Privacy Policy · SublimeTV
In case of any discrepancy between language versions, the French version prevails.
Last updated: 5 July 2026
1. Data controller
The data controller is Arnaud Royo, operating the SublimeTV application as an individual (no company), in Antibes (06169), France. For any question about your data, contact us at contact@sublimetv.app.
2. General principle
SublimeTV is an IPTV player/client. The application requires a SublimeTV account to synchronize your experience across your devices. We collect only what is strictly necessary for the service to work. The application provides no content and does not collect your activity for advertising purposes.
3. Data we process
3.1 Account
- Email address and password (the password is stored securely as a hash, never in clear text).
- If you use Google or Apple sign-in: the identifier provided by these services to authenticate your account.
3.2 Profiles
- The profile name and avatar you choose.
3.3 Your IPTV service credentials (Xtream)
- The portal URL, username and password of the IPTV subscription you provide yourself.
- These credentials are encrypted (AES-256-GCM) on the server. They are only cached on the device after you select a profile, so the service opens quickly.
- We do not provide this subscription and have no relationship with your provider.
3.4 Synchronized usage data (per profile)
- Favorites, playback history (titles and resume position), preferences (interface language, metadata language, appearance, hidden categories, audio/subtitle/ quality preferences, genre affinity computed from your history).
- This data is used solely to restore your experience across your different devices.
3.5 Technical data
- A device identifier generated locally, used for the "Send to TV" feature (remote playback between your own devices) and QR-code pairing.
- Authentication tokens (JWT and refresh token) stored on the device.
- IP address: processed by our backend when you make requests, for network routing and abuse prevention (for example, rate-limiting sign-in attempts). It is not used to profile you.
- Connection status and platform type (phone, TV, computer): sent periodically to the backend while the application is in the foreground, to indicate that a session is active (technical service monitoring). This is suspended when the application goes to the background.
3.6 Diagnostic data (crash reports)
- When an error or crash occurs, a technical report is sent to our stability-monitoring tool Sentry: error type and stack trace, the screen involved, device and platform type, operating-system and application version. This data is used solely to fix malfunctions; it is not used to profile you or for advertising purposes.
3.7 Data stored only on your device (not sent to our servers)
- Technical caches (your provider's catalog, TMDB metadata, images).
- Offline downloads: stored in the application's private storage; removed if you uninstall the application.
The application includes no advertising, no advertising SDK, and no behavioral analytics tracker (no Firebase Analytics, no ad network, no profiling of your activity). The only third-party measurement tool is Sentry, limited to the crash and error reports described in § 3.6 (service stability, not advertising tracking). Two technical flows toward Google remain, for purely functional purposes: Google sign-in (optional, at your initiative) and Cast (Google Cast SDK). The fonts are bundled with the application (assets) and remote loading is disabled: no call is made to
fonts.gstatic.comat runtime.
4. Third parties and recipients
The application and the service rely on the following third parties:
| Third party | Role | Data involved |
|---|---|---|
| Fly.io | Hosting of the SublimeTV backend | All the account/profile/sync data listed above |
| Sentry | Crash and error monitoring (stability) | Diagnostic reports from § 3.6 (error, screen, device, versions) |
| TMDB (themoviedb.org) | Posters, summaries, cast, trends | Metadata requests (searched/viewed titles sent to TMDB to retrieve artwork) |
| Google / Apple | Account sign-in (optional) | Authentication identifier, depending on the chosen service |
| Your IPTV provider | Delivery of the streams you configure | Direct connection from your device using your credentials |
The video stream is played directly from your provider: it does not pass through our servers.
5. Legal basis (GDPR)
- Performance of a contract: management of the account, profiles, playlists and synchronization (without this data, the service cannot function).
- Legitimate interest: account security, abuse prevention (processing of the IP address for rate-limiting) and service stability (Sentry crash reports).
- Consent: sign-in via Google/Apple (at your initiative).
6. Retention period
- Account and synchronization data: kept for as long as the account exists.
- Upon account deletion, all associated data (profiles, favorites, history, preferences, encrypted IPTV credentials, tokens) is erased immediately on the server side through a cascading deletion. Any technical logs (security, diagnostics) are ephemeral and purged within 30 days at most.
- Local caches and downloads: under your control, removable from within the application or by uninstalling it.
7. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability.
- Account deletion (in the application): Settings → Account → "Delete account". After confirmation, the account, profiles, favorites and history are deleted on the server side, and the device's local data is erased. This action is irreversible.
- Deletion without the application (web): you can also request deletion of your account and your data without installing the application, at https://sublimetv.app/account/delete, or by email at contact@sublimetv.app. Accounts signed in with Apple delete from within the application (Settings → Account → Delete account).
- Partial reset: "Sign out of account" clears the session and local caches; each profile has a button to reset its own data (favorites, history, genre affinity) without deleting the account.
Deletion at the account level and profile reset cover your right to erasure; you can remove individual history entries by resetting the relevant profile.
You may lodge a complaint with the CNIL (or the supervisory authority of your country).
8. Security
- IPTV credentials encrypted (AES-256-GCM) on the server side.
- Token-based authentication with refresh.
- Account passwords stored as a hash.
9. Transfers outside the EU
Backend hosting is provided by Fly.io in its Paris (France) region and crash reports are processed by Sentry in Germany: this data is therefore hosted within the European Union. Some optional third-party services (Google or Apple sign-in, TMDB metadata) are based in the United States; any transfers to these services are governed by their own safeguards (standard contractual clauses and applicable data-protection frameworks). The video stream never passes through our servers: it connects your device directly to your provider.
10. Children
The service is reserved for adults (18 years or older). It is not intended for minors and is not offered to them. We do not knowingly collect data about a minor; if such an account were reported to us, it would be deleted.
11. Changes
This policy may be updated. The last-updated date appears at the top of the document; substantial changes will be notified within the application.