RunTV ("we", "our", "us") operates the RunTV applications for Android TV and Google TV (com.runtv.tv), Apple TV, iPhone and iPad, Android phone and tablet, Windows and Mac, together with the RunTV website and web controller at runtv.run (collectively, "the Service"). This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights you have over your data.
This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), Brazil's LGPD, and similar privacy laws.
For the purposes of GDPR, the data controller is the operator of RunTV. You can contact us at [email protected] for any privacy-related questions, or use the form at runtv.run/delete-account to request account deletion.
When you sign up at runtv.run/app using email/password or "Continue with Google":
These stay on your device. To delete them, clear your browser data (for the web controller) or clear the app's data through your device settings.
If you accept the cookie banner on the web controller, or use any of the RunTV apps:
You can decline analytics on the web controller via the cookie banner or "Cookie settings" link. In the Android TV and Android apps you can disable analytics by resetting or clearing the advertising ID in your device settings. On Apple TV, iPhone and iPad, analytics are not used for tracking and no advertising identifier is collected.
Our relay server (running on Hetzner Cloud, EU) handles the following:
None of this is stored on our servers. It is used to complete the request you asked for and then discarded.
Your playlist URL, Xtream credentials and watchlist symbols are also kept out of our logs: our web server records request paths without their query strings, and the application log records only the provider's hostname, never your credentials.
The relay does not log or persist the content of streams, your watch history, or the contents of your IPTV playlists.
When you send a stream from your phone to your TV, its URL is encrypted before it passes through the relay, so it is not exposed in transit or in our logs.
When you pair a phone with a TV, your favorites and any additional provider logins are sent to that TV through the relay, so the TV can load your channels on its own without the phone. This travels over an encrypted connection, and the relay passes it to your TV without keeping a copy.
| Data | Purpose | Legal basis |
|---|---|---|
| Email, password, name, photo, pairing codes | Account creation, sign-in, syncing your TVs across devices | Performance of a contract (Art. 6(1)(b)) |
| Marketing email opt-in | Sending product updates if you opted in | Consent (Art. 6(1)(a)) |
| Analytics events, ad ID | Understanding how RunTV is used to improve it | Consent (Art. 6(1)(a)) on web; legitimate interest on the TV app subject to user opt-out |
| Crash logs | Diagnosing and fixing app crashes | Legitimate interest (Art. 6(1)(f)) |
| Server access logs | Security, abuse prevention, debugging | Legitimate interest (Art. 6(1)(f)) |
| Data | Retention |
|---|---|
| Account data (email, name, photo, devices, prefs) | For as long as your account exists; deleted within 30 days of an account deletion request |
| Analytics events | Up to 14 months (Firebase Analytics default), then anonymized aggregates only |
| Crash logs | Up to 90 days |
| Server access logs | Up to 14 days |
| Account deletion request records | Indefinitely (audit trail required for compliance) |
We use the following service providers to operate RunTV. Each acts as a data processor under our instructions and has its own privacy policy:
| Provider | Purpose | Region |
|---|---|---|
| Google Firebase (Auth, Firestore, Analytics, Crashlytics) | Account storage, user data sync, analytics, crash reporting | USA (with global edge locations) |
| Hetzner Cloud | Relay server hosting | European Union (Germany / Finland) |
| Cloudflare | CDN, DDoS protection, SSL termination | Global edge network |
| Google Play Services | App distribution, in-app updates | Global |
When you use certain features, requests are forwarded to external APIs (often through our relay to avoid CORS). We do not log or store these requests, but the external service may:
Each of these services has its own privacy policy. We do not share account data with them.
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data may be transferred to countries outside your region (notably the USA, where Firebase is hosted). Such transfers are protected by the EU Standard Contractual Clauses (SCCs) and Google's Data Processing Addendum.
The web controller (runtv.run/app) uses two categories of browser storage:
You can decline analytics via the cookie banner shown on first visit, or change your choice anytime via the "Cookie settings" link in the app footer.
This runs only on our public marketing pages. It records page views and clicks through to an app store. It is never loaded inside the RunTV apps or the web controller at runtv.run/app. If you are in the EU or the UK it is not loaded at all unless you accept it on the cookie banner shown on your first visit. You can change your mind at any time using Cookie settings, or use your browser's cookie controls or your Reddit advertising settings.
If you opted in during sign-up or via an in-app prompt, we may send you product updates and feature announcements. Every marketing email includes a one-click unsubscribe link. You can also withdraw consent at any time by emailing [email protected]. We do not sell your email or share it with marketing partners.
Under GDPR, UK GDPR, CCPA, and similar laws, you have the right to:
If you use RunTV without an account (TV app only, no sign-in), we do not associate any personal data with you, and there is no account to delete. You can clear local app data via your TV's system settings.
RunTV is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact [email protected] and we will delete it promptly.
We protect your data with:
No system is perfectly secure. If we discover a data breach affecting your data, we will notify affected users and (where required by law) regulators within 72 hours of discovery.
We may update this Privacy Policy as our service evolves or as the law changes. The "Last updated" date at the top reflects the most recent change. For material changes, we will notify signed-in users by email or in-app notice before the change takes effect.
For privacy questions, deletion requests, or to exercise any of your rights: