Privacy Policy
How NextGen handles data
This policy describes the native NextGen IPTV Player Xtream M3U app and this legal website.
Effective and last updated: 26 August 2026
Plain-language summary
- The app is a player. NextGen IPTV Player does not supply, host or sell IPTV subscriptions or media.
- Your playlist connection and library data are stored locally. Connection secrets are protected using Apple Keychain-backed protection and authenticated encryption where the app must materialise them.
- If an eligible Pro user enables Sync with iCloud, supported personal state and encrypted playlist connection fields are copied to the user's private native CloudKit database so they can be restored on supported devices.
- Apple and RevenueCat process purchase and entitlement information. Apple processes iCloud data.
- Firebase Analytics and Crashlytics remain off unless you expressly opt in. The app never sends playlist URLs, provider credentials, channel or programme names, or media titles to Firebase.
- The app contacts sources you configure to import and play media, and may contact OMDb for optional metadata. Those services receive the information necessary for the request and ordinary network data such as an IP address.
1. Who is responsible for this policy
The app and this website are operated as NextGen IPTV Player ("NextGen", "we", "us" or "our"). For privacy questions or requests, email nextgeniptvplayer@gmail.com.
2. Scope and role of the app
NextGen is a standalone player for user-supplied M3U playlists and Xtream-compatible connections. We do not provide, sell, recommend, host or control the media or provider service you add. Your provider is independent from NextGen and handles data under its own terms and privacy practices.
3. Data handled by the app
3.1 Data stored locally
Depending on the features you use, the app stores the following on your device:
- profiles and active profile or playlist selections;
- playlist names, M3U or custom EPG URLs, provider base URLs and Xtream-compatible usernames and passwords;
- provider catalogues, categories, artwork and metadata caches, EPG data and import state;
- favourites, hidden items, custom names, ordering, reminders, watched state and playback progress;
- appearance, playback and refresh preferences;
- media you expressly choose to download for offline use, plus local download state; and
- a bounded encrypted recovery checkpoint on Apple TV because tvOS may purge local cache storage.
Playlist connection secrets are not kept as ordinary plaintext preferences. The app uses Keychain-backed references and authenticated encryption for credential-bearing values that must be stored locally. No security method can guarantee absolute protection.
3.2 Requests to your chosen provider
To import a catalogue, refresh EPG data, play a stream or download media, the app connects directly to the URL or provider you configure. The request can include the source URL, username, password or access token needed by that provider. The provider and its network infrastructure may receive your IP address, device/network information and request details.
The app allows user-configured sources using HTTP as well as HTTPS because some IPTV providers do not support HTTPS. HTTP traffic is not encrypted in transit. Use HTTP sources only if you understand and accept that risk. App-configured fixed-service connections use HTTPS.
3.3 Optional Sync with iCloud
For eligible Pro users, Sync with iCloud is an optional, device-local setting. When enabled, the app uses Apple's CloudKit service and a dedicated fresh native CloudKit container. It does not read or migrate records created by the previous React Native version.
Supported synced data includes:
- profiles and profile avatars;
- playlist connection definitions, including source or EPG URLs and provider credentials;
- favourites, hidden state, watched state, playback progress and last-played information;
- custom content or category names, content/category ordering and category visibility;
- reminders and deletion markers needed to synchronise removals.
Playlist connection fields are uploaded using CloudKit encrypted-value fields. Synced records are placed in the private CloudKit database associated with your Apple Account. Apple states that private-database records are accessible only to that user by default and are not visible through the developer's CloudKit console.
The app does not sync provider catalogues, provider responses, EPG/XMLTV data, artwork or metadata caches, downloaded media files, raw diagnostics, API keys, or device-only appearance/playback/refresh settings.
Turning Sync with iCloud off stops future app-initiated transfers on that device; it does not delete data already stored locally or in iCloud. Deleting supported profiles, playlists or personal state through the app can create synchronised deletion records. Removing the app or disabling its iCloud access does not necessarily erase existing CloudKit records.
3.4 Purchases and subscriptions
Apple processes App Store billing. RevenueCat helps the app retrieve products, validate receipts, restore purchases and determine Pro entitlement. RevenueCat may process a pseudonymous app-user identifier, Apple receipt and transaction details, product and entitlement information, app/device/OS technical information, country or region, and last-seen timestamps. We do not receive your full payment-card details.
3.5 Optional Firebase Analytics and Crashlytics
Firebase Analytics and Crashlytics are disabled by default and remain disabled while your choice is undecided or denied. They activate only after you expressly opt in on that device. There is no pre-consent event buffer.
If you opt in, the app may send:
- coarse product-interaction events for setup, playback, refresh, feature access and purchase journeys;
- platform/device family, app version and build, OS major version, locale and Free/Pro state;
- coarse duration or item-count ranges, controlled outcome codes and Boolean states; and
- crash stack traces and bounded technical diagnostics needed to investigate unexpected failures.
Firebase also uses installation or crash-installation identifiers and receives ordinary technical information described in its documentation. NextGen does not set a Firebase user ID, request advertising tracking permission, use the data for targeted advertising, or join Firebase data to RevenueCat customer identifiers.
The app's analytics boundary excludes playlist/provider names, URLs, hostnames, addresses, usernames, passwords, content IDs or titles, programme names, email addresses, free text, raw provider errors and CloudKit/RevenueCat/Firebase record identifiers.
