Privacy
Pre-release policy · updated 2026-07-25
WyreDeck is built so that we know as little about you as possible. A WyreDeck account is a randomly generated 16-digit number, and that number is the entire account identity. The optional access request is a separate contact workflow and is never attached to an account number.
What we store
- A one-way fingerprint of your account number. The durable account record does not contain a readable copy of the number, so it cannot be recovered from that record.
- Your account tier and its expiry date.
- While you pair a TV, an encrypted copy of the account number is held for that one transfer. The pairing code expires after five minutes. A successful TV poll clears the encrypted number immediately; otherwise the cleanup process normally removes the live session within about 16 minutes. An outage can delay live deletion until the service resumes. An encrypted database backup that captured the session may retain its encrypted copy for up to 14 days, but the expired pairing cannot be used through the API.
- A record for each paired device: a hashed device token, the device's public identity key, its display or model name and platform, and when it last checked in. The display name is supplied by the client, is limited to a short 128-byte label, and could contain personal text if you put it there. WyreDeck's app normally supplies the device's model name. The service accepts only an Ed25519 or P-256 public identity key. This is what the service uses to list and revoke paired devices for authorized clients.
- Tester issue reports. If you submit a report from the app, it is associated with your anonymous account and the submitting device. We store the category and description you provide; app version, build number, source revision, device manufacturer and model, Android SDK version, locale, and a random session identifier; and, during the private test, bounded diagnostic context such as the current screen, setup mode, tier, provider counts, whether a LAN Backbone is configured, startup state, and up to 50 recent app events. Client- and server-side filters remove detected URLs, bearer values, credential-style assignments, account-shaped numbers, provider identifiers and names, and LAN endpoints before storage. These filters match recognizable patterns, so a provider named in ordinary prose may remain in the text you write. Reports are used to reproduce bugs. Live reports are normally removed after 30 days under the current test configuration. An outage can delay cleanup until the service resumes. A database backup that captured a report may retain it until that backup reaches the end of its separate 14-day lifecycle. Do not include credentials or other sensitive information in the description.
- IP addresses, transiently, for rate limiting only (for example, limiting how many accounts one address can create per day). They live in short-lived in-memory counters and are never linked to account numbers. Our web server discards its per-request access logs for normal pages, HTTP redirects, and unmatched HTTP host or IP traffic. It also discards request-scoped proxy error events because those can contain addresses and URLs. It keeps non-request operational events, such as startup and certificate maintenance, so the service can be kept healthy without building a request history.
- If you submit an access request, your email address is stored in encrypted form, together with the Android TV device category you selected and a random request identifier. The request has no account-number field or account link. It expires after 30 days by default and may be deleted sooner after we follow up. An outage can delay live cleanup until the service resumes. A database backup that captured the request can retain its encrypted copy until that backup reaches the end of its separate 14-day lifecycle.
What we deliberately do not have
- We do not maintain an account profile containing your email address, person name, phone number, or password. An access-request email remains in the separate, expiring contact queue described above. A device display name is stored only as the account-scoped device metadata described above.
- No payment details. Payments are not available on this site.
- No viewing data on WyreDeck's account service. What you watch, your watch history, and your resume positions remain on systems you control, such as your TV or your own LAN Backbone.
- Your IPTV provider credentials are entered and stored on systems you control, such as your TV or your own LAN Backbone. They never reach WyreDeck's account service. WyreDeck supplies no content and has no visibility into your provider relationship.
- No third-party analytics, trackers, or CDNs on this site. It is static files served from our own server — even the fonts are self-hosted, so loading a page sends requests to nobody but us.
The tradeoff you should know about
Because your account number is the only credential and we hold no identity to verify you with, there is no account recovery. If the number is lost, the account is gone. Save it somewhere safe when it is shown to you.
Access requests and direct email
If you submit the access form, we use the address only to manage that request and follow up about testing. It is encrypted before storage and is never linked to an account number. If you email us directly instead, your message and address are handled by our email provider under its normal delivery and retention behavior. We do not add either source to an automated marketing list in this pre-release phase.
Questions
frontrow@wyredeck.com