This Privacy Policy explains how Kaydees Labs ("we", "us")
handles information in connection with the KayCast Android application
(package com.kaycast.player, the "App"). By using the App you agree to the practices
described here.
KayCast is a media player only. It ships with no channels, streams, or other media content. You supply your own local files and your own playlists (IPTV / Xtream / M3U / direct URLs). Because of this, most of your activity in the App stays on your device.
Playlists and source configurations, saved credentials (encrypted), favourites, profiles, watch history, playback progress, and app settings are stored locally on your device. Your playlist URLs and source credentials are never uploaded to us.
The free version of the App displays ads served by Google AdMob. AdMob collects and processes your device's Advertising ID, IP address, and technical/usage data (such as ad interactions) to serve, cap, and measure advertisements. This data is shared with Google as an advertising partner.
When you play a stream or file, the App connects directly to the source you configured — your IPTV/Xtream/M3U provider or a direct URL, or a network share on your own network (an SMB/NAS or WebDAV server) that you added. Your playback requests, and any credentials that source requires, are sent to that server. Network-share credentials are stored encrypted on your device and are used only to open the connection you asked for. Those servers are operated by third parties (or are your own equipment) outside our control, and their handling of your data is governed by their policies, not ours.
Subscriptions are processed by Google Play Billing. We do not receive your name, email, or payment card details. To activate a subscription and prevent fraud/abuse, the App uses Google Play Integrity, which produces a device attestation and a randomly generated, per-install identifier. We store your subscription status (e.g. free / active tier) to unlock paid features.
The App signs you in to Google Firebase with an anonymous, randomly generated identifier. We do not attach your name or email to it. Under this identifier we store your subscription status (entitlement) so your paid features unlock across reinstalls and devices. This anonymous sign-in happens automatically; there is no name/email login. You can request deletion at any time (section 5).
Backup & Restore is separate and local. It exports and imports a file on your device (your app data and, optionally, your music playlists); nothing is sent to us or anyone else, and source credentials are never included in a backup file.
If you use the online subtitle search feature, your search query is sent to the OpenSubtitles service to return matching subtitle files. This happens only when you actively search for subtitles.
If you turn on online lyrics, the current song's title, artist, album and duration are sent to LRCLIB (lrclib.net), a free, community-run lyrics service, to find matching (time-synced) lyrics. This happens only when you tap “Search online”, and the feature is off by default. Downloaded lyrics are cached on your device so the song shows them offline next time.
The App includes a Bluetooth autoplay control that can stop unwanted automatic playback when a Bluetooth device (such as a car stereo or a headset) connects. To do this it uses the Bluetooth permission to recognise the connecting device so it can apply your allow/block choice for it. Your per-device choices are stored only on your device — no Bluetooth information is uploaded to us or shared with anyone.
The App can transfer a saved source — including its server address, username and password — from your phone to the KayCast app on your TV, so you do not have to type it with a remote. This transfer happens directly between your two devices over your own local network. The details are encrypted in transit with a key the two devices agree between themselves for that single transfer, and are confirmed with a code shown on the TV. Nothing about the source is sent to us, to Firebase, or to any third party: there is no server in the middle, and we keep no record of the transfer. Your credentials never leave your local network.
Search offers a microphone button on both phone and TV. Tapping it hands over to your device's own speech recognition service — normally the Google app — which listens, converts what you say to text, and returns only that text to KayCast, which puts it in the search box. The App requests no microphone permission and never records, stores or transmits audio itself: the recording happens inside the recognition service, under that service's own privacy policy, not ours. The microphone button is shown only if such a service is installed, and nothing happens until you press it. We receive the transcribed text and use it only to run your search; the search terms are not sent to us or to any third party.
Settings offers Send feedback and a Full diagnostics report. The report is assembled on your device and describes the device and the App — app version and package, where it was installed from, install and update dates, Android version, device model and build, processor architecture, screen size, font scale, language, time zone, notification and battery-optimisation status, memory and free storage, plus a list of recent app-start times. It contains no playlists, no source credentials, no viewing history and nothing that identifies you personally.
None of this report leaves your device unless you choose to send it. Nothing here is uploaded automatically — see section 2.14 for the separate, automatic crash-report channel. When you tap Email report, Share report or Send feedback, your device's own email or sharing app opens with the text already filled in — you can read and edit it, choose whether to send it, and cancel at any point. If you do send it, we receive it as an ordinary email and use it only to investigate the problem you are reporting. The App also keeps a local activity log in its own storage folder on your device, which you can clear at any time from Settings → Diagnostics & logs; that log is never uploaded on its own.
Guest Pass lets a Pro subscriber share one live stream or movie with someone else for a few hours, using a code, a QR image, or a link — without that person signing in or browsing the rest of your library. What we store to make this work is a code you choose to share and, on our server, an encrypted, unreadable copy of the stream link (readable only by whoever has that code), the item's title, and an expiry time — never a plain-text link, username or password. The link is decrypted only on the recipient's own device, using the code; we never see the decrypted content ourselves. Each code works for one redemption only, and sharing is limited to a set number of passes per month.
