Ninety legal
Privacy Policy
Launch configuration required: this document still contains explicit placeholders and must not be treated as final legal copy.
This Policy explains how [Company legal name], at [Company address], handles information when you use Ninety. Privacy contact: [Support email].
1. Information we process
- Account information from Supabase Auth, including your authentication subject and, when available, email address and sign-in provider.
- TV information including platform, model/model code, app version, connection times, and a locally generated installation identifier.
- When Samsung makes them available, the TV DUID as the primary physical-device signal and the currently configured network MAC address as a secondary security and abuse signal.
- Trial, entitlement, subscription, connected-device, and legal-acceptance records.
- Operational and security information such as timestamps, request metadata, IP-derived rate-limit activity, and service error data. Ninety does not intentionally log raw DUID, MAC, pairing secrets, playlist URLs, or provider credentials.
2. Device identifiers
Raw DUID and MAC values are sent to Ninety over HTTPS during pairing, normalized, and converted to keyed one-way HMAC fingerprints before persistent storage. They are not account passwords or TV credentials, are never shown to users, and are not placed in QR URLs. If ProductInfo or DUID is unavailable, a locally generated installation identifier supports installation continuity but does not establish eligibility as a verified physical TV. A separate high-entropy, revocable credential authenticates the connected TV.
3. Playlist and provider details
If you choose phone setup, the pairing service temporarily holds the playlist URL—or a temporary URL constructed from M3U/Xtream provider server, username, and password—only long enough to hand it to your TV. Ninety Web does not parse the playlist. The TV retrieves and consumes it, after which the pairing service clears it; expired records are also scrubbed. Provider credentials are not stored as permanent account data. Do not send provider details through support messages.
4. Why we use information
We process this information to authenticate you, connect and secure TVs, enforce one-trial-per-account and one-trial-per-physical-TV rules, calculate entitlement, provide support, prevent abuse, meet legal obligations, and operate the service.
5. Legal bases
Depending on the activity and applicable law, processing is necessary to provide the service or take requested pre-contract steps, protect Ninety and users through legitimate security and abuse-prevention interests, comply with legal obligations, or act on consent where consent is required. Final controller analysis and jurisdiction-specific notices must be completed before public launch.
6. Processors and transfers
Supabase processes authentication data. Railway hosts the API and database. Stripe processes checkout, payment methods, subscriptions, and billing-portal activity only when paid billing is configured. These providers may use their own subprocessors. Final processor locations, contractual roles, international-transfer safeguards, and a maintained subprocessor list must be completed before public launch.
7. Retention
Retention is limited to what is reasonably needed for the stated purpose, security, dispute handling, and legal obligations. Account and active device-link data is kept while needed to provide and secure Ninety. Trial-grant and physical-device fingerprint history may be retained after account or device removal to enforce one-time eligibility and prevent abuse. Legal acceptances are retained as records of the version accepted. Pairing records and playlist details are short-lived and scrubbed after consumption or expiry. Billing records follow financial and legal retention requirements. Exact schedules must be finalized before paid public launch.
8. Your choices and data-protection rights
You can rename or remove TVs and manage billing from your account. Removing a TV revokes its credential but does not automatically erase anti-abuse trial history. Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to the competent data-protection authority. To exercise a right or request account deletion, contact [Support email]. Identity verification and lawful retention exceptions may apply. Final response instructions and supervisory-authority details must be supplied for [Jurisdiction].
9. Security and service changes
Ninety uses access controls, revocable device credentials, server-side token verification, encrypted transport, and keyed device fingerprints to reduce risk. No system is completely secure. Material privacy changes will receive a new document version and effective date.
10. Contact
[Company legal name] · registration [Company registration number] · [Company address] · [Support email]