Privacy Policy
We have no server and no first-party analytics. Your playlists, credentials, and viewing activity stay on your device unless you opt in to iCloud sync.
Last updated: 21 July 2026Timonation IPTV is built so that your playlists, credentials, and viewing activity stay on your device. This policy explains exactly what that means.
1. Who we are
Timonation IPTV is a video player application for iPhone, iPad, and Apple TV, developed and maintained by Tiago Azevedo. Contact: support@timonation.app.
2. What this app does
Timonation IPTV plays IPTV streams from playlists you supply yourself — either an M3U URL or Xtream Codes credentials. The app does not include, host, distribute, or curate any media content. You are responsible for ensuring you have the legal right to access the content you supply.
3. What we collect
We have no server and no first-party analytics — the free tier’s ads are the only third-party data collection.
- We never see your playlists, viewing activity, or credentials. We have no first-party telemetry.
- We do not track you across apps or websites ourselves.
- Ads (free tier only). The free version shows one full-screen ad per session via Google AdMob. The ads are non-personalized (contextual) — AdMob does not access your advertising identifier (IDFA) and does not track you across other apps or websites, so there is no “Allow tracking” (App Tracking Transparency) prompt. AdMob still collects a small amount of data to serve the ad (your IP-derived coarse location and ad-interaction/diagnostics data), but not for cross-app tracking. Timonation Pro removes all ads and this ad-SDK data collection. The App Store privacy “nutrition label” lists exactly what the ad SDK collects.
- Ad consent in the EEA, UK, and Switzerland (free tier only). If you are in the European Economic Area, the United Kingdom, or Switzerland, the app shows Google’s consent dialog (Google’s User Messaging Platform, a certified consent-management platform) before any ad can appear. Your choices are saved on your device as an industry-standard IAB TCF consent record — it stays in the app’s local storage and never reaches us — and you can change them at any time via Settings ▸ Privacy options (this entry appears when the consent requirement applies to you). Whatever you choose, ads remain non-personalized: declining consent never enables tracking; it simply means ads may not be shown at all. For how Google handles this data, see Google’s privacy & messaging information.
- Apart from the ad network and the artwork lookup described in Section 7, the app talks directly to your IPTV provider; we are not in the middle.
Crash and hang diagnostics (on-device only)
The app uses Apple’s MetricKit framework to capture crash and hang reports. These reports are saved only into the app’s private storage on your device (the most recent ten are kept) and are never transmitted to us or to any third party.
Local-only counters (dormant)
The app contains a small local-only usage-counter facility (launch counts, channel opens, and similar). It is off by default, and current versions ship no switch to turn it on, so nothing is recorded. If a future version exposes it, the counters will remain stored only in your device’s UserDefaults and will never be transmitted to us or to any third party.
4. What stays on your device
The following data is stored locally on your device and never leaves it under our control:
- The URL or credentials of every playlist you add.
- Your favorite channels and series, and recently watched channels.
- Your settings preferences (auto-refresh, sort order, bitrate, etc.).
- Saved playback progress (where you left off in a movie or episode).
- Recordings you capture with the Record feature — saved into the app’s private storage and never uploaded anywhere.
- Your profiles, parental-control settings, and PIN.
- A local log of playback stalls and the on-device crash diagnostics described in Section 3.
If you enable the optional iCloud sync, playlist references (including the provider login they need), favorites, and playback progress also sync through your personal iCloud account — see Section 5 for exactly what travels and how it is encrypted.
Xtream Codes, Provider Code, and Stalker portal logins are stored on the device in the Keychain, which is encrypted by the operating system. They are never written to UserDefaults or plain files. If you turn on iCloud sync, they also travel in your synced iCloud record so the playlist works on your other devices — see Section 5, which explains exactly how that is encrypted.
5. iCloud sync (optional, Pro tier)
If you opt in (Settings → iCloud Sync), the following data is synchronized between your Apple devices via Apple’s iCloud Key-Value storage:
- Playlist references — identifier, name, the playlist’s source URL, programme-guide (EPG) URLs, refresh settings, and the provider login (Xtream Codes / Provider Code username and password, or a Stalker portal MAC address and optional login).
- Favorite channel and favorite series identifiers.
- Saved playback progress (an identifier, position, duration, and timestamp — no titles or artwork).
Your profiles, parental controls, and PIN never sync — they stay on the device.
