Privacy Policy — CouchPotatoPlayer
Effective from 2026-07-18 for CouchPotatoPlayer 1.1.2 (338).
1. Controller and contact
- Legal controller: Stelios Sakalis (Privatperson)
- Postal address: Talhausring 32, 68219 Mannheim, Deutschland
- Privacy email: stelios@sakalis.eu
- Support email: stelios@sakalis.eu
CouchPotatoPlayer is a player only. It contains, provides, sells, or recommends no channels, films, series, playlists, provider access, or subscriptions. You add your own lawfully obtained source and are responsible for the necessary rights.
2. Data stored on your device
The app stores the settings needed to operate the player, including language, appearance, parental-control settings, favorites, viewing progress/history, selected tracks, player settings, and provider configuration. Provider URLs, usernames, passwords, tokens, optional M3U/EPG addresses, and similar access data are entered by you. Secrets and sync keys are stored through the operating system's secure Keychain/SecureStore where the implementation supports it. Library indexes, EPG data, cache entries, playback history, and other operational records may be stored in local SQLite or app files.
This local processing is required to perform the player functions you request. The developer cannot normally read data that remains only in your app container or Keychain.
3. Communication with sources you choose
The app connects directly to provider and media endpoints that you configure. Those operators receive the network information technically necessary for a connection, such as your IP address, request time, requested endpoint, device/network headers, and the credentials or tokens required by that source. Their privacy terms and retention practices apply independently. The controller of CouchPotatoPlayer neither selects those providers nor receives a copy merely because the app makes the connection.
Legacy providers may use unencrypted HTTP. The app permits this for compatibility, but HTTP can expose credentials and viewing traffic to networks between you and the provider. Prefer HTTPS and only add a service you trust.
4. Optional synchronization
iCloud synchronization is optional and starts only after your explicit consent. A complete encrypted backup can include provider configuration and library settings, including usernames, passwords, tokens, and URLs that contain credentials, as well as M3U/EPG addresses, favorites, viewing progress, and customization.
Before anything is stored in iCloud key-value storage, the app encrypts the backup locally with AES-256-GCM. The random vault key remains in device-bound SecureStore/Keychain storage on this Apple device and is not transferred automatically by iCloud. To use the backup on another Apple device, you must explicitly transfer the key with the recovery code. The recovery code is not stored in iCloud. Apple processes Apple-account and network information under its own terms. The developer receives neither plaintext provider data nor the vault key or recovery code through this feature.
5. Voice search
Voice search is optional. After you grant Microphone and Speech Recognition permission, spoken audio and the resulting transcription are processed through Apple's speech-recognition service to create a search query. CouchPotatoPlayer does not use voice input for advertising or profiling. You can deny or revoke the permissions in system settings and continue using text search.
6. Local network and AirPlay
Prepared AirPlay uses the local network to expose temporary HLS segments to a receiver you select. The receiver and local-network devices involved in routing can observe the connection information needed to fetch those segments. Temporary media is generated locally, served only for the playback session, and deleted when the session stops or cleanup runs. Direct AirPlay is managed by Apple system frameworks.
7. Photos and media selection
The audited release does not request Photo Library permission and does not import photos from the library. A system document picker may be available for files and is controlled by the operating system. If a future release adds photo access, this policy and the App Store privacy disclosures must be updated before release.
8. Diagnostics, support, and updates
Playback observations are kept locally in a bounded diagnostic history. If—and only if—you explicitly choose to submit a diagnostic report, the developer endpoint receives app/build/runtime version, platform and device class, selected player/backend, a technical stream profile, capability results, failure classification, and bounded playback observations. The exporter rejects provider URLs, query strings, credentials, tokens, and credential-like text. The report is not intended to identify you, but the hosting infrastructure may necessarily receive connection metadata such as IP address and request time.
Submitted diagnostics are classified as Product Interaction and Other Diagnostic Data, not linked to your identity, for App Functionality. Diagnostic reports are deleted after 30 days. Reverse-proxy and server access logs are deleted after 30 days. Hosting processor: Hetzner Online GmbH, Deutschland.
The app may contact cpp.team-ei.de for manually initiated support/legal pages, diagnostics, or update metadata. Automatic update checks are disabled on Apple in the current configuration. A support message you send outside the app is processed according to the contact channel you choose and may include the information you voluntarily provide. Support messages and their contact details are deleted no later than 30 days after the request is finally resolved, unless longer retention is required by law or needed to establish, exercise, or defend legal claims.
9. Third-party software
The audited app uses Apple platform services and React Native/Expo modules, including SecureStore, SQLite, speech recognition, iCloud, media playback, and optional sharing/document selection. Its Apple media stack includes CPPlayerKit/MPVKit and FFmpeg-related libraries. No advertising SDK or cross-app tracking SDK was found in the code audit. The Xcode Privacy Reports and third-party manifests for the exact iOS and tvOS build-331 archives were reviewed; both reports are error-free. App Store server validation remains required before release.
10. Purposes, legal basis, and disclosure
Data is processed to perform requested playback, library, synchronization, voice-search, AirPlay, support, security, and diagnostic functions; to remember your choices; and to diagnose a report you voluntarily submit. Depending on jurisdiction, the legal basis is performance of the service you request, your consent for optional permissions/sync/diagnostics, and legitimate interests in security and fault resolution.
The developer does not sell personal data, use it for advertising, or track you across apps and websites. Data is disclosed only to a destination you choose, to processors needed for a feature you enable, or where legally required. Provider operators, Apple, and the developer's hosting processor act under their own or agreed responsibilities.
11. Retention and deletion
Local data remains until you remove a provider, clear the relevant data, uninstall the app, or the operating system removes it. Prepared-AirPlay files are temporary and are deleted after stop/cleanup. Disabling synchronization or deleting local app data does not by itself remove the encrypted iCloud backup. The app's explicit delete-backup action turns off automatic sync and writes an authenticated deletion marker without provider data; Apple may retain service data according to its account rules. Submitted diagnostic reports are retained for 30 days and server/access logs for 30 days.
You can delete provider profiles in the app and delete all local app data by uninstalling it. Revoke microphone, speech, local-network, or iCloud access in the relevant system/account settings. For server-side support or diagnostic deletion, contact the controller with the report identifier where available. Deleting app data does not delete data independently held by a provider you chose.
12. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent for future processing. You may complain to a competent data-protection authority. Identity verification may be required, and legal exceptions may apply. Use stelios@sakalis.eu for privacy requests.
13. Children and changes
The app is not Made for Kids. User-configured sources can contain material unsuitable for children; use the available parental controls and supervise source selection. Material changes to data handling will be reflected in an updated policy and App Store disclosure before release.
Last updated: 2026-07-18.