Privacy Policy
Last updated: August 28, 2026
1. Introduction
VelaTV ("we", "our", "the App") is a private file manager and media player. It respects your privacy. This Privacy Policy describes what data we collect, how we use it, and what rights you have.
2. Data We Collect
We collect the minimum amount of data necessary for the App to function:
- Anonymous user identifier: Automatically created via Firebase Authentication. No email, name, or other personal information is required.
- Telegram User ID: A numeric identifier associated with your Telegram account, used to link your subscription status across devices. This is not your phone number or display name.
- Subscription status: Whether you have an active license (lifetime or annual).
- Device information: Basic device type information for compatibility (Android TV model, OS version).
- Crash reports: Crash and diagnostic data via Firebase Crashlytics to improve stability. These reports can be associated with your numeric Telegram User ID so we can investigate a reported problem.
- Product analytics: Firebase Analytics records controlled app interactions such as first open, source type, connection result, playback milestones, paywall views and purchase status. Event names and values come from fixed lists. We do not send file names, paths, media titles, source names, server addresses, URLs, Telegram chat identifiers, usernames, email addresses, credentials, exception text or user-entered text to Analytics.
- Your synced library (only when you are signed in with Telegram): Cloud library sync keeps your watch history, your "Continue watching" playback positions, and your watchlists the same on every device you use. It is on by default and you can turn it off at any time in Settings > Cloud sync. For each item we store the file name, the display title, the name of the Telegram chat it came from, the file size, duration, resolution and file type, when you last watched it and the position you stopped at, plus the names of the lists you created. This information is stored under your Telegram User ID, so it is linked to you. We never upload the video files themselves - only this descriptive information. This includes items from your other sources: if you watch, or add to a watchlist, a file from a local device folder, a network share (NAS/SMB), a WebDAV server or Google Drive while signed in to Telegram, that item's file name and the name you gave that source are stored too. We still never receive the file itself, its contents, your folder listings, or your credentials. Turning the toggle off stops any further syncing from that device, and deleting your data (in Settings or on the Account Deletion page) erases the synced copy from our servers.
- Support conversations: If you contact us through the App's built-in support chat, your messages and our replies are stored under your Telegram User ID so the conversation stays available to you.
3. Data We Do NOT Collect
- Email addresses (unless you contact us directly)
- Names or physical addresses
- Any viewing history at all, if you are not signed in with Telegram, or if you turn cloud library sync off - in that case your history, playback positions and watchlists never leave your device (see "Your synced library" above for what is stored when it is on)
- Precise location data
- Contacts, photos, or files from your device
- Your video files themselves - no video, audio or image file is ever uploaded to our servers from any source
- File contents, folder listings, or credentials from a local folder, network share (NAS/SMB), WebDAV server, or Google Drive you connect - those connections happen directly between your device and your own storage. The only exception is the file name of an item you actually watched or added to a watchlist while cloud library sync is on, as described above
- The contents of your Telegram messages, chats you did not open a file from, or anything from your Telegram account beyond the fields listed in section 2
Earlier versions used a discovery-signal system that could store Telegram chat details, public usernames or links, file names and a country code. That system is retired. New versions do not collect, log, save or upload those discovery signals. Historical server records may still exist while we make a separate, administrator-approved retention and deletion decision.
4. Payment Data
Payments are processed by Google Play. We do not store credit card numbers, banking details, or payment credentials. Google processes all financial data in accordance with its own privacy policy.
5. How We Use Data
- To verify your subscription status
- To keep your watch history, playback positions and watchlists the same across your own devices
- To answer you when you contact support
- To improve app stability and fix bugs
- To prevent fraud and abuse
We do not sell your data, and we do not use it for advertising. The App contains no ads and no advertising SDKs.
6. Data Storage
Data is stored in Firebase Realtime Database (Google servers) with security rules that restrict access to authorized users only. Your synced library and your support conversation are readable and writable only by your own account.
7. Data Retention
Your account data is retained as long as your VelaTV account is active. You may request deletion at any time.
For synced library data specifically: the most recent 300 watch-history entries are kept, and when you delete an item we keep a small deletion marker for up to 90 days so that the deletion also reaches your other devices.
After account-data deletion, we retain only limited records needed for deletion recovery, free-trial abuse prevention, purchase restoration, purchase anti-replay, security, accounting and disputes. A restricted purchase restoration receipt can include the Google Play purchase token because Google requires the token to verify the purchase. These records are not available to app clients. No automatic retention period is claimed for them; retention and any later purge require a separately reviewed administrative decision.
8. Account Deletion
You can delete your VelaTV account data through the App's Settings or on our Account Deletion page. The process signs out the local Telegram session and removes VelaTV's local Telegram database and downloaded files from that device. It never deletes your external Telegram account or Telegram messages. Another installed device cannot silently recreate deleted VelaTV data. Returning after deletion requires an explicit recreation confirmation, and each additional device must explicitly join the new account generation.
9. Third-Party Services
- Firebase (Google): authentication, database, crash reports
- Google Play Billing: in-app purchases and subscriptions
- Google Play Integrity: device integrity verification
10. Children's Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect data from minors.
11. Changes to This Policy
We may update this Privacy Policy. Changes will be posted on this page.
12. Contact
For privacy inquiries: support@velatv.org