Privacy Policy
Effective date: August 30, 2026
This Privacy Policy describes how SofaCast ("we", "our", or "the App") collects, uses, and shares information when you use our Android application. SofaCast turns your phone into a remote control for your TV and lets you play the videos, photos, and music already on your phone on that TV.
The short version: SofaCast has no servers of its own. Your media never leaves your local network — it travels directly from your phone to your TV over your own Wi-Fi. We do not ask you to create an account, and we cannot see your files, your TV, or what you watch.
1. Information We Collect
1.1 Information collected automatically
- Device information: Device model, operating system version, unique device identifiers, and language settings.
- Advertising ID: Google Advertising ID (GAID), collected by our advertising partner (Google AdMob) to show ads and measure ad performance, subject to your consent choices in the App's GDPR/UMP prompt.
1.2 Information stored on your device only
- TV information: The name, network address, model, and manufacturer of TVs discovered on your local network, plus which TV you last connected to, so the App can reconnect automatically. This is stored only on your device and is never uploaded to us.
- Pairing credentials: Samsung, LG, and Android TV require a one-time approval on the TV itself. The resulting pairing token — and, for Android TV, a client certificate held in the Android Keystore — is stored only on your device. It grants control of that TV and nothing else, and it is never transmitted to us.
- Media selection and playback state: Which file you chose to cast, your play queue, and playback position, kept only for the duration of the session and only on your device.
- Recently cast list: So you can pick up something you were watching, the App keeps a list of items you have cast — title, duration, resolution, and when you cast it. It is capped at a fixed number of recent entries, stored only on your device, and never uploaded. You can erase it at any time from Settings → Recently played, one entry at a time or all at once.
- Playlists you create: If you group media into a playlist, the list and its contents are saved on your device so they survive a restart. Deleting a playlist erases it. The media files themselves are never copied — a playlist only points at files that are already on your device.
- Web browsing in the App: If you use the built-in browser tab, the websites you visit may store cookies and site data on your device, exactly as they would in any browser. The App itself keeps no browsing history and does not save form data or passwords. Clearing the App’s data removes anything those sites stored.
- App settings: Key sound, vibration, auto-play preferences.
- Feedback: If you choose to send feedback through the App, the content of your message is shared via your device's own email client. We receive only what you write and send.
1.3 Information we do NOT collect
- We do not require an account, sign-up, or email address to use any feature of the App.
- We do not collect your name, phone number, or any personal contact information.
- We do not collect your precise or approximate location. The "Nearby devices" permission is declared with the
neverForLocation flag, which tells Android — and enforces at the system level — that it must not be used to derive your location.
- We do not upload, copy, transcode, or scan the contents of your videos, photos, or music. We do not receive their file names, either.
- We do not receive any record of what you play, when you play it, or which TV you play it on. The App keeps a recently-cast list on your device for your own convenience (see 1.2), but that list stays on the device — it is never sent to us or to anyone else.
- We do not collect, transmit, or log the web addresses you visit in the built-in browser. There is no analytics or telemetry on browsing, and we operate no proxy — your device connects to those sites directly.
- We do not access your camera, microphone, contacts, call logs, or clipboard.
- We do not operate any server that stores your data.
2. How Casting Works — And Why It Matters for Your Privacy
TVs cannot read files out of a phone's private storage. So when you cast, SofaCast starts a small web server on your phone and hands your TV a link that only exists on your local network. Your TV then fetches the file directly from your phone. Nothing passes through us, and nothing is uploaded to the internet.
Two deliberate limits on that local server:
- It serves only the specific file you chose, under a randomly generated one-time address. It will not serve any other path, so it cannot be used to browse your storage.
- It runs only while a cast session is active, and stops when you stop casting or the App is closed.
Because this traffic stays inside your home network, it is as private as your Wi-Fi. If you cast while connected to a network you do not control (for example a hotel or office network), other devices on that same network could in principle reach the one-time address while the session is running.
3. How We Use Information
- To provide the service: Discovering TVs on your network, connecting to them, sending remote-control key presses, and streaming your selected media from your phone to your TV.
- To keep a cast session alive: A foreground service and its notification keep the connection from being terminated by the system while you are casting.
- To serve advertisements: AdMob displays ads to support the free version of the App. Ad personalisation is subject to your consent preferences managed through the in-app consent screen (Google UMP).
- To comply with legal obligations.
4. Permissions We Request
The App declares the following permissions. Each one maps to a feature you can see:
- Internet & network state & Wi-Fi state: Required to reach your TV on the local network and to serve AdMob ads.
- Change Wi-Fi state / Wi-Fi multicast: Required for TV discovery. TVs announce themselves using multicast (SSDP and mDNS); without multicast the App cannot find them.
- Nearby devices (Android 13+), declared
neverForLocation: On newer Android versions, local-network device discovery requires this permission. It is used solely to find TVs and explicitly not to determine location.
- Photos, videos, and audio access: To list the media on your phone so you can pick something to cast. On Android 14+ you may grant access to selected items only; the App fully supports that and will show just those items. The App can also delete a file at your request, from the item’s menu — when you do, Android itself shows the confirmation dialog and carries out the deletion, and the file is removed from your device permanently. The App never deletes or modifies anything on its own.
