Legal

Privacy Policy

Last updated: 16 June 2026

Introduction

channl.tv ("we", "us", "our") operates the channl.tv service, a cross-platform BYOS (Bring Your Own Subscription) IPTV, VOD and catch-up streaming application. This Privacy Policy explains how we collect, use, store and protect your personal data when you use our website, desktop application, and mobile application (collectively, the "Service").

By using the Service, you agree to the collection and use of information as described in this policy.

Data We Collect

Account information

  • Email address
  • Display name (optional)
  • Password (securely hashed with bcrypt; we never store plaintext passwords)

Device information

  • Device name and platform (e.g. macOS, iOS, Windows)
  • Device fingerprint (for session management and multi-device limits)
  • A push notification token, if you enable notifications, used solely to route notifications to that device (an APNs, FCM or Web Push token — a routing identifier, not used for tracking)
  • IP address (logged temporarily for rate limiting and security)

IPTV and media source credentials

  • Credentials for the sources you connect — Xtream Codes, Stalker/MAG portals, M3U/M3U8 playlists, and Jellyfin or Emby servers
  • These are encrypted at rest using AES-256-GCM encryption and are never shared with third parties
  • Local-network sources such as HDHomeRun tuners and Tvheadend servers are configured on your device, and their connection details are not sent to our servers

Usage and sync data

  • Watch history (channel names, stream IDs, timestamps)
  • Resume positions (playback progress for movies and series)
  • Favourites and user-created channel groups
  • Application settings and preferences (e.g. time format, theme)
  • EPG reminders and per-category notification preferences (including quiet hours)
  • Your notification consent record (see Notifications & Your Consent)

Payment information

Payment processing is handled entirely by Stripe. We do not store credit card numbers, CVVs or full payment details. We receive only a Stripe customer ID, subscription status and billing events via webhook.

How We Use Your Data

  • To provide and maintain the Service, including user authentication and cloud sync
  • To manage your subscription and process payments via Stripe
  • To sync your watch history, favourites, groups and settings across devices
  • To enforce tier-based feature limits (Free, Standard, Premium)
  • To send transactional emails (verification, password reset, billing notices)
  • To send notifications you have asked for (such as programme reminders, new-content alerts and announcements) by push and/or email. Push is delivered through the platform service for your device — Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and the Web Push standard (VAPID) in your browser
  • To measure whether the notifications we send are delivered and opened, so we can keep the service reliable. This is first-party only and records no message content — see "Notifications & your consent" below
  • To detect and prevent abuse, fraud and unauthorised access

Notifications & Your Consent

channl.tv sends notifications only for the things you ask it to. You can turn each category on or off, per channel (push, email and in-app), at any time from the Notifications screen in the app or from your online account settings.

Categories

  • Programme reminders — a nudge before a show you set a reminder for starts.
  • Account & billing — payment issues, plan changes and renewal notices. Billing emails are essential to the service and cannot be switched off while you have an account; you can still turn off billing push.
  • New content — new episodes for series you follow.
  • Announcements — product news and the occasional update from channl. These are marketing messages and are off until you opt in (see below).

How push is delivered

Push notifications are routed through the push service for your device — APNs on iOS, FCM on Android, and the browser's Web Push service in your browser (see Third-Party Services). To do this we store a per-device push token, which is a routing identifier; we do not use it to build a profile of you or to track you across apps or sites.

Marketing opt-in and withdrawal

Marketing communications (announcements and any promotional email or push) are sent only with your explicit, opt-in consent, in line with UK PECR and GDPR. You can withdraw that consent at any time — from the Notifications screen, from your account settings, or via the unsubscribe link in any marketing email — and we will stop sending them. Withdrawing marketing consent does not affect transactional messages such as email verification, password resets, billing notices or reminders you set yourself.

Consent record

When you grant or withdraw consent (for notification permission or marketing) we keep an append-only record of that decision — the type of consent, whether it was granted or withdrawn, when, from which kind of device, and the policy version in force — so we can demonstrate that we honoured your choices. This ledger contains no message content.

Quiet hours

You can set quiet hours per category so notifications are held back during times you choose (for example overnight). Quiet hours are applied in your time zone.

Turning notifications off entirely

Beyond the in-app controls, you can revoke notification permission at the operating-system or browser level at any time (in your device or browser settings), which stops all push from channl.tv regardless of your in-app choices.

