Privacy Policy for Illumi Player
Effective Date: 20th August 2026
Illumi Player ("we", "our", or "us") respects your privacy. This Privacy Policy explains what information we collect when you use Illumi Player, why we use it, who processes it, and the choices available to you.
1. Information We Collect
Account and personalisation data
We use Sign in with Apple to authenticate users. From this, we store only your Apple-provided user ID—a unique identifier that does not reveal your identity to us.
We do not collect your name, email address, or any other personal information from Apple.
This Apple user ID is used solely to:
- Store and sync your watchlist
- Provide you with personalised recommendations
Product analytics data
Product analytics are optional and off until you turn them on. The app shows a privacy notice offering “Allow analytics” and “Don't share”, and collects nothing until you choose. You can change your choice at any time in Settings → Privacy & Data. Your choice does not affect app features or your subscription. If we materially change what we collect or why, the notice is shown again and collection stops until you make a fresh choice.
When you allow analytics, we collect a defined set of events to understand how the service is used, improve its features, and diagnose reliability problems. The app can only send the events and properties listed here:
- Technical and contextual information, such as the date and time, platform, app version, build number, and pseudonymous installation, profile, session, event, and correlation identifiers
- Account context, including your Apple-provided user ID when signed in, whether the profile is the account's default or an additional household profile, and whether you hold a Pro membership
- App lifecycle activity, such as first launch, session start, sign-in, and sign-out
- Search activity, limited to how many results a search returned, whether it returned none, which filters were active, and the position and media type of a result you open. The search text itself is not included — it is replaced with “redacted” before the event leaves your device
- Playback activity, limited to whether the item is a film or a TV episode, its duration, playback progress or completion, which playback backend was used, and a limited failure code. Media titles and content identifiers are not included — they are replaced with “redacted” in the same way
- Diagnostic logs, drawn from a fixed list covering sign-in, media-server connectivity, search, playback, subscription entitlement, and analytics delivery. Each log carries only a severity, a fixed message key, and a short reason code such as “timeout” or “unauthorized”. Free-form text and raw error messages are not accepted, routine informational logs are sampled, and the number of logs a device can send each day is capped
We do not use analytics to record session replays, screenshots, the video or audio you stream, raw search text, media titles or content identifiers, genres, season or episode numbers, media-server usernames, media-server passwords, authentication tokens, private server URLs, or full network requests and responses.
Search service data
Searching is performed by our search service, so the text you type is sent to us in order to return results. When you have allowed analytics, that request also carries your pseudonymous account and profile identifiers, platform, app version, and membership status, and the search is recorded in our own search database so we can review searches that return no results and improve results. This record is separate from the analytics described above and is not sent to PostHog. When analytics are turned off, no attribution is attached to your searches.
Search text is free-form, so please do not enter personal, confidential, or sensitive information into the search field.
2. How We Use Your Information
We use your Apple user ID to:
- Identify your account securely
- Store and retrieve your media preferences (watchlist and recommendations)
Where you have allowed analytics, we use them to measure use of the app, understand search and playback behaviour at an aggregate level, improve features and recommendations, monitor performance, and investigate errors.
We process account data because it is necessary to provide the service you request. We process optional product analytics and diagnostic logs on the basis of your consent, which you give through the in-app notice and can withdraw at any time in Settings → Privacy & Data. Withdrawing consent does not affect processing carried out before you withdrew it. We process search requests as necessary to return the results you asked for.
We do not sell your information or use it for third-party advertising.
3. Analytics Provider and Data Location
We use PostHog as a data processor to store and analyse app analytics. Our PostHog project uses PostHog Cloud EU, hosted in Frankfurt, Germany. PostHog processes analytics on our instructions and under its data-protection terms. You can read more in the PostHog Privacy Policy. Access to identifiable analytics is restricted to authorised Illumi Player maintainers.
Analytics first pass through our own telemetry service, hosted on Amazon Web Services in London (eu-west-2), before being sent to PostHog. A smaller set of app-usage events is also handled by our existing API on Vercel and stored in our application database. Providers involved in delivering and securing those requests may process technical information such as your IP address. We do not receive or send your name or email address from Apple, and media-server usernames are never included in analytics.
Although our PostHog project is hosted in Germany, PostHog or its service providers may process information from other countries. Where required, transfers outside the UK or EEA are protected by recognised safeguards such as adequacy arrangements or approved contractual clauses.
4. Data Retention and Deletion
Product analytics events are normally retained in PostHog for up to one year, and diagnostic logs for around 14 days. Analytics awaiting delivery may be stored temporarily on your device; the queue is capped and records more than 24 hours old are discarded when the app next processes it. Turning analytics off in Settings deletes that queue and the stored analytics identity immediately, so nothing pending is sent. We may delete information sooner when it is no longer needed, and may retain limited information for longer where required by law or necessary to establish, exercise, or defend legal claims.
If you would like your account data, watchlist, recommendations, or associated analytics deleted, you can contact us at:
Please include your Apple user ID or Illumi Player profile identifier if available so that we can locate the relevant records. We may need to verify your identity before completing a request.
5. Your Privacy Rights
Depending on where you live, you may have rights to request access to, correction of, or deletion of your personal information; to restrict or object to its processing; and to receive a portable copy of information you provided. Where processing relies on consent, you may withdraw that consent at any time. You can exercise these rights by contacting us at the address above.
You can withdraw your consent to product analytics at any time by switching analytics off in Settings → Privacy & Data in the app. You also control your Apple login and can revoke access through your Apple ID settings at any time. If you are in the United Kingdom, you also have the right to complain to the Information Commissioner's Office. If you are in the EEA, you may complain to your local data-protection authority.
6. Security
We use reasonable technical and organisational measures designed to protect your information, including restricted analytics access, a fixed allow-list of the events and properties the app can send, redaction of search text and media titles on the device, daily limits on diagnostic logs, and server-side controls that let us switch off individual events or properties. No method of transmission or storage is completely secure.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted within the app or on our website, and the effective date above will be revised.
Privacy by Design
Product analytics are optional, off until you allow them, and switchable in Settings at any time. They are limited to a fixed list of events, with search text, media titles, and content identifiers redacted on your device before anything is sent. Session replay, streamed media, media-server usernames, credentials, authentication tokens, and private server addresses are excluded entirely. Sign in with Apple lets us authenticate your account without collecting your name or email address from Apple.
Questions About Your Privacy?
If you have any questions about this Privacy Policy or how we handle your data, please don't hesitate to contact us.
Contact Us