1. Genel Bakis
Atlantic Stream Player ("Uygulama"), kullanicilarin kendi medya kaynaklarini oynatmasini saglayan bir medya oynaticisidir. Bu gizlilik politikasi, Uygulama tarafindan toplanan, saklanan ve islenen verileri aciklar.
Onemli: Atlantic Stream Player medya barindirmaz, yeniden yayinlamaz veya IPTV aboneligi satmaz. Kullanicilar kendi yetkili playlist kaynaklarini ekleyebilir. Uygulama ayrica hak sahiplerinin herkese acik resmi baglantilarindan olusan kucuk, incelenmis bir ucretsiz yayin katalogu sunar; erisim, bolgesel kullanilabilirlik ve yayin haklari ilgili yayinciya aittir.
2. Toplanan Veriler
2.1 Hesap Bilgileri
- Google ile Giris: Ad, e-posta adresi, profil fotografi (Google OAuth uzerinden)
- Uyelik Girisi: Kullanici adi (e-posta veya username)
- Cihaz Aktivasyonu: Cihaz kodu
2.2 Kullanim Verileri
- Playlist, sunucu, EPG ve medya akis adresleri ile playlist kullanici adi ve sifreleri; yerel M3U dosya adi ve playlist metadata'si (bulut yedekleme aciksa bunlar sifreli yedek zarfinda yer alabilir)
- Favori kanallar, izleme gecmisi ve profile bagli Daha Sonra Izle secimleri
- Uygulama dil tercih ve gorunum modu ayarlari
- Cihaz modeli, Android surumu (destek ve uyumluluk icin)
- Uygulama ici destek: Gonderdiginiz mesaj metni ve zamani, konu/tur, ilgili ekran, hesap kimligi, ad ve varsa e-posta; uygulama kimligi/surumu, cihaz modeli, Android surumu ve dil bilgisiyle birlikte destek talebini yanitlamak icin saklanir.
2.3 Otomatik Toplanan
- Firebase Analytics, Google Ads olcumu ve Google AdMob: Uygulama etkilesimleri, ekran/ozellik kullanimi, satin alma olaylari, uygulama ornegi, cihaz/reklam kimlikleri ve teknik bilgiler; kullanim, yukleme, kampanya ve reklam performansini olcmek icin islenebilir. Google/Firebase/AdMob, IP adresini yaklasik ulke/bolge/sehir konumu ile guvenlik, olcum ve reklam sunumu amaclari icin isleyebilir; Uygulama kesin GPS konumu istemez. Ucretsiz kullanicilara telefon ve tablette, oynatma veya kritik hesap/satin alma akislarini bolmeden sinirli yerel ve dogal gecis reklamlari gosterilebilir; Premium kullanicilara ve Android TV cihazlarina reklam gosterilmez. AEA, Birlesik Krallik ve Isvicre'de reklam SDK'si baslatilmadan once Google'in izin mesaji gosterilir. Kullanici izni reddedebilir veya daha sonra gizlilik ayarlarindan geri cekebilir; izin yoksa kisisellestirilmis reklam talep edilmez.
- Firebase Crashlytics: Cokme, ANR ve hata raporlari; stack trace, uygulama surumu, cihaz/OS bilgisi, installation identifier ve gelistirici tarafindan eklenen tanisal breadcrumb'lar.
- Firebase Performance Monitoring: Uygulama acilis ve manuel performans sureleri. Surum 1.0.69'dan itibaren HTTP/S istek URL'lerinin otomatik izlenmesi kapatilmistir; onceki dagitilmis surumler otomatik ag performans URL kaliplari olusturmus olabilir.
- Firebase Cloud Messaging: Destek yaniti bildirimleri icin hesaba ve cihaza bagli bildirim tokeni ile teslimat kimlikleri. Bildirim tasima verisinde destek mesajinin metni bulunmaz.
