Privacy Policy
Last updated: July 20, 2026
1001673950 Ontario Inc., operating as Chris TV ("we", "us"), provides the Chris TV application ("the App"). This policy explains, plainly, exactly what we can and cannot see. We deliberately collect as little as possible, and the two most sensitive things — your IPTV login and what you watch — are encrypted on your device so that we cannot read them, even if we wanted to.
We believe the honest way to earn trust is to be precise: below we state clearly what is genuinely private (and why we technically cannot see it), and we are equally clear about the ordinary operational data we do receive to run the service.
The short version
- What you watch is end-to-end encrypted. We cannot see it.
- Your provider login is never readable by us. It is encrypted on your device and stays that way even when you move it between your own devices.
- Playback never touches our servers. Streams go straight from your provider to your device.
- Recommendations run entirely on your device. No viewing data is sent to us to generate them.
- We show ads to no one, run no third-party advertising SDKs, and we do not sell your data.
- We do receive some ordinary operational data — your IP address when the App contacts us, crash diagnostics, and anonymous usage counts. This section explains each one.
What we CANNOT see
What you watch is end-to-end encrypted. Cross-device sync of your watch history, "My List", resume positions, and profiles is encrypted on your device with a per-household AES-256-GCM key before it is uploaded. That key lives only in your devices' operating-system keystores and is shared device-to-device sealed to each device's public key (P-256 ECDH key exchange). It is never sent to our servers in readable form. Our sync relay stores only ciphertext it has no key to read. So we do not, and cannot, see what you watch.
Your IPTV provider credentials are never readable by us. Your Xtream host, username, and password (and any M3U playlist or EPG URLs) are encrypted at rest on your device (AES-GCM, with the key held in your device's OS keystore). When you move a login between your own devices (pairing / "beam"), it travels only inside that same household-key ciphertext — our relay never sees it in the clear, and we never store it on our servers in readable form.
Playback never touches our servers. Streams go directly from your provider to your device. We are a player; we ship no content and no playlists.
Recommendations are computed entirely on your device. The "For You" and "Recommended" rows are generated locally from data already on your device. No viewing data is sent to us to produce them.
What we DO collect, and why
We are honest about the ordinary data our servers receive to operate the App. None of it tells us what you watch.
- IP address. Like any internet service, our servers receive your device's IP address when the App contacts them — for license checks, the sync relay, title-metadata lookups, and rate-limiting to prevent abuse. We use it to operate and secure the service, not to track what you watch, and we do not sell it or use it to build an advertising profile. IP-linked abuse-prevention logs are retained for up to 30 days.
- Crash & error telemetry. When the App hits an error, or a device reports an abnormal exit, it sends a diagnostic beacon to our server (christv.ca) containing the device model, the App version, memory and performance stats (for example available RAM and memory usage), and the technical error text or stack trace. Credentials and stream addresses are scrubbed out before the beacon is sent. We use this only to find and fix crashes.
- Anonymous usage analytics. We keep aggregate, non-identifying counts (for example app opens, which features are used, and overall totals) through our own self-hosted analytics. There are no third-party advertising SDKs, and we do not sell data.
- Access / license code. Your access code ties your own devices into one "household" for licensing and for routing your encrypted sync data. Our servers can see that a given device synced at a given time under a given code (routing metadata) — but not the encrypted content behind it. We also store a generated device identifier and a "last seen" time to enforce how many devices a code may run on and to prevent sharing or abuse.
- Payments. Subscriptions are handled by Stripe. Your card details go to Stripe, not to us. We retain basic billing records — subscription status and dates — to manage your subscription. Stripe's handling of your payment information is governed by Stripe's own privacy policy.
- Email (optional). If you choose to give us an email address — for example to claim a bonus-days offer or to help recover your account — we store it so we can contact you. We don't sell it.
- Title metadata (TMDB). To show posters, plot summaries, and ratings, the App looks up title metadata through our server, which queries TMDB. This sends the title name to fetch its art and information; the lookup is by title only and is not tied to your identity.
Your sources and your content
The credentials and playlists you enter ("Your Sources") are stored encrypted on your device (AES-GCM, key held in your device's OS keystore).
- Adding a service from your phone (the pairing page): your login is encrypted to your household key and relayed to your other device as ciphertext. Our server never sees it in the clear.
- Copying your login to another device ("beam" / "Add another device"): the same household-key end-to-end encryption — your login moves device-to-device as ciphertext we cannot read.
What you watch through Your Sources is between you and your provider.
How information is stored and shared
We operate our own servers (at christv.ca) for licensing, the encrypted sync relay, title-metadata lookups, and crash diagnostics. We use Stripe to process payments. We do not sell personal information. We may disclose information if required by law.
Data retention
We keep licensing and routing data for as long as your access code is active, plus a reasonable period afterward. IP-linked abuse-prevention logs are retained for up to 30 days. Crash diagnostics are retained only as long as needed to diagnose and fix issues.
Your rights
Depending on where you live (for example PIPEDA in Canada, GDPR in the EU, or the CCPA in California), you may have the right to access or delete your information. Contact us at chris@christv.ca and we will respond as required by law.
Children
The App is not directed to children. "Kids" profiles and parental PINs are stored locally on your device; if you enable cross-device sync they are included in the end-to-end encrypted sync data, which we cannot read.
Security
Sensitive data — your provider login and the viewing data that syncs between your devices — is encrypted such that we cannot read it. We use reasonable measures to protect the limited operational data we do hold. No method of transmission or storage is 100% secure.
Changes
We may update this policy; we will post the new "Last updated" date here.
Contact
1001673950 Ontario Inc. (Chris TV), Ontario, Canada
chris@christv.ca