XBPlayer
This policy covers the XBPlayer app for Android, iOS and Steam. Other products have their own pages, listed on the combined policy.
Last updated 10 September 2026 · Controller: Algorion OÜ, Tallinn, Estonia
Sign-in, streams and our relay
Signing in uses Microsoft's own authentication. Tokens are kept in your device's secure storage and are never sent to us, so we never see your Microsoft password and we cannot act on your Xbox account. XBPlayer is an independent client and is not affiliated with Microsoft.
Game video and controller input go straight between your device and your console or Microsoft's services wherever the network allows it. When a direct connection cannot be made, that traffic is relayed through our servers in the EU. It stays encrypted the whole way: we pass it along, we cannot read it, and we never record or store it.
The relay does keep a connection log - your IP address, the endpoint it connected to, when the session started and ended, how many bytes moved, and any error codes - for up to 30 days, to keep the service working and to stop it being abused. The connection quality figures in the diagnostics overlay are worked out on your device.
Who is responsible
Algorion OÜ (trading as Hetko), Tartu mnt 67/1-13b, 10115 Tallinn, Estonia, is the data controller. Contact: hi@hetko.eu.
What we collect
From the app: device and app details (model, operating system, app version, language, rough region), your advertising identifier, the generated device and installation identifiers our analytics, replay and crash tools use to tell one install from another, analytics events describing which screens and features you use, recordings of how you move through the app, crash and diagnostic reports, and purchase and subscription state from the store you bought through.
From our servers: the connection log described above, and the IP address, app version and device type that arrive when the app asks for its configuration.
From you: anything you choose to put in a support message, including logs you attach.
XBPlayer has no account of ours to sign up for, so there is nothing held under your name. We build no advertising profiles of our own, and we are paid for ad space, never for data about you.
Ads and your advertising identifier
The free version shows ads. Appodeal mediates them and Google AdMob supplies demand through it. To request, cap and measure an ad they receive your advertising identifier, IP address and technical device details, and they act as independent controllers when they do - what happens to it next is governed by their policies, not ours.
Nothing is requested until you answer the consent form on first launch, and ads are personalised only if you agree to that. On iOS, Apple's own tracking prompt asks as well; declining it stops your advertising identifier being shared at all. You can change either answer whenever you like in Settings, under Privacy, and in your device's own advertising settings.
Some United States state privacy laws describe passing an advertising identifier to ad partners as "selling" or "sharing" personal information, or as targeted advertising. We take no payment for your data, but if you live in one of those states the control you want is the same one: turn off personalised ads in Settings, under Privacy.
Analytics and session replay
Firebase Analytics, Amplitude and PostHog record which screens you open and which features you use, against generated device identifiers rather than your name. We read them to see what is worth building and what is quietly broken. PostHog keeps its data in the EU.
Microsoft Clarity, Amplitude and PostHog also record replays of your sessions: taps, gestures, scrolling, the layout of the screens you saw, errors you hit, your device details, and the rough region your IP address suggests. Text you type and the game view are masked before a replay leaves your device, so a replay is not meant to carry your gameplay or anything you wrote.
Masking follows rules we wrote rather than judgement, so a screen we did not anticipate can put more of its contents into a replay than we intended. If you see that happen, tell us: we will fix the rule and delete the recording.
These run on our legitimate interest in keeping XBPlayer working and worth using. You can switch them off at any time in Settings, under Privacy.
Crash reporting
When XBPlayer crashes or hits an error it cannot handle, it sends a report to Firebase Crashlytics and to Better Stack. The report holds the state of the app at the moment it broke: the stack trace, device model, operating system, app version and a generated installation identifier. It carries nothing from your Microsoft account and nothing from the stream.
Crash reporting is how a released app gets fixed at all, so it runs on our legitimate interest rather than waiting to be switched on. Better Stack stores its data in the EU.
Our servers
We run two things ourselves, both hosted in the EU: a configuration service the app asks for its settings and feature flags, and the relay described at the top of this page.
Our hosting provider processes that data on our instructions under a data processing agreement, and uses it for nothing else.
Why we process it
To make the app work, to relay a stream when a direct connection fails, and to fix what breaks - our legitimate interest in running a product that works, and the agreement you entered into by installing it.
To complete purchases, honour refunds and keep a subscription valid - that same agreement, and the accounting records the law obliges us to keep.
To show ads, and to personalise them - your consent, which you can withdraw at any time without affecting what was done before you did.
To answer support mail and run beta programmes - your consent, given by writing to us or signing up.
We do not make automated decisions about you that produce legal effects or anything similarly significant.
Who receives your data
Google, for Play distribution and billing, Firebase Analytics, Crashlytics, and AdMob demand. Appodeal, for ad mediation and the demand partners it works with. Microsoft, in two separate roles: an independent controller for your Xbox account and cloud gaming, and the provider of Clarity. Amplitude, for product analytics and session replay. PostHog, for product analytics and session replay, in its EU cloud. Better Stack, for crash and error logs. Apple for App Store distribution and billing, and Valve for Steam. Our hosting provider for the servers above, and our mail provider for support correspondence.
Each acts under its own terms, which are worth reading if you want the whole picture:
Sending data outside the EEA
Our own servers, Better Stack and PostHog keep data in the EU. The others - Google, Appodeal, Microsoft, Amplitude, Apple and Valve - are United States companies and may process data there. Where a recipient is certified under the EU-US Data Privacy Framework we rely on that; where it is not, we rely on the European Commission's standard contractual clauses. Ask us and we will tell you which applies to whom.
How long we keep it
Relay connection logs for up to 30 days. Session replays for up to 30 days, in all three of the tools that make them. Crash reports for up to 90 days. Analytics events for up to 14 months. Support correspondence for up to 24 months. Purchase records for as long as accounting law requires.
Your rights
Under the GDPR you can ask for access, correction, deletion, restriction or portability, and object to processing based on legitimate interest. Mail us and we answer within one month. You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Children
XBPlayer is not directed at children under 13, and an Xbox account is needed to use it. Microsoft tells us the age band of the account that signed in; where that band is a child or a teenager, ad requests are marked as such and personalised ads are not served.
How we protect it
Traffic between the app and our servers is encrypted in transit, relayed stream data stays encrypted the whole way through, and access to our systems is limited to the people who need it. No system is perfect. If we ever have a breach that puts you at risk, we will tell you and the Estonian Data Protection Inspectorate.
Changes
If this policy changes materially we note it here with a new date, and in the app release notes.