Privacy Policy
Last updated: 15 September 2026
1. Who is responsible
The controller for every processing described here is MintFolder AI UG (haftungsbeschränkt), Sudetenstraße 18, 35039 Marburg, Germany, represented by its managing director Thaeer Sukay. Requests about your data: privacy@kinoplayer.app. We are not required to appoint a data protection officer.
2. The short version
KinoPlayer is a media player. It holds no user accounts for viewers, no card or bank details and, unless you write to us or open a reseller account, no names or e-mail addresses. The video and audio you watch never pass through our systems: your television talks to your provider directly. There is no advertising and no tracking. The app sends us short technical reports so that a television that fails can be helped; they are kept for thirty days. If you buy a plan, the payment is made in USDT on the Polygon network from a wallet of your choosing.
3. What we process, why, on what legal basis, and for how long
Legal bases are those of Art. 6(1) GDPR: (b) performance of a contract, (c) a legal obligation, (f) our legitimate interest, named where it applies.
- Device identifier and device key. Two codes generated on your television at first launch. They identify the installation, not you; the key is stored only as a salted hash. Also the device model, platform and app version, so a fault can be matched to the kind of set it happens on, and, if you type one on the website instead of the device identifier, the device's MAC address. Basis: (b). Kept until you delete the device; a device that was never activated beyond its trial, holds no playlist and has not contacted the service for ninety days is deleted automatically.
- Playlist details you enter yourself. The address of your playlist, or the host, username and password of your provider. They are stored so the service can build your listing and your television can play; the password is never shown again after you save it and is sent to nobody but your provider. Basis: (b). Kept until you delete the playlist or the device.
- Channel and title listing. For a provider that allows it, the server fetches the list of channel and title names your provider exposes and keeps it as a file so your television starts quickly. It is the listing only, never the video. Basis: (b). Deleted with the playlist.
- Technical reports. The app sends short entries when it starts, syncs, opens a section, starts or fails to start a stream, or crashes: the kind of event, how long it took, the transport and codec, an error code, and for playback the name of the channel or title concerned. They exist to diagnose a television that does not work and are not analysed for anything else. Basis: (f), keeping the service working. Deleted after thirty days.
- Activation record and payments. Which plan a device holds and when it expires; for a purchase, the order: device, plan, price, exact amount due, the consent you gave when ordering, and once paid the public transaction hash, the sending wallet address and the amount received, all of which are public on the Polygon blockchain. We never see or hold a private key, a seed phrase or a card number. Basis: (b), and (c) for the accounting records. Kept for ten years from the end of the year of the order (§ 147 AO, § 257 HGB), even if the device is deleted.
- Telegram bot. If you talk to our bot, Telegram gives us your numeric chat identifier and the language you chose. The bot keeps the identifier and the language, and for the duration of one operation the device identifier and playlist details you type; when the operation ends the bot deletes those messages from the chat where Telegram allows it. If you order through the bot, the chat identifier is stored with the order so the bot can confirm the activation and remind you before the plan ends. Basis: (b). Kept while you use the bot; the identifier on an order is kept with the order.
- Phone remote and pairing. Short-lived codes that let a phone sign in to a television's portal or act as its remote. Basis: (b). Codes expire within minutes; a remote link is kept until you forget it in the app.
- Contact form. Name and e-mail address you enter, your message, the device identifier if you give one, any screenshot or short recording you attach, and the IP address the message came from (to stop floods). The message is also delivered to our mailbox. Basis: (b) for answering you, (f) for abuse prevention. Kept until your request is settled and then deleted, at the latest after twelve months.
- Reseller accounts. If you open a reseller account: your name, e-mail address, password (as a hash), contact line, language, credit balance, ledger of purchases and activations, notes you write about devices, and the billing address and VAT id you give for invoices. Basis: (b), and (c) for invoices and accounting. Kept while the account exists; invoices and ledger entries for ten years.
- Server logs. Ordinary web-server records of requests, including IP address, kept briefly for security and abuse prevention; pair codes and tokens are removed from the log before it is written. Basis: (f). Deleted after fourteen days.
- Audit records. Actions in the console and on orders (grants, cancellations, settings changes) with the acting IP address, so a mistake can be traced. Basis: (f) and (c). Twelve months; entries about payments ten years.
