Privacy policy

Version 2026-09-27

1. Who processes your data

NEXYRA is a software product developed and operated under the Zamora Systems brand in Ecuador.

Zamora Systems is the brand under which the product is developed and operated; it is not, in itself, a company or a legal entity.

NEXYRA IPTV Player ("NEXYRA") is a service operated by Oscar Andrés Zamora Solano, a natural person. For data protection purposes, the data controller is Oscar Andrés Zamora Solano, with registered address at Av. Principal S26-66 y Pasaje 6, parroquia La Argelia, Quito, Pichincha, Ecuador, phone +593 96 286 3906, email nexyra.iptv@gmail.com. That is also the contact address for exercising your rights.

2. Scope

This policy describes how NEXYRA processes personal data related to the app, the website and associated services.

NEXYRA is a player: it does not provide channels, films, series, M3U playlists, credentials or IPTV subscriptions. All content comes from sources the user provides.

3. What data we process

Only what is needed for the service to work, to authenticate access and to maintain security.

From your device we do NOT collect: your hardware MAC address, your operating system version, a device fingerprint, or the result of any root or jailbreak check. Until 7 September 2026 the app did send such a root check and the server stored it; it was never used for anything —a rooted device was never blocked— so we stopped collecting it and removed the stored values from the database.

Nor do we collect your location, your contacts, your photos, your list of installed apps or advertising identifiers.

  • Email address: identifies the account and is the sign-in channel.
  • OTP codes: one-time sign-in codes. Stored hashed and expiring.
  • Device identifier: IDFV on iOS or the Android ID (Settings.Secure.ANDROID_ID) on Android, to bind the licence to a device. It is the only device identifier we store; in the support console and in the app itself it is displayed with colons, looking like a MAC address, but it is that same value rewritten, not your equipment's MAC.
  • Device model: the model name reported by the system (for example “Fire TV Stick” or “SM-A155M”), so you can recognise each device in your account's list.
  • Device type: whether it is a TV or a phone, to serve the right interface and to count devices per platform.
  • Device key: a six-digit number derived from the identifier above. It is what authenticates the device and what is shown to you on screen.
  • Device sign-in activity: date of last access, number of failed attempts and, if exceeded, the moment until which it stays locked. Used to stop attempts to guess the key.
  • Sessions: active session identifiers and their expiry or revocation date.
  • Playback history: what was played and when, to resume and organise content.
  • Favourites: the channels or titles you mark.
  • Connected playlists: the sources you add: name, type and configuration.
  • Source address: the provider's host and base path, stored WITHOUT any secrets the original URL may have carried.
  • External source username: when the source is Xtream-type and requires one.
  • External source password: stored encrypted. See the next section.
  • Technical data: errors, traces and events needed to diagnose faults and protect service stability.
  • Purchases: plan purchased, amount, currency and date.
  • Payment references: the identifier returned by the gateway. We do not store card numbers.
  • Sanitised logs: access and operation traces from which credentials and full addresses are stripped before storage.

4. External source credentials

This section deserves precision, because these are third-party service credentials that you provide.

External source credentials are stored encrypted and are processed only when necessary to carry out the functions you request.

  • Encrypted at rest: the source password is stored using AES-256-GCM, an authenticated encryption algorithm. The encryption key lives on the server, not in the database.
  • URLs stored without secrets: where the source address you enter contains embedded credentials, they are extracted and encrypted separately before the address is stored.
  • Decrypted only when needed: decryption happens on the server and only when required: importing your playlist, checking your account with the provider, or building the playback address we return to you.
  • They travel to your device during playback: worth stating plainly: when you play a channel from an Xtream source, the address your device receives has your username and password for that source embedded in it. That is how the Xtream protocol works, and it is necessary because it is your own device that connects to your provider, not our server. Traffic with us is encrypted (HTTPS), and that address is only handed to your account's authenticated session.
  • HTTPS with us; whatever your provider offers for your source: NEXYRA uses HTTPS for communications with its own servers. When you use an external provider you configure yourself, the direct connection to that provider uses whatever protocol that provider offers, which may be HTTP or HTTPS. If the provider uses HTTP, we warn you when you configure or edit that source and recommend using HTTPS when it is available; we never convert an HTTPS address you entered into HTTP ourselves.
  • You can retrieve it: the app lets you look up the password of your own source again, signed in to your account and only for playlists that are yours. We show it to no one else.
  • Kept out of logs: credentials and full addresses are removed from traces before they are written.
  • Not shared: they are not sold, transferred or disclosed to any third party. The only destination they reach is your own provider, to whom they belong.
  • Deleted with you: when you delete the playlist or the account, the encrypted credential goes with it.

5. What we use your data for

  • Account access: authenticate via one-time code and maintain the session.
  • Providing the service: manage devices, playlists, favourites, history and preferences.
  • Connecting to your sources: reach your provider with the credentials you configured, when you ask for it.
  • Licences and payments: manage the plan purchased, its validity and payment operations.
  • Security: detect abuse, limit unauthorised access and protect the infrastructure.
  • Support and bug fixing: diagnose incidents and improve how the service works.

6. Basis for processing

Where applicable, we process personal data on the basis of contract performance, compliance with legal obligations, legitimate interest in service security, or consent where requested.

External source credentials are processed because the user provides them and expressly requests the feature that requires them.

7. What happens if you do not provide certain data

Some data is required for a specific feature to work. Not providing it carries no penalty: that feature simply cannot run, and the rest of the service remains available.

  • Email address: required to create and manage the account, because sign-in works through a code sent by email. Without it an account cannot be maintained.
  • Device identifier: required to activate and bind the licence to a device. Without it, activation features cannot run.
  • External source details: the address and, where applicable, the username and password are required for the player to connect to that source. Without them that particular source cannot be played; you can keep using the app with others.
  • Payment details: handled by the payment gateway, not by us. Without them a purchase cannot be completed, but you can keep using the free trial.
  • History and favourites: optional. They let you resume playback and organise your content; without them the app works the same, just without those conveniences.

8. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Nor do we carry out profiling.

There are two automatic processes, and it is worth explaining why they do not fall into that category. Checking whether the free trial has already been used is an eligibility check for a one-per-account offer: it reads a yes/no flag, does not assess your behaviour or score you, and does not prevent you from purchasing any plan. Request rate limits are a technical security measure: they count requests within a time window, lift on their own and leave no consequence on the account.

Suspending an account, where it occurs, is always a human decision reviewed case by case, on the grounds set out in the Terms and Conditions. There is no mechanism that suspends accounts automatically.

Approving or declining a payment is decided by the payment gateway, not by us; we only verify what the gateway confirms.

9. How long we keep each type of data

These periods match the automatic purge implemented in the system.

  • OTP codes: 7 days at most. If you delete your account, yours are removed at that very moment, without waiting for that period.
  • Expired or revoked sessions: 30 days.
  • Playlist import history: 90 days, always keeping the most recent import for each playlist.
  • Ad impression records: 90 days.
  • Free trial record: kept while the account exists, to prevent the trial being consumed more than once.
  • Playlists and source credentials: while the account keeps them configured; removed when you delete them or delete the account.
  • Billing data: the identifiers linking your account to Stripe, Apple or Google are kept while the account exists and are deleted when you delete it.
  • Purchases: while the account exists, because they evidence the plan you bought. On account deletion they are neither erased nor kept whole: they are unlinked from your account (see the next section) and the resulting record is deleted once the applicable legal period expires; we currently schedule that deletion at 7 years from the purchase date, unless a legal obligation requires keeping it longer.

10. Account deletion

You can delete your account from the app. Doing so removes your playlists and their credentials, your channels, favourites, playback history, the record of which in-app promotions you were shown, devices, sessions, subscriptions, your free-trial record, the OTP codes associated with your email address and the identifiers that linked your account to the payment gateways.

Two things remain, unlinked from your account.

The record of your acceptance of the legal documents is unlinked from your account: it keeps which versions were accepted and when, but the field that associated it with you is cleared. It is the evidence that consent was given.