- Kendi Liste Kurulum Sayaci (yalniz Full Production): Yonetim panelinde yaklasik aktif-kurulum sayisini gostermek icin cihazda Android Keystore ile sifrelenen rastgele 256-bit kurulum gizlisinden turetilmis sabit, takma adli (pseudonymous) kurulum kimligi; monoton revizyon ve cihazda en az bir silinmemis kendi listenizin bulunup bulunmadigini belirten boolean durum Cloud Functions'a gonderilir. Firebase UID, Android ID, e-posta, playlist adresi/adi, kimlik bilgisi veya liste/medya icerigi bu telemetriye eklenmez; metrik HTTP istegi Firebase Auth kimlik belirteci veya Firebase Instance ID belirteci icermez. Cloud Functions IP adresini yalniz kotuye kullanim ve hiz siniri icin isler; ham IP metrik kaydinda saklanmaz. Kurulum durumu son rapordan sonra en fazla 30 gunluk aktif pencerede tutulur; hiz-siniri kayitlari yaklasik iki saatlik TTL temizligine girer. Farkli cihazlar ve uygulama verisi silindikten sonraki yeni kurulumlar ayri sayilabildigi icin bu sayi insan veya hesap sayisi degildir ve gelir ya da otomatik karar kaynagi olarak kullanilmaz.
- Hiz Testi: Yalnizca siz testi baslattiginizda Cloudflare ve OVHcloud test dosyalarina ag istekleri yapilir. Bu istekler bir testte en fazla 40 MB veri kullanabilir. Ag saglayicilari IP adresi ve standart baglanti metadatasini gorebilir; Uygulama bu isteklere hesap kimligi, playlist adresi veya playlist kimlik bilgisi eklemez.
- Cihaz kimligi: ANDROID_ID bazli composite fingerprint (cihaz limiti kontrolu icin)
3. Verilerin Saklanmasi ve Guvenligi
- Yerel Depolama: Room veritabani (cihaz uzerinde)
- Bulut Yedekleme: Google Firebase Firestore kullanilir. Playlist/sunucu/EPG ve medya akis adresleri, playlist kimlik bilgileri, yerel M3U dosya adi ve metadata'si, profil/izleme/kategori durumu, uygulama ve ebeveyn kilidi ayarlari ile ebeveyn PIN hash'i dahil kanonik yedegin tamami cihazda sikistirilip tek bir AES-256-GCM zarfi icinde kimlik dogrulamali olarak sifrelenir. Zarf disinda yalnizca sema/surum, degismez Firebase UID, anahtar/sifreleme/sikistirma surumu, rastgele salt, monoton revizyon ve sifreli metin bulunur; profil, saglayici veya oynatma verisi plaintext yazilmaz. Hesap anahtari Cloud Functions'taki surumlu gizli kokten UID icin turetilir, yalnizca e-postasi dogrulanmis oturuma verilir, cihaz belleginde gecici tutulur ve Firestore'a ya da uygulama paketine konmaz. 1086 istemcisi eski e-posta-yollu yedegi hicbir ayar veya e-posta eslesmesiyle okuyamaz. Ilk kanonik yazimdan once sunucu e-posta alanini dondurur; eski kaynaklari uygulamaya, hesaba veya anahtara gostermeden ayri sunucu gizli anahtariyla gecici kasaya sifreleyip plaintext nesli siler. Bu kilit icerik tasimaz ancak kanonik e-posta belge yolunda tutulur; hesap silmeden bagimsiz olarak eski istemci erisimini kapali tutar ve en gec Faz-B/yedi gun kesimi dogrulandiktan sonra denetimli bos-namespace temizligiyle silinir. Ayni cihazda gecerli yerel durum varsa yeni UID-yedegi olusturulabilir; yerel durum yoksa otomatik geri yukleme ya da bos yedek yazimi yapilmaz ve tarihsel kurtarma icin iki operatorlu sahiplik kaniti gerekir. Eski istemci uyumlulugu 1086 yuzde 100 dagitimindan sonra en gec yedi gun icinde kapatilir. Hesap silme aninda henuz kasaya tasinmamis, sahipligi kanitlanamayan eski kaynak varsa Auth kimligi silinmeden once iceriksiz PREPARING/QUARANTINE e-posta-alani kilidiyle yerinde dondurulur; yeniden atanmis e-posta, uygulama, eski istemci ve web paneli bu plaintext kaynagi okuyamaz veya degistiremez. Faz-B erisim kesiminden sonra yalniz iki ayri, guncel ve dogrulanmis yonetici onayli sunucu islemi her nesli ayni transactionda kasaya sifreleyip plaintext kopyayi siler. 90 gunluk TTL dondurulmus gecis plaintext'ine degil, kasa sifreli metni olustugu anda baslar; aktif kilide TTL verilmez, cunku erken otomatik kilit silme eski istemci erisimini yeniden acabilir. Kanitlanamayan kasa hicbir mevcut e-postaya atanmaz, uygulama/web panelinden okunamaz ve en fazla 90 gun sonra kimlik dogrulamali nesil halinde silinir. Normal hesap silme, mevcut e-postayi tarihsel sahiplik kaniti saymadigi icin bu bagimsiz kasa veya dondurulmus tarihsel kaynagi sahiplenmez ya da erken silmez; erken silme/kurtarma da iki operatorlu tarihsel kanit gerektirir. Yenileme sonrasi yerel bekleyen URL durumu Android Keystore ile hesap-kapsamli sifrelenir; plaintext bekleyen bulut belgesi yazilmaz.
