This policy explains how Light Player handles data in the app and this website. Contact the Light Player team through the support page and select Privacy & data for data-related requests. Support page.
Data stored on your device
The app stores playlist settings, source usernames and addresses, favourites, viewing progress and cached data on your device. Source credentials are stored in the system Keychain. Login credentials are sent to the source you select to authenticate your account and play content.
Service operation data
The current app uses Firebase for configuration, connection-code resolution, an anonymous sign-in identifier, and online presence including connection time, platform and app version. Installation identifiers, notification tokens and app-integrity signals may also be processed. Firebase Analytics collection is disabled in the current version. We do not sell your data or use it for targeted advertising.
Sources and third-party services
Your device connects directly to the content and image sources you add. It may contact TMDB for title and cast metadata. Those services receive connection information such as your IP address and content requests and process it under their own policies. Firebase uses Google infrastructure and data may be processed outside your country.
Website and support requests
When you contact us, we store your name, email address, request category, message and reference number to handle your request and respond. Access is restricted to authorised administrators. Name, email and message fields are encrypted in the database. Do not send source passwords or payment details. The web server records technical information including IP address, request path, time and errors for operation and security.
Cookies
The website uses essential cookies for sessions, form protection and administrator sign-in. We do not place advertising trackers or marketing analytics on the website.
Retention
Device data remains until removed through the app or system. Delete saved playlists to remove their credentials; uninstalling alone may not clear Keychain. Firebase online presence is normally removed on disconnect, while anonymous identifiers and installation service data may remain until deleted through the service lifecycle. Support requests are automatically removed 90 days after their last update and administrator audit records after 180 days. Deleted data may remain in backups until replaced within the latest seven daily copies. Technical logs are retained as needed to diagnose faults and investigate abuse, and removed when that need ends; legal obligations may require longer preservation of certain records.
Your choices and rights
Manage notifications in device settings and remove saved playlists in the app. Use the support form to request access to, correction of, or deletion of service data. We may request limited information to verify your connection to the data, without asking for your content-source password.
Policy changes
Updates will be published here with a revised date. Before introducing user accounts, purchases or cloud sync, we will update this policy to describe the data processed by those features.
