Privacy Policy for IPZO
Updated Sun 10, 2026
Privacy Policy
Last Updated: May 2, 2026
Effective Date: May 2, 2026
1. Introduction
Ares Hosting ("we," "our," or "us") operates the IPZO - Stream Player mobile application (the "Application" or "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Application.
By downloading, installing, accessing, or using our Application, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our Application.
2. Information We Collect
We collect information that you provide directly to us and information that is automatically collected when you use our Application. The types of information we collect include:
2.1. Device Identifiers and Technical Information
Device or Other Identifiers:
- Device ID: A custom device identifier generated by our Application for account management and multi-device authentication
- Application ID: Package name (com.ipzo.player) used for API routing
- OneSignal Player ID: A push-notification identifier created by the OneSignal SDK and shared with OneSignal solely to deliver push notifications
We do NOT collect:
- Advertising ID (AAID): We removed all advertising SDKs in v4.8 and the
AD_IDpermission is explicitly removed from the merged manifest (tools:node="remove"). - Android ID (Settings.Secure.ANDROID_ID): Not read or transmitted by the Application.
- IMEI / MAC address / Serial number: The Application does not request
READ_PHONE_STATEand never accesses these identifiers.
Purpose of Collection:
- User authentication and account management
- Device-based login verification (multi-device support)
- Preventing unauthorized access to user accounts
- Delivering push notifications (OneSignal Player ID only)
Technical Device Information:
- Device model, manufacturer, and brand
- Operating system version and type
- Screen resolution and display characteristics
- Network information (IP address, network type, connection status)
- Application version and build information
- Language and locale settings
2.2. Account and Authentication Information
User Account Data:
- Username and password (encrypted and stored locally)
- User account status and expiration date
- Active connection count and maximum allowed connections
- Server configuration and connection details
- Login type (XUI or Stream-based authentication)
- Account activation codes and trial account information
Purpose of Collection:
- User authentication and authorization
- Account management and subscription tracking
- Service delivery and content access control
- Security and fraud prevention
2.3. Usage and Activity Data
Application Activity:
- Pages and screens visited within the Application
- Time spent on different sections of the Application
- Content viewed, searched, and accessed
- User interactions with features and functionalities
- In-app search history and preferences
- Content playback history and watch progress
Watch Progress Data:
- Content identification (content ID, title, type)
- Playback position and duration
- Progress percentage for videos and streams
- Last watched timestamp
- Device association for multi-device synchronization
Purpose of Collection:
- Providing personalized content recommendations
- Resuming playback from last watched position
- Synchronizing watch progress across devices (multi-device sync)
- Improving user experience and service quality
2.4. Location Information
The Application does NOT collect any location data.
Specifically, we do not collect, derive, or process:
- Precise (GPS / fine) location —
ACCESS_FINE_LOCATIONis not requested;LocationManager,FusedLocationProviderClient, andLocationServicesare not used - Approximate (coarse / network-based) location —
ACCESS_COARSE_LOCATIONis not requested; cell tower and Wi-Fi triangulation APIs (getCellLocation,getAllCellInfo,WifiManager.getScanResults) are not used - Background location —
ACCESS_BACKGROUND_LOCATIONis not requested - Media location —
ACCESS_MEDIA_LOCATIONis not requested - IP-based geolocation — the Application does not query MaxMind, ipapi, ipgeolocation, ip-api, or any other GeoIP service to derive a location from an IP address. The Application does not show "near you" content and does not enforce region-based content licensing
To provide a defense-in-depth guarantee against transitive permission injection from any third-party SDK, the merged manifest explicitly removes all four location permissions via tools:node="remove".
2.5. Network and Connection Data
Network Information:
- Internet Protocol (IP) address
- Network type (Wi-Fi, mobile data)
- Connection quality and speed
- Network state and connectivity status
- Server connection details and protocols
Purpose of Collection:
- Establishing and maintaining service connections (HTTPS request routing to panel.ipzoapp.com)
- Adapting stream bitrate to current network speed (e.g., HLS adaptive streaming)
- Troubleshooting connection issues (server-side error logs)
- Security and fraud prevention (rate limiting, abuse detection)
Note on IP address (important for Data Safety transparency):
The server (panel.ipzoapp.com) necessarily sees the client IP address on every HTTPS request — this is an unavoidable characteristic of the TCP/IP protocol, not a deliberate data-collection action. We use the IP address only for:
- Routing the HTTPS response back to the requesting client
- Standard server-side access logs (rotated and purged within 90 days)
- Detecting abuse patterns (e.g., excessive request rates from a single IP)
We do NOT:
- Translate the IP address into a city, region, or country (no GeoIP lookup)
- Use the IP address to personalize content, recommendations, or the user interface
- Build any profile, segment, or audience from IP address data
- Sell, share, or transfer IP addresses to advertising or analytics third parties
The IP address is treated strictly as a transport-layer artifact, not as a user attribute.