- Storage access (Android 12 and below): The older equivalent of the above, used only to read media you choose to cast.
- Storage write access (Android 9 and below only): Requested the first time you ask the App to delete a file, and only then. Older versions of Android have no system confirmation dialog for deleting media, so this permission is the only way the deletion can happen at all; on Android 10 and above the App does not request it, because the system shows its own confirmation instead. It is never used to create or change files — only to carry out a deletion you asked for.
- Notifications (Android 13+): To show the ongoing cast session and give you a way to stop it without reopening the App. All notifications are generated locally on your device.
- Foreground service (connected device): To keep the cast running when you switch away from the App. If the App is stopped, the connection to your TV drops.
- Wake lock / ignore battery optimizations: Requested optionally, and only after you tap the corresponding button, to stop the system from freezing the App mid-cast. Declining it does not disable any feature; it only makes long casts more likely to be interrupted.
- Vibrate: For optional haptic feedback on remote-control key presses.
5. Unencrypted Local Connections
The control protocols built into TVs are plain HTTP: Roku's ECP, DLNA/UPnP, and the local endpoints of Samsung and LG TVs have no certificates, and cannot have any, because devices on a home network cannot be issued trusted certificates. The App therefore permits unencrypted traffic on your local network only. All connections to external services — Google, AdMob, Firebase — are restricted to HTTPS and cannot be downgraded. Android TV's remote protocol is an exception among TVs: it is encrypted with TLS and authenticated with a client certificate.
6. Casting From the Web
The App includes a browser tab so you can find a video on a website and send it to your TV. This is the only part of the App that reaches beyond your own network, so it is worth being precise about what happens:
- You connect directly to the sites you visit. We run no proxy and no server of our own. Your device talks to those websites the same way any browser would, and they see whatever they would normally see — your IP address, and whatever their own cookies and scripts collect. Their privacy policies govern that, not ours.
- We never learn where you go. The addresses you visit are not collected, transmitted, or logged, and there is no analytics or telemetry on browsing.
- Video detection happens on your device. To show a Cast button on a page, the App looks at the addresses of the media files the page loads and checks whether they look playable. This inspection happens entirely on your device, and only the address you choose to cast is passed to your TV. Page contents are never uploaded or scanned by us.
- Large streaming services are handed to your TV instead. For services such as YouTube, Netflix, and Prime Video, the App does not touch the video stream. It asks your TV to open its own app for that service, which is both the better picture and the reason we never come between you and those providers.
- Site data stays on your device. Sites you visit may store cookies and local data, just as in any browser. The App keeps no browsing history and saves no form data or passwords. Clearing the App’s data removes all of it.
Websites you visit in this tab may be served over plain HTTP if that is how the site is published; that is a property of the site, not a downgrade by the App. The external services the App itself uses (Google, AdMob, Firebase) remain restricted to HTTPS as described above.
7. Advertising and Consent (GDPR / EEA)
The App uses AdMob (Google) to display advertisements. For users in the European Economic Area (EEA) and other applicable regions, we use Google's User Messaging Platform (UMP) to request your consent before personalised ads are shown. You may update your consent preferences at any time via the in-app consent settings.
Where ads appear is deliberately limited: never on the remote-control panel and never during playback. Ads are shown only in browsing moments — the device list, the media list, the settings screen — and at most once per session between tasks.
8. Third-Party Services
The App uses the following third-party services, each with their own privacy policies:
Connections to Roku, Samsung, LG, Amazon, and DLNA devices are made directly to the device on your own network. No vendor cloud service is contacted, and those manufacturers receive nothing from the App.
9. In-App Purchases
The App offers an optional one-time purchase to permanently remove ads. This is a one-time purchase, not a subscription, and does not auto-renew. Purchases are processed entirely by Google Play Billing; we do not see or store your payment information. Remote-control and casting features are fully available whether or not you buy it.
10. Data Storage and Security
- Your media, your remembered TV, pairing credentials, and app settings are stored locally on your device.
- The Android TV client certificate is generated inside the Android Keystore (hardware-backed on supported devices) and cannot be extracted from your phone.
- We do not operate any servers that store your personal data, so there is no account of yours for us to lose or be breached.
- Third-party services (Google AdMob, Google Play) may store advertising and billing data on their servers according to their respective privacy policies.
11. Data Retention
- Locally stored data — remembered TV, pairing tokens, settings, your recently-cast list, and any playlists you create — is retained on your device until you delete it in the App, clear the App's data, or uninstall it.
- The one-time media links created for casting are discarded when the session ends.
- Advertising data is retained by Google according to its own data retention policies.
12. Children's Privacy
The App is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
13. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data. Since app data is stored locally, you can:
- Disconnect from a TV, or clear the App's data, to remove the remembered device and its pairing credentials
- Uninstall the App to remove all locally stored data
- Update ad consent preferences via the in-app consent settings
- Reset your Google Advertising ID in your device's Android settings
- Contact us at the email below with any questions
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective date" at the top.
15. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: sedance.studio.support@gmail.com