Sign in
Privacy Policy

Your viewing data stays limited to what Tuneris needs.

Last updated September 16, 2026. Tuneris is operated by Twentythree Dev LLC. This policy describes the Tuneris Android TV app, customer portal, and cloud control plane.

Information we process

We process the email address and basic profile information supplied through Google or email sign-in; subscription, payment-channel, entitlement, and renewal status; paired-device names and technical details such as model, Android and app version, network type, storage summary, last contact time, synchronization health, and Play Integrity risk signals.

For same-device recovery, the Android app locally derives continuity material from Android's app-signing-scoped device identifier, the Tuneris package name, and the app-signing certificate. Tuneris receives a domain-separated lookup hash rather than the raw Android identifier, and protects that lookup again with a server-only keyed hash. This is disclosed as a Device or other ID and is used only to recognize a previously paired TV on the same Android user and device after reinstalling or clearing app data, restore its account-managed state, prevent duplicate slots, and protect the account. Removing a device revokes that recovery path.

If cloud synchronization is enabled, Tuneris stores the account profiles, profile restrictions and PIN verifiers, playlists, guide assignments, favorites, saved movie and show provider identifiers used by Watch Later, hidden and ordered items, search state, viewing history, playback progress, reminders, recording schedules, and user-facing settings selected for synchronization. Watch Later does not upload catalog titles, artwork, or stream URLs. Playlist endpoints and provider credentials are encrypted; administrative views remain redacted.

Information that remains on the device

Channel and programme catalogs, VOD and series catalogs, search indexes, artwork and metadata caches, application logs, timeshift buffers, offline downloads, Android storage permissions, and recorded media files remain local. Offline downloads and timeshift are excluded from cloud and custom backup. Tuneris does not request Wi-Fi passwords, precise location, advertising identifiers, or owner account passwords.

Optional reliability diagnostics

On paired staging and production devices, Share anonymous reliability diagnostics defaults on and can be turned off at any time. Tuneris records only the UTC day, app build, exit kind, aggregate count, and a one-way fingerprint derived from the exception type and up to eight normalized Tuneris class and method names. Messages, line numbers, file names, URLs, provider, channel, account, viewing, token, email, PIN, and full device-identifier data are never stored or uploaded in these reports. The device keeps at most 20 aggregates covering at most 100 events until the service acknowledges them; disabling the choice immediately deletes the queued reports. Acknowledged service aggregates are restricted to service access, follow account deletion, and are retained for no more than 90 days.

Google TV personalization

Google TV recommendations and Continue Watching publishing are disabled unless the device is eligible, the active linked account and adult profile allow it, and the owner turns on cloud-synchronized personalization consent. When enabled, Tuneris can publish a bounded snapshot of eligible titles, artwork, availability, deep links, and meaningful VOD or episode continuation progress to Google TV. Child profiles and timeshift positions are never published. Revoking consent, unlinking, deleting or switching profiles, activating a child profile, or permanently losing access triggers deletion of the published snapshot.

Why we use information

We use this information to authenticate the account owner, pair and manage devices, calculate device allowance, provide subscriptions, synchronize requested data, apply remote settings, diagnose failures, send selected service notices, prevent abuse, secure accounts, and comply with deletion, export, tax, accounting, and legal obligations.

Service providers and payment channels

Tuneris uses contracted infrastructure and service providers to operate the service. These can include Supabase for authentication and the control plane, Vercel for the portal, Google Cloud KMS for managed encryption-key protection, Stripe for website billing, RevenueCat for entitlement reconciliation, Google for sign-in, Google Play billing and Play Integrity, and an email delivery provider. Payment card details are handled by the payment provider rather than stored by Tuneris.

Retention and security

Access is restricted by account and device identity. Exposed database tables use row-level security, device sessions are device-scoped, and synchronized provider credentials use envelope encryption. Account keys are wrapped by Google Cloud KMS with restricted service authority and audit logging, which means Tuneris can technically recover those keys to serve an authenticated account or device. Portal provider editors receive keys encrypted to an ephemeral browser key and keep the unwrapped values in memory only. Removing a device, deleting the account, or disconnecting account access revokes that device's recovery proof and session. Synchronization tombstones are retained for at least 90 days and until active devices have advanced past them. Security, billing, audit, and transaction records can be retained longer where needed for fraud prevention, accounting, dispute handling, or law.

Your choices and rights

You can control optional health notifications, anonymous reliability diagnostics, and Google TV personalization; remove paired TVs; edit synchronized information; and request a machine-readable export from Data & privacy. A paired TV remains managed by your account and restores synchronized state after an app reinstall or data clear until you explicitly remove it. Before selling or giving away a device, use Remove this device on the device or Remove device in the portal; uninstalling the app or clearing its data is not an ownership transfer. You can also schedule account deletion in the portal. Deletion has a seven-day cancellation period before processing. See the account deletion instructions for the exact flow.

Children and changes

Tuneris is not directed to children and the account owner is responsible for account profiles and content restrictions. We may update this policy as the service changes. Material changes will be posted here and, when appropriate, announced through the account.

Contact

Questions about privacy or account data can be sent to support@twentythreedev.com.