Legal
Privacy policy
This policy covers SabiStream on Android, Windows, iPhone, iPad and Apple TV. Platform-specific sections explain differences in storage, backup, playback and deletion.
Last updated: 19 September 2026
Shared policy for Android, Windows and Apple devices
SabiStream is a neutral IPTV/media player. It supplies no channels, streams, movies, series, playlists, subscriptions or TV service. You add sources you have permission to use and are responsible for following the laws and terms that apply to them. Supported source types and features differ by platform. Each platform section below controls its own storage, backup, playback and deletion details; its numbered cross-references refer to that platform.
SabiStream does not operate a content or viewing-analytics server, include an advertising SDK, or sell personal data. Data needed for playback reaches your sources and their guide, artwork and stream hosts. Optional backups, system services, external apps and feedback can also receive data as explained below. A source URL or header may contain a credential. The absence of developer analytics does not mean no data leaves the device.
Local data is normally retained until you clear it, delete the relevant item, or use the applicable platform's erase control. Temporary caches may be removed sooner. An erase reporting a failure can leave cleanup outstanding. Provider records, exported files, another app's copies, system backups and cloud snapshots are controlled separately. Revoking a token or signing out does not by itself delete a cloud snapshot.
Website and configuration requests
sabistream.com is hosted on Cloudflare Pages. Serving pages and Android's configuration file involves IP address, requested path, request time, browser/app headers and connection/security metadata. The site's own files set no cookies and load no JavaScript, analytics, trackers, external fonts or third-party resources. This does not promise that the hosting service receives no request data.
Cloudflare handles request and security logging to deliver and protect the site. Those logs can contain the request information described above. Cloudflare retains and deletes them under its operational practices; this policy does not state a fixed retention period.
Feedback, contact and publisher
Feedback and diagnostic emails are kept only as long as needed to investigate and fix the issue. Ask for access or deletion at privacy@sabistream.com. General support: support@sabistream.com. Both addresses are monitored. We cannot erase a provider's account or a copy retained by an app or storage service you choose.
SabiStream is the publisher and data controller for the limited data it receives as described in this policy. Publisher details are available on request at privacy@sabistream.com.
Children and changes
SabiStream is a general-purpose media player, is not directed at children, and does not knowingly collect information from children. Parental controls help an adult manage a shared device.
We may update this policy as the apps change. The last-updated date above identifies the current public version. Significant new data uses require appropriate disclosure and consent before they begin.
Android
2. Your playlist logins
When you add a playlist, the primary sign-in record (server address, username, password, portal/MAC or playlist URL) is held in Android encrypted storage. The app uses it to authenticate and request your catalogue, guide and streams from your source and the destinations it supplies. SabiStream does not receive your provider login. Optional backups, Cast and external-player handoffs can carry credentials as described below; a stream or artwork address can itself contain a credential. Review your provider's privacy and security practices.
If you add an SMB/network share (a NAS, router disk, or shared PC folder), its host, share name, domain, username, and password are also kept in Android encrypted storage. They are device-local, are never included in a manual backup or Google Drive snapshot, and are sent only to the server you configured so the app can browse and play its files. When you configure a server on your local network, the app connects to it directly. The app does not enforce a local-network-only destination. Transport encryption depends on the SMB server and negotiated SMB version and is not guaranteed by the app; use this feature only on a network and server you trust. Playlist logout keeps these separate network-share settings. Removing the share, Reset app, Clear storage, or uninstalling removes them.
Providers can embed credentials in stream and playlist addresses. Working data also lives in the app's private databases, caches and settings; do not assume all of it has the primary sign-in record's separate encryption. The app opts out of Android system backups. Current download-index writes remove credential-bearing URLs and keep non-secret references so addresses can be resolved again. Old files may have different protection until migrated or deleted. Deleting a playlist clears its source data and matched download addresses; completed video can remain, while matched incomplete downloads are removed. Unmatched legacy entries may need individual deletion. Reset app, Clear storage and uninstall remove app-private files; exported copies and external recordings have separate deletion rules.
Logging out ends the active session and clears the stored sign-in, including your saved passwords. The playlists themselves (name, server address, username) and your favourites, history and recordings stay on the device, so you can sign back in by re-entering the password. Logging out also resets some display and guide preferences — among them locked categories, your EPG source choices, overrides and ordering, which playlists are switched on, section sort orders, the recording folder you picked and the reminder lead time. To remove a playlist completely, delete it or use Reset app.
