Privacy Policy
Last updated: [DATE OF PUBLICATION] · Version 1
This policy explains what information the BetterStream apps and website ("the App") process, why, and your choices. The controller is Kaptivate ([REGISTERED ADDRESS]), contact info@kaptivate.io.
In short: your playlists, logins, history and favorites stay on your device. We don't show ads, don't track you across apps or websites, and don't sell data. We only receive the minimum needed to process purchases and to fix crashes.
1. Information that stays on your device
| Data | Purpose | Where it goes |
|---|---|---|
| Playlists you add: names, M3U links, Xtream server address, username and password | To load and play your playlists | Stored only on your device. Passwords and M3U links are encrypted with a key held in your device's secure hardware keystore (on Samsung and LG TVs, which don't offer one to apps: with a key that the TV keeps for the App and that can't be read out; on a Roku: with the Roku's own device key, in storage only the App can reach). Sent only to the playlist provider you entered. |
| Channel, movie and series lists synced from your provider | Browsing and search | Stored only on your device. |
| Watch history, playback positions, favorites, settings | Continue watching, resume, favorites | Stored only on your device. |
| Offline downloads (where available) | Watching without a connection | Stored in the App's private storage on your device. |
This data is excluded from cloud backups and device-to-device transfers; deleting the App or a playlist deletes it. We never receive it.
2. Your playlist provider
When you add or play a playlist, the App connects directly to the servers you entered (your playlist provider, the TV guide addresses your playlist names, and hosts of logos/artwork referenced by your playlist). With the TV guide available, the App downloads the guide from there in the background about twice a day. Those parties receive your IP address and the login you entered, as with any app connecting to them. Their handling of your data is governed by their own policies; Kaptivate has no relationship with them.
3. Information we or our service providers process
3.1 Purchases
Purchases are handled by Apple (App Store), Google (Google Play) or, for desktop apps, Stripe. We use RevenueCat to validate purchases and know whether BetterStream Pro is active. RevenueCat processes: a random app user ID (or your account ID if you sign in), purchase and subscription history (product, price, currency, dates, store transaction IDs), country and basic device information (platform, OS and app version). We never receive your payment card details. Legal basis: performance of our contract with you.
3.2 Crash reports
If the App crashes or hits an unexpected error, a report is sent to Sentry (Functional Software, Inc.): error type and stack trace, app version, device model, OS version and similar technical state at the time of the error, plus a random installation ID (not linked to you). The App removes playlist logins, stream URLs and your playlist names, hosts and links from every report before it is sent, and never attaches screenshots, screen recordings or your IP address. No usage or session analytics are sent. You can turn crash reports off at any time in Settings → Privacy → Send crash reports; reports are then discarded on your device. Legal basis: our legitimate interest in keeping the App working (you can object via the setting).
3.3 Optional account
Signing in is optional and only needed to use one purchase on several devices (and to buy on desktop). If you create an account we process your email address (or the identifier provided by Sign in with Apple / Google, which may be a private relay address) and a random user ID, via our authentication provider Supabase (Supabase, Inc.; project region [EU — confirm]). The sign-in session is stored encrypted on your device. Your user ID is also your RevenueCat ID, so Pro follows your account; on desktop the App asks our server whether your account has Pro, and our server asks RevenueCat. When you sign in, the App also sends our server the time this device's free trial started; the server keeps the earliest such time for your account, so the trial isn't restarted on each new device. Legal basis: performance of our contract with you. You can delete your account at any time in the App (Settings → Account → Delete account) or by emailing us; this erases your sign-in, email address and trial start. Purchase records are kept as described in section 5.
3.4 Subtitle search
If you search for subtitles, the title, season/episode, year and preferred languages of what you are watching are sent to OpenSubtitles.com to find matching subtitles. Legal basis: our contract with you (you requested the feature).
- With BetterStream Pro or during the free trial, this goes through our server (Supabase). It checks your Pro status with RevenueCat, using your account ID or, without an account, the anonymous purchase ID of your device. It counts your subtitle requests per day to stay within OpenSubtitles' limits. The count is stored under a one-way hash of that ID and deleted after two days. Without Pro, the server also keeps when that hashed ID first searched, to limit the trial to 7 days; this is deleted after 30 days. The search itself is not logged or stored.
- If you add your own OpenSubtitles account in Settings → Subtitles, the App contacts OpenSubtitles directly with it. Your API key and sign-in token stay encrypted on your device, and your password isn't stored.
3.5 Activating a TV
If you link a TV to your account with a code (BetterStream on the TV → Settings → Activate with a code, then the code on our website), our server (Supabase) stores, for that link: the device type and the name the TV reports (for example "Android TV · Living room"), when it was linked and when it last checked in, and a one-way hash of the TV's access token. The TV asks our server now and then whether your account has Pro; our server asks RevenueCat and tells the TV, together with a shortened form of your email address (for example t***@example.com) so you can see which account the TV is on. Codes are kept as hashes for 15 minutes. To prevent abuse we count requests per network under a one-way hash of the IP address and delete the counts within a day. You can see and remove linked devices on the website's activation page, or unlink the TV in its Settings; deleting your account removes them all. Legal basis: performance of our contract with you.
3.6 Sending a playlist to a TV from a phone
Typing a long playlist link with a TV remote is slow, so a TV can show a QR code that opens our website on your phone, where you type the playlist instead. The playlist is encrypted on your phone with a key that only the TV and your phone know (it's in the QR code's link, in the part that browsers never send to a server). Our server (Supabase) only passes the encrypted playlist on: it can't read it, it keeps it for at most 15 minutes, and deletes it as soon as the TV has collected it. It stores only one-way hashes of the TV's code, and counts requests per network under a one-way hash of the IP address (deleted within a day) to prevent abuse. No account is needed. Legal basis: performance of our contract with you (you asked for the playlist to be sent).
3.7 Update check
At launch the App downloads a small configuration file from our website to learn about updates (this reveals your IP address to our website's hosting provider Vultr (Vultr Holdings, LLC; server location [REGION — confirm]) like any web request; the web server's logs keep it for at most 14 days). App stores deliver the updates themselves.
4. What we don't do
- No advertising, no ad identifiers, no tracking across apps or websites (App Tracking Transparency is not needed because we don't track).
- No analytics of what you watch. Titles you play are never sent to us.
- We do not sell or share personal data for marketing.
5. Retention
On-device data stays until you delete it or the App. RevenueCat purchase records are kept as long as needed for your purchases and our legal (tax/accounting) obligations, typically 7 years. Crash reports are kept for at most 90 days. Linked TVs stay listed until you remove them or delete your account. Account data is deleted within 30 days of account deletion.
6. International transfers
Our service providers may process data outside your country, including in the United States. Where required, transfers rely on the EU Standard Contractual Clauses or the EU–U.S. Data Privacy Framework.
7. Your rights
Depending on where you live (for example under the GDPR or CCPA) you can ask to access, correct, delete or export your personal data, object to or restrict processing, and withdraw consent. Email info@kaptivate.io. You can also complain to your data-protection authority. Because most data never leaves your device, you control it directly: delete a playlist, clear watch history in Settings, or uninstall the App.
8. Children
The App is not directed to children and is intended for users aged 18 and over. We do not knowingly collect children's data.
9. Security
Playlist secrets are encrypted at rest; our own backend connections use TLS. Connections to your playlist provider use whatever the provider supports (often plain HTTP) — the App tries a secure connection first.
10. Changes
We will announce material changes in the App. The version and date are shown at the top.
11. Contact
Kaptivate — BetterStream · info@kaptivate.io · [POSTAL ADDRESS]
Questions: info@kaptivate.io