The eyes are bars. By design.
The public privacy notice for twiga player and the twiga service — the web player, the account system, APIs, and twiga.tv. (An Android TV / Google TV app is in development, not part of this beta.) What we process, why, and the long list of things we deliberately don't.
Last updated: 2026-09-03
Controller
- Controller. twiga (private beta — company registration in progress).
- Contact. [email protected] for rights requests, deletion, and questions.
- DPO or representative. None currently designated. Use the contact above.
What we process
- Account & auth. An optional email address (an account can hold none), user ID, display name, sign-in state, your account's public key (your twiga key signs you in — we hold the public half, never a password), and session records for the duration of a session. We do not store your IP address in these records.
- Source credentials. Your M3U/Xtream credentials, sealed in your browser and stored only as ciphertext. twiga opens them in server memory while you watch, then wipes them on idle or restart.
- Operational logs. Minimal security and reliability logs, retained briefly, then rotated.
- Recovery. Account recovery uses a recovery code that identifies your account. No email is required.
Program guide
twiga adds program-guide (EPG) data to your channels — what airs when. It is public TV schedule data only: the same facts on any listings website, fetched over Tor and kept to your own list. Your guide is never pooled with anyone else's, and never built from anyone else's — no credentials, no viewing history, no identity leaves your account.
Payments
Paid plans are settled in Monero, from a wallet you hold. twiga stores no card number, bank detail, or billing address, and asks for no government ID. A payment funds your access without a stored link back to your account — the same principle as your sealed login, applied to paying: what we can't tie together, we don't.
What twiga does not do
No customer data for third-party advertising or cross-app tracking.
We never sell or rent personal data to anyone.
No automated decisions with legal effects under Article 22 GDPR.
Scope
- Covered surfaces. twiga player (the web player today; an Android TV / Google TV app is in development, not part of this beta), twiga.tv, related public pages, twiga account APIs, and support or account-management interactions.
- Not covered. Third-party content providers, playlist providers, metadata providers, or websites and services not operated by twiga.
Categories of data twiga processes
- Account and authentication data. An optional email address (attachable later; an account may hold none), user ID, display name, sign-in state, your account's Ed25519 public key (used to verify your key at sign-in — twiga holds the public half, never a password), login session records (no IP address is stored), and account-security records.
- Source, playlist, and channel data. Source names, playlist or guide URLs, encrypted source credentials, imported channel metadata, and playlist selections linked to the account.
- Playback, operational, and diagnostic data. Stream session records (bytes transferred, startup timing, exit reason — no IP addresses, no channel or content identifiers), relay usage, performance data, audit records, and diagnostics needed to operate, secure, and improve the service.
- Support and communications data. Support emails, verification records, onboarding records, and account-management messages.
- Payment data. twiga stores no card, bank, or billing-identity data. Paid access is settled in Monero from a wallet the user holds, and is not linked to the account — twiga keeps only the fact that an account has paid-through time, never who paid or how.
- Local app data. A future native TV app may store a session token in the platform's secure keystore and cache playlist, favorites, or last-channel state on the device.
Purposes and legal bases
- Account creation, sign-in, and session management. Legal basis: performance of a contract under Article 6(1)(b) GDPR, plus legitimate interests under Article 6(1)(f) for account security and fraud prevention.
- Source handling, playlist organization, EPG, and playback delivery. Legal basis: performance of a contract under Article 6(1)(b).
- Security, abuse prevention, rate limiting, and reliability. Legal basis: legitimate interests under Article 6(1)(f), including protecting infrastructure, credentials, sessions, and service availability.
- Security alerts and account recovery. During the beta twiga sends no email — security events appear in your Activity tab when you sign in. If you attach an email later, alerts can also be sent there, separate from marketing. Legal basis: our legitimate interests in keeping your account secure and recoverable (Article 6(1)(f) GDPR).
- Support and account-management replies. When you contact us, or use a feature that needs a reply, we use your attached email to respond. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- Marketing communications. Marketing email is sent only to an address you have attached and only if you give a separate, explicit opt-in. Consent is not required to use twiga. The opt-in is unticked by default, is never bundled with accepting the Terms or this notice, and can be withdrawn at any time in settings — removing your email also withdraws it. No marketing is sent to an address that has not opted in. Legal basis: consent under Article 6(1)(a) GDPR.