Delivery & open measurement

To keep the service reliable we record whether each notification we send was delivered to your device and whether it was opened. These events are first-party, are stored alongside your account, contain no message content (no titles, bodies or recipients beyond the account itself), and are never shared with advertising networks or used to profile you. They are retained for up to 90 days and then aggregated. These events are included in any data export you request.

What happens when you delete your account

When you delete your account we permanently delete your notification preferences, inbox and delivery/open events. To preserve a defensible legal record of the consent decisions you made (as required to demonstrate compliance), the consent ledger entries are anonymised rather than deleted — your account identifier is removed and replaced with a non-reversible pseudonym, leaving only the consent type, action, timestamps and policy version, retained for a limited period. Because of this, a fresh account registered later with the same email address starts with marketing consent off and inherits none of the previous account's preferences or consent history.

Launch Waitlist & Marketing Emails

If you ask us to tell you when channl.tv launches or when a platform becomes available — for example through the "Notify me" form on our website — we collect your email address and, if you choose to give it, a first name, together with the details needed to evidence your consent (the time, a truncated IP address and browser user-agent, and the version of the wording you agreed to). You do not need a channl.tv account to join the list, and joining does not create one.

Lawful basis & double opt-in

We send these emails only with your explicit, opt-in consent (UK PECR regulation 22 and UK GDPR Article 6(1)(a)). The marketing consent box is never pre-ticked and is separate from agreeing to our Terms. We use double opt-in: after you submit the form we email you a confirmation link, and we do not add you to the list — or send anything further — until you click it. If you receive a confirmation email you did not request, simply ignore it (or use the "remove this address" link in it) and the address is discarded.

How we send them

Marketing and confirmation emails are delivered by Resend, our email service provider, acting as our processor. Your email address may be processed outside the UK and EEA; where it is, the transfer is made under an appropriate safeguard. See the Resend Privacy Policy.

Withdrawing consent & retention

Every marketing email carries a one-click unsubscribe link, and you can withdraw consent at any time; we then stop sending and record the address as unsubscribed so it is not contacted again. If you never confirm, your details are deleted automatically after a short period. We keep an append-only record of your consent (granted or withdrawn, when, and the wording version) so we can demonstrate we honoured your choices; it contains no message content. If you later delete a channl.tv account that uses the same email address, we also delete the matching waitlist entry and its consent record.

Your rights

You can ask us to access or erase the personal data we hold about you on the list at any time by emailing [email protected], and you have the right to complain to the Information Commissioner's Office (ICO).

Data Storage

Cloud storage

Account data, sync data and encrypted source credentials are stored in a MySQL database hosted on Railway. All data is transmitted over HTTPS/TLS.

Local storage

The channl.tv desktop and mobile applications store data locally in a SQLite database on your device. This includes cached channels, EPG data, playback state and locally saved preferences. Local data remains on your device and is not transmitted unless cloud sync is enabled.

Soft deletes

When you delete data (favourites, groups, history), it is soft-deleted in the cloud to support incremental sync across your devices. Soft-deleted records are periodically purged.

Third-Party Services

  • Stripe — Payment processing and subscription management. Subject to the Stripe Privacy Policy.
  • Apple Push Notification service (APNs) — Delivers push notifications to the iOS and iPadOS app. Used only to route notifications you have asked for; the push token is a device identifier, not used to track you. Subject to the Apple Privacy Policy. We do not use Firebase on iOS.
  • Firebase Cloud Messaging (FCM) — Delivers push notifications to the Android app. Subject to the Firebase Privacy Policy.
  • Web Push (VAPID) — Browser push is delivered through the push service operated by your browser's vendor (for example Google, Mozilla or Apple) using the open Web Push standard. We do not load any Firebase or third-party push SDK in the browser; the message payload is encrypted end-to-end to your browser.
  • Google Fonts — Font delivery on the website. Subject to the Google Privacy Policy.
  • Railway — Cloud hosting infrastructure for our API server and database.
  • Resend — Delivers our transactional emails (such as email verification and password resets) and our opt-in marketing emails (launch-waitlist confirmations and updates). Subject to the Resend Privacy Policy.
  • Sentry (EU region) — Crash and performance diagnostics for the app and website. We run Sentry with personal-information collection disabled and scrub credentials before any event is sent. Subject to the Sentry Privacy Policy.
  • TMDB — The app fetches movie and TV artwork and metadata from this service. We do not send it any personal data. Subject to the TMDB privacy terms.
  • Trakt (optional) — Only if you connect a Trakt account, your play/scrobble activity for matched movies and shows is sent to Trakt to sync your watch history. You can disconnect at any time. Subject to the Trakt Privacy Policy.