2a. Filling the TV login from your phone
On TV, the login screen offers "Fill this form from your phone": the TV briefly runs a tiny local web page on your home network and shows a QR code. What you type on the phone is encrypted on the phone with a one-time key that travels only inside the QR code (browsers never send that part of a link over the network), so it crosses your Wi-Fi as ciphertext readable only by that TV pairing session. It goes directly from your phone to your TV on your local network — it never touches the internet or any server, and nothing is stored beyond filling the TV's login form. Each pairing link works exactly once and expires after at most 10 minutes.
Be precise about what this protects: it defends against someone passively listening on the network (they see only ciphertext) and against tampering with what you send (altered submissions are rejected). Because the pairing page itself is delivered over your local network without a certificate, it cannot defend against an actively hostile network — an attacker who controls the Wi-Fi could substitute the page before encryption happens. That is why this feature must only be used on Wi-Fi you trust, such as your own home network, and never on public or shared networks. If you cannot trust the network, type the details on the TV instead.
3. What the app stores locally
The app stores the following on your device. SabiStream does not automatically receive your local library. Optional backup, feedback and handoff paths are described separately. Parental PIN and recovery records are also kept locally; a portable salted PIN verifier, but not the recovery route or clear PIN, can be included in backups.
- Your playlists, favourites, My List, hidden channels/categories, locked channels/categories, watch history, Continue Watching positions, watched episodes, reminders, series you follow for new-episode/season alerts, EPG choices, category customisations, and app settings.
- Your saved SMB/network-share connections, including any share username, password, and domain, in Android encrypted storage as described in section 2.
- Recent searches — the last 10 search terms you used (typed, or the text produced by voice search). A term is remembered only when you open a result from that search, and very short terms (under two characters) are never kept. They stay on the device, are not included in backups, and can be cleared at any time (Settings ▸ Privacy & data ▸ Privacy & security ▸ Clear search history). They are also cleared by Reset app.
- Diagnostics kept locally — a note about the most recent crash and a small rolling log of recent errors, stored only on the device to power the optional "Send feedback" report. They are never transmitted automatically (see section 5) and are erased by Reset app.
- Offline downloads (phones/tablets only) — optional copies of movies/episodes you choose to download. They are stored ONLY in the app's private storage and encrypted with a key held in this install's secure storage: other apps normally cannot access them, and the files are not playable without this installation's key — deliberately, out of respect for content providers. Delete them in the Downloads screen; uninstalling or resetting the app removes them all. Never part of backups.
- Live rewind buffer — "Pause & rewind live TV" (on by default; turn it off in Settings) keeps a rolling copy of the channel you are currently watching in the app's cache so you can pause and rewind. By default it holds up to the last hour, or less if your device recommends a shorter window — whichever is smaller. You can choose anything from 5 minutes to 3 hours in Settings, and every choice is additionally fitted to your free storage: the buffer can never exceed the ceiling for your device's performance tier (about 512 MB on Low, 2 GB on Balanced, 8 GB on High), and on a storage-limited TV device it may hold less than the minutes you chose. On mobile data the buffer is skipped by default, so channels simply play without rewind; you can allow it on mobile data (Settings ▸ Player & live streams, or the prompt shown the first time you press rewind there). Allowing it does not download the channel twice — the buffer is a copy of the stream you are already watching — but it does keep recording while you are paused or watching behind live, which uses data the stream would not otherwise have used. It is deleted automatically: when you close the app, shortly after you settle on another channel, or when storage runs low; if Android terminates the app abruptly, any leftover buffer files are removed at the next launch. It never leaves the device. The buffer does not open an extra connection to your provider — see section 7. Choosing Save rewind retains the selected part as a recording, subject to the recording and external-player rules; it is then no longer only a temporary rewind buffer.
- Recordings — see section 3a.
App-language translations are bundled inside the app and applied on your device — nothing you view is ever sent anywhere to be translated.