How it’s encrypted — read this if your M3U URL contains credentials. iCloud Key-Value storage is encrypted by Apple in transit and at rest, but it is not end-to-end encrypted — it falls under Apple’s standard iCloud data protection. For an M3U playlist, the source URL syncs exactly as you entered it, and many providers embed your username and password inside that URL (for example …get.php?username=…&password=…). If yours does, those embedded credentials are part of the synced record and are protected by Apple’s standard iCloud encryption rather than end-to-end encryption. If that is not acceptable to you, leave iCloud sync off — or use an Xtream Codes login instead, whose secrets never enter these records.
Provider logins are part of the synced record. When iCloud sync is on, your Xtream Codes / Provider Code username and password (and a Stalker portal’s MAC address and optional login) travel inside the synced playlist record, protected by Apple’s standard iCloud encryption — the same protection as the M3U URLs described above, and not end-to-end encryption. We never see them; they go to your iCloud account, not to us.
Earlier versions kept these logins out of the synced record and relied on iCloud Keychain instead. That approach cannot work on Apple TV: Apple documents that tvOS does not synchronize an app’s Keychain items through iCloud in either direction, so a playlist synced to an Apple TV arrived without its login and could not load any channels. Carrying the login in the synced record is what makes iCloud sync work across all of your devices.
If you would rather your provider login never left the device, leave iCloud sync off — the app is fully functional without it.
You can remove the app’s data from iCloud at any time: Settings → iCloud Sync → Delete iCloud Data deletes every Timonation key from iCloud Key-Value storage (data on the device is kept). The sync itself is governed by Apple’s iCloud privacy policy.
6. What we send to your IPTV provider
When you play a stream, the app makes HTTP/HTTPS requests directly to the IPTV server you provided. Those requests contain whatever your provider’s protocol requires (typically the username, password, and stream identifier in the URL path). This is the same traffic any IPTV player generates. We have no involvement in or visibility of those requests.
7. Artwork from TMDB
When a movie or series poster from your provider is missing or fails to load, the app can fetch replacement artwork from TMDB (The Movie Database). This lookup sends the title’s numeric TMDB identifier — supplied by your provider’s catalog metadata — to api.themoviedb.org, and downloads the poster image from image.tmdb.org. Like any internet request, these requests expose your device’s IP address to TMDB. They contain no account data, no credentials, and nothing from your playlists beyond that numeric title identifier. TMDB’s handling of these requests is governed by TMDB’s privacy policy. The attribution required by TMDB’s API terms (“This product uses the TMDB API but is not endorsed or certified by TMDB”) is shown in-app at Settings → Legal & Compliance.
8. Third-party services
- Google AdMob (free tier only) — the Google Mobile Ads SDK shows non-personalized ads. AdMob is governed by Google’s privacy policy and collects the limited ad-serving data described in Section 3 and disclosed in our App Store privacy label. Because the ads are non-personalized, the SDK does not use your IDFA or track you across apps. In the EEA, UK, and Switzerland, ad serving is additionally gated on the Google consent dialog described in Section 3. Timonation Pro removes ads and this data collection entirely.
- TMDB — the artwork lookups described in Section 7. This is a plain web API call; the app embeds no TMDB SDK.
- VLCKit (VideoLAN) — the open-source playback engine compiled into the app. It runs entirely on your device; its network activity is the playback of the streams you choose, and it performs no analytics or tracking.
Beyond these, the app uses only Apple system services (the App Store for purchases, iCloud for the optional sync, MetricKit for the on-device diagnostics in Section 3). We embed no analytics, crash-reporting, or attribution SDKs.
9. Children’s privacy
Timonation IPTV is rated 13+ on the App Store. We do not knowingly collect data from anyone under that age. The app includes on-device parental controls — a PIN-protected gate, per-profile restrictions, and the ability to lock individual channel groups — see Settings → Parental Controls.
10. Your rights
We hold no copy of your data on any server, so there is nothing for us to provide, correct, or delete. The data on your device is yours to manage in-app:
- Delete a playlist (and the channels imported from it): Settings → Your Lists → ⋯ (or long-press a list) → Delete.
- Delete a recording: Library → Recordings → long-press → Delete.
- Remove the synced iCloud copy: Settings → iCloud Sync → Delete iCloud Data.
- Remove everything stored on the device: uninstall the app. Uninstalling does not clear the iCloud copy — use Delete iCloud Data for that.
11. Changes
If we change this policy, we’ll note the new “Last updated” date at the top and surface a “What’s New” screen on next launch with a summary of what changed.
12. Contact
Email: support@timonation.app
If you contact us with a question or bug report, the email itself is processed by our email provider in line with their privacy policy. We retain support emails only as long as needed to respond and follow up.