You can change the choice in the app's Settings. Revoking consent disables future collection, resets local Analytics state and deletes unsent Crashlytics reports. It cannot recall data already transmitted; Firebase retention and deletion processes continue to apply to data already received.
3.6 Optional metadata lookups
When metadata enrichment is enabled and a catalogue item is eligible, the app may send a title, content type, release year or IMDb identifier to the OMDb API to retrieve ratings, identifiers or artwork metadata. Playlist credentials are not included in that lookup. OMDb and its network providers may receive the query and ordinary network data.
3.7 Support and community messages
If you contact us by email or Discord, we receive the information you choose to provide, such as your email address or account name, message, screenshots and technical details. Do not send playlist credentials, full provider URLs, unauthorised media or other sensitive information. Email and Discord process communications under their own terms and policies.
3.8 This website
This is a static Firebase Hosting website. It does not include app-owned analytics, advertising pixels, forms or preference storage. Firebase Hosting processes incoming IP addresses and request/technical data to deliver and protect the site and may retain IP data for a limited period as described by Firebase. See the Cookie Policy.
4. Purposes and legal grounds
Where UK or European data-protection law applies, we process data as follows:
- To provide the app and requested features: performance of our contract with you, including local storage, provider requests, purchases, restoration, support and iCloud sync you enable.
- Optional analytics and diagnostics: your consent, which you may withdraw at any time in Settings.
- Security, fraud prevention and service reliability: our legitimate interests and those of our processors, balanced against your rights.
- Legal and accounting requirements: compliance with applicable law.
5. Service providers and disclosures
| Recipient | Purpose | Relevant information |
|---|---|---|
| Apple | App distribution, purchases, StoreKit, private CloudKit sync and Apple platform services | Purchase/receipt data, Apple Account/iCloud data, device and service data under Apple's policies |
| RevenueCat | Products, receipt validation, entitlements, purchase and restore support | Pseudonymous identifier, transaction/receipt, entitlement and technical data |
| Google Firebase | Consent-based Analytics and Crashlytics; static website hosting | Coarse product interaction and technical/crash data after consent; hosting request/IP data |
| OMDb API | Optional ratings and metadata enrichment | Title, type, year or IMDb identifier and ordinary network data |
| Your provider | Catalogue/EPG import, playback and downloads you request | Configured URL and credentials/tokens, requested resource and ordinary network data |
| Email/Discord providers | Support and community communication you initiate | Your account/contact details and message content |
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal information and do not use it for cross-app advertising tracking.
6. International processing
Apple, RevenueCat, Google, OMDb, email providers and Discord may process information outside your country. Their own policies and contractual safeguards govern those transfers. Firebase states that most Firebase services can process data on global infrastructure.
7. Retention and deletion
- Local app data: remains until you delete the relevant item/data in the app or remove the app, subject to device backups and tvOS recovery behaviour.
- Offline downloads: remain in the app-owned download area until you remove them, delete the owning profile where cleanup applies, or remove the app.
- Private iCloud data: remains until synchronised deletion or Apple account/iCloud controls remove it. Turning sync off alone does not delete it.
- Firebase: only receives app analytics/crash data after consent. Already transmitted data follows Firebase project settings and service retention; Firebase documents 90-day retention before removal begins for Crashlytics crash traces and associated identifiers.
- RevenueCat and Apple: retain transaction, entitlement and accounting records under their policies and legal obligations.
- Support: retained only as reasonably needed to answer the request, protect the service and meet legal obligations.
- Website hosting: Firebase documents that Hosting retains incoming IP data for a limited number of months.
8. Your choices and rights
- Enable or disable Sync with iCloud in the app, subject to Pro access.
- Grant, refuse or later revoke Firebase Analytics and Crashlytics consent in Settings.
- Delete playlists, profiles, downloads and supported personal state using the app's controls.
- Manage subscriptions, refunds and Apple Account/iCloud access through Apple.
- Ask us for access, correction, deletion, restriction, portability or objection where applicable to data we control.
- Complain to the UK Information Commissioner's Office or your local supervisory authority.
Private CloudKit records belong to your Apple Account and are not visible to us through the developer console. This can limit our ability to access or delete them for you. Contact us for guidance, and do not assume that disabling sync or uninstalling the app deletes existing iCloud data.
9. Children
NextGen is not directed to children and does not provide or curate content. User-supplied sources can contain material unsuitable for children. A parent or guardian should supervise use by anyone who cannot lawfully consent for themselves and should control the provider source, purchases, downloads, analytics choice and iCloud settings.
10. Security
We use platform security controls, bounded network/data handling, Keychain-backed secret protection, authenticated encryption for materialised credential-bearing values and CloudKit encrypted fields for synced connection secrets. You are responsible for choosing trustworthy providers and securing your devices and Apple Account. No system is completely secure, and HTTP provider connections are not encrypted in transit.
11. Changes to this policy
We may update this policy when features, providers or legal requirements change. We will publish the revised date here. If a change requires new consent, the app will request it before the relevant optional processing begins.
12. Contact
NextGen IPTV Player
Email: nextgeniptvplayer@gmail.com
United Kingdom
Useful provider policies: Apple Privacy Policy, RevenueCat Privacy Policy, Firebase Privacy and Security, and OMDb Terms.