Privacy policy
Effective date: September 4, 2026 · Last updated: October 1, 2026
This policy explains how Zaphyr Stream handles information in its Android app, its iPhone and iPad app, and this support website. Zaphyr Stream (“we”) operates the apps and this website. For privacy questions or requests, contact us at barqora@outlook.com.
You can open this policy and our terms of use from inside either app: Menu (☰) → Settings → Privacy & storage → Policies, then Privacy policy or Terms of use.
In short
- Zaphyr Stream is a player. Video goes directly from your own provider to your device; our servers never carry, store or forward it.
- Playlist passwords, access tokens, and playlist, guide and stream links stay on your device. They are never sent to us and never included in sync.
- You can use the app as a guest, without an account.
- Analytics and crash reporting are switched off and collect nothing without your consent. The app does not currently ask for that consent, so nothing is collected.
- The Android app may use your Google Advertising ID and other ad request information for Unity ads when ads are enabled and consent allows requests. The iPhone and iPad app has no Unity advertising SDK.
- You can delete your account in the app at any time, and its cloud data is removed immediately.
- We do not sell account records or provider credentials. Unity may share Android ad request information with advertising partners when ads are enabled, as described below.
Signing in
Guest. You can use the app without signing in. A guest has no Zaphyr Stream account and nothing is synced; everything stays on the device. Some features still contact our cloud services without an account: subtitle search, artwork lookups and app configuration, described below.
Google sign-in, and Sign in with Apple where available (we switch it on through the app's remote configuration, so it may not appear in your app), use Firebase Authentication. We receive an account identifier, your name and email address as Google or Apple provide them (Apple may give a private relay address instead of your own), and for Google a link to your profile picture. We never receive your Google or Apple password.
Your playlists and passwords
- Server addresses, usernames, passwords, access tokens, and playlist and guide links you enter are stored only on your device. On Android they are encrypted with AES-256-GCM using a key held in the Android Keystore, and excluded from Android backups and device-to-device transfers. On iPhone and iPad they are kept in the iOS Keychain, restricted to that device, so they are not synced through iCloud Keychain or restored to another device.
- They are never sent to us and never included in sync.
- The app talks to your provider directly to load channels, guides, artwork and video. Your provider receives your IP address and whatever sign-in details it requires, under its own privacy policy.
- If you cast to a Google Cast device (Android) or use AirPlay (iPhone and iPad), the stream address is handed to that device, which plays it from your provider.
Media servers: Plex, Jellyfin and Emby
- Plex: the app asks plex.tv for a one-time sign-in PIN and opens plex.tv in your browser, where you sign in and approve it. Your Plex password is entered only on plex.tv, never in the app. The app receives an access token, uses it to list your servers, and stores the token for the server you choose on your device only.
- Jellyfin and Emby: your username and password, a Quick Connect code (Jellyfin), or an API key go only to the server address you entered. The access token your server returns is stored on your device only.
- So that your server or plex.tv can show which device is signed in, the app sends them the device type or model name, the app name and version, and a random identifier the app creates for this purpose. It is not a hardware or advertising identifier.
Sync across devices (signed-in accounts only)
When you are signed in, the app keeps what you do the same on all your devices, Android and iPhone or iPad alike. Syncing may be part of Zaphyr Pro when Pro is offered. Guests never sync.
What is synced:
- favorites, including the fact that you removed one;
- watch progress: where you stopped in a title, its length, and whether you finished it;
- most-watched channels: an aged count of visits and the total watch time for each channel;
- category usage: how often you open each category, which orders the category list;
- hidden categories;
- profile names and their playback preferences: autoplay next, remember position, use cellular data, captions on or off, preferred audio language, and maximum content rating;
- a few app settings: the app language and, from iPhone and iPad, also autoplay next, remember position, subtitle languages and the hearing-impaired subtitle preference.
Each record names the item or category it concerns the way your playlist identifies it, together with the playlist's fingerprint (below), the profile it belongs to, and the time of the change. A random identifier created by the app tells your devices' changes apart; it is not a hardware or advertising identifier.
Never synced: playlist passwords, access tokens, playlist or guide links, stream addresses, server addresses, catalogue content, your parental PIN, your search history, purchases, or anything about advertising.
How a playlist is identified without revealing it: records say which playlist they belong to with a one-way fingerprint: the first 16 hexadecimal characters of a SHA-256 hash of the playlist type, its server host name, and the account name (your username or user ID, or the username written in a playlist link). If there is no account name, only the type and host are used. A password, token, or any other part of a link never goes into it. A hash is not encryption: someone who already knows or guesses the type, host and account name could recompute the fingerprint, which is why only non-secret details are used.