2.6. Content and Media Data
Media Consumption Data:
- Content categories and genres accessed
- Favorite content and playlists
- Download history and preferences
- Streaming quality preferences
- Player settings and configurations
Purpose of Collection:
- Personalizing content recommendations
- Improving content delivery and quality
- Managing downloads and offline content
- User preference management
2.7. Analytics and Performance Data
The Application does NOT integrate any analytics, crash-reporting, or performance-monitoring SDK.
Specifically, we do not collect, transmit, or store:
- Application crashes or stack traces (Firebase Crashlytics is not integrated)
- Firebase Analytics events (
firebase-analyticswas removed in v4.8) - Firebase In-App Messaging events (
firebase-inappmessagingwas removed in v4.8) - User behavior analytics, engagement metrics, or feature usage statistics
- Sentry, Bugsnag, or any third-party crash/diagnostic SDK
The only client-side logging is a local Logcat trace used for on-device troubleshooting; it is never uploaded to a remote server.
3. How We Use Your Information
We use the collected information for the following purposes:
3.1. Service Provision
- Authenticating users and managing accounts
- Delivering streaming content and services
- Synchronizing watch progress across devices
- Managing downloads and offline content
- Providing customer support and technical assistance
3.2. Personalization
Personalization in the Application is derived exclusively from on-device signals and explicit user choices:
- Content recommendations are based on the user's own watch history, favorites, and previously played categories — all of which are stored locally on the device and synced (only when the watch-progress feature is enabled) with
panel.ipzoapp.com. Recommendations are not derived from IP address, geolocation, advertising profiles, or any third-party data broker. - User-interface adaptations (selected UI theme, language, RTL/LTR direction, sort order) are taken from in-app settings the user has explicitly chosen and stored in
SharedPreferenceson the device. - Remembering user preferences (last server, last category, last playback position) — stored locally; the watch position component is also synced with our backend for multi-device resume.
We do NOT profile users by location, demographic inference, behavioral advertising signals, or any IP-derived attribute.
3.3. Service Improvement
- Aggregated, server-side counts of authenticated requests for capacity planning at panel.ipzoapp.com (no client-side analytics SDK)
- Manual review of opt-in user reports submitted via the in-app Report feature
3.4. Security and Fraud Prevention
- Detecting and preventing unauthorized access
- Protecting user accounts and data
- Investigating suspicious activities
- Complying with legal and regulatory requirements
3.5. Communication
The Application's only outbound communication channel to the user is service-related push notifications delivered via OneSignal. We use this channel solely for:
- Important service notifications (maintenance windows, outages, security advisories)
- Updates about Application changes (new versions, feature changes that require user awareness)
- Responses to user inquiries submitted through the in-app Report feature
We do NOT send marketing emails, promotional SMS, behavioral re-engagement campaigns, or any commercial advertising message. Push notifications can be disabled at any time from the device's system notification settings.
3.6. Advertising
The Application does not display advertisements and does not integrate any advertising SDK (AdMob, Meta Audience Network, AppLovin, Unity Ads, etc.). The Google Advertising ID (AAID) is not read; the com.google.android.gms.permission.AD_ID permission is explicitly removed from the merged manifest.
4. Information Sharing and Disclosure
We may share your information in the following circumstances:
4.1. Third-Party Service Providers
We share information with trusted third-party service providers who assist us in operating our Application and providing services:
Google Services:
- Google Play Services — Cast framework: Used only for Chromecast device discovery and playback control. No user data is sent to Google for this feature.
- Firebase Cloud Messaging (FCM): Pulled in transitively by the OneSignal SDK to deliver push notification payloads. The FCM token is shared with OneSignal/Google solely to route push notifications.
The Application does not integrate Google Analytics for Firebase, Firebase Crashlytics, Firebase In-App Messaging, AdMob, or Google Cloud Services. These SDKs were removed in v4.8.
