Player NextGen
Privacy Policy
Effective 28 September 2026
This policy explains what data the Player NextGen apps handle and why: the Android app (phones, tablets, Chromebooks and Android TV / Google TV), the Apple apps and the app for LG smart TVs. In this policy, "we" means the developer of Player NextGen. You can reach us at admin@playernextgen.com.
Player NextGen is a player only. It does not provide, host or sell any channels, films or series. You add your own IPTV service (Xtream Codes or an M3U playlist), and the app plays what that service gives you. Your IPTV provider is an independent third party with its own privacy practices.
Data you give us
Your account
When you first open the app, an anonymous account is created automatically so your settings can be saved and synced. No name or email is attached to it. If you choose to sign in with Google or Apple, we receive the name, email address and profile picture that Google or Apple share for your account, and use them to sign you in and to show who is signed in.
Your IPTV providers
When you add a provider, the app stores its name, server address, username and password, and any guide (EPG) address you enter. On your device they are encrypted using the device's secure hardware key storage. To make them available on your other devices, they are also saved to your account in encrypted form (AES-256-GCM), with a key specific to your account that our server provides; our database stores only the encrypted data. If you upload a playlist file from your phone, it is stored in our cloud storage and accessible only to your account.
Your viewing activity
To keep your apps in sync across devices, your account stores:
- your favourite channels and recently watched channels (a channel identifier and a time);
- your "continue watching" progress (title, artwork, stream address and playback position) — stored encrypted;
- your last 10 searches — stored encrypted.
The app also keeps a local copy of your provider's channel list, programme guide and catalogue on your device, so it can show and search them. That copy is not uploaded.
Signing in on a TV
When you sign in on a TV by scanning its QR code or entering its code on your phone, a short-lived pairing record is created in our database. It is deleted once used, or when it expires a few minutes later.
Data collected automatically
Usage statistics
We use Google Firebase Analytics to understand how the app is used. When you play something, we record the type of content (live channel, film or episode), its category as named by your provider, how long it was watched, whether it was cast to a TV and whether playback failed. We do not record the titles you watch, your provider's address or your credentials. Firebase also collects standard technical information such as an app instance identifier, device model, operating system and app version, approximate location derived from your IP address (such as country or city), and, where your device allows it, its advertising identifier.
Crash reports and performance
We use Firebase Crashlytics and Firebase Performance Monitoring to find and fix problems. If the app crashes, a report is sent with technical details (the error, the state of the app, device model and operating system version). Performance Monitoring measures things like app start time and screen rendering. Crash and performance reports do not include your provider's credentials or the addresses of the streams you play.
Advertising
The app may show video ads before playback, served through Google's Interactive Media Ads (IMA) SDK. Google may use your device's advertising identifier, IP address and device information to deliver, measure and, depending on your settings, personalise ads. You can reset your advertising identifier or opt out of personalised ads in your device's settings (on Android: Settings › Privacy › Ads). See how Google uses information in ads.
Device permissions and local features
- Camera: (Android phones, optional) only to scan the QR code shown on your TV when you pair it. Images are processed on your device and are not stored or uploaded.
- Local network: to find media servers (DLNA) and cast devices on your home network. This happens on your network and nothing about your devices is sent to us.
- Casting: when you cast to a Chromecast or Google TV device, the stream address and title are sent directly to that device.
The app for LG smart TVs
The app for LG smart TVs runs on a web platform that cannot connect to most IPTV services directly, so in that app your requests to your provider (channel lists, guides and playlists) are relayed through our server. The relayed content is not stored. However, the address of each relayed request — which for Xtream Codes services can include your provider username and password — is recorded in our hosting provider's standard request logs, which are kept for up to 30 days and are used only to operate and secure the service. The Android and Apple apps connect to your provider directly and do not use this relay.
Who processes your data
We do not sell your data. Your data is processed on our behalf by Google (Firebase: authentication, database, file storage, server functions, analytics, crash reporting and performance monitoring; and the IMA ads SDK), and, if you sign in with Apple, by Apple for that sign-in. Your provider's streams and data come straight from your provider. Data is stored on Google Cloud servers, which may be located outside your country.
How long we keep it
- Account data is kept until you delete your account; a provider's details, until you remove that provider.
- An anonymous account that has not been used for 90 days is deleted automatically, with its data.
- Pairing records are deleted after use or within minutes.
- Analytics data is kept for the retention period set in Google Analytics (at most 14 months for user-level data); crash reports are kept for 90 days.
Your choices and rights
- Delete your account and data at any time at playernextgen.com/delete-account. Deletion is immediate and cannot be undone.
- Remove a provider in the app to delete its details from your devices and your account.
- Depending on where you live (for example, under the GDPR in the EU/UK), you may have the right to access, correct, delete or export your data, and to object to or restrict its processing. Write to admin@playernextgen.com and we will respond within 30 days. You can also complain to your local data protection authority.
Security
Provider credentials are encrypted on your device and in your account, connections to our services use HTTPS, and access to your account data is restricted to you. No system is perfectly secure, but we work to protect your data and will notify you as required by law if a breach affects it.
Children
Player NextGen is not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
If we change this policy, we will update it on this page and change the effective date above.
Contact
Questions or requests about your privacy: admin@playernextgen.com.