Privacy Policy
Cedra is a local-first, multi-source media client for playlists and subscriptions you already own. An account is optional. Cedra Cloud works only in builds where the service is configured and after you choose to sign in. We minimise the data we collect, do not sell personal data, and describe third-party processing below.
Data kept on your device
- The current Xtream password is AES-GCM encrypted with a key held by Android Keystore. The Xtream host and username remain plaintext in the local Room database.
- Complete M3U and custom EPG URLs remain plaintext in Room. Those URLs can contain query tokens or embedded credentials. Android app sandboxing and disabled OS backup reduce exposure, but these fields are not application-level encrypted.
- Playlist and catalog contents, locally reconstructed stream URLs, viewing and search history, downloads, and downloaded media.
- Your OpenSubtitles API key, if you configure one. TMDB and OMDb keys are supplied by the app operator in configured builds; there is no Cedra setting for users to enter either key.
- Cached posters, backdrops, EPG programs, metadata, favourites, profile details, folders, category organization, and selected settings, except for the organization fields you choose to sync through Cedra Cloud.
Optional Cedra Cloud
If you choose email sign-in, Supabase processes your email, six-digit OTP authentication, account UUID, random app device/session UUID, device name, signed session data, IP address, and paid/free entitlement mirror.
- Cedra syncs exactly five organization kinds: profiles, favourites, folders, category order/visibility, and selected settings. It does not sync viewing positions or history.
- Raw provider credentials and URLs, playlist contents, stream links, viewing/search history, downloads, and media are excluded from Cloud sync.
- Source-scoped organization rows can include a stable full SHA-256 digest derived locally from source identity. The raw source value is not uploaded, but the digest is pseudonymous and correlatable, not anonymous.
- RevenueCat uses the Supabase account UUID as its App User ID while the verified Cloud account is attached.
Cedra Cloud must remain disabled in production until in-app account deletion, the required public web deletion route, and written legal approval are complete.
Provider intelligence
- If you explicitly enable category-detection telemetry, Cedra sends a taxonomy fingerprint and unrecognized provider-supplied category words through an admitted Cloud session. The aggregate store does not retain the requesting account/device UUID or viewing activity and removes a row 90 days after its last report. Provider menu text can itself contain names, hostnames, URL-like text, or account labels, so it is not anonymous.
- If you invoke Smart Cleanup, Cedra sends up to 120 raw provider category menu names to its server. Shared-cache misses are forwarded to the configured LLM provider for classification. The shared cache retains raw names, hashes, labels, and review metadata until manual deletion or service retirement; it is not linked to the requesting account, but arbitrary menu text can still identify or correlate a provider. Account/session quota events are retained only for a rolling 24-hour enforcement window and removed by an hourly job.
Metadata and other third-party services
- TMDB (themoviedb.org): when the operator configures the shared read token, catalog updates and a periodic schedule automatically send cleaned provider-derived movie/series title and optional year searches to TMDB. Detail, image, and cast requests can follow. TMDB receives the connecting IP address; Cedra does not attach its Cloud account/device IDs. There is currently no in-app TMDB toggle.
- OMDb (omdbapi.com): an operator key can configure the client, but the current app has no runtime OMDb request callsite and sends no catalog data to OMDb today.
- OpenSubtitles: if you save an API key, searches you trigger send the connecting IP and search/title hashes to its service.
- iptv-org GitHub: automatic channel-logo fallback requests expose the connecting IP address and requested repository asset.
Firebase and RevenueCat
- Firebase Analytics and Crashlytics: in a configured
release, Firebase starts automatically, Analytics collects configured
or default interaction and app/device-instance data, and Crashlytics
collects crashes plus pre-redacted breadcrumbs. Cedra currently has no
collection toggle. Resetting Android's advertising ID is not an
opt-out. Builds without
google-services.jsondo not initialize Firebase, and Crashlytics is forced off in debug builds. - RevenueCat: in a billing-configured build, the SDK starts under a RevenueCat-generated anonymous App User ID and immediately requests CustomerInfo, even before a purchase or Cloud sign-in. A verified Cloud attach changes the ID to the Supabase UUID; detach returns it to an anonymous ID. Purchase/subscription information is processed when available. Cedra currently plans monthly and annual subscriptions only; there is no production lifetime product.
Diagnostics
Only when you tap "Share diagnostics", Cedra prepares app version, device model, Android version, network transport, per-source item counts, indexer state, and the last 200 lines of redacted logs. You choose where to send that JSON through Android's share interface; Cedra does not automatically collect the diagnostics package.
What Cedra does not collect in Cloud
- The video or audio content you stream
- Your viewing or search history
- Raw provider credentials, provider URLs, stream links, or playlist contents
- Your name or postal address; email is processed only for an optional Cloud account
Your rights
- Delete local data: uninstalling Cedra or clearing its app storage removes local app data. This is not a request to delete data already processed by a third party.
- Cloud account: signing out detaches the device but does not delete the account. Until self-service account deletion is shipped and verified, contact us for server-side deletion; production Cloud account creation remains disabled.
- Firebase: Cedra has no in-app Analytics or Crashlytics opt-out in a configured release. Resetting the advertising ID does not disable collection.
- Contact us: email hello@cedraplayer.com.
Children's privacy
We do not knowingly collect data from children under 13. The Kids Profile feature filters content client-side; parents remain responsible for reviewing the content sources they configure.
Contact
Email hello@cedraplayer.com.
Changes
We will update this page when the privacy posture changes. The "Last updated" date at the top is authoritative.