This Privacy Policy explains what information Mosaic IPTV (the "App") and its publisher (the "Publisher") collect, why, what your rights are, and how to contact us.
Data controller
The data controller for personal data processed in connection with the App is SoFloWare LLC ("SoFloWare"), a Wyoming limited liability company (the "Publisher"), with a mailing address at 30 N Gould St Ste R, Sheridan, WY 82801, USA, in Wyoming, United States.
General contact: info@sofloware.com.
EU and UK representatives (Article 27)
The App collects no personal data from users (see "What we collect" below). Because the Publisher does not process personal data of data subjects in the European Union or the United Kingdom through the App — beyond occasional, low-risk processing such as responding to legal correspondence — the Publisher has not designated a representative under Article 27 of Regulation (EU) 2016/679 ("GDPR") or under Article 27 of the UK GDPR, relying on the exemption in Article 27(2).
For any data-protection matter, including anything you would otherwise raise with an Article 27 representative, contact the Publisher directly at info@sofloware.com.
What we collect
The App collects no personal data and sends nothing about you to the Publisher. There is no user account, no login, no license server, no activation backend, no advertising SDK, no analytics SDK, no crash-reporting service, and no usage telemetry. The App runs entirely on your device.
The Publisher operates no license server, activation backend, or account system. Purchase and entitlement are handled entirely by the Microsoft Store; the Publisher receives only the aggregate sales and diagnostic data Microsoft exposes in Partner Center, which does not identify individual customers.
If a future release adds an optional diagnostics feature (such as opt-in crash reporting or anonymous usage statistics), it will be off by default, will request your explicit consent before anything is sent, and this Privacy Policy will be updated to describe what is collected, the processor used, the retention period, and the legal basis — before the feature is enabled.
What we do not collect
We do not collect, transmit, or store any information about the streaming URLs, channel names, provider credentials, EPG sources, watch history, or content you play within Mosaic IPTV. This information remains local to your device, with one exception you control: if you enable the optional sync feature described below, the sync-eligible items are also written to a folder you choose. The Publisher never receives that data either way.
Because we collect no information about what you watch or which services you use, we cannot — even when compelled by legal process — disclose your viewing habits, playlist contents, or service subscriptions to third parties.
Sync between devices
Mosaic IPTV includes an optional sync feature, off by default. When you enable it, the App writes the following items as plain-text files into a single folder you choose: your playlist sources including provider credentials and EPG source URLs, favorites, category customizations (pinned, locked, hidden, and deleted groups, and custom group order), smart lists, per-channel audio/video sync offsets, and a small set of app settings (playback, appearance, auto-refresh intervals, and parental-control settings — the parental PIN is stored and synced only as a salted hash, never in plaintext). Watch history, watch progress, and recordings are never synced.
The App itself uploads nothing: it only reads and writes files in the folder you picked. If that folder is managed by a third-party file-synchronization service (for example OneDrive, Dropbox, or a network share), that service's own software may copy the files to its servers under that service's own terms, exactly as it does with any other file in the folder. Provider credentials in the sync files are stored in plain text — the folder you choose is the security boundary, so choose a location you trust. The App shows a warning to this effect when you enable the feature. You can turn sync off at any time from Settings → Sync; doing so stops further writes but does not delete files already in the folder — delete them yourself if you no longer want them there.
Legal bases for processing (GDPR Article 6)
The App does not process personal data on the Publisher's behalf, so no GDPR legal basis is engaged for in-app processing. The limited processing that does occur:
- Microsoft Store purchase processing → Contract (Art. 6(1)(b)) between you and Microsoft; the Publisher is not the controller for this processing.
- Responding to legal process or rights-holder notices → Legal obligation (Art. 6(1)(c)) and the Publisher's legitimate interests in establishing or defending legal claims (Art. 6(1)(f)).
- Any optional diagnostics added in a future release → Consent (Art. 6(1)(a)), requested before the feature is enabled and withdrawable at any time.
Withdrawing any consent you give does not affect the lawfulness of processing carried out before withdrawal.
Retention
- Microsoft Store sales data: retained by Microsoft according to Microsoft's own data-retention policies.
- App-local data on your device: retained until you delete it (Settings → Database → Reset database) or uninstall the App.
- Sync files in your chosen sync folder (only if you enabled the sync feature): retained until you delete them. Disabling sync or uninstalling the App does not delete files already written to that folder.
The Publisher does not itself retain any personal data about you, because it collects none through the App.
Where data lives and international transfers
- App-local data (watch history and progress, image cache, recordings, and — unless you enable the sync feature — playlists, credentials, and settings): stored on your device only, under your Windows user profile. Not transmitted to the Publisher or to any third party.
- Sync data (only if you enable the sync feature): the sync-eligible items described under "Sync between devices" above are additionally written to the folder you chose. If that folder is managed by a third-party file-synchronization service, that service transfers the folder's contents under its own terms and, depending on the service, possibly across borders. The Publisher is not involved in and receives nothing from that transfer.