3a. Recordings
New recordings are saved as encrypted containers using this installation's secure-storage key, in private app storage by default or a folder you choose, such as USB or SD storage. They do not leave the device automatically. A copied container needs the installation key to play. App-private recordings are removed with Clear storage or uninstall; a user-selected external folder can retain files after uninstall, and losing the key can make those files unplayable. Reset app also attempts to delete tracked external recordings. Check any reported failure and remove remaining external files with a file manager. Backups do not contain recordings or the installation media key. Explicit external-player handoffs can expose playable video to the app you select.
4. Backup and sync
You can use manual encrypted backup files and, if you choose, Google backup/sync.
- Manual backup: every backup file the app writes asks you first for a password of at least 8 characters and is encrypted with that password. There is no path in the app that saves a backup file without one — including the “Back up now” offer shown just after you add your first playlist, which earlier versions saved without asking. Keep the password somewhere safe: without it the file cannot be opened by anyone, including us. You choose where the file goes — device storage, USB storage, email, or your own cloud storage — and we do not receive it. Files written by older versions used a key built into the app instead of a password; those remain readable, so an old backup still restores.
- Google backup/sync — protected differently: if you sign in with Google backup, the app stores an encrypted SabiStream snapshot in your Google Drive app data folder (
appDataFolder). This folder is private to this app, hidden from your normal Drive files, and tied to your own Google account. This snapshot is not protected by your manual-backup password. It is encrypted with a key built into the app, so what actually keeps it private is your Google account and Drive's app-data isolation — it is not end-to-end encrypted with a secret known only to you. The two are separate features with separate protection; neither is a substitute for the other. The snapshot is used to restore and sync shared app data across your phone, tablet, and TV. - Cross-platform favourites file: favourites are additionally kept in a second, small encrypted file in the same private Drive app data folder so they can be shared with SabiStream on Windows/desktop (and other supported platforms). It contains each favourite's content type and provider item ID, display name, logo address, category, edit time, and deletion marker. It follows the same automatic-backup switch as the main snapshot. The current compatibility format is used only while exactly one playlist source is configured on Android; with multiple sources the app leaves this file untouched rather than risk attaching a favourite to the wrong provider.
- What the app keeps about your Google session: the email address of the Google account you selected (stored on the device to label the backup account in Settings) and a short-lived Drive access token. The token is held in memory only — it is never written to disk — and the app asks Google Play services for a fresh one when needed. Signing out of Google backup removes the stored email; you can additionally revoke SabiStream's Drive access at any time from your Google Account's security/permissions page.
- What syncs by default: playlists/logins, a portable salted parental-PIN verifier, source/account grouping, sync origin and change metadata, favourites, My List, hidden/locked content choices, EPG choices, reminders, series you follow for new-episode/season alerts, Continue Watching, watched episodes, watch history, recently/most watched data, category customisations, channel collections you create, per-channel customisations (renames, custom icons, per-channel EPG offset and audio/video sync), your custom User-Agent, and records of what you deleted, so that a deletion made on one device is repeated on the others. Recording schedules travel as the schedule itself only (never another device's alarms or files) and arrive switched off, labelled “Backed up — inactive on this device”; nothing records on a device until you explicitly turn schedules on there.
- What stays device-specific, and how. There are two different groups here, and they are protected in two different ways:
- Carried, but never applied from another device: theme, text size, interface scale, TV remote behaviour, phone gestures, subtitle appearance, buffer and decoder choices, startup behaviour and similar display or player preferences. These ARE in the snapshot, so a manual “restore everything” onto a brand-new device can reproduce your setup, but a normal restore or a background sync never applies them — your TV's larger text and your phone's gestures are not overwritten by each other.
- Never enters a backup: the performance level the app measured for this device, the recording folder and channel-logo folder you granted access to, saved SMB/network-share connections, the pause-and-rewind (live buffer) settings, how many simultaneous connections this device may use, the app-lock/screenshot settings, which playlists are switched on here, whether automatic Google backup is on, and the app's record of which Android permissions you granted. None of these is written into any backup file or cloud snapshot, in any mode. SMB details leave the device only when used to connect directly to the server you configured (section 2); the other items remain local. A restored device works these out for itself, which is why restoring a phone backup onto a TV cannot push the phone's performance settings, share credentials, or storage choices onto it.
Recent searches, downloaded files, recordings, the live-rewind buffer and local diagnostics (section 3) are never part of any backup.
