← Back to the app

Privacy notice

Applies to the Android TV app “ArenaNow” and to this website. Last updated: 16 September 2026.

This is a translation. In case of doubt the German version of this document applies.

Draft. This text describes the data flow as actually implemented in the program code. It has not yet been reviewed by a lawyer and may only be published after that review. All [[placeholders]] must be replaced before publication.

1. Controller

Provider
[[ANBIETER]]
Address
[[ANSCHRIFT]]
Email
[[EMAIL]]

A data protection officer is [[APPOINTED / NOT APPOINTED]].

2. Local app and sports data service

ArenaNow is a playback application for your own channel source. The app does not supply channels and does not arrange subscriptions. Credentials are stored protected on the TV. For playback the app connects directly to your provider.

If a sports data service is set up, the app loads events and matches. For the matching it may transfer selected details from your channel catalogue to that service. Provider user name, password and full stream addresses are not part of this catalogue upload. There is no product account.

The app contains no advertising, no analytics or tracking components and no automatic crash reporting to us.

3. What is stored on your device

DataPurposeStorage
Credentials for your source (address, user name and password)Load the catalogue and start playbackIn the private app storage, encrypted with a key from your device’s Android keystore. The complete stream address is only assembled at the moment of playback and is not stored per channel.
Channel catalogue, programme data, sports matchesDisplay and searchLocal database in the private app storage
Favourites, last channel watched, picture and sound settingsOperationLocal settings in the private app storage
Diagnostic report after a failed import (files/import-diagnostic.json)Troubleshooting on your deviceLocal file without credentials. It is not sent automatically. If you pass it on yourself for a support request, that is your decision.
Cached crests and logosDisplay of the eventsLocal image cache, limited to 64 MB

The app is excluded from Android’s automatic backup, so this data does not end up in a cloud backup. You delete the local data by removing the source in the app, clearing the app data in the Android system or uninstalling the app. Channel catalogues already transferred and server logs are not deleted on the server side automatically as a result.

4. Which connections the app makes

4.1 To your own source

During the import and with every playback, the app connects directly to the provider you entered. That provider sees your IP address, the time and the addresses requested. That is your contractual relationship with that provider, not ours; their privacy notice applies to how they handle your data. We receive nothing from these requests.

4.2 To the configured sports data service

Over HTTPS the app loads sports events, competitions, broadcast references, matching rules and, where applicable, supplementary matching and measurement files. The request may contain an identifier of the most recently loaded state so that unchanged data is not loaded again.

With a configured source and sports data connection, the app may transfer selected catalogue data for the matching: channel IDs, channel names, groups, EPG IDs and archive days. Added to this is a panel identifier derived from the provider host and port, and where applicable the time zone of the source. The server matches catalogue states by checksums. That is not a device identifier; the data is therefore not blanket anonymous either.

The catalogue upload contains no provider user name, no password and no complete stream or image addresses. Configured access authentication for the sports data service is used for its requests. Retention period and deletion procedure for the transferred catalogues: [[CATALOGUE RETENTION AND DELETION PROCEDURE]].

As with every request on the internet, technically necessary connection data arises on the server side: IP address, time, requested address, status code, amount of data transferred and the program identifier sent by the app. We use this data solely for secure operation and troubleshooting, do not combine it with other data and do not build usage profiles from it. Log retention period: [[LOG RETENTION]]. Server location: [[SERVER LOCATION]].

The legal basis is Article 6(1)(b) GDPR (providing the function you requested) and Article 6(1)(f) GDPR (legitimate interest in secure, trouble-free operation).

4.3 To image sources

Crests and competition marks are loaded from addresses contained in the sports data packet. If such an address is hosted by a third party, that provider sees your IP address when the image is loaded. The app only loads images from addresses in this packet, follows no redirects and sends no identifiers.

4.4 Unencrypted connections to your source

Our sports data server is only addressed over HTTPS. Some IPTV providers, however, offer their addresses over unencrypted HTTP only. The app therefore uses HTTP only if you explicitly switch it on for exactly your source. In that case your user name, your password and the addresses requested can be read by third parties in transit. This setting applies only to the source you entered and can be withdrawn at any time.

5. App permissions

The app requests only INTERNET (establish connections) and ACCESS_NETWORK_STATE (detect whether a connection exists). It does not access location, camera, microphone, contacts, telephony functions or your media library.

6. Recipients and transfers to third countries

We do not pass personal data on to third parties. As a processor for the operation of our server we use [[HOSTER, ADDRESS]]; a contract under Article 28 GDPR is in place for this. A transfer to third countries [[DOES NOT TAKE PLACE / takes place on the basis of …]].

7. Google Play

If you obtain the app through Google Play, Google processes data under its own responsibility (among other things for installation, updates and stability statistics). We have no influence on that processing; Google’s privacy notice applies. From Google we only receive aggregated, non-personal evaluations.

8. This website

These pages are static. They set no cookies, load no fonts or scripts from external servers and embed no analytics tools. When they are requested, the usual server log data arises at the host (see section 4.2). The locally loaded website script only controls navigation and the product demo; it sends no analytics events and uses no browser storage.

9. Your rights

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to processing based on legitimate interests (Article 21). Please contact the address given in section 1 for this.

There is no product account. You can remove locally stored data on the device. For questions about transferred channel catalogues or server logs, please contact the address in section 1. Whether and how existing server data can be linked to a request has to be examined case by case; please do not include provider passwords.

You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is [[SUPERVISORY AUTHORITY]].

10. Changes

If the functions of the app change, we change this notice accordingly. The version published here with the date given above is the one that applies.