Privacy Policy · SublimeTV
In case of any discrepancy between language versions, the French version prevails.
Last updated: 29 September 2026
1. Data controllers
The joint data controllers are Arnaud Royo (Boulevard Raymond Poincaré, 06160 Antibes, France) and Vincent Bogaert (Avenue de Bordeaux, 11100 Narbonne, France), who operate the SublimeTV application as individuals (no company). They jointly determine the purposes and means of the processing described below. You can exercise your rights with either of them, through a single contact for any question about your data: contact@sublimetv.app.
2. General principle
SublimeTV is an IPTV player/client. The application requires a SublimeTV account to synchronize your experience across your devices. We collect only what is strictly necessary for the service to work. The application provides no content and does not collect your activity for advertising purposes.
3. Data we process
3.1 Account
- Email address and password (the password is stored securely as a hash, never in clear text).
- If you use Google or Apple sign-in: the identifier provided by these services to authenticate your account.
- If you request a password reset: an email containing a single-use link, valid for 30 minutes, is sent to you by our email delivery provider Resend.
3.2 Profiles
- The profile name and avatar you choose.
3.3 Your IPTV service credentials (Xtream or M3U)
- The portal URL, username and password of the IPTV subscription you provide yourself (Xtream), or the URL of your playlist (M3U).
- These credentials are encrypted (AES-256-GCM) on the server. They are only cached on the device after you select a profile, so the service opens quickly.
- We do not provide this subscription and have no relationship with your provider.
3.4 Synchronized usage data (per profile)
- Favorites, playback history (titles and resume position), preferences (interface language, metadata language, appearance, hidden categories, audio/subtitle/ quality preferences, genre affinity computed from your history).
- This data is used solely to restore your experience across your different devices.
3.5 Technical data
- A device identifier generated locally, used for the "Send to TV" feature (remote playback between your own devices) and QR-code pairing.
- Authentication tokens (JWT and refresh token) stored on the device.
- IP address: processed by our backend when you make requests, for network routing and abuse prevention (for example, rate-limiting sign-in attempts). It is not used to profile you.
- Connection status and platform type (phone, TV, computer): sent periodically to the backend while the application is in the foreground, to indicate that a session is active (technical service monitoring). This is suspended when the application goes to the background.
- Temporary technical data: QR-code pairing and remote playback sessions, password reset tokens, abuse-prevention counters (per IP address) and quota counters (per account). They are kept in an in-memory database hosted by Upstash in the Paris region and expire automatically, from a few minutes to one week depending on their use. They never contain your IPTV credentials.
3.6 Diagnostic data (crash reports)
- When an error or crash occurs, a technical report is sent to our stability-monitoring tool Sentry: error type and stack trace, the screen involved, device and platform type, operating-system and application version. This data is used solely to fix malfunctions; it is not used to profile you or for advertising purposes.
3.7 Data stored only on your device (not sent to our servers)
- Technical caches (your provider's catalog, TMDB metadata, images).
- Offline downloads: stored in the application's private storage; removed if you uninstall the application.
3.8 Catalog report (technical support)
- Voluntary submission, never automatic, from Settings > Information, to reproduce a catalog issue (grouping, TMDB matching, categories) on your exact playlist. A confirmation in the application details what is sent before each submission.
- The file is cleaned on-device before it is sent: it contains neither your portal URL, nor your username, nor your IPTV password, only entry metadata (title, category, year, rating, TMDB identifier…) and a flag for whether an image exists.
- Kept for 30 days then automatically deleted; deleted immediately if you delete your account.
3.9 Data related to a Premium purchase
- If you subscribe to the Premium tier, payment is handled by Google Play, Apple's App Store or Stripe, depending on where your installation came from. We never see your card number: it is entered at the payment provider and does not pass through our servers.
- We keep what is needed to grant and evidence your entitlement: a provider customer or transaction identifier, the associated purchase (plan, date, status) and the resulting account tier, with its expiry date where applicable.
- These records are also accounting documents, subject to a separate statutory retention period (see § 6).
3.10 AI search
- The text you type into the AI search is sent, together with the interface language and the type of content searched for, to Google (Gemini API), which generates the suggestions. It is accompanied neither by your email address nor by your account identifier, and we do not keep it: neither the request nor the results are stored on our servers.
- We only record the number of searches made per account and per day, to enforce quotas and spot abnormal use. This counter is kept for as long as the account exists.
The application includes no advertising, no advertising SDK, and no behavioral analytics tracker (no Firebase Analytics, no ad network, no profiling of your activity). The only third-party measurement tool is Sentry, limited to the crash and error reports described in § 3.6 (service stability, not advertising tracking). Two technical flows toward Google remain, for purely functional purposes: Google sign-in (optional, at your initiative) and Cast (Google Cast SDK). The fonts are bundled with the application (assets) and remote loading is disabled: no call is made to
fonts.gstatic.comat runtime.
