Privacy Policy
How ForgeIPTV handles information.
This Privacy Policy explains how ForgeIPTV handles information through the website https://forgeiptv.com/ and the ForgeIPTV Windows app.
Last updated: September 1, 2026
1. Who we are
ForgeIPTV is a Windows IPTV player app focused on helping users organize and play their own legal M3U playlists and Xtream Codes accounts.
Contact email: support@forgeiptv.com.
2. Important content disclaimer
ForgeIPTV is not an IPTV provider.
ForgeIPTV does not provide TV channels, playlists, subscriptions, streams or copyrighted content.
Users are responsible for using their own legal IPTV account or source.
3. Information collected through the website
The ForgeIPTV website includes product information and a device activation page.
Forge account sign-in is passwordless. If you choose to continue a device activation, we collect the email address you provide, send a short-lived authentication link, and create or access your Forge account only after that link is successfully used.
If you contact us by email at support@forgeiptv.com, we receive the information you choose to include in your message.
The hosting provider may process standard technical server logs, such as IP address, browser information, requested pages, date and time, and security-related logs.
Device activation uses random installation and session identifiers, device platform, application version when supplied, trial timestamps, license/device-seat status and security rate-limit records. ForgeIPTV does not collect IPTV provider credentials, playlist URLs or viewing activity for account or licensing purposes.
When you buy a lifetime license through Stripe Checkout, Stripe processes the payment information. ForgeIPTV does not store card details. ForgeIPTV retains the purchase status, limited Stripe payment identifiers needed for licensing/support, the lifetime license, and its device-seat association.
4. Information handled by the app
ForgeIPTV stores account configuration, application preferences, favourites, playback history and EPG cache locally on the user’s device.
Passwords, M3U playlist URLs and EPG URLs are protected at rest using Windows Data Protection API (DPAPI) for the current Windows user. Account display names, usernames, server addresses and other non-secret preferences may remain stored locally.
This local information is not sent to ForgeIPTV unless the user explicitly submits a support request as described below.
ForgeIPTV does not sell IPTV credentials.
ForgeIPTV does not provide IPTV content.
When the app stores configuration locally on the user’s device, it is used only to remember settings and operate the app.
5. How information is used
Information may be used to:
- respond to support requests;
- answer product questions;
- maintain website security;
- operate and improve the ForgeIPTV product;
- authenticate Forge accounts and connect an account to a device activation session;
- associate Forge account identity, licenses and activated device seats for licensing;
- comply with legal obligations where applicable.
6. Support requests
Users may voluntarily submit a support request through the app. A support request includes the selected category, subject, message and, when provided, a contact email address.
If the user chooses to include technical information, the request may also contain the ForgeIPTV version, Windows version, selected theme, account source type, connection status, EPG enabled status, last EPG refresh result and submission timestamp.
Support requests never automatically include passwords, usernames, playlist URLs, provider URLs, EPG URLs, tokens or stream URLs.
Support requests are transmitted over HTTPS to https://forgeiptv.com/api/support/ and are processed only for support, security and product-improvement purposes.
7. Cookies and analytics
ForgeIPTV does not use analytics scripts, advertising cookies or tracking cookies on the activation and sign-in pages.
Device activation and account sign-in use strictly necessary Secure, HttpOnly cookies. These cookies hold high-entropy session credentials used to restore the temporary device activation session and the signed-in Forge account session. The account session is configured to expire after approximately 30 days and may be revoked by logging out.
These necessary cookies allow a signed-in activation session to continue after returning from Stripe Checkout.
8. Third-party services
The website may link to third-party services such as the Microsoft Store.
Those services are operated by third parties and have their own privacy policies and terms.
ForgeIPTV is not responsible for the privacy practices of third-party websites or services.
The app connects directly to IPTV and EPG services configured by the user. Those providers may receive the user’s IP address and request information according to their own privacy policies.
Stripe processes direct website lifetime payments, while Microsoft Store may process Store purchases. ForgeIPTV does not receive or store payment card details.
9. Data sharing
We do not sell personal information.
We may process email messages through our email provider and technical logs through our hosting provider.
We may disclose information if required by law.
10. Data retention
A verified Forge account email and its device-activation association are retained while needed to provide account and licensing services and meet applicable legal or security requirements. Account-session records expire after the configured session period. Unused magic links expire after approximately 15 minutes; only keyed token derivatives are stored server-side, and expired or consumed link/session records are removed in bounded cleanup after a limited operational period.
Support emails and in-app support requests may be kept for as long as needed to handle the request and maintain support history.
Technical server logs are retained according to the hosting provider’s policies.
Users may request deletion of support communications where applicable.
11. User rights
Depending on your location, you may have rights to access, correct, delete or restrict the processing of your personal information.
To exercise privacy rights, contact support@forgeiptv.com.
12. Children
ForgeIPTV is not directed to children.
The website and app are intended for users who are legally allowed to use this type of software and their own IPTV services in their jurisdiction.
13. Security
ForgeIPTV uses reasonable technical measures to protect information. Sensitive connection values stored by the app are protected with Windows DPAPI, support and account requests are transmitted using HTTPS, account and activation bearer tokens are stored server-side only as keyed derivatives, and credentials are excluded from support diagnostics and application logs.
No method of storage or transmission can be guaranteed to be completely secure.
14. Changes to this policy
This Privacy Policy may be updated from time to time.
When changes are made, the updated version will be published on this page.
15. Contact
For privacy questions, contact:
support@forgeiptv.com
16. Pseudonymous technical telemetry
ForgeIPTV may collect limited pseudonymous technical and usage telemetry to improve reliability and understand broad product use. This may include a persistent installation identifier, platform, application version, licensing-state categories, session duration, playback duration, and broad content/source categories.
Telemetry is not marketing tracking. It does not intentionally collect playlist or provider credentials, streaming or playlist URLs, channel, movie, series, or programme titles, or IPTV content identifiers.