Privacy Policy
Last updated 9 August 2026
The short version
Cordbox doesn't run a server, doesn't have user accounts, and doesn't collect analytics. It's a player: it connects directly, from your device, to the IPTV playlists, portals, media servers, or network shares you point it at. Anything it needs to remember — source addresses, login details — stays on your device. The sections below cover the specific, narrower cases where data does leave the app.
Your sources
When you add a source (an M3U playlist, an Xtream Codes or Stalker/ Ministra portal, an Enigma2 box, a Plex/Jellyfin/Emby server, a DLNA device, or an SMB/NFS share), Cordbox connects directly from your device to that source to fetch channels, media, and guide data, and to play streams. That connection and whatever data it carries is between your device and your own source — Cordbox itself never sees or stores it elsewhere. Any address, username, password, or MAC address you enter is stored in your device's Keychain, not in plain settings storage, and never leaves your device unless you explicitly export it yourself (see below).
Exporting or backing up sources
The app's Export Sources feature creates a file — including saved credentials, so a restore is genuinely one step — that goes only wherever you personally send it, through the system share sheet (AirDrop, Files, email, and so on). Cordbox never uploads this anywhere automatically.
Ratings lookups (OMDb)
If you choose to set your own free API key from omdbapi.com in Settings, tapping "Look Up Rating" on the player screen sends the title you're watching to OMDb to fetch its rating and details. This only happens when you've set a key and tap the button — never automatically. OMDb's own handling of that request is governed by their own privacy policy, not this one.
Advertising
Cordbox's free tier shows ads, served by Google AdMob, to fund development instead of charging every user. Where you've given permission (via Apple's App Tracking Transparency prompt and, in the UK/EEA, Google's own consent form), AdMob may use advertising identifiers to personalize which ads you see; if you decline, ads still show but aren't personalized. Google's handling of this data is governed by their own privacy policy, not this one — see How Google uses information from sites or apps that use our services. A paid monthly subscription removes ads entirely.
Playback diagnostics & debug logging
Cordbox keeps a local history of recent playback attempts — useful for troubleshooting a channel that hangs or crashes the app — entirely on your device. It's never transmitted anywhere, and you can find it under Settings → Playback Diagnostics. Settings also has an off-by-default Debug Logging toggle for more detailed technical logging, written to a local file only — it stays off until you turn it on, and only ever leaves your device if you choose to share it yourself (e.g. when troubleshooting a problem).
Local network access
Cordbox asks for local network permission to discover and connect to devices already on your own network (Enigma2 boxes, DLNA/UPnP servers, SMB/NFS shares). This traffic stays on your local network, between your device and your own equipment.
Children
Cordbox isn't directed at children and doesn't knowingly collect information from them. It's a player for content you already have access to elsewhere — it doesn't host, provide, or verify any content itself.
Changes to this policy
If this policy changes, the date at the top of this page will be updated. Continued use of the app after a change means you accept the updated policy.
Contact
Questions about this policy or your data can be sent via the contact link on cordbox.app.