OneSignal:
- Push notification delivery (alerts and service updates)
- OneSignal automatically collects: OneSignal Player ID, FCM token, device model, OS version, language, timezone, and IP address
- See OneSignal's Privacy Policy for full details
Other Service Providers:
- panel.ipzoapp.com (our own backend) — hosting and authentication
- The Xtream Codes / IPTV server selected by the user — receives the username and password supplied by the user; this server is operated by the user's own service provider, not by us
4.2. Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including:
- Court orders, subpoenas, or legal processes
- Government investigations and regulatory compliance
- Protection of our rights, property, or safety
- Protection of user rights, safety, or security
- Fraud investigation and prevention
4.3. Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
4.4. With Your Consent
We may share your information with other parties when you have given us explicit consent to do so.
4.5. Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research or other business purposes.
5. Data Security
We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction:
5.1. Encryption
- All data transmission is encrypted using HTTPS/TLS protocols
- Sensitive information (passwords, credentials) is encrypted at rest
- Application-level encryption for stored user data
5.2. Access Controls
- Limited access to personal information on a need-to-know basis
- Authentication and authorization mechanisms
- Regular security audits and assessments
5.3. Data Protection Measures
- Secure server infrastructure and hosting
- Regular security updates and patches
- Monitoring and detection of security threats
- Incident response procedures
5.4. User Responsibilities
- Users are responsible for maintaining the confidentiality of their account credentials
- Users should not share their login information with others
- Users should use strong, unique passwords
Note: While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
6.1. Retention Periods
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:
- Account Information: Retained for the duration of your account and for a reasonable period after account closure
- Usage and Activity Data (watch progress only): Retained for up to 2 years for multi-device synchronization, or until you delete your account
- Watch Progress Data: Retained until you delete your account or request deletion
- Technical and Log Data: Retained for up to 90 days for troubleshooting and security purposes
- Legal and Compliance Data: Retained as required by applicable laws and regulations
Automatic Data Cleanup:
We automatically clean and delete user data every 90 days as part of our data retention and privacy protection practices. This automated process ensures that:
- Inactive user data is regularly purged from our systems
- Personal information that is no longer necessary is automatically removed
- Our systems maintain optimal performance and security
- We comply with data minimization principles
What Gets Automatically Cleaned:
- Inactive account data (accounts not accessed for extended periods)
- Temporary session data and cached information
- Old technical logs and diagnostic information
- Expired watch progress data
- Redundant backup copies of user data
Note: Active user accounts and data that is still required for service provision or legal compliance will not be automatically deleted. You can also request manual deletion at any time by emailing us at [email protected].
6.2. Data Deletion
Requesting Data Deletion:
IMPORTANT: To request deletion of your personal information, you must send an email to us. This is the required method for processing data deletion requests.
Required Method - Email Request:
You must send a data deletion request via email to:
- [email protected] (Primary contact for data deletion requests - REQUIRED)
- [email protected] (Alternative contact if needed)
Additional Options (Email Still Required):
- Online Request Form:
- Visit our account deletion page at: https://panel.ipzoapp.com/account-delete-request
- Complete the online form to submit your deletion request
- Note: The online form will require you to provide an email address, and we will process your request via email confirmation
- Application Feature:
- Use the account deletion feature in the Application (if available)
- Note: This feature may also require email confirmation for security purposes
Quick Access:
- Email for Data Deletion (REQUIRED): [email protected]
- Data Deletion URL: https://panel.ipzoapp.com/account-delete-request
What to Include in Your Email Request:
- Subject Line: "Data Deletion Request" or "Account Deletion Request"
- Your account username or email address
- Device ID (if available)
- Clear statement that you wish to delete your data
- Any specific data categories you want deleted
- Your contact email address for confirmation
Note: All data deletion requests must be submitted via email. We cannot process deletion requests through other communication channels without email verification.
Automatic Data Cleanup:
In addition to manual deletion requests, we automatically clean and delete user data every 90 days. This automated process helps protect your privacy by:
- Removing inactive user data from our systems
- Purging temporary and cached information
- Cleaning old technical logs and diagnostic data
- Maintaining data minimization practices
Processing Time:
Upon receiving a valid deletion request, we will:
- Acknowledge receipt of your request within 5 business days
- Delete your personal information within 30 days
- Confirm deletion completion via email
Note: Even if you do not request manual deletion, your data will be automatically cleaned every 90 days as part of our regular data maintenance process, unless it is required for active service provision or legal compliance.