- Backups. Nightly copies of the database, held with restricted permissions on the same server. They contain the data above and are kept for ninety days; a deletion reaches the backup when the backup expires.
4. What we never see
We do not receive, store, cache, proxy or inspect any video or audio stream. We do not build a profile of what you watch and we do not use the technical reports for anything but diagnosing faults: they are not analysed for taste, not shared with your provider and not sold. Your full viewing history, favourites and resume points live only on your own television and are deleted when you clear them or uninstall the app.
5. Third parties the app or the site talk to
The website itself loads no fonts, scripts, images or styles from any external service. The apps and the server do contact a few services, each for one purpose:
- Hosting. The service runs on a rented server in Germany operated by IONOS SE, Montabaur, under a data-processing agreement (Art. 28 GDPR).
- E-mail. Contact messages and reseller mails are sent and received through a mailbox at Zoho Corporation B.V. (Netherlands, servers in the EU) under its data-processing terms.
- Telegram. If you use the bot, Telegram carries the messages under Telegram's privacy policy.
- Blockchain explorer. To see whether a payment has arrived, the server asks Etherscan for the transfers into our own wallet; that request carries our wallet address, never yours or your device's.
- TMDB. For a film or series page, the server asks The Movie Database for the description, cast, artwork and trailer of that title; the request names the title, not you or your device. Poster and backdrop images are then loaded by your television directly from TMDB's image host, so your television's IP address reaches TMDB. Basis: (f), showing you the page you opened. TMDB's privacy policy: themoviedb.org/privacy-policy.
- Wikidata and Wikipedia. The server asks the Wikimedia Foundation's services for the same information where TMDB has none; the request names the title only. Basis: (f).
- YouTube. If you open a trailer, it plays in the YouTube app or browser on your device under Google's terms; nothing is loaded from YouTube inside KinoPlayer.
- Speed test. If you run the speed test in the app, your television downloads and uploads test data directly from Cloudflare (speed.cloudflare.com); Cloudflare sees your television's IP address for that. Basis: (b), you started it. The result is shown on the television and not stored on our server.
- Your own provider. Your television, and for the listing our server, connect to the provider whose playlist you entered, with the credentials you entered. What that provider logs is governed by its own policy.
No other recipient has access. We do not sell, rent, share or trade any data with anybody, for any purpose. Data is not transferred outside the European Union except to the services above where you use them (Telegram, TMDB, Cloudflare, YouTube), which rely on standard contractual clauses or the EU-US Data Privacy Framework.
6. No advertising, no tracking, cookies
There are no cookies used for advertising or measurement, no advertising networks, no social media plug-ins and no analytics. Nothing on this site reports your visit to anyone. The site stores a single preference in your browser to remember your chosen language. The web portal and the reseller panel set one session cookie each when you sign in; it is strictly necessary for the sign-in and needs no consent (§ 25 Abs. 2 TDDDG).
7. Security
All traffic between your devices and the service is encrypted in transit. Device keys, passwords and session tokens are stored as salted hashes. Access to the server is restricted to administrative staff and protected by key-based authentication. Backups are readable by the service account only.
8. Your rights
You have the right to obtain access to your personal data (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). Where a processing rests on consent, you may withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority, in particular the one for Hesse: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, datenschutz.hessen.de.
You can exercise most of these yourself: delete a playlist, which removes its address and credentials; unpair a device, which forgets its key on the television; delete a device from Settings in the app, which removes the device, its playlists, its activation record, its listing files and its technical reports from the server at once; close a reseller account by writing to us. For anything else write to privacy@kinoplayer.app quoting your device identifier or reseller id: because viewers have no account and no name, the device identifier is the only way we can find your records. Payment records that the law requires us to keep are excluded from deletion for the required period. We answer within one month.
No decision about you is made by automated means, and there is no profiling.
9. Children
The service is not directed at children and we knowingly collect nothing from them.
10. Changes
If this policy changes, the revised version is published on this page with a new date at the top; a change that matters to you is also announced in the application.
11. Contact
MintFolder AI UG (haftungsbeschränkt)
Sudetenstraße 18, 35039 Marburg, Germany
privacy@kinoplayer.app