Purchases are not deleted straight away either: they are unlinked from your account in the same way. The links are released and only the accounting entry remains —gateway, transaction reference, amount, currency and date—, which is what allows an income to be evidenced before the tax authority. Transaction records that must be kept for tax obligations are retained only for the applicable legal period. Under current Ecuadorian tax rules, certain supporting documents must be kept for a period that, as a general rule, can reach seven years. Once the applicable period expires, the record is deleted. NEXYRA currently schedules the routine deletion of these records at seven years from the date of the transaction, unless an applicable legal obligation requires keeping them for a different period. About the transaction reference specifically: it remains a data point that the payment gateway (Stripe, Google Play, PayPal or Payphone) can associate with that operation in its own system, so we do not claim that this record becomes permanently unlinkable from you through that channel; what we guarantee is that, once unlinked from your account with us, it is no longer part of your active data or your profile. If you would rather it were deleted sooner than the legal period, write to us: we will assess the request against what those rules require in your case.

11. Your rights

As the data subject you may exercise the following rights:

  • Access: find out what data of yours we process and obtain a copy.
  • Rectification: correct inaccurate data.
  • Updating: complete incomplete or outdated data.
  • Erasure: request deletion of your data, within the limits set by law.
  • Objection: object to processing where applicable under the relevant law.
  • Suspension of processing: request that it be temporarily halted, in the cases the law provides for.
  • Portability: receive your data in a reusable format, where applicable.
  • Other rights: any other right granted to you by applicable data protection law.

12. How to exercise them

You can exercise any of these rights by writing to nexyra.iptv@gmail.com, stating which right you wish to exercise.

To protect your data against third-party requests we may ask you to verify your identity, for example by writing from the email address linked to the account.

We will handle the request within the periods set by applicable law. If you believe it has not been handled properly, you may contact the competent data protection authority.

13. Providers and third parties

We rely on providers for infrastructure, email delivery, storage, payment processing and monitoring. We share with them only the information needed to run the service.

The providers of the sources you connect are unrelated to us: when the player accesses your source, it is your provider that receives that connection and applies its own policies.

14. Connection test

The "Speed test" feature has two parts, and both run directly from your device, without going through NEXYRA's servers. NEXYRA does not receive or store the results.

  • Internet test: your device downloads and uploads test data directly from speed.cloudflare.com, a service operated by Cloudflare, Inc. In doing so, Cloudflare may receive your IP address, an estimate of your location (country and city) and the autonomous system number (ASN) of your Internet provider, and handles them under its own privacy policy, over which NEXYRA has no control. We do not send Cloudflare your account, email, device identifier or any other NEXYRA data. This part uses up to about 46 MB of data.
  • Provider test: your device connects directly to your IPTV provider, just as when you play a channel, and downloads a sample of up to 4 MB for a few seconds. Your provider receives that connection and may count it toward your line's connection limit. To run the test, the app uses the same playback information it already uses to play your content. The test does not send NEXYRA any additional information about your provider and does not store the measurement results on our servers. Credentials and full URLs are not included in logs or in the shared result.
  • What is kept: the latest result is stored only on your device. If you choose to share it, the generated text does not include credentials, your provider's address, or identifiers of your account or device.

15. International transfers

Part of the infrastructure we use is hosted outside Ecuador. Where this involves an international data transfer, it is carried out with providers offering adequate safeguards and in accordance with applicable law.

16. Security

We apply reasonable technical and organisational measures: credential encryption at rest, encrypted transport, access control, request rate limiting and removal of secrets from logs.

No system is invulnerable, and we do not claim otherwise. What we do is keep no more data than necessary and avoid exposing what we keep.

17. Minors

NEXYRA is not directed at minors without appropriate legal supervision.

18. Changes to this policy

This policy is versioned. When a new version is published, its effective date will be stated.

Material changes require fresh acceptance before further purchase operations. Editorial corrections that do not alter processing do not.

Contact

If you have questions about this policy or wish to exercise your rights, write to nexyra.iptv@gmail.com.