Effective date: 8 October 2026
Developer: Avorna Yazılım Ltd. Şti. ("we", "us")
Contact: info@avorna.com
OxTV is a media player for iPhone, iPad, Mac and Apple TV. It carries no channels of its own and does not know what is on yours: you give it an address, and it plays what is at that address.
The short version: there is no advertising, no analytics of any kind and no tracking, and OxTV works fully without an account. Keeping your devices in step is optional. If you sign in for it, what your devices share is kept in a database we operate — section 3 lists exactly what that is, and section 6 the one thing it keeps about a subscription — and it is used for that and for nothing else.
1. What we collect
If you never sign in, nothing. The app contains no advertising, no analytics or telemetry of any kind, no tracking, and no third-party software development kits that do any of those things. We do not profile you and we do not know what is on your sources.
If you sign in to sync, we hold your email address, a random identifier for your account, and the records listed in section 3: your sources and their logins, your playlists, your preferences, each source's PIN verifier and what it hides, and what you have watched. If you subscribe through the App Store, we also hold which subscription your account has, until when it runs and whether it is active (section 6). They are kept so that your own devices can share them. We do not analyse them, sell them or share them, and none of it is used for advertising or tracking.
The app's privacy manifest and its App Store privacy label say the same: an email address, a user ID, user content, purchases (which subscription the account holds) and one other kind of data (what has been watched), each linked to your account, used only to make the app work, and never for tracking.
2. What is stored on your device
- The sources you add — an Xtream panel address, a playlist address, or a playlist file you import, with the name you gave it.
- Credentials — the username and password for a source. These are kept in the Apple Keychain, encrypted by the operating system, and are never written into the app's database. Where a panel supplies a playlist address with the login inside it, the login is taken out of the address before the address is stored.
- A cache of what your source lists — its channels, films, series and episodes, including the stream addresses it gave for them. Some panels put your username and password inside those stream addresses; where they do, that cache contains them. It is rebuilt from scratch every time a source is refreshed, it is never synced, and it is never exported.
- What you have watched — favourites, playlists, watch progress, recently watched.
- A source's PIN, if you set one: not the PIN, but a value derived from it (PBKDF2-HMAC-SHA256, 600,000 rounds) against which a PIN typed later can be checked, and the list of what that source hides. Your PIN is not stored anywhere, in any form.
Deleting a source removes its login from the Keychain. Uninstalling the app removes its database and everything cached with it; the operating system may keep an app's Keychain items after the app is deleted, so remove your sources first if you want their logins gone as well.
3. Sync, if you sign in
Sync is opt-in. A device that has never signed in syncs nothing and works exactly as well: the database on the device is the truth either way. There is no switch to find in order to be left alone — being left alone is the default.
Signing in takes an email address and a six-digit code sent to it. There is no password to invent, and a code can be typed into an Apple TV where a link cannot be clicked. We use the address to identify your account, to send the codes, and to send two short messages: one when the account is created and one when it is deleted. Nothing else is ever sent to it — no newsletter, no marketing.
- What syncs: the names, types and addresses of your sources; a source's login, so it need not be typed into every device; your playlists and what is in them; your preferences; a source's PIN verifier and the list of what it hides; and what you have watched — where a film was left, which episodes are seen.
- What never syncs: the cache of what your sources list (including its stream addresses), episode listings, TV guide data, a file bookmark, and anything belonging to a source you marked as staying on this device.
- A source can be kept off sync entirely. Each source carries a switch that keeps it on the device it was added to. The setting itself never travels, so the same panel can be shared from your Mac and private on your phone. A source marked this way is invisible to sync in both directions, and everything under it goes with it — its login, its playlists, what has been watched on it. Turning the switch on takes back what was already sent, the panel password first.
- Where it is kept: a database we operate for this purpose on Supabase, in the European Union (the AWS eu-west-1 region, in Ireland), reached directly from your device over HTTPS. Row-level security means a row can be read only by the account that wrote it, and the hosting provider encrypts the database at rest. We do not mine it, analyse it or share it. It exists so that your devices agree.
- Your sources' logins are stored there as you entered them, so that a new device can use them. They are protected by those access rules and that encryption at rest, not by a key only you hold: they are not end-to-end encrypted. We do not read them. If you would rather a login never left a device, keep that source to the device.
- Who else handles it: Supabase Inc. hosts the database and runs the sign-in. The emails are sent from no-reply@oxtv.app through Apple's iCloud Mail. Like any server, the sync service sees the IP address a request comes from and keeps it for a short time in its request logs, to run the service and prevent abuse; we do not use it to identify you.
- Deleting it: you can delete your account at any time, from inside the app or by writing to info@avorna.com. Deletion removes every record stored for the account at once; what remains is an anonymous note that an account existed and when, with no email address and nothing that leads back to you. Signing out leaves the local database intact and the app fully working.