Earlier versions of the app, for a playlist link with no username in it, used the link's path in place of the account name; only the resulting fingerprint was sent, never the path. Because a path can contain a password, current versions no longer do this. Both apps delete the older copies of the records they hold, once, the first time they sync after updating. Any older copy that remains is deleted when you delete your account.
Where it is kept: in Google Cloud Firestore, under your account. Apps cannot read or write these records directly. Only our sync function can, after checking your sign-in and the app's integrity (App Check), and it refuses records that contain a web link or look like a password.
When: the app syncs shortly after a change, when you open it, regularly while it is open, and when you leave it. Signing out stops syncing on that device. If a different account then signs in on that device, the app does not upload what the device recorded before: only changes made after signing in are synced, together with the profiles those changes belong to and the device's current app language. Deleting your account deletes all synced records immediately.
Subtitle search
When you search for subtitles in the player, the app sends our subtitle function the title (as shown, or as you edited it), the season and episode numbers, and your preferred subtitle languages. The iPhone and iPad app also sends the year, whether it is a film or an episode, and, when it can be calculated, a 16-character fingerprint of the video file (the OpenSubtitles hash, computed on your device from the file's size and its first and last 64 KB). The function forwards these details to OpenSubtitles with our own API key and returns the results. It forwards nothing about your account and does not save your searches. When you choose a subtitle, the app obtains a download link through the same function and then downloads the file directly from OpenSubtitles, which receives your IP address.
Artwork and descriptions
When a film or series in your playlist has no poster or description, the app may send its title, year, and whether it is a film or a series to our artwork function, which looks it up at TheTVDB and returns a poster link and a synopsis. This happens automatically while you browse. The poster image is then loaded from TheTVDB's image server. Nothing about your account is sent to TheTVDB.
Sponsored cards (iPhone and iPad app)
The iPhone and iPad app may show sponsored cards: poster-shaped tiles labelled as ads among the rows of posters. These cards are off unless enabled through remote configuration. They are not shown to Zaphyr Pro subscribers, while the parental lock is on, or during the first two days after installation.
- Card text, links and image addresses come from remote configuration. These cards do not use an advertising SDK or advertising ID.
- When a card image appears, the device downloads it directly from the advertiser's server. That server receives the IP address, app user agent and request time. The app sends no cookie, advertising ID or referrer, and accepts no cookie.
- Images load only over HTTPS. The app blocks private, local and loopback addresses, does not follow redirects, and keeps images in memory only.
- Tapping a card opens the advertiser's website, where its privacy policy applies.
- You can hide a card on that device for 30 days. Zaphyr Pro removes these cards.
- We do not receive a record of cards viewed, hidden or tapped.
Unity Ads (Android app)
When enabled in an Android release, Zaphyr Stream uses the Unity Ads SDK directly. Planned formats are an interstitial after playback and a rewarded ad that you start to unlock a Pro benefit. There are no banner ads. Ads remain off until the feature is enabled and configured. Before initializing Unity Ads or requesting an ad, the app updates consent information with Google’s User Messaging Platform (UMP) and shows any required consent form. If the consent update or required form fails, consent remains unresolved, or UMP reports canRequestAds as false, the app does not initialize the ad SDK or request ads. The app sets Unity’s userOptOut privacy signal, so any ads it requests are contextual and non-personalized. Rejecting personalized advertising does not by itself block contextual ads when UMP allows ad requests. If UMP requires a privacy-options entry point, it is available in Settings → Privacy & storage → Ad privacy choices.
When ad requests are allowed, Unity’s SDK may collect and share your Android advertising ID and other device identifiers, IP address, approximate location (not precise location), device and operating-system details, app identifier, purchase history, diagnostics, and information about ad requests and performance. Unity also documents collection of page views and taps inside the ad experience, not general gameplay; app usage times may be collected if Acquire Optimization is enabled in Unity’s dashboard. Unity and its advertising partners may process or share these data to deliver contextual ads, measure ad performance, limit repeated ads, and detect fraud or abuse. Unity’s partner list and processing details may change; see Unity’s app-user privacy policy and Unity’s privacy choices.
Zaphyr does not send your account identifier, provider credentials, playlist or stream URLs to Unity for advertising. Unity may receive an ad request after playback or when you choose a rewarded ad. The iPhone and iPad app does not include the Unity Ads SDK.
Services that keep the app running
- Firebase App Check (both apps): before the app calls our cloud functions, Google Play Integrity (Android) or Apple App Attest or DeviceCheck (iPhone and iPad) confirms it is a genuine copy of the app on a genuine device. This uses device-integrity signals, not your content.
- Firebase Remote Config (both apps): the app downloads the settings that switch features on or off when it starts and again from time to time, at most once every three hours. The request includes a Firebase installation ID, the app and operating-system versions, and the device's language, country setting and time zone. Unity ads run only in the Android app when configured and when UMP allows ad requests; Remote Config cannot override a denied or unresolved consent choice. Sign in with Apple may be enabled separately. Remote configuration can switch analytics and crash reporting off, but never on.