- Daha Sonra Izle Senkronizasyonu: Premium kullanicinin film/dizi secimleri hesap ve profil kapsaminda Firestore ile cihazlar arasinda eslenir. Playlist adresi, kullanici adi veya sifre bu kayitlara eklenmez; kaynak kimlikleri tek yonlu ozetlenir.
- Destek Verileri: Destek konusmalari Firebase Firestore'da hesap kimligiyle saklanir. Cihazin bildirim tokeni cikista kaldirilir; gecersiz tokenlar da otomatik temizlenir. Konusmalar, hesap/veri silme talebi islenene kadar veya yasal ve guvenlik yukumlulukleri gerektirdigi surece saklanabilir.
- PIN Guvenligi: PBKDF2WithHmacSHA256 + rastgele tuz ile hash'lenir
- Aktarim Guvenligi: Atlantic hesap, destek, satin alma ve hiz testi servisleri HTTPS ve sistem sertifika dogrulamasi kullanir. Kullanicinin ekledigi IPTV saglayici adresleri ise saglayicinin yapilandirmasina bagli olarak HTTP veya eski/self-signed HTTPS kullanabilir; bu kaynaklar kullanici tarafindan secilir.
4. Ucuncu Taraf Hizmetleri
- Google Firebase: Kimlik dogrulama, Firestore, Cloud Messaging, Analytics, Crashlytics ve Performance Monitoring
- Google Ads ve Google AdMob: Uygulama yuklemeleri, kampanya iliskilendirmesi/olcumu ve uygun ucretsiz kullanicilara sinirli uygulama ici reklam sunumu; izin tercihleri Google'in Kullanici Mesajlasma Platformu (UMP) ile yonetilir
- Google Play Faturalandirma: Uygulama ici satin alma islemleri
- Cloudflare ve OVHcloud: Kullanici tarafindan baslatilan Hiz Testi icin gecici indirme uclari; IP adresi ve standart ag metadatasi bu saglayicilar tarafindan kendi politikalari kapsaminda islenebilir
Bu hizmetlerin kendi gizlilik politikalari mevcuttur:
5. Kullanici Haklari (KVKK Madde 11)
6698 sayili Kisisel Verilerin Korunmasi Kanunu kapsaminda asagidaki haklara sahipsiniz:
- Kisisel verilerinizin islenip islenmedigini ogrenme
- Islenmisse buna iliskin bilgi talep etme
- Isleme amacini ve amacina uygun kullanilip kullanilmadigini ogrenme
- Eksik veya yanlis islenmisse duzeltilmesini isteme
- KVKK'nin 7. maddesinde ongoren sartlar cercevesinde silinmesini/yok edilmesini isteme
- Islenen verilerin munhasiran otomatik sistemler vasitasiyla analiz edilmesi suretiyle kisi aleyhine bir sonucun ortaya cikmasina itiraz etme
Veri Silme: Ayarlar > Cikis Yap, cihazdaki hesap oturumunu ve yerel kullanici verilerini temizler; bulut yedeklerini veya destek konusmalarini silmez. Hesabinizi ve Atlantic Player tarafindan tutulan iliskili verileri kalici olarak sildirmek icin
hesap silme sayfasindaki adimlari izleyin veya
atlanticdigital24@gmail.com adresine kayitli hesabinizdan talep gonderin. Google hesaplari yakin zamanda yeniden dogrulanan Google kimligiyle; yonetilen kullanici ve cihaz kodu hesaplari mevcut PIN/cihaz anahtarinin guvenli sunucuda dogrulanmasiyla talep olusturabilir. PIN veya cihaz anahtari URL'ye, loga ya da Firestore talep belgesine yazilmaz. Kimligi dogrulanmis silme talepleri en gec 7 is gunu icinde tamamlanir. Silme tamamlandiginda ilgili Google, yonetilen veya cihaz kodu hesabi; Auth kimligi, UID-kapsamli bulut zarfi ve destek verileri kaldirilir. Mevcut e-posta tarihsel sahiplik kaniti olmadigindan bagimsiz eski-yedek kasasi normal talep tarafindan