1. Who We Are (Data Controller)
Luma Player is a product of Fenixer Labs LLC. The app lets users play video playlists and manage their content through a personal web dashboard at lumaplayer.app. We do not provide, host, or distribute any media content ourselves.
For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent privacy laws, the data controller is:
Fenixer Labs LLC
A Delaware Limited Liability Company
254 Chapman Rd, Suite 101-B, Newark, DE 19702, United States
Privacy contact: privacy@lumaplayer.app
For any privacy-related questions or concerns, you can contact us at: privacy@lumaplayer.app
2. Data We Do Not Collect
Except for the limited service data described in Sections 3 and 4, Luma Player does not collect or store the following on our servers:
- Your name, email address, telephone number, or postal address
- Payment information or financial data of any kind
- Your watch history, viewing habits, or content preferences
- Your precise geographic location (GPS)
- Contacts, photos, or files from your device
- Behavioral advertising profiles or crash reports deliberately linked to your name or contact details
We have deliberately designed Luma Player to operate without registration and without connecting service data to your real-world identity.
3. Data Stored Locally on Your Device
The following information is stored in the app's private storage on your Android, Android TV, or Samsung Smart TV device. Some items are also stored in our cloud backend (Supabase) strictly to provide device activation and the web dashboard — see Section 4 for details:
- Device ID & Device Key: Pseudonymous identifiers used to recognise the app installation and authenticate web dashboard access. On Samsung Smart TV, the app derives a one-way, MAC-formatted identifier from the TV's Samsung Device Unique ID (DUID); the raw DUID is not sent to our servers. On other platforms, the identifier is generated or derived using platform-appropriate device information. The Device ID and Device Key are stored in Supabase.
- Playlists: Media source URLs and connection details you manually enter into the app. Synced to Supabase so you can manage them from the web dashboard.
- App Preferences: Language settings, buffer configuration, parental controls, and other in-app options you configure. Stored locally only — never transmitted.
- Playback Positions: Resume points for video content, allowing you to continue watching from where you left off. Stored locally only — never transmitted.
- Favorites: Channels, movies, and series you have marked as favorites within the app. Stored locally only — never transmitted.
You can clear all locally stored data at any time via Device Settings → Apps → Luma Player → Clear Data. Dashboard data can be removed by deleting your playlists through the web dashboard.
4. Web Dashboard (lumaplayer.app/dashboard)
The Luma Player web dashboard allows you to manage your playlists remotely. Authentication uses your Device ID and Device Key. These values do not directly identify you by name, but they are persistent pseudonymous identifiers and may be considered personal data under applicable privacy laws.
The following data is stored in Supabase (our cloud database provider) to enable the dashboard:
- Device ID — pseudonymous identifier for the app installation or device
- Device Key — 6-digit PIN used to authenticate dashboard access
- Playlist data — media source URLs you add, either from the app or the dashboard
- Last-seen timestamp — when the device last connected, used to display device status
We use this data only to provide activation, playlist synchronization, device status, and dashboard functionality. We do not use it for advertising or behavioral profiling. Supabase processes the data on our behalf as a cloud service provider. Playlist information is also sent directly to the external provider selected by you when the app loads that playlist.
5. App Permissions
Luma Player requests only permissions necessary for core functionality. The exact permissions depend on the platform:
- Internet: Required to fetch and stream playlists from external URLs you provide.
- Access Network State: Checks your internet connectivity before attempting to load playlists or streams.
- Access Wi-Fi State: Determines whether you are on Wi-Fi to support adaptive streaming decisions.
- Wake Lock: Keeps the screen active during video playback so content is not interrupted.
- Foreground Service: Allows playback to continue reliably while the app is in the foreground on Android TV and lock-screen scenarios.
- Read External Storage (Android 12 and below only): Used solely to allow you to import local playlist files from your device storage. This permission is not requested on Android 13 and above.
