Privacy Policy
How ForgeIPTV handles information.
This Privacy Policy explains how ForgeIPTV handles information through the website https://forgeiptv.com/, its web services, and the ForgeIPTV apps for Windows, Fire TV and Android TV.
Last updated: October 5, 2026
1. Who we are
ForgeIPTV is an IPTV player for Windows, Fire TV and Android TV focused on helping users organize and play their own legal M3U playlists and Xtream Codes accounts.
Contact email: support@forgeiptv.com.
2. Important content disclaimer
ForgeIPTV is not an IPTV provider.
ForgeIPTV does not provide TV channels, playlists, subscriptions, streams or copyrighted content.
Users are responsible for using their own legal IPTV account or source. Their IPTV provider is an independent third party; ForgeIPTV does not control or supply that provider’s content.
3. Information collected through the website and licensing services
The ForgeIPTV website includes product information, official TV APK downloads, device activation and an account portal.
Forge account sign-in is passwordless. If you choose to sign in or continue a device activation, we collect the email address you provide, send a short-lived authentication link, and create or access your Forge account only after that link is successfully used.
If you contact us by email at support@forgeiptv.com, we receive the information you choose to include in your message.
The hosting provider may process standard technical server logs, such as IP address, browser information, requested pages, date and time, and security-related logs.
The TV app contacts ForgeIPTV Licensing to register an installation, verify its seven-day trial or license, refresh authorization, and support device activation and license recovery. These services process installation and session identifiers, device platform, application version when supplied, registration and trial timestamps, license/device-seat status and limited security rate-limit records. A device-derived identifier may also be processed to prevent repeated trial claims; the server retains a protected pseudonymous derivative rather than the raw device value. ForgeIPTV does not collect IPTV provider credentials, playlist URLs or viewing activity for account or licensing purposes.
Windows trials and purchases are managed through Microsoft Store, including the seven-day Windows trial. TV trials and Lifetime licenses are managed separately through ForgeIPTV Licensing. Windows and TV licenses are not interchangeable.
Where TV payments are enabled, Stripe Checkout processes the payment information. ForgeIPTV does not receive or store full payment card numbers. ForgeIPTV retains purchase information such as status, amount, currency and timestamps, limited Stripe identifiers needed for licensing/support, the TV Lifetime license and its device-seat association.
4. Information handled by the app
ForgeIPTV stores IPTV connection configuration, application preferences, favourites, playback history, progress, Recently Watched, Continue Watching state and EPG cache locally on the user’s device. This local player data is distinct from Forge account, licensing and technical telemetry records described elsewhere in this policy.
On Windows, protection depends on the data and app version. Forge Licensing data may be protected using Windows Data Protection API (DPAPI), tied to the current Windows user. This does not encrypt all local configuration: IPTV accounts, provider credentials and URLs may be persisted in local JSON without application-level encryption. Do not assume that locally stored provider information is protected by DPAPI.
On Fire TV and Android TV, provider credentials and sensitive M3U playlist and EPG URLs are encrypted at rest using keys protected by Android Keystore. Connection labels, server addresses, preferences and other local metadata are not necessarily encrypted. This protection does not guarantee that data cannot be accessed on a compromised device.
Normal IPTV operation does not require sending your provider credentials or playlist URLs to ForgeIPTV’s backend. The app uses them to connect directly to your configured sources. Licensing, update checks, voluntary support requests and operational telemetry are separate communications; they do not upload your stored IPTV connection configuration as part of normal operation.
ForgeIPTV does not sell IPTV credentials.
ForgeIPTV does not provide IPTV content.
Uninstalling the app, clearing its data or resetting a device can remove local settings and progress. Correctly installed TV APK updates are designed to preserve local data, but cannot guarantee preservation against corruption, data deletion or device failure. Backups or restores may not preserve access to encrypted information or its keys, and protected Windows data may not be usable under another Windows user.
The TV app may contact ForgeIPTV over HTTPS to check a public version manifest for available updates. This request does not require a Forge account, licensing credentials or IPTV data and is not session or playback telemetry. The server or hosting provider can receive standard connection information, such as IP address, requested resource and time. Updates are installed manually over the existing app.
5. How information is used
Information may be used to:
- respond to support requests;
- answer product questions;
- maintain website security;
- operate and improve the ForgeIPTV product;
- authenticate Forge accounts and connect an account to a device activation session;
- associate Forge account identity, licenses and activated device seats for licensing;
- register TV installations, verify trials and licenses, refresh authorization and support license recovery;
- prevent basic trial, activation and payment abuse;
- provide TV version information and update notifications;
- analyze the limited operational telemetry described in section 16 for reliability, compatibility and broad product use;
- comply with legal obligations where applicable.
6. Support requests
Users may voluntarily contact support by email or, where available, submit an in-app support request. An in-app request includes the selected category, subject, message and, when provided, a contact email address.
For Windows in-app support, optional technical information may include the ForgeIPTV version, Windows version, selected theme, account source type, connection status, EPG enabled status, last EPG refresh result and submission timestamp. This does not mean that the TV app automatically sends the same diagnostics.
The automatic diagnostic fields are designed to exclude passwords, usernames, playlist URLs, provider URLs, EPG URLs, tokens and stream URLs. Text, attachments or logs you choose to share may contain additional information: review them before sending and do not include credentials or other secrets.
In-app support requests are transmitted over HTTPS to https://forgeiptv.com/api/support/ and are processed only for support, security and product-improvement purposes. Local diagnostic logs are not the same as an automatically submitted support request.
7. Cookies and analytics
ForgeIPTV does not use analytics scripts, advertising cookies or tracking cookies on the activation and sign-in pages.