We do not sell your personal data to any third party. We do not use advertising trackers or analytics services that profile individual users.

Diagnostics and Telemetry

To keep playback reliable and improve the product, the app sends limited diagnostic telemetry to our servers by default when you are signed in and online: playback diagnostics (which playback route/engine was used, whether it succeeded, startup time, failure category, and the container/codec, platform and app version involved) and anonymous layout and feature-usage signals. The name of your IPTV provider is stored only as a salted hash, never in the clear, and we never send your source credentials or stream URLs. Telemetry is linked to your account and device while you are signed in and is retained for about 90 days. You can turn it off at any time in the app under Settings → Data. Crash and performance diagnostics are handled by Sentry as described above.

Cookies

We use a small number of cookies that are strictly necessary to operate the website and keep you signed in. We do not use cookies for advertising, tracking, profiling or third-party analytics, and we do not sell or share cookie data with anyone.

Because these cookies are essential to provide a service you have requested (signing in and staying signed in), they are exempt from prior consent under the UK Privacy and Electronic Communications Regulations (PECR) and the EU ePrivacy Directive. We do not set any non-essential cookies, so there is no consent banner with on/off toggles.

Cookies we set

  • access_token — an httpOnly session cookie that holds your short-lived access token so the site can authenticate you. Expires within minutes; refreshed automatically while you are signed in.
  • refresh_token — an httpOnly cookie used to renew your session without re-entering your password. Expires after 30 days, or when you sign out.
  • theme — a small preference stored in your browser to remember whether you chose the light or dark appearance. This stays on your device and is never sent to our servers.

The authentication cookies are flagged httpOnly (JavaScript cannot read them), SameSite=Lax, and Secure in production, so they are only transmitted over HTTPS to our own origin. You can clear these cookies at any time through your browser settings or by signing out; doing so will end your session.

Data Security

We implement industry-standard security measures to protect your data:

  • All API communication is encrypted via HTTPS/TLS
  • Passwords are hashed using bcrypt
  • IPTV source credentials and sensitive API keys are encrypted with AES-256-GCM
  • JWT access tokens expire after 15 minutes; refresh tokens after 30 days
  • Rate limiting is enforced on all API endpoints
  • Password changes and resets invalidate all active sessions

Data Breach Notification

We maintain an internal incident and breach-response procedure. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority — in the UK, the Information Commissioner's Office (ICO) — without undue delay and, where required, within 72 hours of becoming aware of it (UK GDPR Article 33).

Where a breach is likely to result in a high risk to you (for example, exposure of account credentials), we will also notify you without undue delay, in clear language, describing what happened, the likely consequences, the measures we have taken, and the steps you should consider — such as resetting your password and rotating the credentials of any IPTV sources you have connected (UK GDPR Article 34).

If you believe your account or data may have been compromised, contact us at [email protected]. Security researchers should follow our security policy.

Data Retention

We retain your account data for as long as your account is active. If you delete your account, all associated personal data, sync data and encrypted credentials will be permanently deleted within 30 days. Notification delivery and open events are retained for up to 90 days and then aggregated. Your notification consent record is anonymised rather than deleted on account closure, as described under Notifications & Your Consent. Anonymised, aggregated usage statistics may be retained for service improvement.

You can delete your account at any time — from inside the app, from your online account settings, or by request without the app. See our account and data deletion page for step-by-step instructions.

Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access — You may request a copy of the personal data we hold about you.
  • Right to rectification — You may request correction of inaccurate or incomplete data.
  • Right to erasure — You may request deletion of your personal data ("right to be forgotten").
  • Right to data portability — You may request your data in a structured, machine-readable format.
  • Right to restrict processing — You may request that we limit how we use your data.
  • Right to object — You may object to processing based on legitimate interests.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

Children's Privacy

The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Contact

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

channl.tv
Email: [email protected]

channl.tvMade for people who love TV
UpdatesSupportPrivacyTermsCopyrightDelete accountContact
© 2026 channl.tv · All rights reserved