ARGUS PLAYER
Privacy Policy — Argus Player
Last updated: October 7, 2026 · Version 1.6
1. Scope and Controller
This Privacy Policy applies to the Argus Player iPhone and iPad application, the Argus Player website, and optional Argus account services (together, the "Service"). It explains what data is handled, why it is used, where it goes, how long it is kept, and your choices.
The data controller for Argus account and website data is Hello Darkness LLC, Texas, United States. Privacy questions may be sent through argusplayer.com/contact or to info@argusplayer.com.
2. Data Handled on Your Device
Argus is designed to keep core playback data local.
- Manual sources: server address or M3U URL and username are stored in the App sandbox; passwords and sensitive source secrets are stored in iOS Keychain. They are sent only to the source host you entered.
- Favorites and playback state: favorites, continue-watching progress, and capped history records are stored locally. History uses one-way content-identity digests and timestamps rather than titles, stream URLs, or credentials.
- Recent searches: up to five search terms for each of Live TV, Movies, and Series are stored locally so you can repeat or remove them. Search terms are not sent to Argus servers or analytics.
- Profile avatar: your Argus artwork choice is stored on this device and does not require an Argus account.
- Live recordings: scheduled and saved broadcasts remain in the App sandbox. Movie and Series downloads are no longer available. Existing files from earlier versions are not uploaded or automatically deleted by this update.
- Parental Controls: protected-category choices, a random salt, and a one-way PIN verifier remain local. Argus never stores the plaintext PIN or protected category titles in that record.
- Application Security: the Biometric Unlock preference remains local. Face ID, Touch ID, and device-passcode authentication are performed by iOS; Argus never receives biometric templates or your passcode.
- Cached data: guide data, artwork, and selected subtitle files may be cached to operate the requested feature and are removed when their cache expires, is cleared, or the App is deleted.
Deleting the App normally removes its sandbox data. Apple Keychain items may survive deletion so a prior secure connection can be reviewed or released after reinstall. Argus does not silently use such a connection during first-run onboarding.
3. Optional Argus Account and Website Data
You do not need an Argus account to enter a manual source. If you create or use an optional account, the Service processes:
- Normalized email address, password hash, email-verification status, optional display name and locale.
- Versioned Terms, Privacy, Acceptable Use, and copyright-policy acceptance records.
- Secure browser-session records, CSRF protection data, and sign-in/security events.
- Argus-generated Device ID, device platform, model family, operating-system version, App version, pairing state, and last-seen status.
- Short-lived pairing-session data and hashed, attempt-limited verification or reset challenges.
- Account-managed source label, source type, sanitized hostname, encrypted source settings, assignments to paired devices, validation status, and synchronization state.
- Support tickets, feature requests, copyright reports, account-deletion requests, and the information you intentionally submit in them.
Argus account passwords are processed only to create or verify a one-way Argon2id hash. Plaintext account passwords are not stored. Pairing keys, session tokens, refresh tokens, verification codes, and reset codes are stored as hashes or protected secrets where applicable and are never displayed in admin tools.
For a playlist already assigned from your Argus account, you may enable “Sync changes to my Argus account” when editing it in the app. This sends the playlist name and connection settings, including its provider password or credential-bearing URL, over HTTPS to Argus so your account and its assigned devices can use the updated settings. Provider credentials are encrypted at rest and are not included in support/admin views or diagnostic logs. This is separate from iCloud Sync and does not upload media catalogs or viewing history. The option is off unless you enable it; turning it off keeps subsequent edits on that device and does not delete a previously synchronized account copy. A pending update stays protected on the device until it can sync; conflicting account edits require review. Removing the account playlist or deleting your Argus account removes its stored connection secrets through the existing deletion flow.
4. Optional Premium iCloud Sync
Premium iCloud Sync is off until you enable it. You may separately select Settings, Favorites, and Watch Progress. Selected records are stored in your private Apple CloudKit database and are available to devices using the same Apple Account with iCloud Drive enabled. When Settings Sync is enabled, the latest five Live TV, Movies, and Series search terms and playlist-scoped organization metadata—custom group names and order, Favorites display order, visibility choices, and one-way channel references—are included in that private settings record. Favorites Sync includes favorite membership. These records are used only to restore your choices on your devices and are not sent to Argus servers, advertising services, or analytics.