sahiplenilmez veya erken silinmez. Mevcut e-posta, ayrica bagimsiz PIN/cihaz anahtariyla korunan yonetilen kullanici, cihaz aktivasyonu, deneme veya finans kaydinin sahiplik kaniti degildir; Google-UID talebi yalniz e-posta eslesen bu kayitlari otomatik silmez veya anonimlestirmez, UID ile kanitlanan ya da sunucuda kimligi muhurlenmis kayitlarla sinirli kalir. Talep sirasinda henuz kasaya alinmamis kanitlanamayan tarihsel kaynak varsa yeniden atanmis e-posta erisimini engelleyen iceriksiz PREPARING/QUARANTINE kilidiyle dondurulur; Faz-B sonrasinda iki ayri dogrulanmis yonetici onayli sunucu islemi plaintext nesli atomik olarak kasaya tasir. Kasa sifreli metni olustuktan sonra en fazla 90 gunluk TTL uygulanir; daha erken silme veya kurtarma iki operatorlu tarihsel kanit gerektirir. Satin alma dogrulamasi, iade ve muhasebe icin gerekli Play finans kayitlari korunur; UID, e-posta ve cihaz kimligi UID ile kanitlanan kayitlardan kaldirilir ve baska hesabin satin almayi sahiplenmesini engelleyen kimliksiz bir yetki mezar tasi tutulur. Icerik, e-posta veya ham UID tasimayan anonim tamamlama makbuzu denetim ve yeniden olusturmayi engelleme amaciyla en fazla 3 yil saklanabilir. Eski oturumlarin veri yeniden olusturmasini engelleyen, e-posta/icerik tasimayan UID-yollu kilit 48 saat sonra TTL temizligine girer. Google ayrica kendi yasal saklama kurallarini uygular.
6. Cocuk Guvenligi
Uygulama 13 yasindan kucuk cocuklara yonelik degildir. Ebeveyn kontrolu ozelligi mevcuttur: PIN korumasyla belirli kategorileri kilitleyebilir, cocuk kilidi zamanlayicisi ile izleme suresi sinirlandirilabilir.
7. Degisiklikler
Bu gizlilik politikasi guncellenebilir. Onemli degisiklikler uygulama ici bildirim ile duyurulacaktir.
8. Iletisim
Sorulariniz icin: atlanticdigital24@gmail.com
1. Overview
Atlantic Stream Player ("App") is a media player that lets users play their own media sources. This privacy policy explains the data collected, stored, and processed by the App.
Important: Atlantic Stream Player does not host, retransmit, or sell IPTV subscriptions. Users may add their own authorized playlist sources. The App also offers a small, reviewed free-stream catalog using rights holders' official public links; access, regional availability, and media rights remain with each broadcaster.
2. Data Collected
2.1 Account Information
- Google Sign-In: Name, email, profile photo (via Google OAuth)
- Membership Login: Username (email or username)
- Device Activation: Device code
2.2 Usage Data
- Playlist, server, EPG, and media-stream addresses and playlist credentials; local M3U filename and playlist metadata (when cloud backup is enabled, these may be included inside the encrypted backup envelope)
- Favorite channels, watch history, and profile-scoped Watch Later selections
- App language and view mode preferences
- Device model, Android version (for support and compatibility)
- In-app support: The message text and time, topic/type, relevant screen, account identifier, name and email if available, together with the application identifier/version, device model, Android version, and language, are stored so the support request can be answered.
