Privacy Information
How the Delta Player website, application update service and supporting cloud API process technical data.
1. Project and privacy contact
Delta Player is a private and non-commercial software project. The application is provided completely free of charge.
Privacy questions may be sent to privacy@yourdelta.link.
2. Website and server logs
When you access this website or the Delta API, the web server and reverse proxy may process the IP address, date and time, requested path, HTTP method, response status, transferred data volume, referrer and user-agent. These data are required to deliver the service, detect abuse, investigate faults and protect the infrastructure.
Legal basis: Article 6(1)(f) GDPR. The legitimate interests are secure, reliable and abuse-resistant operation of the website and update infrastructure.
Application-database request logs are automatically deleted after no more than 30 days. Reverse-proxy and hosting logs must be configured by the operator to a maximum of 14 days, unless a longer period is necessary to investigate a specific security incident or comply with a legal obligation.
3. APK download and local verification
APK downloads necessarily expose the requesting IP address and technical request data to the server. The public verification page downloads the official release manifest and calculates the selected APK's SHA-256 hash locally in your browser.
The selected APK file is not uploaded to the Delta server by the verification page. The browser compares the locally calculated hash with hashes published in the official release manifest.
4. Application update requests
The app may contact yourdelta.link to check for updates and download an official APK. The server receives the network address and may receive the currently installed version code. This is used only to determine whether an update is available and to deliver the requested file.
Legal basis: Article 6(1)(f) GDPR. The legitimate interests are secure software distribution, vulnerability remediation and prevention of modified or counterfeit releases.
5. Anonymous installation and online statistics
The app may send a randomly generated installation identifier, app version and platform value to the Delta server. Before storage, the installation identifier is converted into a SHA-256 hash. The server stores only the hash, first and last activity timestamps, app version and platform. It does not store the original installation UUID in the device-statistics table.
An installation is counted as online only while a recent foreground heartbeat exists. Hashed device records are deleted after no more than 730 days without activity.
Legal basis: Article 6(1)(f) GDPR. The legitimate interests are capacity planning, compatibility monitoring and displaying aggregate service statistics. No advertising profile or cross-service tracking profile is created.
6. Media metadata and subtitle services
To resolve metadata or subtitles, the app may send technical search parameters to the Delta API, such as a title, media type, year, season, episode and requested language. Depending on the enabled feature, the server may forward only the relevant search parameters to external metadata or subtitle services. Those services normally receive the Delta server's network address, not the user's provider credentials.
Delta does not require users to submit IPTV provider usernames, passwords, portal tokens or MAC addresses to the Delta cloud service. Provider credentials should remain on the user's device. When optional catalogue synchronisation is disabled, provider catalogues are not uploaded. If that deployment setting is changed, this policy must be updated before the feature is made available to users.
Metadata and subtitle cache entries may be retained while they remain technically useful. They generally describe media titles rather than identifiable users.
7. Cookies and local storage
The public website does not use advertising cookies, marketing trackers, analytics pixels or behavioural profiling. The protected admin area uses one strictly necessary, HTTP-only session cookie restricted to the /admin path. It expires after a maximum of 12 hours. Public visitors do not receive that admin cookie.
The APK verification page reads the file selected by the user in browser memory only. It does not place the APK in browser storage.
8. Recipients and hosting
Technical data may be processed by the VPS/hosting provider acting as infrastructure provider:
InterServer, Inc.PO Box 1707, Englewood Cliffs, NJ 07632
United States of America
External metadata, subtitle and communication services process requests under their own terms and privacy information. Data are disclosed to an external communication service only when a user intentionally follows the corresponding external link. No third-party communication widget is embedded on the website.
9. Contact by email
When you contact Delta by email, the email address, message content and technical mail metadata are processed to answer the request and protect against abuse. Do not send provider passwords, portal tokens, payment information or other unnecessary secrets.
Legal basis: Article 6(1)(f) GDPR and, where the communication concerns steps requested before entering an agreement, Article 6(1)(b) GDPR. Messages are normally deleted no later than 12 months after the matter is closed, unless legal retention duties or the defence of legal claims require longer storage.
10. Your rights
Subject to the legal requirements, you may request access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Where processing is based on consent, consent may be withdrawn for the future.
Requests can be sent to privacy@yourdelta.link. The controller may request information necessary to verify the identity of the requester.
11. Automated decision-making and children
Delta does not use personal data for automated decisions producing legal or similarly significant effects. The service is not designed to collect personal information from children. Parents or guardians who believe a child has submitted personal data may contact the privacy address above.
12. Changes to this policy
This policy may be updated when the service, infrastructure or legal requirements change. The current version is published on this page with its revision date.
Last updated: 20 July 2026