Basis
Legal Disclosures & Compliance

Privacy Policy

How Basis handles your data: what stays on your device, what your Basis account stores, and what we never collect.

Provider: Sound Enterprises Pvt. Ltd.
Applies to: Basis for Android, iOS, macOS, and Basis Website
Last updated: August 10, 2026

Summary

Basis is a media player. The app contains no advertising SDKs, and we do not track you across apps or other companies' websites. The Android app uses Google Firebase for crash reporting and product analytics, which starts only once you accept the in-app Terms of Use and which you can switch off at any time in Settings, Privacy (see Section 1a). Our website uses one analytics tool, and only if you accept it when asked (see Section 11).

Basis requires a free Basis account to use. Creating that account means we collect your email address. There is no anonymous mode: if you do not create an account, you cannot use the app.

Separately, the IPTV service you connect Basis to is yours. Its address and credentials are stored encrypted on your device and are sent only to that service. That is the default for every account and it does not change unless you ask it to. Basis Pro adds one optional convenience: for a server you choose, Basis can keep an encrypted copy of that one login in your account so you do not have to type it again on another device. It stays off until you switch it on, it is encrypted before it is stored, it is never shown to anyone else, and you can delete it at any moment (see Section 4).

1. What we do not collect

The Basis app contains no advertising SDKs and collects no advertising identifier. We do not sell or share personal data with data brokers. We do not track you across apps or across other companies' websites. We do not receive the titles of what you watch. Your IPTV provider's address, username and password stay on your device and are sent only to your provider; the single exception is the optional Pro feature in Section 4, which you have to switch on yourself, per server, and which you can switch off again at any time to remove the copy.

The Android app does send crash reports and usage analytics to Google Firebase once you accept the in-app terms. That is described in Section 1a, and you can turn it off. Website analytics are separate again, covered in Section 11, and never involve the app.

1a. Diagnostics and analytics in the app

We use two Google Firebase services in the app, with Google acting as our processor:

  • Firebase Crashlytics for crash and error reports. A report contains the technical error, a stack trace, your device model, your OS version and the app version. We use it to find playback failures we cannot reproduce, because Basis has to work against thousands of IPTV provider setups we have no way to test.
  • Firebase Analytics for how the app is used: how far people get through setup, whether a provider connected, whether playback started or failed, which features are used, and interactions with the membership screen.

What we deliberately keep out of these reports: your provider username and password, and the titles of anything you watch. These are stripped on your device, before anything is sent, and the code that does it fails closed: anything it cannot confidently parse is removed entirely rather than passed through. Your provider's address is replaced with a one-way fingerprint, so reports from the same provider group together while the address itself is never sent. Analytics events carry only fixed values we define, never text echoed back from your provider.

These reports are linked to your Basis account identifier and to an installation identifier generated by Firebase. Neither is an advertising identifier.

When it starts: nothing is collected until you accept the in-app Terms of Use, whose clause 8 covers this. Accepting turns it on.

Turning it off: Settings, Privacy, "Share usage data and crash reports". Switching it off stops both services immediately on that device.

This section applies to Basis for Android. The iOS and macOS apps contain no analytics or crash-reporting SDK at all, so there is nothing to collect and no switch to show.

2. Your Basis account (required)

An account is required to use Basis. Accounts are provided through our backend provider Supabase, which stores data on our behalf. When you register and use the app, the following is stored on Supabase servers:

  • Email address and password. Your password is stored only as a salted hash; we never see it in plain text.
  • Display name, and an avatar URL if you set one.
  • Acceptance of the in-app disclaimer, recorded as a timestamp, so we have a record that you agreed to the terms.
  • Subscription state: your Basis Pro tier and its expiry date, if any.
  • Referral data: your referral code, and the account that referred you, if you used a referral link.
  • Account timestamps: when the account was created and last updated.
  • Waitlist and interest entries: if you ask to be notified about a plan, the email address or account you used and which plan you asked about.
  • Feature requests: anything you submit through the public feature-request board, including the email address that form marks optional. These are shown publicly on this website and are not tied to your account.

On iOS you may register using Sign in with Apple instead of a password. If you choose Apple's private relay option, we receive only the relay address, not your real email.

3. Cloud Sync

If you use Cloud Sync, your watch progress and favourites are stored on Supabase servers so they follow you between devices. This is deliberately limited to opaque identifiers:

  • Watch progress: the numeric stream, series, season and episode identifiers used by your provider, plus your playback position and the item's duration.
  • Favourites: the numeric identifier and type (live, movie or series) of each item you favourite.

These identifiers are meaningful only against your own IPTV service. We do not store the titles of what you watch, artwork, or your provider's address, so the sync records do not tell us what you watched. Your device re-attaches titles and posters locally from your own provider's catalogue.

