Privacy
The short version: Nebula has no sign-up, no email, no ads, no analytics and no trackers. Your library, watch progress and settings live on your device. A Nebula Profile is optional: it is a handle you choose and a password, nothing else, and it exists only so your own devices can share what you watch. Our servers hold only what you explicitly opt into (a profile, Friends, a watch party), and nothing is ever sold or shared.
What stays on your device
Your add-on list, watch progress, My List, subtitle style and player settings are stored locally — in your browser's storage on the web, and in app storage on Android, Windows, Linux and LG TVs. You can clear them at any time by removing items in the app, clearing site data, or uninstalling. Signing out of a profile never deletes what is on the device.
What our server sees
- Ordinary web logs. Like every web server, ours (play.rifflehq.in) keeps standard access logs — IP address, browser type, requested URL and time — used only to keep the service running and to stop abuse. They are rotated automatically and kept for about two weeks.
- Update checks. The app fetches a small version file on launch to offer updates. That is a normal web request with no identifiers in it. Android checks our releases feed instead, and the desktop app asks GitHub for the newest release and downloads it from there when you ask it to.
- A profile — only if you create one. A profile is a handle (3–20 letters, numbers or underscores), a display name, a colour, and a password. We never ask for an email address, a phone number or a real name. The password is stored only as a salted scrypt hash, and so is the one-time recovery key you are shown when you create the profile — we cannot read either, and we cannot reset a password without the key. Each device you sign in on gets its own token, named after the device ("LG TV", "Chrome on Windows", "Linux PC") so you can recognise and remove it from the Devices list; changing your password signs every other device out. Signing a TV in uses a six-character code that expires after ten minutes and only works once a device that is already signed in approves it.
- Sync — what a profile carries. With a profile, your add-on list, watch progress, My List, ratings and subtitle style are stored on our server so your other devices can pull them. They are tied to the profile, not to you. Devices that were linked with a code in an earlier version keep working the same way until they add a profile. Data that goes unused is deleted automatically after about 13 months, and deleting the profile removes all of it at once.
- Friends — only if you turn it on. Friends shares your display name, your recent titles, your ratings and your list with people you add by handle, and no one else. Turning Friends off deletes what was shared from the server immediately.
- Supporting Nebula — only if you choose to. Payments happen at a payment service (Pocketsflow), not with us; we never see card or bank details. When a payment completes, the service tells our server the order number and which tier was bought, and — if you opened the support page from the app — which profile it was for; our server keeps the order number, the tier, since when, and the mark you picked. Every paid order also creates a Nebula Sports install key: the sports server keeps that key against the order number with a masked copy of the e-mail the payment service reported (so a lost key can be found), and the thank-you page shows it whenever it is opened with the same link. If you were not signed in, a one-time code for the app is shown on the thank-you page as well and kept until it is used. Your name appears on the wall or the Founders list (in the app and on this site) only if you switch it on, it is your profile's display name and nothing else, and you can switch it off at any time. Nothing else changes: every feature stays free.
- Watch party — only if you start or join one. The relay passes the stream link and playback positions between party members while the party is open. Rooms disappear when everyone leaves, or after 12 hours at most. Nothing about a party is stored.
- Compatibility fetches. When an add-on blocks browser requests, the app may fetch it through our server instead. The requested URL passes through, is size- and rate-limited, and is not stored beyond the ordinary logs above.
- Skip intro. When a series episode starts, the app asks our server where that episode's recap, opening titles and closing credits fall. The request carries the episode's public id (its IMDb number, season and episode) and nothing about you; our server answers from a cache or looks it up in IntroDB (introdb.app), a community-run database, which then sees only that episode id and our server's address. Set Skip intros to Off in Settings and nothing is asked.
Third parties
- Your add-ons are independent services. When you browse, search or play, Nebula sends those requests to the add-ons you installed — they see the titles you look up and the streams you request, under their own privacy practices. The starter add-ons are independent community-run services for catalogs and subtitles, and you can remove them.
- Artwork and metadata load directly from your catalog add-ons and their image hosts.
- Downloads and updates are served from GitHub, which keeps its own logs under its own policy.
- Plain-HTTP add-ons. Some community add-ons and streams only work over plain HTTP. Nebula allows those connections for compatibility; anything you request from such an add-on travels unencrypted between you and it.
P2P streams (Android)
Some add-ons answer with a file shared between viewers rather than a link to a server. Playing one of those means taking part in that exchange, so it is switched off until you turn it on in Settings › Streams › P2P streams, and nothing below happens until you do.
- Other people see your address. While a P2P stream plays, your device connects directly to the other devices sharing that same file, and to public trackers and the wider peer network that introduce you to them. All of them see your IP address and the identifier of the file you asked for. That is how this kind of sharing works everywhere, not something Nebula adds — but it is the reason the switch starts off. Anyone watching such a network, including rights holders, can see it too.
- You share back while you watch. The parts you have already received are offered to other people in the same exchange for as long as the player is open, at a limited rate. It stops when you leave the player.
- No server of ours is involved. The exchange runs entirely on your device and never touches play.rifflehq.in. We cannot see what you played, and we keep no record of it.
- What lands on your phone. The file is written to Nebula's own private storage while it plays and deleted when the player closes, unless you turn on Keep downloads. Clear P2P downloads on the same page removes anything kept, and uninstalling removes all of it.
What never happens
- No email, no phone number, no real name — a profile is a handle and a password, and even that is optional. We could not identify you if we wanted to.
- No analytics, tracking pixels or fingerprinting, in the apps or on this site.
- No advertising, and no selling or sharing of any data with anyone.
Children
Nebula is not directed at children and collects no personal information from anyone.
Deletion and questions
Settings › Profile › Delete profile removes the profile, everything it synced and everything Friends shared, in one step, and frees the handle. Devices linked without a profile simply expire and are deleted once unused. If you have any question about this policy, open an issue on GitHub and we'll handle it there.
Changes
If this policy changes, the date at the top changes with it. The apps will never interrupt you about it.