Privacy Policy
Universal TV Remote — Mobile Application
1. Who we are
Universal TV Remote(“the App”, “we”, “us”) is a mobile application that turns your phone into a remote control for smart TVs (Samsung, Android TV / Google TV, Roku and compatible devices) over your local Wi-Fi network, and for other TVs through your phone’s built-in infrared (IR) blaster where available.
Contact for all privacy matters: chepkwonyke2@gmail.com
2. What the App never collects
The App has no user accounts and no backend servers of our own. Nothing the App sends — to us through Firebase (Section 5) or to our advertising partners (Section 6) — includes:
- Your name, email address, phone number, or any contact details
- Your precise location (GPS)
- Your contacts, photos, files, messages, or call logs
- Recordings of your voice (see Section 4)
- What you watch, the text you search for, or which apps you launch on your TV
- The names or MAC addresses of your TVs, or the name of your Wi-Fi network
- Passwords or payment information — the App has no logins and no in-app purchases
3. Data processed on your device and network
To do its job, the App processes some information locally— on your phone and across your own Wi-Fi network. This information never reaches us:
TV discovery and control
- Local network scanning:the App uses standard discovery protocols (mDNS/Bonjour and SSDP) to find TVs on the Wi-Fi network you are connected to. It learns each TV’s name, model, IP address, and port — the same information any device on your network can see.
- Remote commands: button presses, text you type into the search box, and channel digits are sent directly from your phone to the selected TV over your local network (or over infrared light for IR remotes). They are not routed through the internet and are not visible to us. The one exception is a TV connected through YouTube, described next.
- TVs connected through YouTube:when you link a TV through YouTube (marked “YT” in the TV list), the App works the way casting from YouTube’s own app does: it links to the TV through YouTube’s servers, and a search you make is sent to YouTube to find the video, which then plays on your TV. This exchange is between your phone and YouTube; we do not receive it. The Google Privacy Policy covers how YouTube handles it.
- Pairing: Android TV devices require a one-time pairing code shown on the TV. The pairing credentials this produces are stored only on your phone so you do not need to re-pair every time.
App preferences
Small settings — for example whether you have completed the onboarding walkthrough — are stored in a local preferences file on your device. They are deleted when you uninstall the App or clear its data.
4. Microphone and voice search
- The microphone is used only when you tap the Voice/mic button.
- Speech is converted to text by your device’s built-in speech recognition service (e.g. Google’s speech services on Android, Apple’s on iOS). That service’s own privacy policy governs how it processes audio.
- The resulting textof your query is sent from your phone directly to your TV to perform the search (or to YouTube, for a TV connected through YouTube — see Section 3). We never receive or store your audio or your queries.
- You can deny or revoke the microphone permission at any time in system settings; everything except voice search keeps working.
5. App analytics and crash reports (Google Firebase)
To learn whether the App works for the people using it — whether they manage to connect to their TVs, which features they use, and when it crashes — the Android app uses two Google services: Google Analytics for Firebase and Firebase Crashlytics. Google provides them to us and processes this data on our behalf, as our data processor, under the Firebase Data Processing and Security Terms.
What is sent
- Usage events the App defines:finishing the onboarding walkthrough; whether connecting to a TV worked, with the kind of TV (for example “Samsung” or “Roku”), whether it was over Wi-Fi or infrared, whether a pairing code was needed, and a short technical code when it failed; the first command that reaches a TV; which feature you used (keyboard search, voice search or launching an app) — never what you typed, said or launched; when the App asks Google Play to show its rating card; and each ad shown, with the value the ad network reports for it.
- Collected automatically by Firebase: app opens, sessions and time spent in the App, app version, device model, operating system version, language, and an approximate location (country or region) that Google derives from your IP address.
- Random identifiers:an app-instance ID, a Firebase installation ID and a Crashlytics installation ID, created for this installation of the App. They are not your advertising ID and are not linked to your name. Clearing the App’s data or reinstalling it replaces them.
- Crash reports: when the App crashes, the stack trace, the state of the App, and basic device details at that moment. A crash report describes the error itself, which on rare occasions can include the local network address of the TV the App was talking to.
Firebase is not used for advertising. The App does not let it collect your advertising ID, and it switches off Google Analytics’ ad storage, ad user data and ad personalisation signals. The iPhone version of the App does not use Firebase.
Google’s handling of this data is described in Privacy and Security in Firebase and the Google Privacy Policy.
6. Advertising and our advertising partners
The App is free and is supported by advertising. Ads are mediated by Unity LevelPlay (ironSource) and served by Meta Audience Network(Facebook). When an ad is requested or displayed, these partners’ SDKs inside the App collect and transmit certain data directly to those companies, for their own advertising purposes. This may include:
- Your device’s advertising identifier (Google Advertising ID on Android / IDFA on iOS, where you have permitted tracking) and other device identifiers
- A list of other apps installed on your device — our advertising partners may collect information about which apps are present on the device (for example, whether the Facebook app is installed) in order to select, deliver, and measure ads. This check is performed by the partners’ SDKs; the App itself does not read, store, or receive your app list.
