Legal
Privacy
Version 4 · updated 2026-09-14
Your library is stored locally, and playback connects directly to your provider. Some features also send data to KimberPlay and the services described below. This page covers Fire TV / Android TV, Windows, Linux and the web player.
Local storage
- Your library, source URLs and provider credentials are stored on your device.
- Your favorites, profiles and viewing progress are stored locally; Cloud Sync can also upload selected settings and progress as described below.
- Your Private (After Dark) PIN — stored only as a salted hash, on the device.
- Your recordings — they are files on your device’s own storage.
The web player and desktop apps use localStorage and IndexedDB for their library and preferences. Desktop recordings are separate files on your computer. Clearing browser site data removes the locally stored library and preferences. Exported backups can contain provider credentials; store them somewhere you trust.
Cloud Sync on Fire TV and Android TV
Cloud Sync requires a paid Plus key. In the updated app it stays off until you enable it in Settings → Cloud Sync; an existing explicit choice is preserved. Older releases enabled it by default. Check Settings on each device. It uploads an encrypted settings backup including playlist credentials, favorites, channel groups, guide settings and viewing progress, and shares it with registered devices using the same key. It does not upload your recordings or the full channel catalogue. Cloud Sync requires a paid key and is not included in the trial.
Encryption happens on your device, using a key derived from your license key. KimberPlay also stores that license key, so this design does not prevent the service from decrypting the backup. The server stores the encrypted backup, its version, update time and the device that last updated it. Turning sync off stops syncing on that device; it does not delete a backup already on the server. Contact support if you want that backup deleted.
Payment processing recovery
Verified payment events are stored while we process your purchase or resolve a failure. They can include contact and payment-reference information supplied by Stripe. Completed events keep processing metadata and remove their event payload; unfinished events are retained for recovery and support review. Payment processing records are not public.
Phone Remote
When you pair a phone with a TV, commands pass through KimberPlay servers. They can contain key presses, typed text, searches, channel names and stream links, including any credentials in those links. Pairing sessions expire after twelve hours. Delivered commands are deleted when the TV collects them; commands older than two minutes are ignored and cleared during subsequent remote activity. This is not a guarantee that an inactive mailbox is deleted within two minutes.
Other network calls
| Call | When | What is sent |
|---|---|---|
| License check (api.kimberplay.com) | App launch, key entry and periodic verification | Your license key, installation and device identifiers, a one-time request token, app and OS version, platform, model and, where supported, an app-signing fingerprint. The server also records verification history and IP-derived location (country, region and approximate city coordinates). |
| Trial and device activation (api.kimberplay.com) | Launch, periodic trial checks and while waiting for a purchase to activate | Device and installation identifiers, app version, platform, model and signing information where supported. Desktop and Android identifiers can remain stable across reinstalls. The service uses IP-derived information for trial eligibility and abuse checks. |
| Crash report (kimberplay.com) — TV and desktop apps | The launch after the app crashes | The crash stack trace, app version, OS and device information. Error text can contain contextual information; these reports are used to diagnose failures. |
| Update checks and downloads — TV and desktop apps | App launch | App/version and standard network information. TV update checks also carry the usage statistics below. Desktop updates contact the release download host. Downloads require the receiving server to process your IP address. |
| Launch ping (kimberplay.com) — Windows, Linux and web player | App launch, after you have accepted the user agreement | The app version, platform and usage statistics below. The server derives a device-counting hash from the IP address and browser string. |
| The app itself (kimberplay.com) — desktop apps and web player | App launch | The desktop apps and web player load interface files from kimberplay.com/app, including language resources. Requests contain standard network information. |
| Live sports scores (ESPN) and news headlines (public wire feeds) | While the Sports or News hub is open | Requests for public feeds and fixtures. KimberPlay-hosted hub endpoints can also receive your license and device identifiers to check Plus or trial eligibility; requests made directly to external services expose standard network information to them. |
| Your own sources | Sync and playback | Requests go directly from your device to the provider you configured — never through our servers. This is also why the web player cannot load providers that refuse browser requests: we do not proxy them |
Usage statistics in the launch ping
These exist so we can see what devices and libraries KimberPlay has to work with and which parts of the app matter, and fix what breaks. The server attaches them to a hash derived from IP address and browser information to count devices. A hash is a pseudonymous identifier, not a guarantee of anonymity. The statistics include:
- The app version, the platform and operating system version, the screen size, and the language.
- How many playlists you have and of which type (M3U, Xtream Codes, Stalker portal); how many channels, movies and series they contain; whether a TV guide is loaded; how many profiles and favorites you have. Counts only — never the names or contents.
- Which features you opened and how many times since the previous launch (for example the guide, the sports hub, search, a movie playing), and how long the previous session lasted.
- How many playback errors happened, by type (for example “provider refused” or “could not decode”) — never which stream.
- For each provider you have configured, the country where its server is hosted. The app sends the server’s hostname once; our server looks up its country at that moment and keeps only a one-way code of the hostname and the country. The hostname is not stored, and your username, password and playlist URL are never sent.
Country lookup for provider servers uses GeoLite2 data created by MaxMind, available from maxmind.com.
If you buy KimberPlay Plus
Payment is processed by Stripe (we never see your card number). We store the purchase email, license key, plan, payment references, subscription/refund status, registered devices, activation and verification history, and related device/location information. Referral and partner attribution are stored when used. License emails are delivered through Resend. Database records are hosted by Supabase, and the website and API run on Vercel.
This website
The public website uses Vercel’s cookieless analytics to count page views and selected actions such as install clicks. The owner administration area uses a sign-in cookie. When you download the app from kimberplay.com/apk or kimberplay.com/windows we record the download with your country, the page that linked to it, and any campaign tag in the link — not your IP address in that download event. Hosting and payment services still process the network information needed to serve requests.
Your data, your call
Want your customer record or crash reports deleted? Email support@kimberplay.com from your purchase address. You can also request deletion of a cloud backup. We use the service providers listed above to operate the product. This page does not promise an automatic deletion schedule for customer, telemetry or backup records.
Kimber