Caudal
Privacy
Caudal Privacy Policy
_Last updated: August 25, 2026_
Caudal is a neutral media player for Android. This policy explains what data the app handles. In short: your credentials and preferences are stored encrypted on your own device and never leave it. The app does send anonymous usage metrics (on by default, with a switch to turn them off; see §2B) so we can tell whether the app is being used and what is worth improving. Beyond that, there are three optional transmissions that you control: (1) an opt-in diagnostics system, off by default (technical usage signals, with no credentials or URLs; see §2A); (2) syncing between your devices / "send to TV", which only works if you turn it on and which uploads to a developer server an end-to-end encrypted bundle containing your favorites, history and profiles —the server cannot decrypt it— (see §2D); and (3) Premium purchase verification, if you buy, which sends a developer server the signed Google Play receipt and an installation identifier (see §5). Outside of these cases, your data is not sent to any server.
1. Who we are
Caudal (hereinafter, "the app") is a playback application. It does not provide, host or distribute any channels or content: you supply your own sources (M3U/M3U8 playlists or Xtream Codes credentials).
2. What data the app handles and where it is stored
- Connections and credentials that you enter (M3U playlist or server URL, Xtream username and password): they are stored encrypted on your device (Android's
EncryptedSharedPreferences) and are used solely to connect to the provider you choose. They are not sent to Caudal or to any third party, except if you turn on syncing between your devices or "send to TV": in that case your profiles (which include those credentials) form part of an end-to-end encrypted bundle that is uploaded to a developer server, which cannot decrypt it (see §2D). - App preferences (language, theme, player settings, favorites, "keep watching", reminders, hidden groups): they are stored locally on your device.
- We do not collect location data or advertising identifiers. We do not use commercial analytics, third-party advertising or any third-party SDK. There are two usage-data transmissions and both go to developer servers: the anonymous usage metrics (§2B), which are on by default and can be turned off, and the opt-in diagnostics (§2A), which are off by default.
2A. Diagnostics (optional, opt-in, off by default)
So that problems can be detected and fixed (freezes, video/audio failures, errors and crashes), the app includes a diagnostics system that only works if you turn it on in Settings → Send diagnostics. By default it is off and the app sends nothing.
When you turn it on, the following technical signals are sent to a developer server:
- Device: model, manufacturer, Android version, app version and whether it is a TV.
- Usage: the name of the channel being played (never the URL or the credentials) and timestamps.
- Player state: whether video and audio are progressing, reconnections and playback errors.
- Crashes: the exception and its stack trace, sanitized of credentials and URLs.
Processing details:
- Identifier: a random anonymous per-installation ID, not linked to your identity or your accounts; it is regenerated if you reinstall.
- Where it goes: to a developer diagnostics server (our own VPS), not to third parties.
- Retention: 48 hours; after that, each event is deleted automatically.
- Credentials, passwords and full URLs of your sources are never sent.
- How to turn it off: uncheck Settings → Send diagnostics at any time; from that moment on the app stops sending.
Current technical limitation: transmissions to the developer servers (diagnostics, syncing and purchase verification) may travel over unencrypted HTTP in transit. An intermediary on your network could observe the technical diagnostics signals (while diagnostics are on) and the metadata of the sync (group identifier, timestamps, sizes, your IP address), although the content of the sync is end-to-end encrypted and is not readable in transit or by the server. If this concerns you, leave diagnostics off (its default state) and do not use syncing.
2B. Anonymous usage metrics (on, and you can turn them off)
To find out whether the app is really being used and what is worth improving, Caudal anonymously counts things such as how many times it is opened, whether you have managed to connect a playlist, whether you have played anything, which features you use, how long it takes to start up and how long a channel change takes. These are sent to a developer server.
What is sent:
- A random installation identifier. It is not the advertising identifier, it is not linked to your identity and it disappears when you uninstall the app.
- Device data: Android version, architecture, whether it is a phone, tablet or television, screen size, manufacturer, model, memory in ranges, connection type (Wi-Fi, mobile data or wired), installation channel (store or APK), and system language and region.
- Usage counters for a closed list of events, and amounts in ranges (for example "5-15 min" or "1-2 s"), never exact values.
What is NOT sent, by design: channel names, the URLs of your playlists, credentials, content, location, the advertising identifier, IMEI, serial number, MAC address, phone number, contacts or the list of applications you have installed. The app can only send events and values from a closed allowlist: anything not on it is discarded before it leaves the device.
