ModelTV is a video player for Android, Android TV and Google TV. It plays the M3U playlists and Xtream accounts you provide yourself. ModelTV does not provide any channel, movie or subscription.
This policy describes the data ModelTV uses, where it goes and how long it is kept. It applies to the Google Play and GitHub versions of the app.
Controller: the developer of ModelTV, reachable at [email protected].
1. What stays on your device
- Your playlists: M3U addresses, Xtream servers, usernames and passwords. They are stored only on the device and are never sent to the ModelTV server. The app uses them to contact your provider directly. To set up a TV, a phone can send it the playlist directly over your local network, encrypted, without going through the ModelTV server.
- Your library, profiles, favorites, history, progress and settings, as long as you do not use a ModelTV account.
- The report of the last crash (Settings → About), which contains no address or credential and is sent nowhere.
Uninstalling ModelTV erases this data.
2. What is sent, even without an account
- ModelTV server (Google Firebase, Paris region): when the app starts, a pseudonymous device identifier (a fingerprint computed from the Android ID, which cannot be used to recover it), the app version and variant. The server keeps the date of the first launch, the date of the last contact, the version and the variant. This is used to deliver service information (for example a required update) and to manage a possible trial period. This identifier is stored neither with your account nor with your e-mail address; it is erased two years after the device’s last contact. To limit abuse, the server counts requests per fingerprint of the IP address and per minute; these counters are erased automatically within 48 hours.
- TMDb (The Movie Database): the titles and years of the movies and series in your playlist, to get posters, synopses and cast. TMDb also receives your IP address, like any website you visit. The information received is kept on the device for six months at most. TMDb policy: https://www.themoviedb.org/privacy-policy
- IntroDB: the IMDb identifier, season and episode of a series, to know where its opening credits are.
- YouTube: a trailer opens in the YouTube app or website, subject to Google’s rules.
- Google Cast: when you cast to a TV, the video address is sent to the Cast device.
- Your IPTV provider receives playback and catalog requests, as with any player.
3. With a ModelTV account (optional)
The account is used to sync your devices. It uses Google sign-in (Firebase Authentication) or, on a TV, a QR code approved from a phone that is already signed in.
- Identity: e-mail address, name and photo of your Google account, and a technical account identifier.
- Synced data: profiles (name, color, avatar), favorites, watch history and progress (titles, TMDb identifiers, positions), appearance and playback settings, favorite channels, custom categories, recently watched channels, channel grouping rules. Settings specific to a playlist are stored under an anonymous fingerprint of the playlist: never its address or its credentials.
- Connecting a TV: a five-minute session with the device name, erased automatically within 48 hours.
- Sign-in security: Firebase Authentication also processes the IP address and the device type (user agent) to prevent abuse.
- Trakt (if you link it): Trakt access tokens are kept on the ModelTV server, without being readable by the app, and the titles you have watched with the linked profiles are sent to Trakt. Trakt policy: https://trakt.tv/privacy
This data is hosted by Google Firebase and kept until the account is deleted.
Built-in Google services
ModelTV uses Google libraries that send technical data to Google, under the Google privacy policy:
- Firebase (account, sync, ModelTV server): IP address and user agent of requests.
- Google Cast: anonymous usage logs (device discovery, casting sessions, device model), with no identifier that could be traced back to you.
- QR code scanner from Google Play services: performance and usage metrics of the scanner.
4. Deleting your account
- In the app: Settings → Account & profiles → Delete my account. Synced profiles, favorites, history, progress and settings are erased from the server, linked Trakt accounts are disconnected (tokens revoked), TV connections and any access granted to your address are erased, then the account itself is deleted.
- Without the app: follow the page Delete your ModelTV account
5. What ModelTV does not do
- No advertising. No audience measurement or ad tracking tools: only the technical data of the Google services described above is sent to them.
- No sale or rental of data.
- No audiovisual content provided: you are responsible for holding the rights to the playlists you use.
6. Security
Exchanges with the ModelTV server, TMDb, IntroDB and Trakt are encrypted (HTTPS). Exchanges with your provider use the address you entered: if it starts with http://, your username, password and video streams travel unencrypted and can be read on the network. Before saving such a playlist, ModelTV points this out, checks whether the provider also answers over https:// and, if so, offers that encrypted address. Account data is accessible only to that account.
7. Children
ModelTV is not intended for children under 13 and does not knowingly collect their data.
8. Your rights
You can request access to your data, its correction, deletion or portability, or object to its processing, by writing to [email protected]. You can also contact the French data protection authority, the CNIL (www.cnil.fr).
9. Changes
Any change to this policy is published at this address with its update date.