- Coarse technical data: device model, operating system version, language, app version, screen size, mobile network/carrier, and IP address (which implies approximate location)
- Ad interaction data: which ads were shown, viewed, and clicked
- Diagnostics: crash and performance information relating to the ad SDKs
This data is transmitted in encrypted form (HTTPS/TLS). We do not receive it ourselves, apart from which network filled each ad and what it was worth, which LevelPlay reports to the App and the App passes to Firebase (Section 5). It flows from the SDKs to Meta and Unity LevelPlay, who act as independent controllers of it — not as service providers acting on our instructions. Their handling of it is described in the Meta Privacy Policy and Audience Network documentation, and in the Unity Player & App User Privacy Policy.
Because advertising keeps the App free, this data collection is required and there is no in-app opt-out; you can, however, limit personalisation using the system controls below.
Your advertising choices
- Android:Settings → Privacy → Ads lets you delete or reset your advertising ID and opt out of ads personalisation.
- iOS:Settings → Privacy & Security → Tracking lets you block apps from requesting to track; the App respects the system tracking permission.
- Ads personalisation controls in your Facebook account settings apply to ads served in this App too.
7. Messages you send us
If you contact support — by WhatsApp, by email, or with the connection report the App offers when a TV will not connect — we receive what you send, through the app you send it with. The connection report contains the App’s version, the TV’s name as the App shows it, the error you saw, and a short log of recent connection attempts written in codes (the TV’s brand family, which control ports answered, the connection method and the outcome). It holds no IP or MAC addresses and no identifiers, and you can read and edit the whole message before you send it. We use messages only to answer you and to fix the App.
8. Permissions the App requests
INTERNET / NETWORK STATE
Communicating with your TV over Wi-Fi, loading ads, and sending analytics and crash reports.
WI-FI STATE & MULTICAST
Discovering TVs on your local network (mDNS/SSDP need multicast).
MICROPHONE (RECORD_AUDIO)
Voice search only, on demand. Optional.
VIBRATE
Haptic feedback when you press remote keys.
INFRARED (TRANSMIT_IR)
Controlling TVs via the phone's IR blaster, on phones that have one. Optional hardware.
ADVERTISING ID (AD_ID)
Lets our advertising partners read the advertising identifier described in Section 6. Firebase does not use it.
The App never requests location, camera, storage, or contacts permissions.
On Android, the advertising SDKs bundled in the App declare package visibility (a <queries>entry) so they can check whether certain apps — such as the Facebook app — are installed on your device. See Section 6.
9. Data retention and deletion
- All data the App itself creates (preferences, pairing credentials) lives only on your device. Uninstalling the App, or clearing its data in system settings, permanently deletes it.
- Analytics data in Firebase is kept for up to 14 months, and crash reports for 90 days, then deleted. Clearing the App’s data or reinstalling it gives it new identifiers, so nothing it sends afterwards is linked to what it sent before.
- Data collected by Meta Audience Network and Unity LevelPlay is retained under those companies’ own policies; use the controls in Section 6 or their tools to manage it.
- Support messages are kept only as long as we need them to answer you and fix the problem you reported.
10. Security
Remote-control traffic stays inside your local network. Connections to Android TV devices are encrypted (TLS) using the pairing certificate created during setup; Samsung connections use the TV’s secure WebSocket channel where the TV supports it. Because some older TV protocols (e.g. Roku ECP) are unencrypted by design, we recommend using the App only on Wi-Fi networks you trust — the same advice that applies to the TVs’ own official apps.
Everything the App sends over the internet — to Firebase, to YouTube and to our advertising partners — is encrypted in transit (HTTPS/TLS).
11. Children
The App is a general-audience utility and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has used the App in a way that raises concern, contact us and we will assist.
12. Your rights
Depending on where you live (including under the Kenya Data Protection Act 2019, the EU/UK GDPR, or the California CCPA/CPRA), you may have rights to access, correct, delete, or object to processing of personal data. The analytics and crash data we receive through Firebase is tied to a random identifier, not to your name, so the quickest ways to exercise these rights are:
- Clearing the App’s data or uninstalling it (Section 9), which deletes everything on your device and cuts the link to anything already sent to Firebase;
- Exercising your rights against Meta and Unity LevelPlay for advertising data (Section 6); and
- Writing to us about anything else, including support messages you have sent.
We are happy to help with any request: chepkwonyke2@gmail.com.
13. International transfers
Data processed by Google (Firebase and YouTube), Meta and Unity LevelPlay may be transferred to and processed in countries other than your own, including the United States, under those companies’ applicable transfer safeguards.
14. Changes to this policy
We may update this policy as the App evolves (for example if we add new features or change advertising partners). The “Last updated” date at the top will change, and material changes will be highlighted in the App or its store listing. Continued use of the App after an update means you accept the revised policy.
15. Contact
We aim to respond to all enquiries within 5 business days.
Last updated: October 6, 2026
© 2026 Kelvin Kipkoech Chepkwony. All rights reserved.