Stremlix
How it worksFeaturesPricingAbout
Sign inStart free trial

On this page

1Who is responsible for your data2What we collect3How we use it, and our lawful basis4Advertising5Who we share it with6International transfers7How long we keep it8Security9Your rights10Children11Cookies and similar technologies12Changes to this policy13Contact

Related

Terms of ServiceCookie Policy

Legal

Privacy Policy

What we collect, why we are allowed to, and how you take it back.

Version 6 · Effective 2026-09-03

This policy explains what personal data Stremlix collects, what we do with it, and the rights you have over it. It is written to the standard of the EU General Data Protection Regulation (GDPR) and the UK GDPR, so that visitors from those regions get that level of protection regardless of where we are based.

On this page
1Who is responsible for your data2What we collect3How we use it, and our lawful basis4Advertising5Who we share it with6International transfers7How long we keep it8Security9Your rights10Children11Cookies and similar technologies12Changes to this policy13Contact

MAFFEITECH INFORMATION TECHNOLOGY L.L.C, a limited liability company registered in Dubai, United Arab Emirates, is the data controller for the personal data described in this policy. That means we decide what is collected and why, and we are the party you exercise your rights against.

DetailValue
ControllerMAFFEITECH INFORMATION TECHNOLOGY L.L.C
AddressDowntown, Dubai, United Arab Emirates
Privacy contactlegal@stremlix.com
Data protection officerNot appointed. Our processing does not meet the Art. 37 thresholds that require one.
EU / UK representativeNot appointed. We have not appointed a representative in the European Union under Article 27 GDPR, or in the United Kingdom under the UK GDPR. If you are in the EU or the UK and wish to exercise a right, write to legal@stremlix.com and we will deal with it directly.

We collect only what the Service needs in order to work, to be paid for, and to stay secure. We do not buy personal data from anyone, and we do not build advertising profiles.

CategoryWhat it is
Account dataYour email address, your name if you give one, a password hash (never the password itself), and whether you signed in with Google or Apple.
Provider credentialsThe server address, username, and password of the IPTV or Xtream Codes account you choose to connect.
Subscription dataYour plan, trial and renewal dates, payment status, and the customer and subscription identifiers Stripe gives us. We do not receive or store your card number.
Session dataFor each active sign-in: a session token, the IP address the session was created from, and the browser or device user-agent string.
Usage data inside the appYour favourites, playlists, and watch history — the data the features themselves exist to store, held so the app works the same on your other devices.
Consent recordsWhich cookie purposes you accepted or refused, the policy version in force at the time, the timestamp, and a pseudonymous identifier stored in a first-party cookie.
Error and diagnostic dataWhen something breaks, our error monitoring provider (Sentry) receives the error, a stack trace, the page or screen, and technical context about the device and session.
Email delivery dataOur email provider (Resend) processes your address and delivery events in order to send verification, sign-in, and billing emails.

Your provider credentials are encrypted at rest with AES-256-GCM before they are written to our database. They are decrypted only in order to make the request your device asked us to help with.

We store your provider credentials so the app can talk to your provider. We do not inspect them, sell them, or share them, and we do not supply the service they unlock.

We do not deliberately collect special categories of data (health, beliefs, biometrics, and the like), and you should not put such data into free-text fields such as playlist names.

Under the GDPR every use of personal data needs a lawful basis. This table is ours: what we do, why, and which basis it rests on. Where the basis is consent, the processing does not happen until you give it and stops when you withdraw it.

