Privacy policy
The short version: we collect the minimum data needed to keep the service running. We do not log what you watch.
Scope
This policy applies to all users of NANO IPTV, regardless of where you are located. It describes how we collect, use, store, share, and protect your personal data when you use our IPTV streaming service, website, and related applications.
By using the service, you acknowledge that you have read and understood this policy. If you do not agree with our data practices, please do not use the service.
What we collect
To deliver the service, we collect the following categories of personal data:
- Account data— your email address, hashed authentication credentials, and billing details necessary to manage your subscription.
- Authentication data— your M3U URL or Xtream Codes login, the IP address and device fingerprint required to authenticate your stream requests and enforce connection limits.
- Payment data— orders are placed through WhatsApp and paid by the method agreed in the chat (typically bank transfer). We store only the transaction ID, amount, and payment method type. We never process, store, or collect card numbers, CVVs, or cryptocurrency wallet details.
- Support data— any information you voluntarily provide when you contact our support team, including correspondence and any attachments.
We do not log viewing history, channel switches, playback duration, or anything that would tell us what you watched, when, or on which device. We have no interest in your viewing habits and no technical mechanism to record them.
Legal basis for processing (GDPR)
Under the EU General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:
- Contract performance(Art. 6(1)(b)) — processing is necessary to provide the service you have subscribed to, including authentication, streaming, and billing.
- Legitimate interest(Art. 6(1)(f)) — we process data to prevent abuse, ensure security, and improve the reliability of the service. These interests are balanced against your rights and do not override them.
- Legal obligation(Art. 6(1)(c)) — we retain certain billing records for the period required by tax and accounting law.
- Consent(Art. 6(1)(a)) — where applicable, for optional communications such as service newsletters (you may withdraw consent at any time).
Why we collect it
- To deliver the service (authentication, stream routing, billing, and account management).
- To prevent abuse (rate limiting, anti-leech, DDoS mitigation, and fraud detection).
- To respond to support requests and provide customer assistance.
- To comply with applicable law, including tax, accounting, and data-protection regulations.
- To communicate service changes, security alerts, and updates that affect your account.
How long we keep it
We retain your data only as long as necessary for the purposes described in this policy:
- Account and billing data— for as long as your account is active, plus 7 years for tax and accounting purposes (required by Swedish law).
- Authentication logs— 30 days, then aggregated into anonymous, non-identifiable metrics. Individual IP addresses are not retained beyond this period.
- Support correspondence— 2 years from the last interaction, then permanently deleted.
When data is no longer needed, it is securely deleted or irreversibly anonymised so that it can no longer be associated with you.
International data transfers
Some of our subprocessors (such as Vercel and Supabase) may process or store data outside the European Economic Area (EEA). When this occurs, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable (e.g., transfers to countries recognised by the EU as providing adequate data protection).
- Contractual obligations on subprocessors to maintain a level of protection equivalent to GDPR.
You may request a copy of the applicable transfer safeguards by contacting legal@nanoiptv.com.
Your rights (GDPR)
Under the GDPR, you have the right to:
- Access— request a copy of the personal data we hold about you.
- Rectification— correct inaccurate or incomplete data.
- Erasure— request deletion of your account and associated personal data (subject to legal retention obligations).
- Portability— export your data in a structured, machine-readable format (JSON or CSV).
- Restriction— request that we limit processing of your data in certain circumstances.
- Objection— object to processing based on legitimate interests, including for direct marketing.
- Withdraw consent— where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint— file a complaint with your local data-protection authority if you believe your rights have been violated.
To exercise any of these rights, email legal@nanoiptv.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.
Children’s privacy
The service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided personal data to us, please contact legal@nanoiptv.com.
Security
We take the security of your data seriously and employ industry-standard measures to protect it:
- Encryption in transit— all data is transmitted over TLS 1.3, the latest and most secure version of the protocol.
- Encryption at rest— stored data is encrypted using AES-256, a military-grade encryption standard.
- Access control— internal access is gated by least-privilege IAM policies. No employee has blanket access to user data.
- Security reviews— we undergo an annual third-party security assessment and promptly address any findings.
No system is perfectly secure. If we become aware of a data breach that affects your personal data, we will notify you within 72 hours in accordance with GDPR Article 33 and provide information about the nature of the breach and the steps we are taking to address it.
Changes to this policy
We may update this privacy policy from time to time. We will notify active subscribers by email at least 30 days before any material change takes effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Previous versions of this policy are available upon request by contacting legal@nanoiptv.com.
Contact
For privacy-related questions, data requests, or to exercise your rights, email legal@nanoiptv.com.
Our Data Protection Officer can be reached at the same address. We aim to respond to all privacy inquiries within 5 business days and resolve them within 30 days.
You may also contact your local data-protection authority. If you are in the EU, a list of authorities is available at edpb.europa.eu.