2.3 Automatically Collected
- Firebase Analytics, Google Ads measurement, and Google AdMob: App interactions, screen/feature usage, purchase events, app-instance and device/advertising identifiers, and technical information may be processed for usage, install, campaign, and ad-performance measurement. Google/Firebase/AdMob may process the IP address for approximate country/region/city location, security, measurement, and ad delivery; the App does not request precise GPS location. Free users may see limited native and natural-break ads on phones and tablets without interrupting playback or critical account/purchase flows; Premium users and Android TV devices do not receive ads. In the EEA, United Kingdom, and Switzerland, Google's consent message is shown before the advertising SDK is initialized. Users can refuse consent or withdraw it later from privacy settings; personalized ads are not requested without consent.
- Firebase Crashlytics: Crash, ANR, and error reports, including stack traces, app version, device/OS information, an installation identifier, and developer-provided diagnostic breadcrumbs.
- Firebase Performance Monitoring: App-start and manual performance timings. Automatic HTTP/S request URL monitoring is disabled from version 1.0.69; earlier distributed versions may have generated automatic network-performance URL patterns.
- Firebase Cloud Messaging: An account- and device-linked notification token and delivery identifiers are used for support-reply alerts. The notification transport data does not contain the support message text.
- Own-Playlist Installation Counter (Full Production only): To show an approximate active-installation count in the administration panel, the App sends Cloud Functions a stable pseudonymous installation identity derived from a random 256-bit installation secret encrypted with Android Keystore, a monotonic revision, and a boolean stating whether at least one undeleted user-added playlist exists on the device. Firebase UID, Android ID, email, playlist URL/name, credentials, and playlist/media content are not attached to this telemetry; the metric HTTP request carries no Firebase Auth ID token or Firebase Instance ID token. Cloud Functions processes the IP address only for abuse prevention and rate limiting; raw IP is not stored in the metric record. Installation state remains in an active window for at most 30 days after the last report, while rate-limit records enter TTL cleanup after about two hours. Different devices and a fresh installation after clearing app data may count separately, so this is not a person or account count and is not used as a revenue or automated-decision source.
- Speed Test: Network requests are made to Cloudflare and OVHcloud test files only when you start a test. A test can use up to 40 MB of data. Those network providers can observe your IP address and standard connection metadata; the App does not attach an account identifier, playlist address, or playlist credentials to these requests.
- Device identifier: Composite fingerprint based on ANDROID_ID (for device limit enforcement)
3. Data Storage and Security
- Local Storage: Room database (on device)
- Cloud Backup: Google Firebase Firestore is used. The full canonical backup—including playlist/server/EPG and media-stream addresses, playlist credentials, local M3U filenames and metadata, profile/viewing/category state, app and parental-lock settings, and the parental-PIN hash—is compressed and authenticated-encrypted on the device inside one AES-256-GCM envelope. Outside the ciphertext Firestore stores only schema/version, immutable Firebase UID, key/encryption/compression version, random salt, monotonic revision, and ciphertext; no profile, provider, or playback data is written in plaintext. The account key is derived for the UID from a versioned Cloud Functions secret, supplied only to a verified-email session, held temporarily in device memory, and never stored in Firestore or packaged in the App. The 1086 client cannot read an old e-mail-path backup through any setting or e-mail match. Before the first canonical write, the server freezes that e-mail namespace, encrypts legacy sources into separate server-only escrow without returning any content, key, existence, or count to the App/account, and deletes the exact plaintext generation. The lock contains no backup content but is stored at the canonical e-mail document path; independently of account deletion it keeps older-client access closed and is removed by audited empty-namespace cleanup only after the Phase-B/seven-day cutoff is verified. Valid same-device local state may then create a new UID backup; if local state is empty, no automatic restore or empty backup is written and historical recovery requires two-operator ownership proof. Older-client compatibility closes no later than seven days after 1086 reaches 100% rollout. If account deletion finds unproven historical sources that have not yet entered escrow, a content-free PREPARING/QUARANTINE namespace lock freezes them in place before Auth deletion; a reassigned e-mail, the App, old clients, and the web panel cannot read or alter that plaintext. After the Phase-B access cutoff, only a server workflow approved by two distinct, current authenticated administrators encrypts each generation into escrow and deletes the plaintext in the same transaction. The 90-day TTL begins when escrow ciphertext is created, not while transitional plaintext is frozen; active locks have no TTL because automatic early lock removal could reopen old-client access. Unproven escrow is never assigned to a current e-mail, is inaccessible to the App/web panel, and is deleted as an authenticated generation after at most 90 days. Ordinary account deletion does not treat the current e-mail as proof to claim or erase either that independent escrow or the frozen historical source; early deletion/recovery also requires two-operator historical proof. Local pending URL state is account-bound and Android-Keystore encrypted; no plaintext pending cloud document is written.
