Privacy

Global Privacy Notice

How DIXJUIN LTD processes account, device, subscription, support and user-directed source data in PlaysAll.

1. Controller and scope

DIXJUIN LTD, company number 16274568, registered in England and Wales, with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF is the controller for personal data processed to operate PlaysAll accounts, applications, the website and related services. Contact privacy@dixjuin.com for privacy matters.

This notice covers data handled by Dixjuin. A media provider, app store, device platform or external website may independently process data under its own notice.

2. Product boundary and your media provider

PlaysAll does not supply channels, playlists or media. You choose and add a source that you are authorised to use. Direct-play clients normally contact that provider directly. On supported Smart TV clients, catalog or playlist requests may be relayed through the authenticated PlaysAll provider gateway because television browsers restrict those requests.

Your provider receives the information needed to answer your request and applies its own terms. If you use an HTTP rather than HTTPS source, credentials and responses can travel unencrypted between the requesting client or gateway and the provider. PlaysAll never bypasses certificate errors.

3. Personal data we process

We collect most data directly from you or the PlaysAll client and device you use. We receive purchase, payment-status and entitlement events from the purchase channel you choose, including app stores, Stripe and RevenueCat; request and security metadata from our infrastructure providers; and provider catalog or playback responses only when you direct PlaysAll to contact your chosen media source.

If you choose Apple or Google sign-in in a supported Apple app, or Facebook sign-in on Android or the web, that provider processes the authentication request and returns a signed token and identity claims needed to authenticate or link your PlaysAll account. Google states that Google Sign-In may process an IP address and use it to estimate the device's general location for fraud prevention.

CategoryExamplesMain purpose
Account and profileEmail, display name, avatar, account ID, adult/child profile typeRegistration, sign-in, profiles and support
Optional social sign-inProvider user ID, signed authentication token, available name/email, and IP address or general device location processed by the selected providerAuthenticate or link the account, prevent fraud and protect the sign-in flow
Credentials and securityPassword and parental-PIN salts/hashes, tokens, consent version and timestampAuthentication, parental controls and proof of acceptance
DeviceInstallation hash, device token hash, device name, platform/OS/app version, created, last-seen and revoked timesDevice registration, limits, pairing and security
Source and playbackSource URL, Xtream username/password, encrypted source envelope, source ID, favorites, recent items and progressConnect to your chosen provider and provide player features
Subscription, web purchase and usageAccount ID, product, purchase channel, purchase country/region, currency, entitlement/expiry, provider transaction or customer reference, event ID/type/time, daily reserved playback secondsCreate and manage Pro access, restore purchases, reconcile billing, prevent duplicate events and apply Free limits
Support and networkMessage content, attachments you choose, IP address, request ID, timestamps and security logsAnswer requests, prevent abuse and operate secure infrastructure

4. Source credentials and local storage

Apple and Android clients use protected application storage for source credentials. Smart TV clients encrypt saved source credentials with AES-256-GCM in the television’s application storage; the client must also be able to access the local encryption key to use the source. Protect the device account and remove the source before transferring or disposing of a device.

Favorites, recent items, playback progress, search and category preferences, subtitle settings, active profile and similar player state may remain locally until you remove the source, clear app data or uninstall the app.

5. Encrypted sync, pairing and the Smart TV gateway

If you enable source sync, credentials are encrypted on the client using AES-256-GCM before upload. PlaysAll stores the nonce, ciphertext, version and source identifier; the service does not receive the plaintext sync key. A temporary QR/pairing transfer becomes unusable after no more than ten minutes and clears the ciphertext earlier when it is consumed. Expired pairing rows and any unconsumed encrypted transfer material are physically purged by scheduled maintenance no later than 24 hours after expiry.

The Smart TV provider gateway receives source connection details inside an encrypted TLS request, forwards the request to your provider, enforces host, redirect, timeout and response-size controls, and returns the response. Application code does not write provider credentials or provider response bodies to the database, files, analytics or application logs. Infrastructure providers may still process limited request and security metadata.

6. Purposes and lawful bases

An account email, password, required consent record and basic device/security data are necessary to create and authenticate an account and deliver account-connected features; without them, those features cannot be provided. Source connection details are necessary only when you ask PlaysAll to connect that source. Profile customisation, support attachments, encrypted source sync and optional marketing consent are optional, and declining them does not prevent unrelated core features.

PurposeLawful basis where GDPR/UK GDPR applies
Create accounts, register devices, connect sources, sync encrypted envelopes and deliver player featuresPerformance of our contract and steps you request before entering it
Authenticate users, prevent fraud, rate-limit abuse and protect servicesLegitimate interests in service and account security; legal obligation where applicable
Manage purchases, entitlements, quotas, restoration and billing disputesContract, legitimate interests and legal obligations
Provide support and answer rights requestsContract, legitimate interests, legal obligation or consent depending on the request
Send optional product marketingConsent where required; marketing consent is separate, optional and off by default
Comply with law, enforce terms and establish or defend claimsLegal obligation and legitimate interests

