Privacy Policy for Premium TV Launcher

Effective Date: September 21, 2026

This Privacy Policy describes how Smartago LLC (“we,” “us,” or “our”) handles information in connection with your use of Premium TV Launcher UI (PLUI) (the “App”), a home-screen replacement for Android TV, Google TV and Fire TV devices.

This version replaces the policy dated January 14, 2026. The App has since been rebuilt as a native Android application and no longer uses Google Firestore or Google Analytics. This document describes what the current version of the App actually does.

THE SHORT VERSION

  • No account, no sign-up, no password. The App never asks who you are.
  • No advertising SDK and no third-party analytics SDK. The Google Play build contains no ad network, no Google Analytics and no Firebase library.
  • Your settings, your parental PIN, your camera passwords and your user profiles stay on the TV.
  • What reaches our servers: an anonymous device registration, a licence check, crash reports, and — only if you ask for it — a backup of your settings.
  • We do not sell, rent or trade data, and we do not build advertising profiles.

1. WHAT STAYS ON YOUR DEVICE

The following is stored in the App’s private storage on your TV and is not transmitted to us, with the single exception of the optional cloud backup described in section 4:

  • Home screen setup — categories, tile order, hidden apps, wallpapers, themes, layout.
  • Parental control PIN and lock state.
  • User profiles (up to ten) and their individual settings.
  • IP camera details — address, username and password for ONVIF/RTSP cameras. These are used only to reach the camera on your own local network and are never sent to us.
  • Screen-time statistics — read through Android’s “Usage access” grant, calculated and displayed on the TV.
  • The list of installed applications — read on the device to draw the app drawer and to let you launch, categorise or hide apps.

2. HOW THE APP IDENTIFIES YOUR DEVICE

Because there is no account, licences and support are tied to the device rather than to a person:

  • Device ID — the Android ANDROID_ID value provided by the operating system (a random identifier generated by the App is used if it is unavailable). It is what our licence system uses to know that this TV owns an Elite edition. The App shows it to you under Options.
  • Visitor ID — a random identifier generated by the App itself on first run. Crash reports are keyed to this one rather than to the Device ID.

Neither identifier is linked to a name, an e-mail address or an account. The App does not read or use the Android advertising ID.

3. WHAT THE APP SENDS TO OUR SERVERS

Our servers (smartago.net and api.smartago.net) receive only the following:

WhatWhenWhy
Device registration: app code, Device ID, backup identifier, Android version and API level, CPU architecture, total RAM and storage, manufacturer, model, brand, app version and build, whether the App was installed from Google Play or sideloaded, and the package name of the application that installed itOnce per device, and at most once a day thereafterTo count installations, to know which hardware and Android versions to support, and to attribute installations to the app or site they came from
Licence check: Device ID and app codeAt start-up and when an Elite feature is usedTo confirm the edition this device is entitled to, without requiring an account
Crash and stability reports: Visitor ID, error type and message (truncated), app version and build, Android API level, manufacturer and modelAfter a crash or a freeze. Identical reports are suppressed and the number per day is cappedTo find and fix faults
Interface texts and curated lists: your chosen language codeAt start-upTo download translations and the App’s content lists. This is a download; nothing about you is uploaded
Suggested language: nothing beyond the request itself; the suggestion is derived from your IP address on our sideFirst launch onlyTo open the App in a plausible language instead of English for everyone
Feedback: whatever you type in the form, plus Device ID, app code and form codeOnly when you press sendTo answer you and to group feedback by app
Settings backup: see section 4Only when you choose itTo restore your setup on the same or a replacement device

4. CLOUD BACKUP — OPTIONAL, AND ONLY IF YOU ASK

Under Tools → Cloud backup you can store your setup on our server and restore it later, on this device or on a replacement one. One backup is kept per device and each new backup replaces the previous one. Nothing is backed up automatically.

Included: categories, tile order and assignment, hidden apps, wallpaper and theme choices, weather preferences, user profiles and their settings.

Deliberately excluded: the parental control PIN (the Device ID is displayed on screen and would otherwise be the only thing needed to read it back), your licence or edition status, and the device’s own identifiers.

Please note: because the backup records which applications you hid or placed in categories, it necessarily contains the package names of some applications installed on your TV. If you would rather that information never left the device, simply do not use this feature — everything else in the App works without it.

5. THIRD-PARTY SERVICES THE APP CONTACTS

Besides our own servers, the Google Play build of the App connects to the following, and to nothing else:

  • ip-api.com, falling back to freeipapi.com — to turn your IP address into an approximate city for the weather widget. If both fail, the App defaults to London. No identifier of yours is sent; the service sees the request and therefore your IP address, as any web server does. This is why the Google Play data safety card lists “approximate location”. You can also type a city yourself, in which case the App uses what you typed. Note: ip-api.com is queried over plain HTTP, because its free tier does not offer HTTPS.
  • open-meteo.com (and its geocoding service when you search for a city by name) — to fetch the forecast for those coordinates. No identifier of yours is sent.
  • speed.cloudflare.com — used by the internet speed-test widget, when you run it.
  • raw.githubusercontent.com — to fetch the public Earth View image index used by the dynamic wallpaper feature, when you enable it.
  • Google Play Billing — for purchases and subscriptions. Payments are handled entirely by Google under Google’s privacy policy; we never see or store card details. We receive only the purchase token, transaction identifier, purchase date and subscription status needed to unlock your edition.
  • lunona.com — our own site, which serves the featured content shown under Options → Bonus. Opening that screen sends your Device ID, language, app code and app version, so that the correct page is shown and the visit is attributed. Nothing is sent unless you open that screen.