- Watch Later Sync: A Premium user's movie and series selections are synchronized between devices in the account and profile scope. Playlist addresses, usernames, and passwords are not added to these records; source identifiers are one-way hashed.
- Support Data: Support conversations are stored in Firebase Firestore under the account identifier. The device notification token is removed on sign-out and invalid tokens are cleaned automatically. Conversations may be retained until an account/data deletion request is completed or for as long as legal and security obligations require.
- PIN Security: Hashed with PBKDF2WithHmacSHA256 + random salt
- Transport Security: Atlantic account, support, purchase, and speed-test services use HTTPS with system certificate validation. User-added IPTV provider addresses can use HTTP or legacy/self-signed HTTPS depending on the provider configuration; users choose those sources.
4. Third-Party Services
- Google Firebase: Authentication, Firestore, Cloud Messaging, Analytics, Crashlytics, and Performance Monitoring
- Google Ads and Google AdMob: App-install and campaign attribution/measurement plus limited in-app ad delivery to eligible Free users; consent choices are managed with Google's User Messaging Platform (UMP)
- Google Play Billing: In-app purchase processing
- Cloudflare and OVHcloud: Temporary download endpoints for a user-initiated Speed Test; these providers may process the IP address and standard network metadata under their own policies
These services have their own privacy policies:
5. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request data deletion ("right to be forgotten")
- Data portability (cloud backup export)
- Object to automated processing
- Withdraw consent at any time
Data Deletion: Settings > Sign Out ends the account session and clears local user data on that device; it does not delete cloud backups or support conversations. To permanently delete your account and associated data held by Atlantic Player, follow the steps on the
account-deletion page or send a request from your registered account to
atlanticdigital24@gmail.com. Google accounts use recent Google reauthentication; managed-user and device-code accounts can create a request by having the current PIN/device key verified on the secure server. A PIN or device key is never written to the URL, logs, or Firestore deletion request. Verified deletion requests are completed within 7 business days. Completion removes the relevant Google, managed, or device-code account, Auth identity, UID-scoped cloud envelope, and support data. Because a current e-mail is not proof of historical ownership, independent legacy-backup escrow is not claimed or erased early by an ordinary request. A current e-mail is also not proof of ownership of an independently PIN/device-key credentialed managed user, device activation, trial, or financial row; a Google-UID request does not automatically delete or anonymize those e-mail-only matches and is limited to UID-proven or server-sealed identities. If a request finds unproven historical sources that have not yet entered escrow, a content-free PREPARING/QUARANTINE lock freezes them against reassigned-e-mail access; after Phase B, a server workflow approved by two distinct authenticated administrators atomically moves the plaintext generation into escrow. Once ciphertext is created it is deleted by its at-most-90-day TTL; earlier deletion or recovery requires two-operator historical proof. Play financial records required for purchase verification, refunds, and accounting are retained; UID, email, and device identity are removed from UID-proven records, and a de-identified entitlement tombstone prevents another account from claiming the purchase. An anonymous completion receipt containing no content, email, or raw UID may be retained for up to 3 years for audit and anti-recreation controls. A UID-path lock containing no email or content prevents stale sessions from recreating data and enters TTL cleanup after 48 hours. Google also applies its own legal-retention requirements.
6. Children's Privacy
The App is not intended for children under 13. Parental control features are available: PIN-protected category locking and child lock timer to limit viewing time.
7. Changes
This privacy policy may be updated. Significant changes will be announced via in-app notification.
8. Contact
For questions: atlanticdigital24@gmail.com