Privacy Policy

UltraCast IPTV Player

Last updated: August 26, 2026
Developer: Catsizer Lab
Contact: thecatsizer@gmail.com
Android package: com.ultracast.iptvplayer

This policy explains how UltraCast IPTV Player accesses, uses, stores, transmits and deletes data. The app is a media player only. It does not provide, host or sell television channels, films, series or IPTV subscriptions.

1. Data you provide

2. Data stored locally

Playlist data, channel, film and series caches, favorites, viewing history, playback progress, EPG cache and application settings are stored on your device using Android preferences and Hive databases. Xtream credentials are kept separately in Android Keystore-backed protected storage.

Removing a playlist deletes the locally stored Xtream credentials associated with that playlist. Signing out clears account-related and media-related local data for the signed-in session, including playlists, protected Xtream credentials, cached channels and VOD data, favorites, viewing history, playback progress, EPG cache, last-playlist state and the local Premium-status cache. Device-level preferences such as language, theme, onboarding state and the local advertising cooldown are preserved, and completed recordings are not deleted by sign-out.

The in-app “Clear all data” action clears the main Android preferences and Hive data used by UltraCast and deletes known Xtream credentials from protected storage. It does not delete completed recordings. The current “Clear all data” implementation does not explicitly clear the separate EPG cache; that cache is cleared on account sign-out, when Android app storage is cleared, or when the app is uninstalled.

Some IPTV providers only support unencrypted HTTP. In that situation, data sent to that provider, including a stream URL or credentials embedded by the provider, may travel without transport encryption. UltraCast cannot convert a third-party HTTP server into HTTPS. Prefer providers that support HTTPS.

3. Account and cloud synchronization

If you use the app as a guest, UltraCast account synchronization is not used. If you sign in, Firebase Authentication processes authentication data and issues an account identifier and security token. Firebase supports email/password accounts, Google Sign-In, email verification and password-reset emails.

For signed-in users, the UltraCast backend may store the following under the Firebase account identifier:

Xtream usernames and passwords are not included in the playlist synchronization payload sent to the UltraCast backend. Firebase authentication tokens are sent to the backend to protect account-specific requests.

4. Purchases

Google Play processes Android purchases. UltraCast sends the purchase platform, product identifier and Google Play purchase verification data to its backend, together with a Firebase authentication token. The backend verifies the purchase before Premium access is activated. Purchase and subscription records may be retained as needed to verify entitlement, restore purchases, detect expiry, refunds or revocation, and prevent duplicate use of a purchase token.

5. Advertising and consent

The free mobile version uses Google Mobile Ads (AdMob). Google and its advertising partners may process device identifiers, IP address, advertising identifiers, approximate location derived from signals, ad interactions, diagnostics and other data described in Google’s policies. Where required, Google’s User Messaging Platform is used to request or manage advertising consent before ad requests are enabled. Premium users do not receive ads from the app after Premium status is confirmed. The Android TV version is configured without UltraCast advertising.

6. EPG, artwork and third-party content services

To display programme information, the app may contact the XMLTV/EPG URL supplied by your playlist, your Xtream provider, an XMLTV URL entered by you, or supported public EPG sources. Requests may expose standard network information such as your IP address and user agent to those services. The app may use the device region or language, or a country selected by you, to choose an appropriate public EPG source.

Channel logos, movie or series artwork and other media metadata can be loaded from URLs supplied by your IPTV, EPG or related content source. The host serving that resource receives the normal information required for a network request, such as your IP address.

7. Analytics, crash diagnostics and remote configuration

UltraCast uses Google Firebase Analytics to measure general application usage and technical behavior. UltraCast records custom technical events such as screen navigation, app lifecycle, generic authentication-flow stages, operation outcomes and selected error categories. UltraCast’s custom diagnostics are designed not to include IPTV credentials, playlist or stream URLs, media titles, email addresses or raw user-provided content.

Firebase Crashlytics is used to diagnose crashes, non-fatal errors, ANRs and stability problems. Crashlytics may process crash stack traces, application and device state, operating-system and app-version information, session information and installation identifiers. UltraCast also attaches technical screen/state keys and sanitized diagnostic events to assist troubleshooting. Firebase Sessions, included transitively with Firebase diagnostics components, may process app and device metadata, network connection type and foreground-session timing to support stability and session metrics.

Firebase Remote Config is used to remotely manage technical application settings, including whether an app version must be updated before continuing. Remote Config uses Firebase Installations to identify an app installation for configuration delivery. Firebase services may process technical information such as app version, operating-system/platform information, language, country code, time zone, application identifiers and a per-installation Firebase identifier.

These Firebase technical services can operate whether or not you sign in to an UltraCast account.

8. Google Cast and local-network playback

When you choose to use Chromecast or another Google Cast-compatible device, UltraCast discovers compatible receivers and communicates with the receiver selected by you. To start playback, UltraCast sends the media information required by the Cast receiver, which can include the selected media URL, title, subtitle, artwork URL, content type and playback state.

