LumaPlay

LumaPlay is a playlist player for iPhone. You add your own M3U or TXT playlists, Xtream Codes or Stalker Portal sources, single stream URLs, or local video files. It does not include any built-in live channels or programme catalogues. Playback supports HLS (.m3u8), HTTP(S), and RTMP/RTMPS, plus imported files such as MP4, MOV, M4V, MKV, AVI, and TS. You are responsible for using only sources you have the right to play.

Your own M3U / TXT playlists
HLS, HTTP(S), RTMP & local video
Picture in Picture & AirPlay
Optional iCloud backup of configs

Privacy Policy

Your privacy is important to us. We are transparent, comply with privacy regulations such as GDPR where applicable, and provide this privacy policy in clear language.

Who collects the data?

The legal entity which owns LumaPlay is:
I-Mars Limited
Room 803, 8/F, K Wah Center, 191 Java Road, North Point, Hong Kong

What LumaPlay is (and is not)

LumaPlay is a player. It does not operate a TV service, does not sell channel packages, and does not ship any live streams. Every playlist, portal, stream URL, EPG URL, and video file comes from you. Stream content is fetched from the servers you configured, not from I-Mars.

What data do we collect and why?

LumaPlay does not require an account. We do not run a LumaPlay login, and we do not operate a Firebase backend for this app.

  • Playlist & config data (on device) — names of configs you create, playlist URLs, Xtream/Stalker host and login details you enter, EPG URLs, user-agent strings, channel names, groups, stream URLs, favorites, history, and playback settings. Stored locally with SwiftData so the app can list and play your sources.
  • Imported videos (on device) — when you import a video from Files, LumaPlay copies the file into the app’s private storage so it remains playable after import. The original file is not uploaded to I-Mars.
  • Channel logos (on device) — logo images referenced by your playlist may be downloaded and cached on the device to speed up the channel list.
  • Optional iCloud backup — if you turn on iCloud Sync, LumaPlay stores a backup of your configs (including remote playlist URLs, EPG URLs, user-agent, and config names) and favorite channel names/URLs in your private iCloud (CloudKit). Imported video files are not uploaded to iCloud.
  • Network requests you trigger — when you add or refresh a playlist, LumaPlay downloads that list from the URL you provided. When you play a channel, the player connects to that stream URL. Logo URLs and EPG URLs you configured are requested the same way. Those destinations are chosen by you, not by us.
  • Local network — the app may use the local network to discover AirPlay / cast devices, as described in the system permission prompt. We do not collect a map of your home network.
  • Advertising data — LumaPlay shows Google AdMob banner, app-open, and interstitial ads. Google may collect device advertising identifiers, IP address, approximate location, and ad interaction data according to Google’s policies. You can limit ad tracking in iOS Settings. Ads are not shown on the video player screen.

LumaPlay does not include an analytics SDK or crash-reporting SDK of its own. The operating system, App Store, AirPlay, Picture in Picture, and Google AdMob may process data according to their policies independently of I-Mars servers.

Credentials you enter

If you use Xtream Codes or Stalker Portal, the username, password, and portal URL you type are stored on the device so LumaPlay can load your lists. If iCloud Sync is enabled, related config fields that are part of a config backup may be included in that private iCloud record. We do not receive a copy of these credentials on I-Mars servers. Protect your device passcode and your iCloud account.

Where are the data stored?

By default, configs, channels, favorites, history, logo cache, and imported videos stay on your iPhone.

If you enable iCloud Sync, a backup of configs and favorites is stored in your Apple iCloud private CloudKit database, associated with the Apple ID signed in on the device. Apple may store that data in regions determined by Apple. I-Mars cannot read your private iCloud contents.

How are the data secured?

On-device data is protected by iOS app sandboxing and your device lock. iCloud backups use Apple’s CloudKit transport and your Apple ID. Playlist and stream traffic uses whatever protocol the source offers (HTTPS where available; some IPTV sources still use HTTP or RTMP). If you suspect a security issue in LumaPlay itself, contact us immediately at imars@i-mars.cc.

What is shared with other users?

Nothing by default. LumaPlay has no public profiles, no social features, and no shared catalogues. AirPlay sends audio/video to a device you choose on your local network.

What is shared with third parties?

We do not sell your personal data. We share data only with service providers necessary to operate the app:

  • Apple — App Store distribution, optional iCloud / CloudKit backup, AirPlay, Picture in Picture, and Now Playing / media controls
  • Google — AdMob ads (banner, app open, interstitial). See Google’s advertising privacy policy.
  • Servers you configure — playlist hosts, stream servers, logo CDNs, EPG hosts, Xtream/Stalker portals, and any HTTP headers (such as User-Agent) you set. Those operators receive whatever is required to serve the URL (typically your IP address and the request itself). I-Mars does not control their privacy practices
  • When required by law or to comply with a valid legal process
  • In connection with a sale of all or part of our business

Your responsibility for sources

LumaPlay only plays URLs and files you add. You must ensure you have the legal right to access those playlists, portals, and videos. I-Mars Limited does not provide, host, or endorse any live TV or copyrighted stream. Misuse of third-party content is your responsibility.

How long are the data stored?

On the device, until you delete the relevant config/channel, clear cache, or uninstall LumaPlay. iCloud backups remain until you turn off iCloud Sync and delete the backup from iCloud, uninstall and remove app data, or we discontinue the CloudKit container after notice.

How to export your data?

Your playlists and stream URLs are already under your control: you can copy playlist URLs from Configs, and imported videos remain as files you originally owned. For other questions, contact us at imars@i-mars.cc.

How to delete my data?

LumaPlay has no cloud account with I-Mars. To remove data:

  • Delete configs, channels, and imported videos in the app
  • Turn off iCloud Sync, then manage iCloud storage for LumaPlay in iOS Settings if you want the CloudKit backup removed
  • Uninstall LumaPlay to delete on-device storage

There is no separate web “delete account” page because LumaPlay does not create an I-Mars user account.

Children

LumaPlay is not directed at children under 13. We do not knowingly collect personal data from children.

How to raise a complaint?

Contact us at imars@i-mars.cc.

What happens when the service is shut down?

Core playback does not depend on an I-Mars server. If we discontinue the app or the optional iCloud backup container, we will update this page. Keep copies of your playlist URLs outside the app if they matter to you.

Changes to this policy

We may update this privacy policy from time to time. Material changes will be reflected on this page with an updated effective date.

Last updated: 16 September 2026