- Write External Storage (Android 9 and below only): Used solely to save exported playlist data on older Android versions. This permission is not requested on Android 10 and above.
- Samsung Product Information: On Samsung Smart TV, used to read the DUID and derive a stable pseudonymous Device ID for activation. The raw DUID is not transmitted to our servers.
- Samsung TV Input Device: Used to support remote-control navigation.
Luma Player does not request and has no access to your camera, microphone, precise location, or contacts. Storage permissions are scoped to the minimum Android version range where they are technically required and are used exclusively for local file import/export — not for browsing, reading, or transmitting any personal files.
6. Third-Party Services
Luma Player contains no advertising networks or behavioral-tracking SDKs. The Android version uses Firebase Crashlytics only for stability diagnostics; the Samsung Smart TV version does not use Firebase Crashlytics. Specifically:
- No Google Analytics
- No Facebook SDK or Meta Pixel
- No in-app advertising or ad tracking
The following third-party services are used for specific, limited purposes:
| Service | Purpose | Data sent | Privacy policy |
|---|---|---|---|
| Supabase | Web dashboard backend — stores your Device ID, Device Key, and playlist URLs so you can manage playlists remotely. Data is synced both when you add playlists from the app and when you use the web dashboard. | Pseudonymous Device ID, Device Key (6-digit PIN), playlist URLs and connection details you add, last-seen timestamp | supabase.com/privacy |
| Google Firebase Crashlytics (Android only) | Identifies crashes, startup failures, and playback stability problems so we can diagnose and improve the Android app. | Crash stack traces, app version and state, Firebase installation identifier, device model, OS/SDK and architecture, memory class, and limited technical playback diagnostics such as engine, content type, URL scheme, phase, fallback state, and timing. We deliberately do not add playlist URLs, provider hosts, usernames, passwords, channel names, Device ID, or Device Key to Crashlytics reports. | firebase.google.com/support/privacy |
| ip-api.com | Weather widget (optional) — derives your approximate city from your IP address | Your IP address (standard HTTP request) | ip-api.com/docs/legal |
| Open-Meteo | Weather widget (optional) — fetches current weather for the city detected above | Approximate latitude/longitude (city-level, not precise) | open-meteo.com/en/terms |
The weather widget does not request your device's GPS location. City-level geolocation is derived server-side from your IP address by ip-api.com — Luma Player never reads or transmits your device's precise location. If you prefer not to share this, there is no account or registration that ties these requests to your identity.
Playlists you add to the app are loaded directly from the servers of the provider you choose. Luma Player has no relationship with and no control over those external servers or their privacy practices. Any interactions with those servers are governed by the respective provider's own terms and privacy policy.
7. Security
Luma Player limits cloud processing to the service data described in Section 4. Network requests to our backend use HTTPS, and locally stored data is protected by the application sandbox and security mechanisms provided by Android, Android TV, or Samsung Tizen. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
We strongly recommend keeping your Device ID and Device Key private and not sharing them with anyone you do not trust.
8. Children
Luma Player is not directed at children under the age of 13. We do not knowingly connect the limited service data described in this policy to a child's real-world identity. If you are a parent or guardian and have a privacy concern, contact us using the address below.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of personal data, and to lodge a complaint with a data protection authority. You can also:
- Delete all app data instantly via Device Settings → Apps → Luma Player → Clear Data
- Remove individual playlists or favorites from within the app at any time
- Clear playlist data through the web dashboard
- Request deletion of cloud-stored Device ID, Device Key, playlist data, and last-seen timestamp by contacting us and providing the Device ID and Device Key needed to locate the pseudonymous record
If you have any specific privacy concerns or requests, contact us at privacy@lumaplayer.app and we will respond promptly.
10. Changes
We may update this Privacy Policy occasionally to reflect changes in the app or applicable regulations. Any updates will be reflected by a revised "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the Application following any changes constitutes acceptance of the updated policy.
11. Contact
For any questions, concerns, or requests related to this Privacy Policy, please contact us at: