Privacy Policy

Last updated: July 2026

1. Data Controller

The data controller for the "Tunvio" app within the meaning of the GDPR is the operator of the Tunvio Project named in the legal notice (https://tunv.io/impressum).

Contact for data protection matters: support@tunv.io

Tunvio is solely a viewer / player application. Content is not provided by the Tunvio Project; every IPTV connection goes directly to a server you have entered yourself as a profile (Xtream Codes or M3U).

2. Nature of the Service

Tunvio is solely a viewer / player application. The Tunvio Project does not provide any content, does not host any streams, and does not operate any media services. For information on your responsibility when choosing a source, see the Terms of Use (https://tunv.io/terms-of-use).

3. Data Stored Locally on Your Device

Tunvio stores the following information exclusively on your device:

  • Server URL, username, and password of the IPTV provider you configured
  • Profile names (optionally assigned by you)
  • Watch history (recently viewed content)
  • Favourites list
  • Downloaded content and recordings (if created by you)
  • Optional parental PIN per profile
  • Image cache (thumbnails for channels and movies)
  • TMDB metadata cache (see Section 7)

None of this data leaves your device towards the Tunvio Project. It can be fully removed by uninstalling the app; history and favourites can be cleared directly in Settings.

4. Connections to Your IPTV Server (Third-Party Servers)

When you use Tunvio, the app establishes a direct connection to the IPTV server you provided yourself (Xtream Codes API or M3U URL). How that server processes your data is the responsibility of your IPTV provider, not the Tunvio Project. Please review your provider's privacy policy.

5. Purchases and Subscriptions (RevenueCat, App Store / Google Play)

Tunvio offers optional premium features that can be unlocked via in-app purchase or subscription. This feature is available only on Android and iOS; on other platforms (e.g. Tizen / Smart TV, desktop) no payment processing takes place.

  • Payment processing: Purchases are handled exclusively through the Apple App Store or Google Play. Your payment details (e.g. credit card) are processed directly by Apple or Google; the Tunvio Project receives and stores no payment data.
  • Subscription management: To manage subscriptions and verify entitlement status we use RevenueCat, Inc. (USA). RevenueCat receives an anonymous, randomly generated app user ID together with purchase/receipt information from the App Store or Google Play to determine whether an active subscription exists. No real names, email addresses, or payment details are transmitted to RevenueCat. Privacy notice: https://www.revenuecat.com/privacy

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for providing the purchased features.

6. Firebase (Google) – Remote Config, Analytics and Crash Reports

On Android and iOS Tunvio uses services provided by Google Ireland Ltd. / Google LLC ("Firebase"). On other platforms these services are inactive.

  • Firebase Remote Config: Controls the rollout of individual features (e.g. whether the premium / paywall feature is active) and update notices. Firebase may process technical data such as an app instance ID and the IP address to deliver the configuration. The legal basis is our legitimate interest in a secure, up-to-date and manageable app (Art. 6(1)(f) GDPR).

We collect the following two services only with your consent. They are switched off by default; on first launch we ask you once whether you want to enable them. Without your consent no data is collected through them:

  • Firebase Analytics: Collects pseudonymous usage statistics (e.g. screens viewed, coarse device and app-version information, approximate region) so we can improve the app. Analysis relies on pseudonymous identifiers; no IPTV credentials, profile names, passwords, or playback URLs are transmitted to Firebase.
  • Firebase Crashlytics: Collects crash and error reports (technical stack trace, device and app-version information) so we can fix crashes. Here too, no credentials, profile names, or playback URLs are transmitted.

The legal basis for analytics and crash reports is your consent (Art. 6(1)(a) GDPR, and § 25(1) TDDDG for accessing information on your device). You can withdraw your consent at any time with effect for the future — under Settings → Data & Storage via "Usage data & crash reports". The change takes effect immediately. If you decline on first launch we will ask you at most one more time; never again after that.

Data may be transferred to the USA; Google relies on the EU Standard Contractual Clauses for this.

Google privacy notice: https://policies.google.com/privacy

7. Metadata Enrichment via the Tunvio Proxy (TMDB)

Tunvio enriches movies and series with extra information (descriptions, ratings, logos, posters, age ratings) from The Movie Database (TMDB). This feature is enabled by default and can be turned off at any time in Settings.

Requests do not go directly to TMDB but through a caching proxy operated by the Tunvio Project (https://tmdb.tunv.io). For each item only the cleaned title and — where detectable — the release year are transmitted; for technical reasons the proxy briefly processes your IP address in doing so. No profile, credential, password, or playback data is transmitted. The proxy adds the required TMDB API key server-side and queries TMDB with it — you do not need a TMDB API key of your own. Results are cached both on the proxy and locally on your device to reduce requests.