- Firebase Crashlytics and Google Analytics for Firebase (Android app, switched off): the Android app contains both, but they are switched off when the app starts and send nothing. Only your consent can switch them on, and the app does not currently ask for it. Advertising-ID collection and ad-personalization signals stay off in the Analytics SDK even with consent.
- Cloud Functions and Cloud Firestore (both apps): run our sync, account-deletion, subtitle and artwork functions, and store synced data. Google Cloud keeps technical request logs.
- Google Cast (Android app): the Cast SDK, provided by Google, finds Cast devices on your network; Google receives information about Cast use under its own policy.
The iPhone and iPad app contains neither Crashlytics nor Analytics.
Support
When you email us, we receive your email address and anything you include. Do not send passwords, provider credentials, payment details, or full playlist or stream links.
How information is used
We use information to sign you in, provide the features you use (playback, sync, subtitles, artwork), keep your settings, protect our services from abuse, diagnose problems, and respond to requests.
Services and sharing
We do not sell your account records or provider credentials. Google (Firebase and Google Cloud), Apple (Sign in with Apple and App Attest), OpenSubtitles, TheTVDB, Microsoft Outlook, and—when Android ads are enabled—Unity process information for the services described in this policy. Unity may share ad request information with its advertising partners for ad delivery and measurement. Some privacy laws may treat this kind of advertising disclosure as a sale or sharing for targeted advertising; available choices depend on applicable law. See Firebase privacy information, Microsoft's privacy statement, Unity's app-user privacy policy, and Unity's privacy choices.
Your media providers and guide sources receive the requests needed to supply their content, as described above; their privacy policies apply. On iPhone and iPad, advertiser image servers receive the requests described under Sponsored cards. Unity may receive Android ad request information as described above. This website itself shows no advertising.
This website
This is a static website with no scripts, no cookies, no analytics, no advertising, and no fonts or other files loaded from third parties. Firebase Hosting may process technical request records, such as IP address and browser type, to deliver and secure it. Email links open your email app; nothing is sent until you send the message.
Retention and deletion
- Account and cloud data: kept while your account exists. Deleting your account in the app removes it immediately. For requests by email, our target is to complete deletion within 30 calendar days after we verify the request; if a shorter legal deadline applies, we follow it, and we will explain any necessary delay.
- Support messages: retained for up to 90 days after your request is closed, then deleted from our active mailbox. We keep only what is needed to resolve your request.
- Device data: stays on your device until you remove it in the app (for example by removing a playlist or deleting your account), clear the app's storage in Android Settings, or delete the app. On iPhone and iPad, iOS can keep Keychain items after an app is deleted, so remove your playlists or use Delete account first if you want saved passwords erased for certain. Offline copies and files you exported may need to be removed separately.
- Technical records: our infrastructure providers apply their own retention schedules; Google Cloud keeps request logs for its own periods. Crash reporting and analytics are switched off in the apps, so they hold no data from them. Deleting an account does not instantly erase every infrastructure log or backup.
- Limited exceptions: records required for legal obligations, security investigations, or dispute resolution may be retained only as necessary for that purpose. We explain applicable exceptions when responding to a deletion request unless legally prohibited.
Delete your account in the app with Menu (☰) → Settings → Privacy & storage → Delete account, or request deletion by email. Deleting Zaphyr Stream data does not delete your Google or Apple account or cancel a third-party media subscription.
Your choices
- Use the app as a guest; nothing is synced.
- Sign out to stop syncing on a device.
- Remove a playlist to delete its saved credentials from that device.
- On iPhone and iPad, hide sponsored cards or remove them with Zaphyr Pro.
- On Android, manage ad privacy at Settings → Privacy & storage → Ad privacy choices when UMP requires this entry point. If UMP does not allow ad requests, no ads are requested; if UMP allows requests but personalization is rejected, contextual non-personalized ads may still appear. Android device settings also let you reset or limit use of the advertising ID.
- Use privacy controls in a Unity ad when available, or follow Unity’s privacy policy for requests about information Unity handles.
- Delete your account in the app or by email.
- Ask us by email for access to, correction of, or deletion of specific data. We verify account ownership before releasing or deleting account data. Your rights and our response deadlines depend on applicable law.
Security and children
Our services use access controls and encrypted connections (HTTPS). Connections to your own provider use whatever that provider supports, which may be unencrypted HTTP. No system guarantees absolute security. The service is not directed to children under 13; a parent or guardian who believes a child has supplied personal information should contact us.
Changes and contact
We update this policy before enabling any new data use. Updates appear on this page with a revised date, and we provide additional notice when required for material changes. Questions: barqora@outlook.com.