Any website you open in the App’s built-in browser, and any application you launch from the launcher, is governed by its own privacy policy, not by this one.

6. PERMISSIONS AND WHY THEY ARE NEEDED

PermissionWhy
QUERY_ALL_PACKAGESTo list and launch your installed applications. This is what makes a launcher a launcher. The list is processed on the device.
SYSTEM_ALERT_WINDOWTo start reliably at boot on Android 12 and later, and for the parental lock to be able to appear over another app.
RECEIVE_BOOT_COMPLETEDTo appear as the home screen when the device is switched on.
PACKAGE_USAGE_STATS (“Usage access”, granted by you)For the daily screen-time limit in parental control and for the screen-time widget. Read and calculated on the device.
REQUEST_INSTALL_PACKAGES, REQUEST_DELETE_PACKAGESTo let you install and uninstall applications from within the launcher, each confirmed by the system dialog.
INTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATEWeather, translations, licence checks, and the network status shown on the home screen.
CHANGE_WIFI_MULTICAST_STATETo discover ONVIF cameras on your local network when you add one.
BLUETOOTH, BLUETOOTH_CONNECTTo show the battery level and name of connected remotes and gamepads.
READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGETo use your own images as wallpapers and to handle files you download.
READ_TV_LISTINGS, TV_INPUT_HARDWARETo show live-TV inputs and channel information on devices that provide them.
FOREGROUND_SERVICE (and media playback / special use), WAKE_LOCK, REORDER_TASKS, POST_NOTIFICATIONSMedia playback on the home screen, keeping the screen awake while it plays, switching between running apps, and notices such as a completed download.

7. THE VERSION DOWNLOADED FROM OUR WEBSITE IS DIFFERENT

The build distributed outside Google Play, for TV boxes that do not allow a third-party launcher to be set as the default home screen, additionally contains:

  • An Accessibility Service, used for one purpose only: to notice the Home key and bring the launcher forward on devices where the system setting is not available. It is not used to read the content of your screen, and nothing it observes leaves the device. The Google Play build contains no accessibility service at all.
  • WRITE_SECURE_SETTINGS, where the device allows it, to set the launcher as the home screen.
  • An exemption from battery optimisation, so that the launcher is not killed in the background.
  • Access to your photos, if you choose one as a wallpaper.

8. WHAT WE DO NOT DO

  • We do not show advertising and we embed no advertising SDK.
  • We embed no third-party analytics SDK. There is no Google Analytics, no Firebase and no Crashlytics in the App.
  • We do not sell, rent or trade your information, and we do not use it to build advertising or behavioural profiles.
  • We do not read the content of your screen, and the App never uses a camera or a microphone on your TV.
  • We do not collect precise or GPS location, contacts, messages, photos or documents.

9. STORAGE, SECURITY AND RETENTION

  • Everything sent to our servers travels over an encrypted HTTPS connection, with the single exception noted for ip-api.com in section 5, which carries no data of yours.
  • Registration records, licence records and crash reports are kept on our own servers for as long as they are needed to support the App, and are accessible only to authorised personnel.
  • Data held on the device is removed when you uninstall the App or clear its data. A cloud backup stays on our server until it is replaced by a newer one, or until you ask us to delete it.

10. SHARING AND DISCLOSURE

We do not share your information with other companies or organisations for their own purposes. We may disclose information where we are legally required to do so. Service providers, such as the hosting provider that runs our servers, process data only on our instructions and only to the extent needed to operate the service.

11. PURCHASES AND SUBSCRIPTIONS

Elite is available as a lifetime licence or as a subscription, purchased through Google Play. Subscriptions renew unless cancelled, and are managed in your Google Play account under Payments & subscriptions. Uninstalling the App or deleting its data does not cancel a subscription.

12. YOUR RIGHTS

Depending on where you live, including under the GDPR and the CCPA/CPRA, you may have the right to access, correct, delete or restrict the processing of information relating to you, and to object to that processing.

Because we hold no account, the Device ID is the only way for us to find the records associated with your TV. You will find it in the App under Options. Write to support@smartago.net quoting that identifier and we will act on your request.

13. INTERNATIONAL TRANSFERS

Our servers may be located outside your country of residence. Where information is transferred, we apply appropriate safeguards to protect it.

14. CHILDREN’S PRIVACY

The App is not directed to children under 13 and we do not knowingly collect personal information from them. The parental control feature is provided for adults who wish to restrict what a shared television can do.

15. CHANGES TO THIS POLICY

We may update this policy as the App changes. The effective date at the top always reflects the current version, and significant changes will be announced on this page or in the App.

16. CONTACT US

Smartago LLC, 5305 Limestone Road, Wilmington, DE 19808, United States
E-mail: info@smartago.net · Privacy requests: support@smartago.net
Website: www.smartago.net · Phone: +1 864 528 0626

Important Legal Disclaimer: This document is for informational purposes only and does not constitute legal advice. You must consult with a qualified legal professional to ensure full compliance with all applicable laws and regulations in your specific jurisdictions.