What we doWhyLawful basis
Create and run your account; authenticate youYou cannot use the Service without an accountContract (Art. 6(1)(b))
Store and use your provider credentials to fetch your streamsThis is the function of the product you subscribed toContract (Art. 6(1)(b))
Sync your favourites, playlists, and watch historyFeatures you asked for, working across your devicesContract (Art. 6(1)(b))
Take payment, manage trials, renewals, and cancellationsTo provide a paid subscription and get paid for itContract (Art. 6(1)(b))
Send service emails — verification, sign-in codes, password resets, receipts, and material changes to these documentsRequired to operate the account you asked forContract (Art. 6(1)(b))
Keep session records including IP address and user-agentSo you can see and end your active sessions, and so we can detect account takeoverLegitimate interests (Art. 6(1)(f)) — securing accounts
Rate-limit, detect abuse, and block attacksKeeping the Service available and accounts safeLegitimate interests (Art. 6(1)(f)) — security
Receive crash and error reportsSo faults are found and fixed rather than silently enduredLegitimate interests (Art. 6(1)(f)) — service reliability
Remember non-essential preferences such as your themeConvenience only; the app works without itConsent (Art. 6(1)(a))
Analytics about which features are usedTo decide what to improveConsent (Art. 6(1)(a))
Advertising, and any profiling for advertisingNot done today. If it is ever introduced it will be asked for separatelyConsent (Art. 6(1)(a))
Keep records of consent, acceptance of terms, billing, and taxWe have to be able to show what was agreed and what was chargedLegal obligation (Art. 6(1)(c)) and our legitimate interest in defending claims

Where we rely on legitimate interests we have weighed them against your rights and concluded the processing is what you would reasonably expect. You can object at any time — see section 9 — and we will stop unless we have compelling grounds that override your objection.

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.

Stremlix shows no advertising today, and sets no advertising or profiling cookies today.

We may introduce advertising in future. If we do, it will be on the basis of consent: you will be asked, the request will name the purposes it covers, and the choices are recorded per purpose rather than as one blanket switch.

Refusing advertising and advertising-related purposes keeps the application fully usable. Nothing you pay for is withheld, degraded, or gated behind agreeing to ads.

Your provider credentials, and what you watch, will never be used to target advertising and will never be shared with an advertising partner.

We share personal data only with service providers who process it on our instructions under a data processing agreement, and only as far as they need it to do their job.

RecipientWhat they doWhat they receive
StripePayments and subscription billingYour email, billing details, and payment data you enter with them
ResendTransactional email deliveryYour email address and message content
SentryError and performance monitoringError reports and technical context, with text and media masked in session replays
RailwayHosting for our backend and databaseData at rest and in transit, as infrastructure
VercelHosting for the website and web applicationRequest and infrastructure logs
Apple, GoogleSign-in with Apple / Google, and app store billingThe identifiers those services provide when you choose to use them
CloudflareTurnstile, the bot check that runs on our sign-in, sign-up and email-code pagesYour IP address, browser user agent, TLS fingerprint and similar signals from the browser making the request, taken only while the check runs

Cloudflare Turnstile is a bot check. It loads on the sign-in, sign-up and email-code pages only, and it reads signals from the browser making the request — IP address, user agent, TLS fingerprint and similar — to decide whether that request comes from a person or from software. It is not a tracker: it does not follow you between sites, and Cloudflare does not use these signals to build a profile of you or to target advertising. We rely on our legitimate interest in keeping accounts from being created and attacked in bulk. If you would rather not use it, the check is the only thing standing between you and those three pages, so there is no alternative route to them; you can still contact us at the addresses in section 1.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We never share your provider credentials with anyone.

We may disclose data where the law requires it, where we must to establish or defend a legal claim, or to a successor if the business is transferred — in which case this policy continues to apply until you are told otherwise.

When you play a stream, your device contacts your provider directly. That provider will see your IP address and the requests you make. That is a transfer between you and them, on your instruction; we do not control it and it is governed by their policy, not ours.

We are based in the United Arab Emirates and our providers operate in the United States, the European Union, and elsewhere. Using the Service therefore involves transferring personal data outside the country where you live, including outside the EEA and the UK.

Where data leaves the EEA or the UK we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where the UK GDPR applies), incorporated into our agreements with each provider, together with the technical measures in section 8. You can ask us for a copy of the safeguards in place.

We keep data only as long as it has a purpose, then delete or anonymise it.