- Compliance and legal requests. Legal basis: legal obligation under Article 6(1)(c), plus legitimate interests under Article 6(1)(f) where rights must be enforced or defended.
- Server access logs and operational monitoring. Legal basis: legitimate interests under Article 6(1)(f) for security, abuse prevention, and infrastructure reliability. Logs are access logs only — no behavioural or user tracking.
Recipients and service providers
- Edge and infrastructure. Cloudflare operates the edge for all twiga.tv traffic — the player, the stream path, and adding a source included. It terminates TLS at the edge, so it processes your IP address and the encrypted bytes in transit under its own terms as a processor. It never sees inside your sealed vault. On the sign-up step, Cloudflare Turnstile runs a bot check. twiga also uses hosting and network infrastructure to deliver the service.
- Email. During the beta twiga sends no email — there is no email provider in the loop. Security and account events appear in your Activity tab when you sign in. If email sending is turned on later, it will go out from twiga's own systems, with no email company in between, and email will never be your only copy.
- Relay and network infrastructure. twiga may use infrastructure or relay providers that support secure service delivery.
- Server logs and operational monitoring. twiga's application request logs record the HTTP method, path, status code, and user agent — no client IP address. Rate limiting uses in-memory counters, not stored IPs. Admin actions are audit-logged with the acting admin's own IP. Logs are rotated, not kept indefinitely. (Cloudflare, as the edge, processes IP addresses under its own terms — see above.) twiga uses self-hosted, cookieless page-view analytics (Umami) to measure aggregate traffic. No personal data is collected, no cookies are set, and no cross-site tracking is performed.
- Legal and transactional disclosures. twiga may disclose data where required by law or in connection with a merger, financing, or similar transaction.
International transfers
twiga and its service providers may process personal data in countries outside the country where the user lives. Where twiga transfers personal data outside the EEA, UK, or Switzerland, twiga intends to rely on lawful transfer mechanisms such as an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another mechanism permitted by applicable law.
Users may request more information about relevant transfer safeguards by contacting [email protected].
Cookies and similar technologies
- Essential session cookies. twiga uses session cookies on the web to keep users signed in, protect authenticated routes, and maintain session integrity.
- Device storage in native TV apps. A future native TV app would use the platform's secure keystore and local preferences instead of browser cookies.
- No advertising cookies described here. twiga does not describe the current product as using third-party advertising cookies or cross-site tracking technologies.
Retention and deletion
twiga keeps personal data only for as long as needed for service delivery, security, support, dispute resolution, and legal compliance. Account records and configured source data are generally retained while the account remains active. Session records expire and may be rotated or deleted after expiry. Security, audit, and diagnostic records are retained only for as long as needed for fraud prevention, troubleshooting, reliability analysis, and legitimate business operations. Local app data remains on the device until it is cleared, replaced, or removed by the user.
Consent records. Where you opt in to or withdraw from marketing email, twiga keeps a versioned record of that choice as an audit trail. It is kept for the life of your account and for a limited period afterwards, only to evidence the lawful basis for any messages sent.
Until self-service account deletion is fully shipped across every client surface, account-deletion and rights requests can be sent to [email protected].
Rights and complaints
- Rights. Subject to applicable law, users may have rights of access, correction, deletion, restriction, objection, and portability.
- Withdrawal of consent. Marketing consent is a separate, explicit opt-in. You can withdraw it at any time in settings, and removing your attached email also clears it. Withdrawal does not affect processing carried out before you withdrew.
- Complaint right. Users have the right to lodge a complaint with the supervisory authority in the EU or EEA member state where they live, work, or where the alleged infringement took place.
- Verification. twiga may request reasonable information to verify identity before acting on a privacy-rights request.
Whether providing data is required
- Account data. None required. An account is a key: creating one needs no email, name, or other details from you. An email is optional. Attach one for email-based recovery and security alerts, or for marketing if you separately opt in.
- Source data. Source details and credentials are needed if you want twiga to fetch, organise, and relay that source.
- Operational data. Some session, device, and network information is processed automatically because it is necessary for authentication, delivery, and security.
- Consequence. Creating an account needs no details from you. If you do not attach an email, twiga cannot send you email-based recovery or security alerts. Source features still require the relevant source details.
Privacy contact
Privacy questions, rights requests, and account-deletion requests can be sent to [email protected]. Until final company registration details are published, this page should be read as twiga's current beta privacy notice.