4. What stays on your device

The following stays on your device by default and, except for the one optional Pro feature described in the box below, is never transmitted to us:

  • IPTV credentials (server address, username, password), encrypted at rest: on Android via EncryptedSharedPreferences (AES-256, backed by the Android Keystore) and excluded from cloud backup and device transfer; on iOS via the iOS Keychain; on macOS via Apple's safeStorage API, backed by the macOS Keychain.
  • Saved server addresses you add.
  • Your catalogue cache, watch history and favourites in a local database, including the titles and artwork Cloud Sync never receives.
  • Downloaded files, which come solely from your own IPTV service.
  • App settings.

Optional: saving a server to your account (Basis Pro). By default, nothing about your IPTV service leaves your device. Basis Pro adds one optional feature for people who use Basis on more than one device: for a server you choose, Basis can keep a copy of that login in your account so you do not have to re-enter it by hand.

  • It is off until you turn it on, and you turn it on for one server at a time, not once for everything.
  • It is encrypted before it is stored, with a key held separately in our server-side vault rather than in the database next to the data. This covers the whole login, including a playlist or TV-guide address, since those can carry credentials of their own.
  • Only your account can retrieve it. Access is scoped to your signed-in user, so no other account can reach it, and it is never displayed to anyone else.
  • It is used for one thing only: signing you back in to the server you saved. It is not analysed, not shared, and not sent to any third party.
  • You can delete it whenever you want, from the app or by contacting us. Deleting your account removes it too.

If you never enable this, your credentials stay only on your device as described above.

5. Connections to your IPTV service

Basis connects directly to the third-party IPTV service you configure, sending your credentials only to the server you entered, in order to authenticate and stream what you request. That service is operated by a third party we do not control, do not endorse and have no affiliation with; its handling of your data is governed by its privacy policy, not this one. Posters, logos and backdrops are loaded from URLs your service supplies. We do not select those hosts and receive no information about those requests.

5a. Cinemeta (metadata)

On Android and iOS, to label and group titles it finds in your provider's catalogue, the app requests general catalogue data from Cinemeta, a public metadata service run by the Stremio project. As with any request to any website, Cinemeta sees your device's IP address.

The requests are for fixed, general catalogues. They carry no search term, no title, no identifier of yours and no information about your provider; nothing about what you personally watch or search for is sent. Matching happens on your device, against the catalogue your own provider returned, and results are cached locally so the same request is not repeated. The macOS app does not use Cinemeta at all.

6. Purchases

Basis Pro is sold from our website. The checkout page states what you are buying, the price and the billing terms before you pay.

Payment is taken on basisiptv.com and processed by Razorpay, acting as our payment processor. Your card details are entered on Razorpay's own hosted form and are never sent to us or stored by us. Razorpay returns to us only the outcome of the payment: an order reference, a payment reference, the amount, the currency and the type of instrument used. Razorpay processes your payment information under its own privacy policy.

We use that record to unlock Pro on your account, to restore it when you sign in on another device, and to match a refund or a dispute back to a purchase. We keep it for as long as your account exists. Deleting your account deletes our copy; Razorpay keeps its own record under its own policy.

Subscriptions

Basis Pro can be bought outright or as a monthly or yearly subscription. If you subscribe, you authorise Razorpay to charge your card automatically at the end of each billing period. We store the subscription reference, the plan, the amount and currency, the current billing period and the date of the next charge, so that your account can show you what you are paying and when. We never receive or store your card number.

You can cancel at any time from your account page or from the app. Cancelling stops the next charge; it does not end the period you have already paid for, and we do not take Pro away early.

Free trials

A free trial requires a card up front. Your card is authorised at the start of the trial but is not charged until the trial ends, and cancelling before then means you are never charged at all.

To keep a trial to one per person, we store a one-way cryptographic hash derived from your card's type, issuer, last four digits and expiry date, combined with a secret key that is not stored in the same place as the hash. We do not store your card number, and the hash cannot be turned back into your card details. It records only that a card has used its trial. See the deletion section below for how this interacts with account deletion.

6a. Who processes your data for us

These are the companies that handle your data on our behalf, and what reaches each of them:

  • Supabase, our backend. Stores your account, your saved settings and your encrypted provider logins.
  • Razorpay, our payment processor. Handles payment and returns the outcome to us.
  • Resend, our email provider. Sends account emails such as your sign-in confirmation code.
  • Google Firebase, for crash reports and app analytics, and only after you accept in the app.
  • OpenAI, for Basis AI search. Receives the sentence you type into search. It is not sent your name, your email or your account id.
  • Telegram, which carries an internal alert to our own operator when a payment completes. That alert names the buyer's email address.