DataKept for
Account dataThe life of your account, then deleted within 30 days of deletion or account closure
Provider credentialsUntil you remove the provider or delete your account, then deleted immediately
Session recordsUntil the session expires or you sign it out, and no more than 7 days after expiry
Favourites, playlists, watch historyThe life of your account, or until you delete the item
Consent records tied to an accountThe life of the account plus 12 months, as evidence of what was agreed
Anonymous consent records (no account)13 months, then deleted
Error and diagnostic data90 days at our monitoring provider, then deleted automatically
Billing, invoice, and tax recordsAs long as tax and accounting law requires, typically 5 years

Backups roll off on their own schedule, so data can persist in a backup for a short period after it is deleted from the live system. It is not restored into use.

We take technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (HTTPS/TLS) for every connection to our systems
  • AES-256-GCM encryption at rest for your provider credentials, with the key held outside the database
  • Passwords stored only as salted hashes, never in a form we can read
  • Session cookies that are HTTP-only, Secure, and SameSite-restricted, with sessions you can view and revoke
  • Rate limiting and abuse detection on authentication endpoints
  • Server-side validation of every outbound request to a user-supplied address, to stop our servers being used to reach systems that are not yours
  • Masking of text and media in error-monitoring session replays, so a stream URL cannot leak a provider password into a bug report
  • Access to production data limited to those who need it

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required, and tell you directly where the risk is high.

Subject to the conditions in the law, you have the right to:

  • Access — get a copy of the personal data we hold about you
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — have your data deleted where we no longer have grounds to keep it
  • Restriction — have us pause processing while a dispute about it is resolved
  • Portability — receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible
  • Object — object to processing based on legitimate interests, including profiling
  • Withdraw consent — withdraw any consent you gave, at any time, without affecting what was lawful before you withdrew it
  • Complain — lodge a complaint with your local supervisory authority

You can exercise most of these from your account settings. For anything else, write to us at the privacy contact in section 1. We will respond within one month, and will tell you if we need longer because the request is complex. We may need to verify who you are first. Exercising a right costs nothing unless a request is manifestly unfounded or excessive.

Withdrawing cookie consent must be as easy as giving it, so the same control that took your choices reopens them here and in the footer of every page:

The Service is for adults. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and accounts are restricted to people aged 18 or over.

If you believe a child has given us personal data, contact us and we will delete the account and the data.

We use a small number of first-party cookies and browser storage items. Every one of them, what it is for, how long it lasts, and whether it is essential, is listed in the Cookie Policy.

Read the Cookie Policy

We will update this policy when what we do changes. Each published version carries a version number and an effective date, shown at the top of this page.

For a material change we increase the version number and ask you to review it the next time you use the Service, and we record which version you saw. Where the change is significant we also give notice by email in advance.

VersionEffectiveWhat changed
12026-08-18First published version.
22026-08-20Subscription prices restated; the EU Article 27 / UK representative row now says plainly that none is appointed.
32026-09-02Cloudflare added to the processor table and Turnstile, the bot check on our auth pages, described in section 5.
62026-09-03The registered business address of the operating entity was filled in. No change to how we handle personal data.
52026-09-03Published alongside the Terms yearly-price update; no change to how we handle personal data.
42026-09-03Published alongside the Terms price update; no change to how we handle personal data.

For any privacy question or to exercise a right, write to legal@stremlix.com.

MAFFEITECH INFORMATION TECHNOLOGY L.L.C, Downtown, Dubai, United Arab Emirates.

If you are in the EEA or the UK you also have the right to complain to your national data protection authority.

Already paying for IPTV? Give it a player worth using.

Have your provider’s server URL, username, and password to hand. Setup takes about a minute.

Start free trial
Stremlix

A fast, modern player for the IPTV service you already pay for. Bring your own provider — we build the app around it.

Product

  • Features
  • Pricing
  • How it works

Company

  • About
  • Contact

Legal

  • Terms of Service
  • Refund Policy
  • Privacy Policy
  • Cookie Policy

Stremlix is a media player. It does not provide, host, sell, or index any channels or content. You bring your own IPTV service.

© 2026 Stremlix · Dubai, United Arab Emirates

Sign inStart free trial