What is stored on the server: aggregate counters, not individual events. Your IP address is not stored (the region is inferred from the language configured on your device, not from geolocating the connection) and the installation identifier is stored encrypted with a key held by the server.
How to turn it off: Settings → Anonymous usage metrics. Once you turn it off, the app stops sending immediately.
2C. App updates (sideload variant)
The version distributed outside Google Play (sideloaded APK) can check whether a newer version exists by querying a public file on GitHub (caudal-app repository) and, if you confirm, download and install the new APK. That check involves a connection to GitHub; no personal data is sent in it. The Google Play version does not include this self-updater.
2D. Syncing between your devices and "send to TV" (optional, opt-in)
The app can sync your favorites, your history ("keep watching") and your profiles between your own devices, and "send to TV" a piece of content from your phone to another device. These features are only enabled if you use them by linking your devices with a code; by default the app syncs nothing.
When you do use them:
- What is transmitted: an end-to-end encrypted (E2E) bundle containing your favorites, your history and your profiles. Your profiles include the credentials of your connections, so those credentials travel inside the encrypted bundle.
- Where it goes: to a developer sync server (our own VPS, port 8091), not to third parties. It acts only as a mailbox to pass the bundle from one of your devices to another.
- E2E encryption: the encryption key is derived from the code you enter and is never sent to the server. The server cannot decrypt the bundle: it stores and forwards data that is unreadable to it. Only your devices, which know the code, can decrypt it.
- Retention: the encrypted bundle is kept on the server for a maximum of 90 days and is then deleted automatically. The "send to TV" command is single-use.
- How to avoid it: do not link devices and do not use "send to TV". If you do not turn it on, nothing is transmitted through this channel.
3. Network connections
The app connects directly to the IPTV provider you configure in order to play the content you supply. Those connections go from your device to your provider's server; Caudal neither acts as an intermediary nor logs that traffic.
4. Permissions
- Internet and network state: to connect to your provider.
- Notifications (optional, Android 13+): only for the program reminders that you schedule. You can deny or disable it.
- Receive boot completed (
RECEIVE_BOOT_COMPLETED): solely to reschedule your program reminders after the device restarts (Android forgets alarms when it shuts down). It does not involve sending any data. - Install applications (
REQUEST_INSTALL_PACKAGES, only in the sideload variant): solely to install the update to Caudal itself that you confirm (see §2C). It is not used to install any other package. The Google Play version does not include this permission.
No permissions are requested for location, contacts, microphone, camera or sensitive storage.
5. Purchases (Premium)
The Premium purchase is processed through Google Play Billing. Caudal does not store your payment details (card, etc.): they are handled entirely by Google Play.
To verify the purchase and activate Premium, the app sends to a developer licensing server (our own VPS) the signed Google Play receipt (purchase token) and a stable installation identifier for the device. The server validates the receipt and ties the license to your device to prevent a single purchase from being shared across many devices. This processing is limited to license verification and is not used for advertising or analytics.
- Data transmitted: Google Play purchase token and installation identifier (pseudonymous, not linked to your identity).
- Where to: developer licensing server (our own VPS), not to third parties.
- Legal basis: performance of the contract (activating the Premium you buy) and legitimate interest in preventing license sharing/fraud.
- Retention: for as long as the license is active, so that it can be revalidated; the installation identifier is regenerated if you reinstall.
- Note: this transmission only happens if you buy Premium. The free features do not trigger it.
6. Minors
The app is intended for an adult audience and is not directed at minors.
7. Your controls
- Anonymous usage metrics: Settings → Anonymous usage metrics. They come switched on; once you turn them off, the app stops sending immediately.
- Diagnostics: Settings → Send diagnostics. It comes switched off; nothing is sent unless you turn it on.
- You can delete any saved connection from the app at any time.
- Uninstalling the app erases all local data (including the encrypted credentials).
- Any backup you export is encrypted with a password that you choose.
8. Changes
We may update this policy. The "last updated" date reflects the version currently in force.
9. Contact
For any privacy enquiry (including exercising your rights of access to or erasure of the diagnostics data), write to: [email protected]
This policy is declared and signed by whoever publishes the app. Fulgeon only hosts it and shows it: it does not review it, verify it or approve it, and it does not answer for its truthfulness or for it being honoured. The party responsible for handling your data and for your rights is the app's author, not Fulgeon.