Privacy

Vortexo Privacy Policy

Last updated: September 10, 2026

Overview

No advertising business.

Vortexo does not sell personal data and does not use personal data for advertising. The app connects to media services and libraries you choose and are authorized to access. Available integrations vary by platform and app version.

Vortexo account

One account across your devices.

If you create a Vortexo account, we process your email address, display name, linked sign-in provider identifier, app-store entitlement status, device pairing records, profiles, preferences, and the source configuration you choose to synchronize. We use this data only to authenticate you, connect your devices, restore eligible purchases, synchronize your selected settings, provide support, prevent abuse, and operate the service.

Cloud service providers

Limited infrastructure processing.

Cloudflare hosts Vortexo account services, stores account configuration, and provides security controls. Resend may deliver one-time sign-in codes by email. Google or Apple processes sign-in when you choose its sign-in button. Apple App Store and Google Play process purchases and provide transaction or entitlement identifiers. These providers process data under their own policies; Vortexo does not receive your Google or Apple password or your payment-card details.

Authentication security

No reusable Vortexo password.

Vortexo uses one-time email codes, Google sign-in, Apple sign-in, or a short-lived TV pairing code. Email codes expire after 5 minutes, browser sessions after 15 minutes unless refreshed, TV pairing codes after 10 minutes, and device refresh credentials after 30 days. We store keyed hashes or encrypted one-time protocol material rather than the plain code or provider access token. Expired and consumed authentication records are retained only as needed for security, abuse prevention, and service integrity.

Media sources

Your configured services.

Server addresses, account details, add-on configuration, playback settings, source settings, and guide data are provided by you and used to connect to your selected services. Stremio and other service credentials are stored in protected device storage and sent only to the service needed to complete your request. Vortexo does not place auth tokens, debrid keys, private add-on URLs, or stream URLs in ordinary cache or diagnostic logs.

Stremio account sync

Your account, library, and playback state.

On Android TV, connecting Stremio lets Vortexo request your account email, Library, Continue Watching state, installed add-on roster, and playback progress from Stremio. Library and progress changes you make in Vortexo are sent back to Stremio. When you ask to play a title, Vortexo sends its media identifier to eligible add-ons already installed on your account. The Google Play version does not provide an add-on directory or use account add-ons to build its metadata catalogs.

Diagnostics

Crash and error reports.

Release builds may send crash reports, app hang reports, device and app version, failed-request status, and sanitized playback breadcrumbs when diagnostics are enabled for that build. Diagnostics are currently disabled in the Android TV build when no Sentry connection is configured. Diagnostic reports must not contain auth tokens, debrid keys, private add-on URLs, or stream URLs. These reports are used for reliability and security, not advertising.

Third-party content

Vortexo is a client.

Vortexo does not provide, host, sell, or distribute media content. It acts as a media-player client for services and libraries you choose, including a connected Stremio account, Plex servers, Live TV sources, and account add-ons. You are responsible for using only sources you are authorized to access.

Purchases

Handled by the app store.

Purchases and subscriptions offered in Vortexo are processed by Apple App Store or Google Play, depending on your platform. Vortexo does not receive or store payment-card information. Manage or cancel a subscription through the store account used for the purchase.

Other services

Their policies still apply.

When you connect Vortexo to Stremio, Plex, Live TV providers, add-on providers, or other user-selected services, those services receive requests directly and may process data under their own privacy policies. Vortexo does not control those services or their content.

Optional subtitle translation

Off until you enable it.

If you enable AI subtitle translation and provide your own Gemini API key, subtitle dialogue selected for translation is sent to Google Gemini. Vortexo does not include the video, account credentials, private source URL, or media file in that request. The feature sends nothing to Gemini while disabled or without a user-provided key.

Source reports

You choose what to send.

The Android TV app can create a short report code derived from a one-way provider hash. The code does not contain your account key or private source URL. If you email support, your email address, report code, and details you voluntarily include are used to investigate and respond. Do not send passwords, auth tokens, debrid keys, private add-on URLs, or stream URLs.

Control and deletion

Export, disconnect, or delete.

You can export your Vortexo account data or permanently delete the account from the Account hub. Account deletion removes the account, synchronized profiles, preferences, devices, source descriptors, and encrypted source credentials from active Vortexo systems. A minimal deletion receipt and security audit record may remain to prove the request, prevent abuse, and meet legal obligations; it does not contain a reusable password, provider token, debrid key, or private stream URL. On Android TV, Reset App Setup removes locally stored Stremio and Plex credentials and reopens onboarding. Uninstalling removes app-local data according to your operating system. These actions do not delete data held independently by Stremio, Plex, Google, Apple, an app store, or an add-on provider; use that service's controls for its copy.