Exceptions:
We may retain certain information where required by:
- Legal obligations (tax records, financial transactions)
- Regulatory requirements (compliance records)
- Legitimate business purposes (fraud prevention, security)
- Ongoing legal proceedings or disputes
Note: Some information may be retained in anonymized or aggregated form for service improvement purposes, but it will no longer be associated with your identity.
7. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
7.1. Access and Portability
- Request access to your personal information
- Receive a copy of your data in a portable format
- Review the information we hold about you
7.2. Correction and Update
- Update or correct inaccurate information
- Modify your account settings and preferences
- Change your account information
7.3. Deletion
- Request deletion of your personal information (Email required - send to [email protected])
- Delete your account and associated data (Email required - send to [email protected])
- Withdraw consent for data processing
7.4. Opt-Out Rights
- Opt-out of service-related push notifications (via system notification settings or by uninstalling — note that we do not send marketing emails or commercial messages, so there is no separate marketing opt-out to manage)
- Uninstall the Application to stop all data collection
7.5. Data Portability
- Export your data in a machine-readable format
- Transfer your data to another service provider
7.6. Objection and Restriction
- Object to certain types of data processing
- Request restriction of data processing
- Withdraw consent where processing is based on consent
To exercise these rights, please contact us at:
- [email protected] (Primary contact for privacy rights)
- [email protected] (Alternative contact)
We will respond to your request within 30 days, subject to applicable legal requirements and verification of your identity.
8. Children's Privacy
8.1. Age Restrictions
Our Application is not intended for children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect, use, or disclose personal information from children under 13.
8.2. Parental Controls
If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us immediately at:
- [email protected] (Primary contact)
- [email protected] (Alternative contact)
We will take steps to delete such information from our servers promptly.
8.3. Age Verification
If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.
When we transfer your information internationally, we take appropriate measures to ensure that your information receives adequate protection, including:
- Using standard contractual clauses approved by data protection authorities
- Ensuring that recipients are bound by appropriate data protection obligations
- Implementing additional security measures where necessary
10. Third-Party Services and Links
10.1. Third-Party Services
Our Application integrates with third-party services that have their own privacy policies. We encourage you to review the privacy policies of these services:
- Google Play Services Privacy Policy (used only for the Cast framework and Firebase Cloud Messaging transport)
- OneSignal Privacy Policy (push notifications)
10.2. External Links
Our Application may contain links to external websites or services. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Advertising and Service Notifications
11.1. Advertising
The Application does not display advertisements, does not use the Google Advertising ID (AAID), and does not integrate any advertising SDK. The com.google.android.gms.permission.AD_ID permission is explicitly removed from the Application's merged manifest.
11.2. Service Notifications (No Marketing)
We do not run marketing campaigns, behavioral re-engagement, or commercial advertising messages. The only outbound channel is service-related push notifications delivered via OneSignal (e.g., maintenance announcements, security advisories, version updates). You can opt out at any time by:
- Disabling notifications for IPZO in your device's system settings
- Uninstalling the Application
- Contacting us at:
- [email protected] (Primary contact)
- [email protected] (Alternative contact)
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify you of any material changes by:
- Posting the updated Privacy Policy on this page
- Updating the "Last Updated" date at the top of this policy
- Sending a notification through the Application (for significant changes)
- Posting a notice on our website
Your continued use of the Application after any changes to this Privacy Policy constitutes your acceptance of the updated policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Regional Privacy Rights
13.1. European Economic Area (EEA) and United Kingdom
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Access: You can request a copy of your personal data
- Right to Rectification: You can request correction of inaccurate data
- Right to Erasure: You can request deletion of your personal data
- Right to Restrict Processing: You can request limitation of data processing
- Right to Data Portability: You can request transfer of your data
- Right to Object: You can object to certain types of processing
- Right to Withdraw Consent: You can withdraw consent at any time
Legal Basis for Processing:
- Performance of a contract (service provision)
- Legitimate interests (security, fraud prevention)
- Consent (optional features such as multi-device watch progress sync)
- Legal obligations (compliance, law enforcement)
13.2. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of sale or sharing of personal information
- Right to Non-Discrimination: Exercise rights without discrimination
- Right to Correct: Request correction of inaccurate personal information
- Right to Limit: Limit use of sensitive personal information
We do not sell personal information for monetary consideration, and we do not share information with advertising partners (the Application does not display ads).
