Privacy Policy
This is a courtesy translation. The German version at /datenschutz/ is legally authoritative to the extent permitted by the mandatory consumer-protection and data-protection law of your country of habitual residence. This policy applies to the website qoraplayer.com and to the QORA app (Android, Android TV, Google TV, Fire TV; Windows and Apple to follow).
1. Controller
Dominique Feld Jolie Webdesign An der Schule 20 54296 Trier, Germany Email for privacy requests: privacy@qoraplayer.com
2. Overview: what QORA processes, and what it does not
QORA does not supply any television, film, or series content itself. You enter the access credentials of your own provider (Xtream Codes or M3U link). These credentials belong to your contractual relationship with your provider, not with us; we process them purely technically so the app can play your programming.
Without an account (free use): access credentials, favourites, progress, and parental controls stay exclusively on your device, encrypted in the Android Keystore (AES-256-GCM). Nothing is transmitted to our servers.
With an account (QORA Plus / QORA Ultra): for cross-device sync we additionally process the data listed in section 5 via Google Firebase.
The website itself is static, sets no cookies, uses no tracking, and self-hosts its font without contacting a third-party font server.
3. What we process, and why
3.1 Visiting the website
When you visit the website, our host, united domains GmbH (Germany), technically processes standard server access data (IP address, date and time of access, page requested, user agent) to deliver the website and maintain operational security. Legal basis: our legitimate interest in a secure, functioning website (Art. 6(1)(f) GDPR).
[TO CHECK: exact retention period of server access logs at united domains; not yet confirmed against a hosting contract or data-processing agreement excerpt. Do not publish a specific retention period until confirmed with the host.]
3.2 Registration and sign-in (QORA Plus / QORA Ultra)
When you create an account, we process either your Google-provided identifier (Firebase UID, email address if provided by Google) for Google sign-in, or your email address and password (stored encrypted) for email sign-in. Legal basis: performance of the usage contract (Art. 6(1)(b) GDPR).
3.3 Cross-device sync (core feature of QORA Plus / QORA Ultra)
To keep your progress, favourites, and playlists consistent across devices, we store in your account: the names of your playlists and devices; progress and favourites per list and device; your provider's access credentials in a client-side encrypted block; the key belonging to that encrypted block (since version 0.9.70/0.9.71); and playback logs per device (channel names watched, timestamps, technical metrics such as buffering and error events: never credentials or location data) if you send your report to support for review.
Important transparency notice on encryption (please read in full): Your provider's credentials are encrypted on your device before transmission. Up to version 0.9.69, the key required to decrypt them existed only on your devices and was transferred solely through an end-to-end encrypted device-pairing process (QR code); mere read access to our database would not, under that model, have been enough to obtain your credentials in plain text. Since version 0.9.70/0.9.71, that key itself is additionally stored, also in your account, in the same database as the credentials it encrypts, so that a new device can take it over automatically without you re-entering or re-pairing it.
In practical terms: the encryption still effectively protects against eavesdropping on the transmission and against a misconfigured access rule. It no longer protects against someone with genuine, authorised read access to the database itself, for example through the Firebase console, an administrative interface, or a data export. Such access is technically available to us as the controller, even though it is not intended to be exercised. We are therefore not a "zero-knowledge" service with respect to your provider's credentials. We do not access this data in normal operation, but the technical possibility exists, and you should know this before using cross-device sync.
Legal basis: performance of the usage contract for your booked plan (Art. 6(1)(b) GDPR).
3.4 Stutter analysis (QORA Ultra only)
If you send us your playback report as part of the stutter analysis, we evaluate it to give you an assessment of the likely cause within the promised timeframe. Legal basis: performance of the usage contract (Art. 6(1)(b) GDPR).
3.5 Support communication
If you contact us via WhatsApp or email, we process your message and the contact data needed to handle your request. WhatsApp is operated by WhatsApp Ireland Limited and/or Meta Platforms Ireland Limited; processing of your message outside the EU cannot be excluded. If you want a reply processed exclusively within the EU, please write to support@qoraplayer.com instead. Legal basis: performance or pre-contractual measures, or legitimate interest in handling your request (Art. 6(1)(b), (f) GDPR).