- After you opt in, the app backs up automatically in the background when your data changes, until you sign out or turn automatic backup off.
- Wiping Google backup: Settings deletes the current and previous main snapshots and the separate favourites file from your private Google Drive app data folder. This does not delete local data on the device. Automatic uploads remain paused after a wipe so the deleted data is not silently recreated; signing in again or explicitly choosing Back up now resumes them.
5. Error and crash reports
SabiStream does not automatically upload its local crash or diagnostic reports. If you choose feedback or an error report, the app opens an email draft for you to send. Its optional technical report is encrypted to the developer's public key and known credential patterns are redacted before inclusion. Free text you type and your email sender details are also received if you send the message; avoid including credentials. Redaction cannot guarantee that every possible secret in an unusual error message is recognised. A report may contain the app version, device model, Android version, and technical error details. Sending is always your choice.
Retention of what you send: feedback and diagnostic emails arrive in the developer's mailbox and are kept only as long as needed to investigate and fix the issue. You can ask for your messages and any attached report to be deleted at any time, by emailing privacy@sabistream.com (see Feedback, contact and publisher above).
6. No developer analytics, ads, or playlist sales
SabiStream contains no advertising SDK and runs no developer-operated analytics or behavioural profiling. We do not sell data. SabiStream does not sell, provide, recommend, or bundle IPTV playlists or subscriptions.
Google Cast: if you enable the Cast setting, Google's Cast framework may automatically send anonymized app-interaction, device, and client metadata to Google for Cast service operation and analytics under Google's privacy policy. Cast is off by default on phones, tablets and TVs. Keeping it off prevents SabiStream from initializing the Cast framework. Once enabled, SDK collection can begin before you start casting. Google describes its Cast SDK logs as encrypted in transit, with raw logs retained briefly and aggregate information kept for service improvement; the SDK provides no user/developer collection opt-out or deletion control. Switching the app's setting off is not a promise to erase data Google already received. In addition, when you start casting, the app sends the selected stream's address, its title/subtitle, and its artwork address to the Cast receiver you chose — that transfer is what makes casting work. Be aware that some IPTV providers embed your playlist username/password or an access token inside stream addresses, so casting on a shared or unfamiliar receiver shares that address with it.
7. Network connections
The app connects over the internet only to:
- the IPTV service, portal, playlist URL, programme-guide source, artwork URL, or stream URL you add or that your source provides (including a guide address your playlist itself announces via its
url-tvgheader; when you download a movie or episode, up to the number of simultaneous connections you allow for that playlist — 1 by default, at most three — fetching different parts of the file at once; and, while new episode/season alerts are enabled — they are on by default and can be turned off in Settings ▸ Notifications — a periodic check, a few times a day including in the background, that asks your own provider for the current episode list of the series you follow; if you follow no series, this check contacts nothing). Live rewind does NOT add a connection: the app opens one connection per playing channel and splits that single stream on your device between playback and the rewind buffer; - Google services when you choose Google sign-in/backup (including automatic background backups after you opt in);
- Google Cast services when you enable Cast, and the receiver you choose when you cast; SDK service/analytics traffic may start before a receiver connection;
- Google Play, through the official in-app update service, which handles device metadata, this app's version and its installed module/asset-pack list to determine update availability and size. Google encrypts that service's data in transit and retains it for its stated fixed retention period. Choosing Rate on Google Play opens this app's store listing in the Play app or your browser; any review you submit is handled by Google. Optional feedback from the rating prompt can include the stars you selected in the email subject.
- sabistream.com, normally at most once per 24-hour interval, to fetch
/app/config.jsonfor support/privacy contacts, legal links and, for eligible non-Play installs, update information. The app supplies a generic SabiStream User-Agent and no account, playlist or usage payload. Cloudflare necessarily receives connection and request metadata, including IP address, requested path, time and headers. See the shared website disclosure for retention. Clearing app data or reinstalling can restart the interval. If the file is unavailable or invalid, built-in contacts and links remain available. - your email provider when you choose to send feedback.
Data-network choices are yours: downloads wait for Wi-Fi and the live rewind buffer is skipped on mobile data unless you allow each of them (Settings ▸ Downloads / Settings ▸ Player & live streams, or the one-tap offers shown where the wait happens). Watching itself is never blocked by these settings — only the extra background traffic is.
SabiStream provides no content server. Its automatic SabiStream-domain request is the configuration check described above; opening support, legal or download pages also contacts the website in your browser. SabiStream prefers HTTPS when available, but user-supplied HTTP sources are not encrypted in transit. Android's guarded provider clients reject HTTPS-to-HTTP redirects. Use HTTPS sources wherever possible.
7a. Voice search
The microphone button in Search hands off to your device's own speech-recognition service (for example Google's). SabiStream never records or receives audio — it receives only the recognized TEXT of what you said and runs it as the search query. Like a typed query, a spoken query can then be kept in the on-device Recent searches list (last 10) so you can repeat it easily; it never leaves your device, is not included in backups, and you can clear it at any time (section 3). The speech provider you have configured on your device processes the voice audio under its own privacy policy. If your device has no speech service, the button does not appear.
7b. Trailers
When your IPTV provider supplies a trailer reference for a movie or series, a "Watch trailer" button opens it in your YouTube app or browser. That playback happens entirely outside SabiStream, under YouTube's/your browser's own terms and privacy policy. SabiStream only opens the link (restricted to YouTube addresses) and sends nothing else.
7c. Opening a stream in another player
"Open externally" hands the current stream to a video player app you choose (for example VLC or MX Player). The app you pick receives the stream's address — which can include your playlist username/password if your provider embeds them in stream links — plus the title and the User-Agent needed to play it. SabiStream shows a one-time notice before the first hand-off. What the chosen player does with that information is governed by its own privacy policy, so only hand streams to player apps you trust.
8. Permissions
- Internet & network state — to connect to your source and stream.
- Notifications — to show programme reminders, recording and download progress, and (when enabled) new episode/season alerts.
- Foreground service & wake lock — to keep a scheduled recording or an in-progress download running.
- Exact alarm — to start scheduled recordings on time when you grant it. Programme reminders deliberately use battery-friendly inexact timing and do not depend on this permission.
- Run at startup — to re-arm scheduled recordings after a restart.
- Modify audio settings — an install-time permission (no prompt) used only when you drag SabiStream's player volume gesture to change the device's media volume. It does not change your ringer or audio routing. Night mode processes decoded playback audio inside SabiStream and does not use this permission.
- Google account / Drive app data — only when you choose Google backup/sync.
The app does NOT request microphone permission: voice search delegates to the system recognizer. Biometric/fingerprint permissions support optional device authentication for app lock; the operating system supplies an authentication result, not your fingerprint image. Android's user-initiated transfer permission supports downloads on compatible versions. Folder/file access is granted through system pickers where used.
10. Your control and deletion
- Log out of playlists ends the active IPTV session and clears the stored playlist sign-in, including your saved playlist passwords. Your playlists (name, server address, username), favourites, history, recordings, and separate SMB/network-share connections stay on the device, so you can sign back in by re-entering the playlist password; logging out also resets some display and guide preferences (see section 2). Delete a playlist or use Reset app to remove a playlist completely.
- Network shares can be removed individually in Settings. Reset app, Clear storage, or uninstalling removes all saved shares and their credentials.
- Reset app erases app-managed data, including recent searches and local diagnostics, and attempts to delete tracked external recordings. Check for reported failures. Android's Clear storage or uninstall removes app-private storage; external recordings, exported backups and recipient copies require separate handling.
- Recordings in a folder you picked yourself survive uninstall (section 3a) — delete them with a file manager.
- Manual backup files stay wherever you saved them until you delete them.
- Google backup snapshots can be deleted from Settings using Wipe Google backup; you can also revoke the app's Drive access from your Google Account.
- Recent searches can be cleared from Settings ▸ Privacy & data ▸ Privacy & security.
- For anything you sent us by email (feedback, diagnostics), request deletion by emailing privacy@sabistream.com (see Feedback, contact and publisher above).
Windows
2. Your playlist logins
Provider passwords, portal MAC values and remote playlist/guide addresses are protected using an installation encryption key protected by Windows DPAPI under your Windows user account. Credential-bearing server and artwork addresses are protected as well; ordinary base addresses, names, usernames and other non-secret library metadata can remain readable in the app's files. DPAPI is not isolation from every program running as the same Windows user. The app sends provider credentials to the source and destinations needed to play it; optional backups and handoffs are described below.
Providers can embed credentials in stream, playlist and guide addresses. Working copies can occur in catalogue, download and schedule records. Current guarded writes encrypt credential-bearing addresses using the installation key, and refuse a required protection operation that fails. Ordinary non-secret addresses and metadata may remain readable. Older files can need migration or deletion.
App-managed files normally live under %LOCALAPPDATA%\SabiStream. Deleting a playlist removes its scoped data. Log out of playlists removes saved playlist configuration and sign-ins, while keeping the local library and parental protection. To return, add/sign in to the source again. Erase everything removes app-managed data; independently exported files and remote copies have separate deletion rules.
3. What the app stores on this PC
The app stores the following on this PC. SabiStream does not automatically receive your local library. Optional backups, feedback and external-player transfers have the separate rules described below.
- Your playlists, favourites, My list, collections, hidden and locked channels and categories, watch history, Continue watching positions, watched episodes, reminders, repeating recording rules, guide choices, category customisations and app settings.
- Recent searches — the last 10 searches you actually opened a result from. They stay on this PC, are not included in backups, and can be cleared at any time in Settings ▸ Data.
- Offline downloads — optional copies of films and episodes you choose to download. They are stored only in the app's own folder and encrypted with a key belonging to this installation: they are not playable without it, deliberately, out of respect for content providers. Delete them in the Downloads screen; "Erase everything" removes them all. They are never part of a backup.
- Recordings — see section 3a.
- The live rewind buffer — "Pause and rewind live TV" keeps a rolling copy of the channel you are watching in the app's own folder so you can pause and rewind. It is bounded by the size and time limits you choose in Settings, is deleted when you leave the channel or close the app, and is not uploaded automatically. Choosing Save rewind makes a retained encrypted recording; deleting the temporary buffer does not delete that saved recording. The recording's deletion and external-player rules then apply.
- The parental PIN — stored as a salted PBKDF2 digest, never as the PIN itself.
3a. Recordings
Recordings are saved into the app's own folder as encrypted containers belonging to this installation, for the same reason downloads are. They never leave this PC by themselves. "Erase everything" deletes them; a backup never contains them.
Windows has no equivalent of the phone's alarm clock, so a scheduled recording runs while SabiStream is running. The app tells you this on the Recordings screen and on the recording-readiness page rather than implying otherwise.
4. Backup and sync
You can write manual encrypted backup files and, if you choose, use Google Drive.
- Manual backup: a backup file asks you for a password of at least 8 characters and is encrypted with it. Keep the password safe: without it the file cannot be opened by anyone, including us. You choose where the file goes and we never receive it.
- Google Drive: when you sign in, SabiStream keeps an encrypted snapshot in your Google Drive app data folder, which is private to this app and tied to your own Google account. It uses a key built into the app, not a secret known only to you. That snapshot is not protected by your manual-backup password; what keeps it private is your Google account and Drive's app-data isolation. The two are separate features with separate protection, and neither is a substitute for the other.
- What travels: playlists and their sign-ins, favourites, My list, collections, watch history and Continue watching, watched state, reminders, repeating recording intent, category and channel customisations, locked categories and the parental PIN digest, and records of what you deleted so a deletion made on one device is repeated on the others. Repeating recording rules arrive switched off and never start recording on a machine you have not turned them on.
- What is excluded from SabiStream backups: downloaded and recorded video, the live rewind buffer, recent searches, the VLC path and logo folder you chose, this monitor's interface scale, this PC's speaker volume, whether app lock and screenshot blocking are on, whether automatic Google backup is on here, and this PC's unlock records. A separate external-player action can send playable media to the app you choose.
- Automatic backup: once you are signed in and automatic backup is on, a fresh snapshot is uploaded in the background shortly after your library changes, and when the app opens. You can switch it off, press Sync now yourself, Undo last sync to go back to the previous snapshot, or Wipe Google backup to delete the snapshots from Drive. A wipe pauses automatic uploads so the deleted data is not silently recreated; Sync now resumes them.