7. Legal basis and data security

Where the GDPR or UK GDPR applies:

  • Account data is processed to perform our contract with you, namely providing the account and sync features you requested.
  • Your acceptance of the terms is processed on the basis of our legitimate interest in keeping a record that our terms were agreed to.
  • Diagnostics and analytics (Section 1a) are processed on the basis of your consent, which you give by accepting the in-app Terms of Use and may withdraw at any time using the switch in Settings, Privacy. Withdrawing affects future collection, not data already recorded.
  • A login you save to your account (Section 4) is processed on the basis of your consent, given per server when you enable the option.

Account data is transmitted over HTTPS and protected by row-level security scoped to your account, so one account cannot read another's data. Local credentials are encrypted by the platform keystore as described in Section 4. Any credentials you opt in to save to your account (Section 4) are encrypted with a key held in our server-side vault before they are stored. To be precise about the limit of that: the key lives on our servers, so it protects the stored data, and it is not end-to-end or "zero-knowledge" encryption.

Connections to your IPTV service use whatever that service supports, which for many IPTV panels is plain HTTP on a custom port. We allow that because refusing it would make the app unusable with a large share of real providers, but it means traffic between your device and your provider may not be encrypted. That is a property of the service you choose, not something Basis can change.

8. Retention, your rights and deletion

We keep your account data until you delete your account. Signing out removes your stored IPTV credentials from the device immediately.

You can permanently delete your account and all associated data directly in the app: open Settings → Account → Delete account and confirm. Deletion is immediate and removes your account, watch progress, favorites and any cloud-saved playlists. If you no longer have the app installed, submit a request through our contact form, giving the email address your account uses, and we will delete the account for you.

Deleting your account also removes any waitlist entry made with that email address, and strips your email address from any feature request you posted publicly. The post itself remains, with nothing attached to it that identifies you.

One thing is deliberately not removed: if you have used a free trial, the one-way hash described in section 4.

The trial hash is kept deliberately, and we would rather say so plainly than leave it unstated: if it were deleted with your account, anyone could delete and re-create an account to take an unlimited number of free trials. When you delete your account the link between that hash and you is severed, so what remains is not connected to you, to your name or to your email address. It is not your card number, it cannot be turned back into your card details, and it is used for nothing other than deciding whether a card has already had a trial.

Diagnostics already sent to Google are held under Google's own retention schedule, and payment records held by our payment processor are retained under its own policy and under financial regulation. Neither is ours to remove.

A full account of what is deleted, what is kept and how to request deletion without the app installed is on the Delete your account page.

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with your data protection authority. To exercise any of these, submit a request through our contact form. We will honour requests as required by applicable law.

9. International transfers

Our backend provider Supabase stores data in the region configured for our project. If you are located outside that region, your data will be transferred and processed there (United States).

10. Children's privacy

Basis is not directed to children under 13, or the equivalent age in your jurisdiction, and we do not knowingly collect their personal information.

11. The Basis website

This section covers our marketing website only. The app's own diagnostics and analytics are separate, use different tooling, and are described in Section 1a.

If you accept when the cookie banner asks, the website loads Google Analytics 4 (Google Ireland Limited / Google LLC, acting as our processor). If you decline, or ignore the banner, the tool is never loaded and no analytics cookie is written. Your choice is remembered in your browser's local storage, and you can change it any time with the Cookie settings link in the footer.

When accepted, Google Analytics sets first-party cookies (_ga and _ga_*) and records:

  • Pages you view on the Basis website, and how far you scroll.
  • Download clicks, including which build you chose: platform (macOS or Android), version number, and which button on the page you used.
  • Device and browser type, operating system, screen size and language.
  • Approximate location (city or region level) derived from your IP address. Google does not log the full IP address for Analytics.
  • How you arrived: the referring site or campaign link.

We use this only to count downloads and understand which parts of the page are useful. We do not upload it to advertising products: Google Signals and ads personalisation are switched off, we run no advertising or remarketing tags, and nothing here is combined with your Basis account. We do not attempt to identify you personally from it. Data is retained for 14 months and then deleted automatically. Google may process it in the United States under the European Commission's Standard Contractual Clauses.

Our legal basis is your consent, which you may withdraw at any time. Withdrawing affects future collection, not data already recorded. Links we set to auth-related pages are stripped of any one-time codes before a page address is reported, so verification links from your email are never sent to Google.

Some things load regardless of your analytics choice, because the page cannot be built or served without them. Each necessarily sees your IP address in order to answer:

  • Google Fonts and Cloudflare, for fonts and icons.
  • jsDelivr, for the code that talks to our backend.
  • Supabase, our backend, which the page queries to show the current download builds and the public feature-request board.
  • Vercel Web Analytics, run by our hosting provider. It counts page views and does not use cookies or build a profile of you across sites.

None of these is used for advertising, and none is combined with your Basis account.

12. Changes and contact

We may update this policy. The current version is always posted at basisiptv.com/legal/privacy with the "Last updated" date above.

Sound Enterprises Pvt. Ltd.

Email: support@basisiptv.com

Or use the contact form.