If a media URL supplied by an IPTV provider contains credentials or other access information, that information may necessarily be included in the URL used for Cast playback. For some HLS providers, UltraCast may temporarily run a local HTTP relay on the device’s private local-network address so that the selected Cast receiver can access the stream. The relay fetches the provider stream and forwards/re-writes the HLS resources for the receiver; it is a local playback mechanism and is not an UltraCast cloud-storage service.

The Google Cast SDK also collects anonymized technical information about Cast discovery, session management, the mobile device and the Cast client application and sends that information to Google for Cast diagnostics, performance measurement and product improvement.

9. Camera and QR scanning

UltraCast requests camera access only when you choose to open its QR/barcode scanner. Camera frames are passed to the barcode-scanning component to recognize the code and return its decoded value to UltraCast. UltraCast does not intentionally save camera frames or upload those camera images to the UltraCast backend.

On Android, the scanner uses Google ML Kit barcode-scanning components. ML Kit may process technical device information, app information, performance information and per-installation identifiers for diagnostics and usage analytics. The ML Kit SDK may also generate per-installation identifiers that are not intended to identify a specific person or physical device.

10. Purposes and legal bases

Data is processed to provide playback and account features, synchronize user-selected data, verify purchases, restore Premium entitlement, prevent fraud, display and measure ads in the free mobile version, comply with consent choices, provide Cast and QR-scanning features when requested, deliver compatibility and update settings, maintain security, measure technical app usage, troubleshoot failures and comply with legal obligations. Depending on your location, processing may rely on performance of a contract, legitimate interests, consent or legal obligations.

11. Sharing and processors

We do not sell your personal data. Data may be processed by:

12. Retention and deletion

Clearing local data or signing out does not by itself delete a Firebase account, Google Play purchase history, cloud account data already stored by UltraCast, or records held by third-party providers.

13. Account deletion

Users may request deletion of their UltraCast IPTV Player account and associated cloud data at any time. The request can be initiated inside the app from Settings → Legal → Request account deletion. On mobile this opens an email request when an email application is available; on Android TV the app displays the deletion email address and account details needed to make the request.

Request account deletion by email

Alternatively:

  1. Email thecatsizer@gmail.com with the subject “UltraCast account deletion”.
  2. Send the request from the email address associated with your UltraCast account. If that is not possible, include the Firebase account email or UID so the account can be identified.
  3. We may request reasonable verification to prevent unauthorized deletion. Never send your password, Google password, purchase token or IPTV credentials.

After verification, we will process the request within 30 days and delete the Firebase Authentication account and associated cloud-synchronized data controlled by UltraCast, including synchronized playlist information, favorites and viewing history.

Local app data on the device is separate from an account-deletion request. Signing out clears account-related local session data as described in section 2. Android app-storage controls or uninstallation can remove remaining app-specific storage. Completed recordings published to shared media storage are not removed by account deletion, sign-out, “Clear all data” or, on Android 10 or later, by uninstalling UltraCast; those recordings must be deleted separately by the user.

Purchase or transaction records may be retained only when necessary for entitlement verification, refunds, accounting, disputes, fraud prevention or legal compliance, for the period described in section 12. Google Play purchase history and data held by IPTV, EPG, advertising, analytics, Cast, ML Kit or other third-party providers are governed by those providers and cannot be deleted by UltraCast.

Deleting an UltraCast account does not cancel an active Google Play subscription. Subscriptions must be cancelled separately through Google Play.

14. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability of personal data, and may withdraw consent where processing relies on consent. You may also change ad-consent or advertising settings through the app or device where available, and lodge a complaint with your local data-protection authority.

15. Children

UltraCast IPTV Player is not directed to children. The app does not knowingly seek to collect personal data from children. Users are responsible for complying with age requirements applicable to Google accounts, purchases, advertising and content accessed through their own providers.

16. Content responsibility

UltraCast provides no content. Users must only add sources they are legally entitled to access. UltraCast is not responsible for the availability, legality, security or privacy practices of third-party IPTV, XMLTV, EPG, artwork or other content services.

17. International transfers

Google and infrastructure providers may process data in countries other than yours. Their contractual safeguards and privacy terms govern those transfers. Contact us for questions about the safeguards relevant to UltraCast backend data.

18. Security

We use Firebase authentication tokens for account-protected requests, server-side purchase verification, access controls and Android Keystore-backed AES-GCM encryption for locally stored Xtream credentials. UltraCast’s synchronization payload intentionally excludes Xtream usernames and passwords. No system is completely secure. Users should protect their device, Google account and IPTV credentials, avoid untrusted networks and use HTTPS-capable providers where possible.

19. Changes

This policy may be updated when the app, providers, legal requirements or data practices change. The “Last updated” date identifies the current version.

20. Contact

Privacy and deletion requests: thecatsizer@gmail.com.

Summary

UltraCast stores media configuration and caches locally, uses Firebase for optional accounts as well as analytics, crash diagnostics and remote configuration, synchronizes selected signed-in account data through the UltraCast backend, verifies Premium purchases with Google Play, uses AdMob and UMP in the free mobile version, supports Google Cast, uses camera-based ML Kit barcode scanning when requested by the user, creates local recordings, and contacts IPTV, artwork and EPG services selected or referenced by the user’s sources.