Privacy Policy

How NextGen handles data

This policy describes the native NextGen IPTV Player Xtream M3U app and this legal website.

Effective and last updated: 26 August 2026

Plain-language summary

1. Who is responsible for this policy

The app and this website are operated as NextGen IPTV Player ("NextGen", "we", "us" or "our"). For privacy questions or requests, email nextgeniptvplayer@gmail.com.

2. Scope and role of the app

NextGen is a standalone player for user-supplied M3U playlists and Xtream-compatible connections. We do not provide, sell, recommend, host or control the media or provider service you add. Your provider is independent from NextGen and handles data under its own terms and privacy practices.

3. Data handled by the app

3.1 Data stored locally

Depending on the features you use, the app stores the following on your device:

Playlist connection secrets are not kept as ordinary plaintext preferences. The app uses Keychain-backed references and authenticated encryption for credential-bearing values that must be stored locally. No security method can guarantee absolute protection.

3.2 Requests to your chosen provider

To import a catalogue, refresh EPG data, play a stream or download media, the app connects directly to the URL or provider you configure. The request can include the source URL, username, password or access token needed by that provider. The provider and its network infrastructure may receive your IP address, device/network information and request details.

The app allows user-configured sources using HTTP as well as HTTPS because some IPTV providers do not support HTTPS. HTTP traffic is not encrypted in transit. Use HTTP sources only if you understand and accept that risk. App-configured fixed-service connections use HTTPS.

3.3 Optional Sync with iCloud

For eligible Pro users, Sync with iCloud is an optional, device-local setting. When enabled, the app uses Apple's CloudKit service and a dedicated fresh native CloudKit container. It does not read or migrate records created by the previous React Native version.

Supported synced data includes:

Playlist connection fields are uploaded using CloudKit encrypted-value fields. Synced records are placed in the private CloudKit database associated with your Apple Account. Apple states that private-database records are accessible only to that user by default and are not visible through the developer's CloudKit console.

The app does not sync provider catalogues, provider responses, EPG/XMLTV data, artwork or metadata caches, downloaded media files, raw diagnostics, API keys, or device-only appearance/playback/refresh settings.

Turning Sync with iCloud off stops future app-initiated transfers on that device; it does not delete data already stored locally or in iCloud. Deleting supported profiles, playlists or personal state through the app can create synchronised deletion records. Removing the app or disabling its iCloud access does not necessarily erase existing CloudKit records.

3.4 Purchases and subscriptions

Apple processes App Store billing. RevenueCat helps the app retrieve products, validate receipts, restore purchases and determine Pro entitlement. RevenueCat may process a pseudonymous app-user identifier, Apple receipt and transaction details, product and entitlement information, app/device/OS technical information, country or region, and last-seen timestamps. We do not receive your full payment-card details.

3.5 Optional Firebase Analytics and Crashlytics

Firebase Analytics and Crashlytics are disabled by default and remain disabled while your choice is undecided or denied. They activate only after you expressly opt in on that device. There is no pre-consent event buffer.

If you opt in, the app may send:

Firebase also uses installation or crash-installation identifiers and receives ordinary technical information described in its documentation. NextGen does not set a Firebase user ID, request advertising tracking permission, use the data for targeted advertising, or join Firebase data to RevenueCat customer identifiers.

The app's analytics boundary excludes playlist/provider names, URLs, hostnames, addresses, usernames, passwords, content IDs or titles, programme names, email addresses, free text, raw provider errors and CloudKit/RevenueCat/Firebase record identifiers.

You can change the choice in the app's Settings. Revoking consent disables future collection, resets local Analytics state and deletes unsent Crashlytics reports. It cannot recall data already transmitted; Firebase retention and deletion processes continue to apply to data already received.

3.6 Optional metadata lookups

When metadata enrichment is enabled and a catalogue item is eligible, the app may send a title, content type, release year or IMDb identifier to the OMDb API to retrieve ratings, identifiers or artwork metadata. Playlist credentials are not included in that lookup. OMDb and its network providers may receive the query and ordinary network data.

3.7 Support and community messages

If you contact us by email or Discord, we receive the information you choose to provide, such as your email address or account name, message, screenshots and technical details. Do not send playlist credentials, full provider URLs, unauthorised media or other sensitive information. Email and Discord process communications under their own terms and policies.

3.8 This website

This is a static Firebase Hosting website. It does not include app-owned analytics, advertising pixels, forms or preference storage. Firebase Hosting processes incoming IP addresses and request/technical data to deliver and protect the site and may retain IP data for a limited period as described by Firebase. See the Cookie Policy.

4. Purposes and legal grounds

Where UK or European data-protection law applies, we process data as follows:

5. Service providers and disclosures

RecipientPurposeRelevant information
AppleApp distribution, purchases, StoreKit, private CloudKit sync and Apple platform servicesPurchase/receipt data, Apple Account/iCloud data, device and service data under Apple's policies
RevenueCatProducts, receipt validation, entitlements, purchase and restore supportPseudonymous identifier, transaction/receipt, entitlement and technical data
Google FirebaseConsent-based Analytics and Crashlytics; static website hostingCoarse product interaction and technical/crash data after consent; hosting request/IP data
OMDb APIOptional ratings and metadata enrichmentTitle, type, year or IMDb identifier and ordinary network data
Your providerCatalogue/EPG import, playback and downloads you requestConfigured URL and credentials/tokens, requested resource and ordinary network data
Email/Discord providersSupport and community communication you initiateYour account/contact details and message content

We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal information and do not use it for cross-app advertising tracking.

6. International processing

Apple, RevenueCat, Google, OMDb, email providers and Discord may process information outside your country. Their own policies and contractual safeguards govern those transfers. Firebase states that most Firebase services can process data on global infrastructure.

7. Retention and deletion

8. Your choices and rights

Private CloudKit records belong to your Apple Account and are not visible to us through the developer console. This can limit our ability to access or delete them for you. Contact us for guidance, and do not assume that disabling sync or uninstalling the app deletes existing iCloud data.

9. Children

NextGen is not directed to children and does not provide or curate content. User-supplied sources can contain material unsuitable for children. A parent or guardian should supervise use by anyone who cannot lawfully consent for themselves and should control the provider source, purchases, downloads, analytics choice and iCloud settings.

10. Security

We use platform security controls, bounded network/data handling, Keychain-backed secret protection, authenticated encryption for materialised credential-bearing values and CloudKit encrypted fields for synced connection secrets. You are responsible for choosing trustworthy providers and securing your devices and Apple Account. No system is completely secure, and HTTP provider connections are not encrypted in transit.

11. Changes to this policy

We may update this policy when features, providers or legal requirements change. We will publish the revised date here. If a change requires new consent, the app will request it before the relevant optional processing begins.

12. Contact

NextGen IPTV Player
Email: nextgeniptvplayer@gmail.com
United Kingdom

Useful provider policies: Apple Privacy Policy, RevenueCat Privacy Policy, Firebase Privacy and Security, and OMDb Terms.