- iptv-org logo CDN: when the channel-logo backfill feature fetches a public channel logo for one of your channels, the App makes an anonymous HTTP request to the iptv-org GitHub-hosted CDN. The CDN operator (GitHub Pages / Fastly) sees the requesting IP address and the request URL, but receives no identifying information from the App. This is the unavoidable minimum disclosure required to fetch a public web resource.
The Publisher makes no other automated transfer of your data, inside or outside the EU or UK.
Data security
The App stores its data locally under your Windows user profile and relies on the operating system's user-account isolation and any device encryption you have enabled (for example, BitLocker). Locally-stored secrets are protected in line with their sensitivity — for example, the optional parental-control PIN is stored only as a PBKDF2-SHA256 hash, never in plaintext. Because the Publisher collects no personal data through the App, there is no server-side store of your personal data to secure.
Data breach notification
In the event of a personal data breach affecting personal data for which the Publisher is the controller, the Publisher will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, the Publisher will also notify affected users without undue delay, as required by GDPR Article 34. As described above, the App transmits no personal data to the Publisher, which substantially limits the scope of any such breach.
Your rights (EU GDPR and UK GDPR)
You have the right to:
- Access the personal data the Publisher holds about you (Art. 15);
- Rectify inaccurate personal data (Art. 16);
- Erase your personal data, the "right to be forgotten" (Art. 17);
- Restrict processing in certain circumstances (Art. 18);
- Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller — data portability (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Withdraw consent at any time, without affecting prior processing (Art. 7(3));
- Lodge a complaint with a supervisory authority. For EU users, the supervisory authority is the data-protection authority of your country of habitual residence. For UK users, the supervisory authority is the Information Commissioner's Office (ico.org.uk).
To exercise these rights, email info@sofloware.com. The Publisher will respond within one month, as required by GDPR Article 12(3).
For data that lives only on your device (playlists, watch progress, image cache, recordings), you can clear it yourself from Settings → Database → Reset database, without contacting the Publisher.
Your rights (California — CCPA / CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), California residents have the following rights:
- Right to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties with which it is shared.
- Right to delete personal information.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. The Publisher does not sell or share personal information for cross-context behavioral advertising; there is no opt-out for sale or sharing to exercise because no sale or sharing occurs.
- Right to limit use of sensitive personal information. The Publisher does not use sensitive personal information for purposes that trigger this right.
- Right to non-discrimination for exercising any CCPA/CPRA right.
In the twelve months preceding the date of this Privacy Policy, the Publisher has not collected personal information from California residents through the App, has not sold or shared personal information, and has not disclosed personal information to any third party except as necessary to respond to legal process. The App contains no advertising or analytics SDK.
To exercise CCPA/CPRA rights, email info@sofloware.com with a description of the right you wish to exercise. The Publisher will verify your identity by a reasonable method and respond within the time periods required by California law (generally 45 days, extendable to 90 days where reasonably necessary).
Your rights (other U.S. states)
Residents of Colorado, Connecticut, Florida, Montana, Oregon, Texas, Utah, and Virginia have rights under their respective comprehensive privacy laws (CPA, CTDPA, FDBR, MCDPA, OCPA, TDPSA, UCPA, VCDPA) that broadly parallel the CCPA rights above — access, deletion, correction, portability, opt-out of certain processing, non-discrimination. The Publisher honors valid requests from residents of these states on the same terms and through the same email address (info@sofloware.com).
Cookies and web tracking
The in-app experience uses no cookies and no web tracking. The App embeds no analytics SDK and no advertising SDK.
Children
The App is not directed at children under 13 (or under 16 in jurisdictions where that is the digital-consent age). A parental-control feature with PIN-protected category locking is included but is off by default. The Publisher does not knowingly collect personal data from children. If you believe a child has provided personal data through the App, contact info@sofloware.com and we will delete it.
Subprocessors
- Microsoft — Microsoft Store distribution, purchase processing, license enforcement, and the diagnostic data Microsoft itself collects under its own terms (independent of the Publisher).
The optional sync feature engages no subprocessor: the App only writes files to a local folder you choose. If you point that folder at a location managed by a third-party file-synchronization service (OneDrive, Dropbox, a NAS vendor's software, or similar), that provider processes the folder's contents under its own terms as a service you engaged directly — not as a processor acting on the Publisher's behalf.
The Publisher engages no other subprocessor for the App's operation. The App contacts the iptv-org public logo CDN (GitHub Pages) to fetch public channel logos, as described under "Where data lives and international transfers" above; that provider is a content-delivery source, not a processor of your personal data on the Publisher's behalf. If a new subprocessor is engaged, this section will be updated and renewed consent will be requested where applicable law requires it.
Marketing
The Publisher does not operate a marketing mailing list, send promotional emails, or run any digital marketing campaign that involves processing your personal data. You will not receive marketing email from the Publisher unless you have separately contacted the Publisher and the email is a direct response to your enquiry.
Updates to this Privacy Policy
The Publisher may revise this Privacy Policy. Material changes (defined in the End User License Agreement, Section 9.3) will be surfaced in the App and, where required by applicable law, will require renewed consent before processing under the revised terms begins. Non-material clarifications may be made without notice; the "Last updated" date at the top of this document will always reflect the most recent revision.
Questions: info@sofloware.com.