The legal basis is our legitimate interest in convenient, fast metadata display (Art. 6(1)(f) GDPR). TMDB's own processing is governed by its terms (https://www.themoviedb.org/privacy-policy). The Tunvio Project has no affiliation with TMDB.

Online Subtitles via the Tunvio Proxy (OpenSubtitles)

If you search for online subtitles for a movie or episode (or enable automatic loading in Settings — off by default), the request is routed through a caching proxy operated by the Tunvio Project (https://subs.tunv.io). Only what is needed to find matching subtitles is transmitted: the title's TMDB/IMDB id — or, where unavailable, its cleaned title, release year and season/episode numbers — plus the requested subtitle languages; for technical reasons the proxy briefly processes your IP address. No profile, credential, password, or playback data is transmitted. The proxy queries OpenSubtitles (https://www.opensubtitles.com) with server-side credentials — you do not need an OpenSubtitles account. Subtitle files are cached both on the proxy and locally on your device to reduce requests.

The legal basis is our legitimate interest in the convenient display of subtitles (Art. 6(1)(f) GDPR). OpenSubtitles' own processing is governed by its privacy policy (https://www.opensubtitles.com). The Tunvio Project has no affiliation with OpenSubtitles.

8. Device Sync via Your Own Cloud Account (iCloud / Google Drive)

Optionally, Tunvio can keep your profiles, favourites, watch history and settings in sync across your devices. This feature is switched off by default and only becomes active once you explicitly connect it under Settings → Device Sync.

  • On iOS the sync data is stored in your personal iCloud account (Apple), inside the app's own iCloud container.
  • On Android it is stored in your personal Google Drive account, inside the app's hidden application-data folder (not visible among your regular Drive files).

The data travels directly from your device to Apple or Google — the Tunvio Project does not operate a sync server and never receives this data. The synced data also includes the access data of your configured IPTV profiles (server URL, username, password); it is stored exclusively in the private app area of your own cloud account, which other apps cannot read. In the app you choose which categories are synced, and you can disconnect the sync at any time. After disconnecting, the sync file already uploaded remains in your cloud account; you can delete it yourself at any time (iCloud: Settings → your name → iCloud → Manage Account Storage; Google Drive: Settings → Manage apps → delete hidden app data).

The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by actively connecting the feature and can withdraw at any time by disconnecting. Apple's and Google's processing is governed by their own privacy policies (https://www.apple.com/legal/privacy, https://policies.google.com/privacy).

Sync on Your Home Network (LAN)

In addition — or as an alternative — Tunvio can keep your devices in sync directly on your local network, including on platforms without cloud sync (e.g. smart TVs). This feature is also switched off by default: you enable it under Settings → Device Sync and pair your devices once using a six-digit PIN. The paired devices then exchange the sync data (including the categories and IPTV access data described above) directly from device to device — end-to-end encrypted (AES-256) with a key stored only on your paired devices.

The data never leaves your local network: no server and no internet connection is involved, and neither the Tunvio Project nor any other third party receives this data. The legal basis is again your consent (Art. 6(1)(a) GDPR), given by actively enabling the feature and pairing your devices; you withdraw it by unpairing devices or switching the feature off.

9. Recipients / Processors at a Glance

Service Purpose Platform Privacy
Apple App Store / Google Play Payment processing iOS / Android Apple / Google
RevenueCat, Inc. Subscription / entitlement management iOS / Android revenuecat.com/privacy
Google Firebase Remote Config, analytics, crash reports iOS / Android policies.google.com/privacy
Your IPTV provider Stream delivery all provider
Tunvio metadata proxy Caching layer for TMDB requests all this policy
TMDB Movie / series metadata all themoviedb.org
Apple iCloud / Google Drive Device sync (optional, your own account) iOS / Android Apple / Google

10. Local Data Storage

Credentials and settings are stored using the Flutter package shared_preferences in the app's internal storage. Image caches and the TMDB metadata cache are stored in the app-specific cache directory. All data can be completely removed by uninstalling the app.

11. Your Rights

Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection. For matters within the Tunvio Project's responsibility (in particular Firebase analytics and crash reports) contact support@tunv.io. You can also withdraw your consent to analytics and crash reports at any time, with effect for the future, directly in the settings (Data & Storage). You can delete locally stored data yourself at any time (Settings or uninstall). You also have the right to lodge a complaint with a data protection supervisory authority.

12. Changes to This Policy

This privacy policy may be updated when future changes to the app warrant it. The current version is always available at https://tunv.io/privacy-policy and in the app under Settings → About → Privacy Policy.