7. Recipients and external services

RecipientRole and data
CloudflareWebsite, edge security, Workers, database and authenticated gateway infrastructure; request/security metadata and service records
HetznerAccess-restricted standby application, media and disaster-recovery infrastructure; service records and rolling database recovery copies
RevenueCatSubscription and entitlement administration; account identifier, product, store, environment, event and expiry information
StripePayment processing for direct web purchases; checkout, billing, tax, fraud and transaction information under Stripe’s own privacy notice. Full card details are entered into Stripe-controlled fields and are not received or stored by Dixjuin
Apple, Google and AmazonApp distribution, purchases, receipts, subscription management and fraud controls under their own terms; Apple or Google also processes identity and related security/network data when you choose that provider for sign-in
MetaFacebook sign-in only when you choose it on Android or the web; identity claims or tokens and necessary authentication/network metadata. Apple platform apps currently do not offer Facebook sign-in. Android uses standard Facebook Login, initializes its SDK on demand and disables SDK auto-initialization, advertiser-ID collection and automatic app-event logging; the web uses Meta's standard provider sign-in flow. Meta applies its own privacy notice
Your chosen media providerSource credentials, requested catalog/media path and necessary network metadata, as directed by you
Email/support providers and professional advisersSupport correspondence or limited records needed for security, compliance and legal claims
Authorities or transaction counterpartiesOnly when legally required or necessary for a genuine corporate transaction with safeguards

8. International transfers

Dixjuin is established in the United Kingdom. Service providers may process data in the United Kingdom, EEA, United States and other countries in which they operate. A restricted transfer will be made only when an applicable lawful mechanism is in place, such as an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or another permitted mechanism, together with supplementary safeguards where appropriate.

You may ask privacy@dixjuin.com for information about the safeguard relevant to your data. Your own media provider is selected by you and may be located in a country without equivalent privacy protection.

9. Retention

RecordRetention rule
Registered account recordsAccount, profile, other registered-device, consent, encrypted-sync and PlaysAll entitlement records are kept while the account is active, then deleted with the account unless a narrow legal exception applies
Current anonymous installation and one-time Free playback allowanceAfter account deletion, the current installation is de-linked and continues anonymously. Only pseudonymous device-authentication fields — its hashed installation identifier and authentication token — plus a neutral device label, platform and app/system versions, creation and last-seen timestamps, and its one-time Free playback allowance are retained to secure the service and prevent deletion/re-sign-up abuse, while the installation remains active and for no more than 180 days after it was last seen
Pairing session and encrypted transferAccess expires after no more than 10 minutes; ciphertext is cleared earlier when consumed, and expired rows and any remaining encrypted transfer material are physically purged no later than 24 hours after expiry
Playback leaseUntil its short authorisation window expires
RevenueCat customer and webhook recordsA customer-deletion request is sent to RevenueCat when the PlaysAll account is deleted. Our account reference is removed from retained webhook events, and those de-linked events are kept for no more than 180 days
Direct web purchase, tax, refund and dispute recordFor the period required to perform the purchase and then as required by applicable tax, accounting, fraud-prevention, chargeback and legal-claims duties; provider-held records follow the provider’s policy
Administrative security audit365 days
Infrastructure request and security metadataFor the period made available under the active hosting/security configuration; an exported incident record may be retained for up to 365 days or longer when a legal claim requires it
Disaster-recovery copiesCloudflare D1 point-in-time recovery history remains within the provider’s applicable window, no longer than 30 days. Access-restricted Hetzner daily database copies use a rolling maximum of 14 copies. Deleted data may remain only in these recovery copies until rotation; it is not used for normal operation, and deletion controls must be reapplied if a recovery copy is restored
Local player dataUntil you remove the source, clear application data or uninstall
Support correspondenceNormally 24 months after the last substantive contact; a restricted record may be kept longer when tax, fraud, security or claim law requires it

10. Security and incident handling

We use hashed passwords and tokens, protected device storage, encryption for synced source envelopes, access controls, response-size limits, timeouts, rate limits and credential redaction. No system is completely secure. Keep device software current, use unique passwords and never send source credentials to support.

We assess suspected incidents and notify regulators or affected people when applicable law requires it.

11. Your rights and choices

Depending on your location and the processing, you may request information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, or review of a qualifying automated decision. PlaysAll does not make decisions producing legal or similarly significant effects solely by automated processing.

We do not sell personal information, share it for cross-context behavioural advertising or use personal data for behavioural advertising. Facebook sign-in is currently offered only on Android and the web; Apple platform apps do not offer it. Android uses standard Facebook Login with SDK auto-initialization, advertiser-ID collection and automatic app-event logging disabled, while the web uses Meta's standard provider sign-in flow. We will not discriminate against you for exercising a privacy right. We may verify identity and authority before acting.

12. Your separate right to object

Where we rely on legitimate interests, you have the right to object at any time on grounds relating to your particular situation. We will stop the affected processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. If personal data is ever used for direct marketing, you may object at any time and that marketing processing will stop.

13. Regional information

  • EEA: you may complain to the data protection authority where you live, work or believe an infringement occurred. Mandatory GDPR rights and local consumer rights remain unaffected.
  • United Kingdom: you may complain to the Information Commissioner’s Office (ICO). Contact us first so we can try to resolve the concern.
  • California and other US states: where applicable, you may request access, correction or deletion and opt out of sale, sharing or targeted advertising. We currently do not sell or share data for those purposes.
  • Brazil: you may exercise LGPD rights through privacy@dixjuin.com and petition the ANPD after first contacting the controller.
  • Canada and Australia: you may request access/correction and complain to our privacy channel before contacting the OPC, OAIC or applicable provincial regulator.
  • Türkiye: you may begin a KVKK request through privacy@dixjuin.com. A formal application must use the account email already recorded by Dixjuin or another method permitted by the applicable application rules and must include the legally required identity, contact and request details. Valid applications are answered within the statutory period.

14. Children

Accounts are for adults aged 18 or over. PlaysAll is not directed to children under 13 and does not ask a child to create an account. An adult may create a managed child profile with a profile name, avatar and profile type. Do not use a child’s full legal name. See the Child Safety page for controls and limits.

15. Changes and contact

We will update the date and version when this notice changes. If a change materially affects account processing, we will provide a prominent notice or request renewed acknowledgement where required. The current version is 2026-08-24.