3.6 Payment processing
Purchases of QORA Plus and QORA Ultra are processed through the respective app store (currently Google Play, Apple App Store to follow). Payment data (e.g. card details) is handled exclusively by the store and is never disclosed to us; we only receive confirmation that a purchase or renewal occurred, plus a pseudonymous purchase identifier. The store's own privacy notices apply to that processing, which is outside our control.
4. Recipients and processors
| Recipient | Purpose | Location / region of processing | |---|---|---| | Google Ireland Limited (Firebase Authentication, Cloud Firestore) | Sign-in, cross-device sync, account data storage | Database region europe-west3 (Frankfurt am Main); Google group also based in the USA | | Google Ireland Limited / Google LLC (Google Play, Google Play Billing) | App distribution, subscription payment processing | EU/USA, see Google's own privacy notices | | united domains GmbH | Website hosting, domain and email mailbox | Germany | | WhatsApp Ireland Limited / Meta Platforms Ireland Limited | Support communication, if you contact us via WhatsApp | EU, with possible processing within the Meta group outside the EU |
A data-processing agreement with Google exists based on the Google Cloud/Firebase data processing terms. [TO CHECK: confirm conclusion and current version of this data-processing agreement for Firebase project qora-dac08 before publishing this policy, with the confirmation date added here; without a confirmed agreement, outsourcing to Google is not properly secured under data-protection law.]
5. International data transfers
Google is a company also based in the USA. Even though your account data is stored in the Frankfurt region (europe-west3), processing by Google entities outside the EU cannot be fully excluded in the context of maintenance, support, or intra-group access. Google LLC states it is certified under the EU-US Data Privacy Framework (DPF), which the European Commission recognised as providing an adequate level of protection by adequacy decision of 10 July 2023. [TO CHECK: current DPF certification status of Google LLC at time of publication, since certifications are time-limited and must be renewed annually; verify on privacy.google.com or dataprivacyframework.gov before going live.] Additionally or alternatively, transfers rely on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, to the extent Google offers these in the relevant processing relationship.
6. Retention periods
- Account data and cross-device sync: for as long as your account exists. Deleted upon account deletion, see section 8.
- Playback logs: until your support request has been resolved, then deleted. [TO CHECK: a fixed deletion period for logs not submitted for review within a defined time has not yet been technically implemented; set a concrete period before going live, e.g. automatic deletion after 90 days without a support case, and update this policy accordingly.]
- Website server access logs: see section 3.1.
- Data stored locally on your device (free use, or in addition to your account): until you uninstall the app or delete it in settings.
7. Your rights
Under the GDPR you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and withdrawal of any consent given, with future effect (Art. 7(3)). To exercise these rights, email privacy@qoraplayer.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for Dominique Feld, based in Rhineland-Palatinate, is:
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz Hintere Bleiche 34, 55116 Mainz, Germany
If you habitually reside in France, Belgium, or Luxembourg, you may instead contact the supervisory authority there (in France the CNIL, in Belgium the Data Protection Authority / Autorité de protection des données, in Luxembourg the CNPD).
8. Account deletion
You can delete your account and the associated data at any time: via the website at /en/delete-account/, or directly in the app, in account settings.
Deletion removes your account data, your cross-device sync state, and your stored provider credentials from our systems. [TO CHECK: confirm the concrete technical deletion timeframe after deletion is triggered (immediate or batch job) and whether backup copies at Google/Firebase are subject to their own, shorter retention period; confirm before going live and state it concretely here, otherwise this commitment is unprovable in a dispute.]
9. No automated individual decision-making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR, that produces legal effects concerning you or similarly significantly affects you.
10. Changes to this policy
We update this policy when our data processing changes. The version published at the time of your website or app visit governs.
Legal note
This draft has undergone internal legal hardening and does not replace sign-off by a licensed attorney. Final legal responsibility rests with the reviewing attorney before publication. Points marked [TO CHECK] must be resolved before going live.