13.3. Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate. If you have questions about your privacy rights in your jurisdiction, please contact us.
14. Cookies and Tracking Technologies
14.1. No Cross-App Tracking
The Application does not use browser cookies (it is a native Android app), and it does not integrate any cross-app tracking technology, advertising SDK, or analytics SDK.
14.2. Identifiers Used
The only identifiers used by the Application are:
- Custom Device ID — generated locally by the Application for multi-device authentication; sent only to panel.ipzoapp.com (our backend)
- OneSignal Player ID — generated by the OneSignal SDK to address push notifications
- Application ID (
com.ipzo.player) — used for API request routing
14.3. Managing Identifiers
- You can disable push notifications in your device's system settings, which prevents the OneSignal Player ID from being usable
- You can request full data deletion (see Section 6.2) to remove your device identifier from our backend
- Uninstalling the Application stops all data collection
15. Data Breach Notification
In the event of a data breach that may affect your personal information, we will:
- Investigate the breach promptly
- Notify affected users within 72 hours (where required by law)
- Report to relevant data protection authorities (where required)
- Take appropriate remedial measures
- Provide guidance on protective steps users can take
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Ares Hosting
Primary Email: [email protected]
Alternative Email: [email protected]
Website: https://panel.ipzoapp.com
Data Protection Inquiries:
For questions about data protection, privacy rights, or to submit a data request, please email us at:
- [email protected] (Primary contact - recommended)
- [email protected] (Alternative contact)
Please use the subject line "Privacy Inquiry" or "Data Request" for faster processing.
Data Deletion Requests:
To request deletion of your personal information, you must email us:
- Email us at [email protected] with the subject "Data Deletion Request" (REQUIRED)
- Include your account information and specify what data you want deleted
- You may also visit our online deletion form: https://panel.ipzoapp.com/account-delete-request for additional information, but email submission is mandatory for processing
Response Time:
We aim to respond to all privacy-related inquiries within 30 days, in accordance with applicable data protection laws. Data deletion requests are typically processed within 30 days of receipt.
17. Consent
By using our Application, you consent to:
- The collection, use, and disclosure of your information as described in this Privacy Policy
- The processing of your information in accordance with this policy
- The transfer of your information to countries where we operate
If you do not agree with any part of this Privacy Policy, please do not use our Application.
18. Governing Law
This Privacy Policy is governed by and construed in accordance with applicable data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR) for EEA users
- California Consumer Privacy Act (CCPA/CPRA) for California residents
- Other applicable privacy and data protection laws in your jurisdiction
19. Additional Information
19.1. Account Deletion and Data Removal
How to Request Account Deletion:
REQUIRED: You must send an email to request account deletion and data removal. Email is the mandatory method for processing deletion requests.
Required Method - Email Request:
You must send an email to request account deletion:
- Primary Email (Required):
- Send an email to: [email protected]
- Subject line: "Account Deletion Request" or "Data Deletion Request"
- Include the following information:
- Your account username
- Your email address
- Device ID (if available)
- Clear statement that you want to delete your account and all associated data
- Alternative Email (If needed):
- You may also send your request to: [email protected]
- Include the same information as above
Additional Information:
- Online Form: You may also visit https://panel.ipzoapp.com/account-delete-request to access our deletion request form, but email confirmation is still required for processing.
Important: All account deletion requests must be submitted via email. We cannot process deletion requests without email verification for security and verification purposes.
What Happens After Deletion:
- Your account will be permanently deleted
- All personal information associated with your account will be removed
- Watch progress, preferences, and usage data will be deleted
- You will receive confirmation once deletion is complete
Important Notes:
- Deletion is permanent and cannot be undone
- Some information may be retained for legal or regulatory compliance
- You may need to create a new account if you wish to use our services again
19.2. Data Processing Agreement
If you are a business user or require a Data Processing Agreement (DPA), please contact us at:
- [email protected] (Primary contact)
- [email protected] (Alternative contact)
19.3. Privacy Policy Updates
This Privacy Policy was last updated on May 2, 2026. We reserve the right to update this policy at any time. Material changes will be communicated through the Application or via email.
Thank you for using IPZO - Stream Player. We are committed to protecting your privacy and providing you with a secure and enjoyable experience.
This Privacy Policy is effective as of May 2, 2026, and supersedes all previous versions.