5. Error reports
SabiStream has no automatic developer crash-upload service in this implementation. Send feedback opens your email program with a message you can read and edit. An optional footer adds the app build and operating-system version. The app does not automatically attach your playlist or login, but whatever you type, your sender address and mail metadata reach the mailbox if you send them. Local operating-system or runtime diagnostics are separate. The shared feedback-retention and deletion policy applies.
6. No analytics, no ads
The app contains no developer analytics or advertising SDK. Your source sees its playback requests. Optional Google Drive backups can contain viewing records, and an external player you select receives the media needed for playback. SabiStream does not operate a viewing-analytics service or sell your data.
7. Network connections
The app connects to the IPTV/portal or local/UNC source you configure, guide addresses you or your playlist supplies, artwork/stream destinations supplied by your sources, and their required redirects. Windows handles authentication to network shares using your Windows session. Google sign-in opens your browser at Google's authorization service, exchanges authorization codes at Google's token service, and uses the Drive app-data API after you opt in. A refresh token is encrypted on this PC; short-lived access tokens stay in memory. Sign out removes the local Google session; Wipe Google backup separately deletes snapshots. YouTube trailers open externally; selected external players receive stream addresses/headers or local playable media. Feedback uses your mail app. Artwork's local-network restrictions are controlled in Settings. This implementation has no automatic sabistream.com configuration/update fetch; a browser visit to the site uses the shared website policy. HTTP sources are not encrypted in transit.
Playback uses libVLC on this PC. When a channel needs request headers VLC cannot send, SabiStream serves it through a loopback address on this machine only; that address is never written into a backup or a schedule.
8. Windows permissions
The app asks Windows for nothing beyond ordinary network access and the folders you choose. Blocking screenshots and previews, when you turn it on, asks Windows to exclude the window from capture; some third-party capture tools may not honour that request, which the setting says.
10. Your control and deletion
- Clear watch history removes Continue watching positions, recently watched films and series, and watched ticks. Favourites, My list, collections, recordings and downloads stay.
- Log out of playlists removes saved playlists and sign-ins. Favourites, history, recordings, locked categories and parental protection remain; add the source again to use it.
- Reset settings to defaults returns every setting to its default and removes per-channel tweaks, category edits and the parental PIN. Playlists, favourites, history, My list and recordings are kept.
- Erase everything deletes data in the current app-managed SabiStream storage folder, including recordings and downloads. Check any reported failure and retry cleanup where needed. Independently exported backups, other copies and cloud data are not erased by this local operation.
- Wipe Google backup deletes the snapshots from your Drive app data folder; you can also revoke SabiStream's Drive access from your Google Account.
- For anything you sent by email, request deletion by emailing privacy@sabistream.com.
iPhone, iPad and Apple TV
1. Your sources and connections
SabiStream is a media player. You supply your own Xtream, M3U/M3U8, local playlist or Stalker/Ministra source and must have permission to access its content. The app connects to your source and to the stream, guide, artwork and redirect destinations it supplies. These services receive your IP address, requested addresses, request headers and any credentials or tokens needed for that request. A Stalker portal receives the MAC address you entered as a provider login; this is not a scan of your device's hardware MAC address.
Some sources use HTTP, which is not encrypted in transit. Use HTTPS sources where available. Do not assume the Android app's redirect protections apply to every Apple playback or image-loading path.
2. Storage and protection
Provider passwords and endpoint records, including server, username, playlist/guide addresses and portal MAC, are held in the device Keychain with access after first unlock and device-only accessibility. Stored media references use protected references to those credentials. This does not mean every app file is separately encrypted: personal databases, settings and imported local M3U files also use the app's private storage and operating-system protection. Imported playlist files can contain credentials verbatim.
The app keeps your library choices, favourites, My List, collections, category and channel customisations, parental protection records, watch history, playback positions, watched episodes, guide choices, reminders and followed series locally. Recent searches are stored in local preferences; use Search or Settings to clear them. Catalogue and image data can be rebuilt from your sources. Local notifications can display programme or series information, subject to the app's privacy controls.
Keychain storage is not a promise that uninstalling erases every Keychain item. Use the app's deletion controls before removing it, and see section 10.
3. Saved video and playback
On iPhone and iPad, completed downloads are encrypted in private app storage using an installation key kept in the Keychain. Downloading temporarily stages unencrypted video under operating-system file protection before encryption completes. Media, staging and imported local playlists are excluded from device backup. Apple TV does not offer this download library.