Argus does not place source URLs, usernames, passwords, provider keys, STB credentials, Parental Control PINs, raw playlist contents, EPG databases, saved recordings, or advertising identifiers in iCloud Sync. Playlist media catalogs are not uploaded by this feature.
The earliest Premium welcome-period start is stored locally and in Apple's iCloud key-value store so reinstalling or using another device does not normally create another welcome period. You may turn sync off without removing local data, use Sync Now, or delete the Argus sync record from iCloud in Settings.
5. Casting
If you choose an AirPlay or Chromecast destination, Argus temporarily supplies the selected receiver with the current stream URL, title, optional artwork URL, live or on-demand type, and on-demand starting position. The receiver then requests media from your provider.
Argus does not persist the authenticated casting URL or send it to an Argus server. AirPlay routing is handled by iOS. Chromecast discovery uses the local network only after you choose Cast and grant local-network permission. Google Cast SDK analytics logging is disabled by Argus.
In development builds, an unsupported MKV title can be adapted on this device for AirPlay. The device requests your selected source, keeps compatible compressed video unchanged, and converts audio to stereo AAC. The chosen receiver requests the adapted video and sound through a temporary, random-address HTTP stream on your Wi-Fi network. Only a limited media window is kept in memory; no saved movie or episode is created, and your provider URL and credentials are not included in this stream. The local transfer is unencrypted, so use a trusted network and keep Argus open during playback. The stream closes when the AirPlay session ends. This development capability is not yet enabled in public Release builds.
For Chromecast, an online subtitle you selected can be sent directly from this device to your selected receiver on the local network. Argus converts the cached text to WebVTT in memory and serves only that subtitle through a temporary, random-address HTTP resource restricted to the receiver. No account token, provider password, or subtitle download token is shared. This local transfer is unencrypted; use a trusted local network. The resource closes when Cast ends or after six hours, and nothing is uploaded to a new cloud service. Keep Argus open until the subtitle has been sent. A media provider that does not permit external text tracks may prevent Cast subtitles; Argus explains this without changing the video source.
6. Subtitles, EPG, Support, and Feature Requests
A subtitle search begins only after your action. The minimum available title identity, year, optional IMDb ID, season, episode, and chosen language are sent to the Argus subtitle service and OpenSubtitles. Source credentials, stream URLs, and watch history are not included. A selected subtitle is delivered with a short-lived token and may be cached locally for up to 24 hours.
An external EPG URL, including any query token in it, is stored in this device's Keychain. The guide mode is stored in the App sandbox. Argus requests that URL only when the guide is needed; the selected guide service and any redirect destination can receive the request. Temporary XMLTV data is used for matching and removed when its cache expires or the source is invalidated. Argus account servers do not receive your external EPG URL.
Feature Request transmits only the message, optional reply email, a random duplicate-prevention key, and whether the request came from the App or website. It does not attach your Device ID, account, sources, watch history, diagnostics, analytics, or advertising identifier. Do not include passwords, source URLs, activation codes, API keys, tokens, payment information, or other secrets.
Support and copyright forms process the contact and case information you choose to submit. These records may be retained as needed to respond, protect the Service, establish legal claims, or meet legal obligations.
7. Why Data Is Used
Depending on the feature and applicable law, data is processed to:
- Perform the Service you request, including account creation, authentication, pairing, synchronization, support, and account deletion.
- Protect accounts and the Service through authentication, rate limits, fraud prevention, abuse prevention, security auditing, and incident response.
- Record consent and meet tax, accounting, consumer, copyright, App Store, and other legal obligations.
- Improve reliability using sanitized, DEBUG-only diagnostics during development. Release builds do not include Argus analytics by default.
- Act on your consent for optional iCloud Sync, casting, subtitle requests, and feature requests. You may stop future use by disabling or not using the relevant feature.