4. Source PINs and hidden items
Any source can be given a PIN, and anything inside it — a category, a channel, a film, a series, a playlist — can be hidden. A hidden item is filtered out of every screen in the app: the home screen, the tabs, its category, every playlist and search. Revealing hidden items asks for the PIN and lasts only until the app goes into the background; nothing about it is written down.
We say plainly what this is. What is stored is a verifier, not a key, and hidden items are not encrypted. That is on purpose: what is hidden is mostly a cache your panel would send again on request, so sealing it would be theatre. The feature keeps things off every screen in the app. It is not a defence against somebody opening the database file with a tool.
Changing a source's PIN and taking its lock off both ask for the PIN.
There is no recovery. We cannot lift a source's PIN and neither can Apple. If you forget it, what that source hides stays hidden. The screen where you set it says exactly this, because a sentence there is the only warning anybody gets.
5. Where your device connects
OxTV connects directly from your device to the servers you configure, with no involvement from us. Those servers receive your credentials, your IP address and the details of what you asked for — which stream, which listing, when. We are not a party to that connection and have no visibility into it. Their privacy practices are their own; please read them before adding a source.
Many panels are reachable only over plain, unencrypted HTTP. OxTV allows this because the alternative is not being able to use those panels at all, and it warns you when the address you have entered is not https. Over plain HTTP, your username and password are readable by anyone able to observe the network between you and that server. This is a property of the server you chose, not of the app, but you should know it.
Two other kinds of connection are worth naming:
- Artwork. Posters, logos and stills are loaded from whatever addresses your source gives for them. These are often third-party image hosts that have nothing to do with us or with your provider. Such a host sees your IP address and which image was requested.
- AirPlay. When you send video to an Apple TV or another receiver, your device serves the video to it over your local network. Nothing leaves your network in doing so, and the app asks for local-network permission for exactly this reason.
Beyond these — your sources, Apple's App Store and, if you have signed in, our sync service — the app does not connect anywhere.
6. Purchases
Subscriptions and free trials are sold and billed by Apple. We never see your payment method, billing address, card details, the price you paid or your Apple Account. Apple gives us aggregate, anonymous sales figures that cannot be connected to any individual. Apple's handling of purchase data is governed by Apple's Privacy Policy.
If you are not signed in, the app checks whether a subscription is active using Apple's StoreKit, a check that happens between your device and Apple, and nothing about your subscription reaches us.
If you are signed in, your subscription is attached to your OxTV account, so that it opens OxTV on every device signed in to that account — including one that uses a different Apple Account. To do that, the app sends our server the record of the purchase that StoreKit keeps on your device, as Apple signed it. Our server checks Apple's signature, asks Apple whether the subscription is active and until when, and keeps beside your account: which plan it is, when the current period ends, its state (active, in a billing grace period, waiting on a payment, expired or refunded), whether it was a test purchase, and Apple's identifier for the original purchase. From then on Apple tells our server when that subscription renews, lapses or is refunded, and the record is kept up to date. Notices Apple sends about a purchase that is not attached to any account are read for its identifier and nothing else, and nothing is stored. Like any server's, these requests are logged for a short time.
A subscription shared with you through Family Sharing is not attached to your account. A purchase is attached to one OxTV account at a time: signing in with another account on a device that holds it moves it there. Deleting your OxTV account deletes this record with everything else; the subscription itself carries on with Apple until you cancel it there.
7. Crash reports
If you have turned on "Share with App Developers" in Settings → Privacy & Security → Analytics & Improvements, Apple may pass us anonymised crash reports. These contain no sources, no credentials and no viewing history. You can turn it off in the same place.
8. Children
OxTV is a general-purpose player and is not directed at children. We do not knowingly collect personal data from children: the only personal data OxTV handles is the email address, and the records in sections 3 and 6, of whoever chooses to sign in to sync. What can be watched depends entirely on the sources added to it, which is the responsibility of whoever adds them. A PIN per source, and the ability to hide anything inside one, exist to help keep a household's viewing apart.
9. Your rights
Avorna Yazılım Ltd. Şti. is the data controller. Unless you have signed in, we hold no data about you at all. If you have, we hold an email address, the records listed in section 3 and, for a subscriber, the record of the subscription described in section 6 — and all of it stays under your control:
- Remove a source, a playlist or the whole app's data from within the app.
- Keep any source to its device, which takes back what was already sent for it.
- Delete your account, and everything synced with it, from within the app or by writing to us.
- Delete your sources and then the app to remove everything local, logins included.
The sync database is in Ireland, so for someone in Türkiye signing in means a transfer of personal data abroad under KVKK. Sync is optional, and the app works fully without it.
People in the EU/EEA, the UK, Türkiye and other places with data-protection law (GDPR, KVKK and their equivalents) keep every right those laws give them, including access, correction, export and erasure. Write to info@avorna.com and we will answer within the period the applicable law requires.
10. Changes
We will update this policy when the app changes in a way that makes it wrong. The current version is always at https://oxtv.app/privacy and reachable from inside the app. A material change comes with a new effective date.
11. Contact
info@avorna.com