Device activation and account sign-in use strictly necessary Secure, HttpOnly cookies. These cookies hold high-entropy session credentials used to restore the temporary device activation session and the signed-in Forge account session. The account session is configured to expire after approximately 30 days and may be revoked by logging out.
These necessary cookies allow a signed-in activation session to continue after returning from Stripe Checkout.
These flows also use temporary browser session storage to remember activation or checkout navigation state, not for advertising or analytics. Stripe’s own checkout page is subject to Stripe’s privacy and cookie practices.
8. Third-party services
Microsoft Store handles Windows distribution, trials and purchases under Microsoft’s Privacy Statement. ForgeIPTV’s hosting and email providers process website/backend traffic, technical logs, support correspondence and sign-in email delivery as needed to provide those services.
Those services are operated by third parties and have their own privacy policies and terms.
ForgeIPTV is not responsible for the privacy practices of third-party websites or services.
The app connects directly to IPTV and EPG services configured by the user. Those providers may receive the user’s IP address and request information according to their own privacy policies.
Where enabled, Stripe processes TV Lifetime payments through its hosted checkout under Stripe’s Privacy Policy. ForgeIPTV receives the limited purchase information described in section 3, not full payment card numbers. A TV purchase does not include a Windows license.
9. Data sharing
We do not sell personal information.
We may process email messages through our email provider and technical logs through our hosting provider.
We may disclose information if required by law.
10. Data retention
Verified Forge account emails, installation/trial records, protected trial-abuse identifiers, licenses, purchase records and device associations are retained while needed to provide account and licensing services, recover licenses, prevent abuse and meet applicable legal or security requirements. Expiry of a trial or browser session does not automatically delete these persistent records. Account sessions expire after the configured session period; unused sign-in links normally expire after approximately 15 minutes. Inactive link/session records are removed through bounded operational cleanup rather than necessarily at the instant they expire.
Support emails and in-app support requests may be kept for as long as needed to handle the request and maintain support history.
Technical server logs are retained according to the hosting provider’s policies.
Technical diagnostic and operational telemetry records are retained according to their operational purpose and applicable cleanup procedures, separately from persistent license records. Database backups may follow separate retention schedules and are not necessarily removed when live telemetry records are purged. You can contact us for information about retention or to request deletion; requests are handled through support rather than an automatic account or license deletion tool.
Users may request deletion of support communications and other personal information where applicable, using the contact details below.
11. User rights
Depending on your location, you may have rights to access, correct, delete or restrict the processing of your personal information.
To exercise privacy rights, contact support@forgeiptv.com.
12. Children
ForgeIPTV is not directed to children.
The website and app are intended for users who are legally allowed to use this type of software and their own IPTV services in their jurisdiction.
13. Security
ForgeIPTV uses reasonable technical measures to protect information, with different local protections on Windows and TV as described in section 4. TV uses encryption with Android Keystore-protected keys for sensitive connection values; Windows DPAPI protection, where used for Forge Licensing data, is not a guarantee that IPTV account configuration is encrypted. ForgeIPTV licensing, account, in-app support, update and telemetry communications use HTTPS, and server-side authentication records use protected derivatives rather than storing plaintext session credentials.
User-configured IPTV and EPG sources may use HTTP. Those connections are separate from ForgeIPTV’s HTTPS services, and unencrypted provider connections may expose credentials or request data in transit. Technical diagnostic fields and logging are designed to exclude or redact secrets, but this is not a guarantee that manually supplied text or every error message can never contain sensitive information.
No method of storage or transmission can be guaranteed to be completely secure.
14. Changes to this policy
This Privacy Policy may be updated from time to time.
When changes are made, the updated version will be published on this page.
15. Contact
For privacy questions, contact:
support@forgeiptv.com
16. Platform-specific telemetry and diagnostics
ForgeIPTV releases with telemetry enabled on Windows, Fire TV and Android TV can send limited allowlisted pseudonymous operational events to ForgeIPTV’s backend over HTTPS. This includes the published Windows 2.0.2.0 version and the current TV app. Events cover licensing resolution, app session start/end and playback start/end. They help us understand general app use and aggregate session behaviour, diagnose technical playback success or failure, and identify reliability, compatibility and licensing problems.
Data can include a pseudonymous installation identifier, random event/session/playback identifiers, platform, app version, event type and timestamps, licensing-state and offline authorization categories, aggregate session and playback durations, and normalized technical playback outcomes. Broad content categories distinguish Live TV, movies and series; broad source categories distinguish M3U, Xtream Codes or an unknown source type. These durations and categories do not identify the particular channel, movie, series or episode played and do not form a remote detailed viewing history. Favourites, Recently Watched, Continue Watching and playback progress remain local player data.
The allowlisted event data excludes IPTV usernames, passwords, tokens, provider URLs, playlist/M3U URLs, EPG URLs, stream URLs, provider or channel names, movie, series, episode or programme titles, searches, favourites, detailed viewing history, IPTV content identifiers and email addresses. Technical credentials linked to the installation may authenticate HTTPS requests, but are not stored as telemetry event data.
This telemetry is not used for advertising, personal profiling or tracking the specific content you watch. It does not use Advertising IDs, additional device fingerprinting or real names for these events. Pseudonymous identifiers allow technical events to be associated with a ForgeIPTV installation for operation and licensing; the data should not be treated as completely anonymous.
Telemetry delivery is best-effort. Events can be missing, including session or playback end events if the app or device stops abruptly. The public version-manifest check is a separate update request, not an analytics event. Local technical diagnostics and information you voluntarily share with support remain separate from these operational events and are handled as described above.