8. Cookies and Network Data
The website uses one strictly necessary Secure, HttpOnly session cookie to keep you signed in and browser-local storage to remember acceptance of the website legal notice. It does not use advertising or cross-site tracking cookies.
Like any internet service, hosting and security systems receive network information needed to deliver a request, such as IP address, time, user-agent family, and requested endpoint. Argus uses this information for transport, rate limiting, security, and abuse prevention, not targeted advertising.
9. Sharing and Service Providers
Argus does not sell personal information, source credentials, or viewing data. Data is shared only as needed with:
- Apple: StoreKit purchase verification, iCloud key-value storage, private CloudKit Sync, AirPlay, and platform services.
- Google Cast and the selected receiver: local discovery and media information needed for casting after your action.
- OpenSubtitles: subtitle search details sent through the Argus subtitle service.
- Your source or EPG provider: credentials and requests needed for the source you configured.
- Hosting, database, security, and transactional-email providers: limited account and operational data required to run the optional Argus services.
- Authorities or affected parties: only when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish and defend legal claims.
Each independent third party may apply its own terms and privacy policy.
10. Retention and Deletion
Local playback history keeps no more than the latest 200 records per content type. Recent search history keeps no more than five terms separately for Live TV, Movies, and Series. You may remove one recent search or clear a section’s recent searches at any time; an enabled Settings Sync may synchronize that deletion to your other devices. Subtitle cache files are retained for up to 24 hours unless cleared sooner. Saved recordings remain until you delete them, delete the App, or iOS removes them under platform behavior. Legacy Movie/Series downloads from earlier versions remain local until the App is deleted or iOS removes them; the removed download screen is no longer available.
Optional account data is retained while the account is active and as needed to operate requested features. Verification and reset challenges expire after 10 minutes and are invalidated after successful use; expired, used, or revoked session and pairing records are removed during scheduled cleanup. Security, legal-acceptance, support, and copyright records may be retained for a limited period required for fraud prevention, dispute handling, enforcement, and legal obligations.
When you complete account deletion, active sessions and device-token families are revoked, pending pairings are cancelled, paired devices are revoked, saved source secrets are cryptographically deleted, and the account is anonymized. Limited non-secret records may remain where retention is legally required or necessary to document deletion and protect legal rights.
11. Your Choices and Rights
In the App you can remove sources, clear Live TV, Movies, Series, or all playback history, remove individual recent searches, clear each section’s recent searches, delete saved recordings and cached subtitles, manage permissions, disable iCloud Sync, delete the Argus CloudKit record, disconnect an account, and initiate optional Argus account deletion.
On the website you can review paired devices and sessions, remove account-managed sources, export account data, sign out other sessions, and delete the account.
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing and to complain to a data-protection authority. Argus does not sell or share personal information for cross-context behavioral advertising. Submit a rights request through argusplayer.com/contact.
12. Security and International Processing
Argus uses HTTPS, encryption at rest for account-managed source secrets, hashed credentials and tokens, device-bound pairing, least-privilege access controls, and audited administrative actions. No system can guarantee absolute security.
The controller and Service infrastructure are based in the United States. If you use optional online services from another country, data is processed in the United States and may be subject to different laws. Appropriate transfer safeguards are used where required.
13. Children
The Service is not directed to children under 13 or the higher minimum age required by local law. Argus does not knowingly collect personal information from children. Contact us if you believe a child submitted account data.
14. Advertising and Tracking
The current App does not load third-party advertisements and does not use an advertising identifier, cross-app tracking, or third-party analytics. After the Premium welcome period, eligible non-playback screens may show a first-party Argus Free banner that opens the in-app Premium area and makes no external ad request.
Any future external advertising provider requires a separate consent design, privacy review, App Privacy update, and release decision before enablement.
15. Changes and Contact
Material changes to this policy may require renewed acceptance. The current version is available in Settings and at argusplayer.com/legal/privacy.
For privacy or support questions, use argusplayer.com/contact or email info@argusplayer.com.