Legal

Privacy

Last updated: 2026-08-05.

The short version

Sipario has no user accounts, advertising, tracking cookies, or playback telemetry. App settings, source credentials, and viewing history stay in each app’s local storage unless you explicitly use encrypted pairing or library sync.

Data kept by the apps

The native apps store the sources you configure, provider credentials, preferences, favorites, and playback progress on your device. They contact the providers and media hosts you choose, so those providers receive normal request data such as your IP address and the resource requested. Sipario does not receive those media requests.

Platform backup, Keychain, and app-container behavior is controlled by macOS, Android TV, Windows, and tvOS. Remove data with the app’s reset/remove-source controls or by uninstalling the app.

Encrypted pairing and sync

Pairing stores a hashed bucket identifier and end-to-end encrypted setup payload for up to 10 minutes. A successful read deletes the payload. The pairing code and encryption key never reach the relay.

Optional library sync stores one end-to-end encrypted document under a hashed 256-bit sync identifier. Its sliding retention period is 90 days. The relay can see the bucket hash, ciphertext size, timing, and ordinary network metadata, but cannot decrypt the document.

Website visits and downloads

The public website records aggregate page views without cookies. It derives a salted, truncated SHA-256 value from IP address and user agent; the unique-visitor marker expires after 30 days. Raw IP addresses are not stored by this counter.

App-download links similarly keep a salted, truncated fingerprint, first/last download times, repeat count, platform, and Cloudflare country code for up to 180 days. Bots and common monitoring tools are excluded. Aggregate totals may be retained longer.

Android TV beta signup

If you join the beta, Sipario stores the email address and any name, device, notes, or source label you submit, plus submission dates and user agent. The list is used only to operate the beta and is protected by an administrator token. It is retained while the beta is active or until you request removal.

Metadata services

Sipario uses TMDB for title metadata and Rotten Tomatoes pages for rating consensus. Apple TV may contact Cinemeta for catalog/search data and OpenSubtitles for subtitle candidates. These services receive the requested search terms or title identifiers and ordinary network metadata under their own privacy policies.

Downloads are hosted by GitHub Releases. Cloudflare serves sipario.tv and its encrypted relays; both providers process standard web-request metadata as infrastructure operators.

What Sipario does not collect

  • Media bytes, stream URLs, or a server-side viewing history.
  • Source credentials in plaintext.
  • Advertising identifiers or cross-site profiles.
  • Microphone, camera, or precise location data.

Deleting data

Reset or uninstall an app to remove its local data. To leave the beta list or ask about aggregate website records, use the contact listed on the DMCA / takedown page. Pairing payloads expire automatically; stopping sync and waiting 90 days expires its relay document.

Changes

Material changes to these data flows will be reflected here before or with the corresponding release.