third parties, not by us. Their handling of your data is governed by their privacy policies, which we neither control nor monitor. Please review your provider's policy before entering credentials.
Please also note: many IPTV providers offer only unencrypted http:// endpoints, and the app supports these for compatibility. When a server does not use https://, the request - including any Xtream username and password - travels across the network without encryption and could be observed on an untrusted network. Where your provider offers an https:// address, we recommend using it.
8. THIRD-PARTY SOFTWARE IN THE APP
The app is built with the following libraries. Apart from the Firebase services, they perform local functions only - playback, storage, networking, image decoding and interface rendering - and do not transmit data to their authors or to us:
- AndroidX Jetpack (Core, Lifecycle, Activity, Navigation) and Jetpack Compose with Material 3 - user interface.
- AndroidX Media3 / ExoPlayer - media playback.
- AndroidX Room - the local channel and playlist database.
- AndroidX DataStore - local settings storage.
- OkHttp (Square) - network requests to the servers you specify.
- Coil - loading and caching channel logo images.
- Feather icons (compose-icons) - interface icons.
- Google Analytics for Firebase, with Google Play Services Measurement - the anonymous usage statistics described in section 5.
- Firebase Realtime Database - stores the anonymous diagnostics described in section 5.
- Firebase Authentication, anonymous sign-in only - gives each installation a random identifier so that it can write only its own diagnostic record. It creates no account, asks for no email or password, and is never shown to you.
The app contains no advertising or attribution libraries. The only Firebase services it uses are Analytics, Realtime Database and anonymous Authentication, all described in section 5.
9. DEVICE BACKUPS
Android's own backup feature is enabled for this app. If you have device backup turned on in your Android settings, your app data - which includes your saved playlists, any stored Xtream usernames, passwords and playlist passcodes - may be copied into your personal Google account backup and restored onto your device or a new device.
That backup is created and held by Google under Google's Privacy Policy (https://policies.google.com/privacy), not by us, and we have no access to it. You can disable it at any time in your device's Settings > Google > Backup, or turn off backup for this app specifically where your device supports that.
10. RETENTION AND DELETION
Your playlists and settings are stored only on your device, so you remain in full control of them:
- Delete one playlist - removing a playlist in the app also deletes its stored credentials, passcode and all of its channels.
- Delete everything - clear the app's data in Settings > Apps > Smart M3U IPTV Player > Storage > Clear storage, which erases the database and all settings.
- Uninstall the app - this removes all of its local data from your device.
There is no server-side copy of your playlists for us to delete, and no account for you to close. If you have enabled device backup (section 9), remember to remove the backup through your Google account settings as well. Analytics and diagnostic retention, and their limits, are described in section 5.
11. SECURITY
Your data stays inside the app's private storage area, which Android's application sandbox protects from other apps on the device. We recommend that you also protect the device itself with a screen lock, PIN or biometric, since anyone with access to an unlocked device can open the app.
Please be aware of two limitations, so that you can make an informed choice:
- Saved Xtream credentials and playlist passcodes are stored in the app's private storage in readable form. They are not additionally encrypted, and they could be read on a device that has been rooted or otherwise compromised.
- The in-app playlist passcode is a convenience feature that hides a playlist behind a prompt. It is not an encryption feature and should not be relied on to protect sensitive material.
Data sent to our analytics and diagnostics is transmitted over an encrypted connection.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
12. CHILDREN'S PRIVACY
The app is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect personal information from children. If you believe a child has used the app and you have a concern, contact us at the address in section 16. The app does not supply any content itself; a parent or guardian is responsible for the playlists added to it and the material they contain.
13. YOUR PRIVACY RIGHTS
Privacy laws such as the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD and similar regimes give you rights to access, correct, delete, port and restrict the processing of your personal data, and to object to it.
For the playlists, credentials and settings you enter into the app, we are neither controller nor processor, because that data never reaches us. You can exercise the substance of these rights directly and immediately: it is all on your device, visible in the app, and removable by you at any time using the steps in section 10.
For the anonymous usage statistics and diagnostics in section 5, we act as controller and Google acts as our processor. That data is pseudonymous and we cannot connect it to you, which means we are unable to identify, export or delete the records for one particular person. You can stop future collection and reset the identifiers at any time using the options listed in section 5.
We do not sell or share personal information, and we do not engage in targeted advertising or profiling - so there is nothing to opt out of in that respect.
To make a request or ask a question about your rights, contact us at anisrahman.contact@gmail.com and we will respond within the period required by applicable law.
14. CONTENT
Smart M3U IPTV Player does not provide, host, store, curate or sell any media content. It is a player for content that you supply, and it is not affiliated with any content provider. You are responsible for the playlists you add and for holding the necessary rights to the material you play through the app, as set out in the license agreement shown when you first open it.
15. CHANGES TO THIS POLICY
We may update this policy to reflect changes in the app or in applicable law. The revised version will be published at this address with a new "Last updated" date. If a change materially affects how information is handled, we will make that clear in the app or in the store listing. Continuing to use the app after an update means you accept the revised policy.
16. CONTACT US
Questions, concerns or requests about this policy or your privacy:
Algesoft
Email: anisrahman.contact@gmail.com