Privacy Policy – Watch More
Summary
Watch More is a player for media sources you supply. Your media library stays on your device. If you choose the optional encrypted source transfer during setup with a supported Samsung Tizen TV or Android/Fire TV, only the selected sources use the temporary relay described below. Watch More Pro uses a pseudonymous identity and an entitlement service to validate purchases and link devices. Optional crash reporting and Chromecast have separate controls. Watch More has no ads and does not use your data for cross-app advertising or sell your personal data.
Data stored on your device
Source credentials and playlist URLs, catalog and guide data, favorites, watch progress, search history, profile names, parental PINs, downloaded media and cached artwork are stored locally. On iOS and Android phones, source credentials use secure platform storage. On Samsung TVs, source data is stored in the app's private storage. Your catalogs, guide data, history and settings are not sent to DevDad's entitlement service or RevenueCat.
Setting up a supported TV from your phone
If you choose to approve a source transfer during setup on a supported Samsung Tizen TV or Android/Fire TV, your phone sends the selected source details and credentials through our server as an encrypted payload. The server cannot decrypt it. This source-only transfer is independent of Watch More Pro: free users can transfer one selected source, and Pro is optional. Catalogs, guide data, history and settings are not transferred.
An active transfer is available for three minutes. The server deletes it after the TV acknowledges that it saved the source durably, or during expiry cleanup if there is no acknowledgement. Encrypted copies can remain in infrastructure backups or snapshots and are scheduled for deletion after 90 days under the current backup retention schedule. Deleting the active transfer does not immediately remove those copies, and we do not claim secure erasure from backups.
Watch More Pro and linked devices
To validate and restore purchases and share Pro across devices, the app creates a random Watch More ID. It is not your name, email address or profile name, but it identifies your Pro account. RevenueCat processes that ID, purchase and entitlement metadata and app/platform information. DevDad's entitlement service additionally processes device public keys, platform and form factor, generic device labels, pairing records and security/rate-limiting information. We use these records to provide Pro, prevent abuse and support purchase restoration and device linking. RevenueCat's automatic device-identifier collection is disabled.
Apple, Google, or Amazon processes payment details for purchases made through its store. We do not receive your payment-card details. Each store's privacy policy applies to its transactions. RevenueCat describes its processing at RevenueCat Privacy Policy.
Optional diagnostics
Crash reporting is off by default. If you opt in, redacted crash, performance and diagnostic data is sent to Sentry's EU service and retained for 30 days. Sentry may infer approximate location, including city, from the connecting IP address. Nothing is sent to Sentry before consent. You can turn this off in Settings. Export Diagnostics creates a local report that leaves your device only when you choose to share it.
Casting and media services
Chromecast is available on supported Apple and Google Play Android builds and is off until you enable it in Settings → Casting. It is not included in the Amazon Appstore Fire TV build. Google's Cast SDK discloses Device ID, Other Diagnostic Data and Product Interaction collection for analytics and app functionality. Watch More disables optional Cast analytics logging. AirPlay on supported Apple devices and DLNA communicate with receivers on your local network. Casting sends the selected media or its address to your receiver; phone-side conversion takes place locally.
Your device connects to source providers to fetch catalogs, guide data and media. Those providers receive the requests and apply their own privacy policies. Optional subtitle and metadata services receive the searches needed for those features. Use trusted sources and HTTPS where available.
Retention, deletion and your rights
Local data remains until you remove it. After ownership verification, we permanently delete the related primary-service identity, entitlement, linked-device and pairing records, then request RevenueCat customer deletion. Processing is asynchronous; support checks the exact Watch More ID in RevenueCat customer search again until it is no longer returned. A keyed, one-way digest of the deleted Watch More ID is retained indefinitely only to prevent re-creation. The deletion page explains the 30-day diagnostic log period, up-to-90-day replay-ledger and backup retention, subscriptions and local data. Deleting the app alone does not delete service records or cancel subscriptions.
For access, correction, deletion, restriction, portability or objection requests, contact DevDad at [email protected]. We may need to verify ownership. We process service data to provide the requested functionality and protect it against abuse; optional crash reporting relies on your consent, which you can withdraw in Settings. You may also complain to your data-protection authority.
Children and changes
Watch More is not directed at children. Available media depends on the sources you add. We update this page when data practices change and describe material changes in the app where appropriate.