4. Third parties and recipients
The application and the service rely on the following third parties:
| Third party | Role | Data involved |
|---|---|---|
| Fly.io | Hosting of the SublimeTV backend | All the account/profile/sync data listed above |
| Sentry | Crash and error monitoring (stability) | Diagnostic reports from § 3.6 (error, screen, device, versions) |
| TMDB (themoviedb.org) | Posters, summaries, cast, trends | Metadata requests (searched/viewed titles sent to TMDB to retrieve artwork) |
| Google / Apple | Account sign-in (optional) | Authentication identifier, depending on the chosen service |
| Your IPTV provider | Delivery of the streams you configure | Direct connection from your device using your credentials |
| Discord (internal channel) | Notification that a catalog report was received (§ 3.8), without the attached file | Report reference, account email, size, platform |
| Stripe | Premium payment (computers, and Android installed outside the Play Store) | Email address, customer identifier and payment details entered at Stripe |
| Google Play | Premium payment (installations from the Play Store) | Purchase tied to your Google account, verified with Google |
| Apple (App Store) | Premium payment (iPhone and iPad) | Purchase tied to your Apple Account, verified with Apple through its transaction identifier; we receive neither your Apple ID nor your payment details |
| Google (Gemini API) | AI search (§ 3.10) | Search text, language and content type, without email or account identifier |
| Resend | Delivery of the password reset email | Email address and reset link |
| Upstash | In-memory database for temporary technical data (§ 3.5), Paris region | Account and device identifiers, IP addresses in abuse-prevention counters, reset tokens |
The video stream is played directly from your provider: it does not pass through our servers.
5. Legal basis (GDPR)
- Performance of a contract: management of the account, profiles, playlists, synchronization and AI search (without this data, the service cannot function).
- Legitimate interest: account security, abuse prevention (processing of the IP address for rate-limiting, quota counters) and service stability (Sentry crash reports).
- Consent: sign-in via Google/Apple (at your initiative).
- Legal obligation: retention of accounting records relating to a Premium purchase (see § 6).
6. Retention period
- Account and synchronization data: kept for as long as the account exists.
- Upon account deletion, all associated data (profiles, favorites, history, preferences, encrypted IPTV credentials, tokens) is erased immediately on the server side through a cascading deletion. Any technical logs (security, diagnostics) are ephemeral and purged within 30 days at most.
- Local caches and downloads: under your control, removable from within the application or by uninstalling it.
- Catalog report (§ 3.8): kept for 30 days then automatically deleted, or immediately upon account deletion.
- Temporary technical data (§ 3.5): automatic expiry, from a few minutes to one week.
- AI search (§ 3.10): the text is not kept; the daily search counter is kept for as long as the account exists.
- Exception: accounting records of a Premium purchase. The law requires transaction records (amount, date, transaction identifier) to be kept for 10 years, including after you delete your account. Those records are then detached from your profile and kept for accounting and tax purposes only: they no longer identify you within the service, no longer grant access to it, and are used for no other processing. If you never made a purchase, nothing is kept after account deletion.
7. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability.
- Account deletion (in the application): Settings → Account → "Delete account". After confirmation, the account, profiles, favorites and history are deleted on the server side, and the device's local data is erased. This action is irreversible.
- Deletion without the application (web): you can also request deletion of your account and your data without installing the application, at https://sublimetv.app/account/delete, or by email at contact@sublimetv.app. Accounts signed in with Apple delete from within the application (Settings → Account → Delete account).
- Partial reset: "Sign out of account" clears the session and local caches; each profile has a button to reset its own data (favorites, history, genre affinity) without deleting the account.
Deletion at the account level and profile reset cover your right to erasure; you can remove individual history entries by resetting the relevant profile.
You may lodge a complaint with the CNIL (or the supervisory authority of your country).
8. Security
- Communications between the application and our servers encrypted (HTTPS).
- IPTV credentials encrypted (AES-256-GCM) on the server side.
- Token-based authentication with refresh; refresh and reset tokens are kept on the server only as a fingerprint, never in clear text.
- Account passwords stored as a hash.
9. Transfers outside the EU
Backend hosting is provided by Fly.io in its Paris (France) region, temporary technical data by Upstash in the same region, and crash reports are processed by Sentry in Germany: this data is therefore hosted within the European Union. Card payments are processed by Stripe, whose European entity is established in Ireland. Other third-party services are based in the United States: AI search (Google, Gemini API), delivery of the password reset email (Resend) and optional services (Google or Apple sign-in, payment through Google Play or the App Store, TMDB metadata). Any transfers to these services are governed by their own safeguards (standard contractual clauses and applicable data-protection frameworks). The video stream never passes through our servers: it connects your device directly to your provider.
10. Children
The service is reserved for adults (18 years or older). It is not intended for minors and is not offered to them. We do not knowingly collect data about a minor; if such an account were reported to us, it would be deleted.
11. Changes
This policy may be updated. The last-updated date appears at the top of the document; substantial changes will be notified within the application.