Apple live rewind uses the seekable window supplied by the stream. SabiStream does not make the Android or Windows rolling recording buffer on Apple devices. This build does not offer their scheduled live-recording feature.
4. Backups and nearby transfer
Manual SabiStream backup exports require a passphrase of at least eight characters. They can include provider logins, library and viewing records, content customisations, reminders, follows, deletion records and a portable salted parental-PIN verifier. They do not include saved video. You choose where to save or share the encrypted file; a Files or sharing service you choose handles that copy under its own terms. Delete exported copies separately.
Google Drive sign-in and automatic Drive sync are not available in this Apple build. Android and Windows Drive instructions do not apply here.
Ordinary personal app data and preferences may be included in Apple's device backups according to your system settings. That is separate from a SabiStream export. Catalogue caches, the playlist configuration file, imported playlist files, downloaded media and staging have backup exclusions; the credential Keychain items use device-only accessibility. Manage existing system backups with Apple's backup controls.
When you choose nearby transfer, the app discovers nearby SabiStream devices using MultipeerConnectivity and the local-network service sabi-backup. It advertises a temporary random SabiStream peer name and receiver role. A six-digit pairing code is used to accept an invitation; the backup payload is separately encrypted with your backup passphrase and the peer session requires encrypted transport. The recipient receives the backup you selected. No SabiStream relay server is involved. Use a trusted nearby device and keep the passphrase private.
5. Feedback and diagnostics
SabiStream does not automatically upload its own crash reports or use a developer analytics service. Local diagnostic messages can be written to the operating system's logs. Apple's operating-system diagnostic services have separate controls.
Send feedback opens your email app with your message and an app/platform subject. Nothing is submitted until you send that email. Whatever you type, your sender address and the email's normal metadata then reach the support mailbox and its mail service. The message is not automatically scrubbed of information you type. Feedback retention and deletion follow the shared contact policy: kept as long as needed to investigate and fix the issue; request access or deletion at privacy@sabistream.com.
6. Transfers you choose
AirPlay can send playback and associated media information to a receiver you select. Provider addresses may contain credentials or access tokens; use receivers you trust. SabiStream does not add the Android Google Cast SDK on Apple platforms.
Opening a stream in another player or using Share transfers the selected stream URL, potentially including provider credentials, to the chosen app. Opening a saved download in another app makes a temporary decrypted copy for the share sheet. SabiStream removes its temporary copy when the handoff ends and sweeps leftovers at launch; the recipient may retain its own copy, which SabiStream cannot delete.
A provider's trailer opens a validated YouTube link in an external app or browser. YouTube and that app then handle playback under their own privacy practices. Artwork and guide hosts can also be third parties selected by your source.
7. Permissions
The app uses network access for your sources and may request local-network access for local sources and nearby backup transfer. Notification permission is requested for reminders and alerts. Files you select are accessed through system file-selection controls. Background audio and download handling use Apple's system facilities. This version does not request access to your microphone, contacts or device location, capture speech, or read an advertising identifier.
8. Retention
Library data remains until you clear or delete it; caches can also be reclaimed or refreshed. Downloads remain until deleted. Signed-out library records can remain for reattachment when you add the same source again. Exported backups, another app's copies, provider records and system backups have separate lifetimes. An operation reporting a storage error may leave data pending cleanup; do not interpret an error as successful erasure.
10. Your control and deletion
- Clear recent searches in Search or Settings; clear viewing history with the app's history control.
- Delete a playlist to remove its source configuration, credentials and associated library/download data. Follow any reported cleanup failure before treating deletion as complete.
- Log out removes saved source sign-ins while retaining favourites, My List, history, collections and other retained library records. Adding the source again can reattach that library.
- Use Erase everything to remove app-managed library data, sources, downloads, settings, parental protection and notifications. This does not delete exported backups, files copied to another app, your provider's records or existing system backups. Some installation security material can remain in the Keychain; uninstalling alone is not a verified Keychain-erasure mechanism.
- Remove exported backups and recipient copies in the locations/apps that hold them. Manage Apple's device backups in your system or account backup controls.
- Request deletion of email sent to SabiStream at privacy@sabistream.com. General support is available at support@sabistream.com.