Privacy Policy

Last updated 27 August 2026

The short version

CurioPlay runs no servers. We have no account for you, we do not sell your data, we do not advertise to you, and we do not track you across other apps or websites.

Information leaves your device in the ways listed in section 3, and nowhere else: looking up artwork and descriptions, an app-authenticity check, syncing to your own private iCloud, crash reports on Apple TV, the cloud AI assistant if you switch it on, your own Calendar if you tap Add to Calendar, and a Watch Party if you start one.

1. No CurioPlay account

CurioPlay has no sign-up and no CurioPlay login. We hold no name, email address or profile for you, and we run no server that stores what you watch.

You may sign in to services you already have — such as your IPTV provider. Those are your accounts with those companies, not with us.

2. What stays on your device

iCloud sync is on by default while you are signed in to iCloud, and you can turn it off in Settings. It uses your own private iCloud database — your Apple account, governed by Apple's privacy policy. We cannot read it.

3. What leaves your device

a) Artwork and descriptions. To show posters, summaries, cast and programme guides, CurioPlay looks titles up with third-party catalogue services: TMDb, TheTVDB, TVmaze, Wikidata, Wikipedia and Wikimedia, the Apple iTunes Search directory, TheSportsDB, fanart.tv, radio-browser.info, and the iptv-org logo directory. For the trending rails, the app also downloads Simkl's public chart documents — a plain file fetch that carries nothing about you or your library. What is sent for lookups is the channel, title, person or team name being matched, and no identifier for you is attached. One exception: TMDb uses an API key you supply yourself. Each service has its own privacy policy.

b) App authenticity. On iPhone and iPad the app uses Apple's App Attest through Firebase App Check to confirm requests come from a genuine copy of CurioPlay. This validates the app, not you, and it runs at launch whether or not the cloud assistant is switched on. The Mac version does not use it.

c) Crash reports — Apple TV only. On Apple TV, CurioPlay uses Firebase Crashlytics so crashes can be fixed. It is on by default and you can turn it off in Settings on the Apple TV. It sends the crash, your device model and system version, a random per-installation identifier, and the app's recent diagnostic log lines. Those log lines can include the name of the title you were playing, your list of favourites, and the hostname of your provider — they are how a playback crash is diagnosed. They never include your provider username or password, your name or your email. Crash reporting also brings a component that reports an app-open session event; turning crash reporting off stops that too. The iPhone, iPad and Mac versions have no crash reporting at all.

d) The cloud AI assistant — off unless you turn it on. Ask Curio normally runs entirely on your device using Apple's on-device model, and nothing leaves. A cloud assistant is available as an option, is switched off by default, and requires you to turn it on in Settings after an explanation naming the provider.

If you turn it on, what is sent to Google's Gemini service is: your question, a small summary of your taste, titles from your library, and recent items from your watch history when they help answer. Your provider username, password and address are never sent. No account identifier is attached. These requests are handled under Google's Gemini API terms, which can allow Google to use them to improve its services; if that is not acceptable to you, leave the cloud assistant off.

e) Your Calendar — only when you ask. If you tap Add to Calendar on a programme, CurioPlay asks for Calendar permission and writes one event — the programme name, the channel and, where available, the summary — into your default calendar. It requests write-only access and cannot read your calendar. The event then belongs to your Calendar, not to us; if your default calendar is an iCloud one it syncs like any other event.

f) Watch Party. If you start or join a Watch Party, CurioPlay uses Apple's SharePlay inside your FaceTime call. What reaches the other people in that call is the reactions you send, the name of a channel when you propose switching to it, and a random per-session token so their app can group your messages. Your name, contacts, playlists, provider details and viewing history are not sent.

4. What we do not do

5. Purchases

CurioPlay Pro is sold through Apple. Apple tells the app whether a valid purchase exists — nothing more. We never receive your payment details.

6. Children, and what Kids Mode is not

CurioPlay is not directed at children under 13, and we knowingly collect nothing from them.

Kids Mode restricts what can be watched and keeps all AI processing on the device — nothing reaches the cloud assistant while it is active. Be aware of what it does not do: the other connections in section 3 carry on unchanged, including artwork lookups, iCloud sync and Apple TV crash reports. CurioPlay also plays whatever your provider supplies; we do not rate, filter or classify that content. Kids Mode works from rules stored on your device — a convenience for parents, not a substitute for Screen Time or your provider's own controls.

7. Your choices

You have the right to ask for access to, correction of, or deletion of personal information about you, to object to or restrict its use, and to complain to your data protection authority. We hold no account and no copy of your library, so in most cases there is nothing for us to retrieve or erase — requests about data held by Apple, Google or the catalogue services need to go to them. Write to us anyway if you are unsure and we will tell you where to ask.

8. Changes

If what the app sends ever changes, this policy is updated in the same release. The date shown at the top tells you which version you are reading.

9. Contact

Questions about this policy, or about information held about you, go to curioplayapp@gmail.com.