One thing worth knowing if you share: once decrypted, the stream link is in your IPTV provider's own format, which — like most IPTV services — embeds your provider account's username and password inside the link itself. This is a property of how your provider's streaming technology works, not something the App or we control or can change. In practice this means whoever redeems your code could, with technical effort, recover your provider login from it. The App shows a plain warning about this every time you share, and we recommend the same here: only share a Guest Pass with someone you trust, the same as you would a password. If you ever suspect a shared code was misused, the pass expiring on its own does not change your provider password — you would need to change that directly with your IPTV provider.
The App does not request or use the camera permission and never accesses your camera. A Guest Pass QR code can be scanned with your device's own camera app, which opens the App through a link; the App itself never sees the camera image. You can also type the code in by hand.
If the App crashes or encounters certain errors, it automatically sends a crash report to Google Firebase Crashlytics — unlike every other item in section 2, this happens without you taking any action. The report contains technical information only: what code was running when the problem happened, the type of error, and device/app information similar to section 2.11 (app version, Android version, device model, and similar). It contains no playlists, no source credentials, no viewing history and nothing that identifies you personally. This is separate from the Diagnostics report and Send feedback described in section 2.11, which are never sent without you choosing to send them.
If your provider supplies a trailer for a movie and you tap “Watch trailer”, the App opens that trailer in the YouTube app or your web browser, like tapping any YouTube link. The App itself sends nothing to Google when you do this; once YouTube opens, your use of it is governed by Google's Privacy Policy. This only happens when you tap to watch a trailer, and no video is ever extracted or downloaded by the App.
If your provider supplies no trailer for a movie, the App instead offers “Search trailer on YouTube”. Tapping it opens a YouTube search for that movie's title (plus the word “trailer”) in the YouTube app or your browser. The title is placed in that link, so YouTube receives it when the link opens; the App itself makes no request to Google and sends nothing else.
If you cast, the App sends the address of the stream you are watching to the device you choose, and that device then fetches the stream itself from your source. For IPTV providers that address can contain your provider account's username and password, so cast only to devices you own or trust. Casting to a Chromecast or Google Cast device uses Google's Cast technology in Google Play services (under Google's own privacy policy); casting to a DLNA/UPnP TV or speaker happens directly over your local network. Nothing is sent to us.
| Purpose | Data involved |
|---|---|
| App functionality (play your media, remember your setup) | Local playlists, credentials, settings, watch history |
| Advertising (free tier) | Advertising ID, IP address, technical/usage data (via AdMob) |
| Payments & subscription management | Subscription status, purchase tokens (via Google Play) |
| Fraud prevention / security | Play Integrity attestation, per-install random identifier |
| Anonymous account & entitlement | Anonymous Firebase ID + subscription status (via Firebase) |
| Optional subtitle search | Subtitle search query (via OpenSubtitles) |
| Optional online lyrics | Song title, artist, album, duration (via LRCLIB) |
| Bluetooth playback control | Connecting device identity + your per-device choice (on-device only) |
| Guest Pass sharing (Pro, optional) | Encrypted stream link, item title, expiry time, your anonymous Firebase ID (via Firebase) — never a readable link, username or password |
| Crash/error reporting (automatic) | Crash report technical details, app/device info (via Google Firebase Crashlytics) |
| Casting (optional) | Stream address sent to the device you choose; nothing sent to us |
| Movie trailers (optional) | None sent by the App — tapping “Watch trailer” or “Search trailer on YouTube” opens the YouTube app or your browser (a search includes the movie title in the link) |
We do not sell personal data. We share data only with the service providers needed to run the features above:
Where the EU/UK GDPR applies, we rely on the following legal bases:
Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to:
Because we identify you only by an anonymous, per-install identifier and do not hold your name or email, we may ask you to provide that identifier (shown in Settings → About → Device ID) so we can locate your data. To exercise any right, contact us (section 11). We do not sell your personal data. EEA/UK users also have the right to lodge a complaint with their local data-protection supervisory authority.
The service providers we use (Google, OpenSubtitles, LRCLIB) may process data on servers located outside your country, including in the United States. Where required, these transfers are covered by appropriate safeguards such as the providers' Standard Contractual Clauses or equivalent mechanisms. This policy is governed by the laws of India, without prejudice to any mandatory consumer-protection or data-protection rights you have under your local law.
KayCast is a general-purpose media player intended for a general audience aged 13 and over. It is not directed at children under 13, and we do not knowingly collect personal data from children under 13. The optional "Kids Mode" is a parent-controlled, PIN-locked viewing filter for content the account holder has added; it does not change the data practices described here.
Source credentials (including network-share logins) are encrypted on-device using the Android Keystore.
Data transmitted to Google, OpenSubtitles and LRCLIB is sent over encrypted (HTTPS) connections. Note that
some sources you add — certain IPTV feeds, or a WebDAV server configured over plain http —
may be unencrypted; the security of your connection to those third-party servers is determined by the
provider you chose, not by us.
For privacy questions or deletion requests, contact us at kaydeeslabs@gmail.com.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through an in-app notice.