F
Filmithila
/ Privacy Policy & Play Safety
Home Terms of Service
Google Play Console & App Safety Compliant

Privacy Policy & Data Safety

Application Package: filmithila_app (v1.0.0+1) • Last Updated: August 16, 2026

0 Application Specification

App Name: Filmithila (filmithila_app)

Description: Filmithila — Premium movie streaming with maximum playback security.

Target SDK: Flutter Android & iOS (Environment SDK: >=3.3.0 <4.0.0)

Current Release Version: 1.0.0+1

1 Introduction & Scope

Filmithila ("we", "our", or "us") operates the Filmithila OTT video streaming application (filmithila_app). This Privacy Policy provides explicit, transparent disclosures required under the Google Play Developer Policy and Apple App Store Review Guidelines.

2 Google Play Data Safety Disclosures

This table details exact data types collected, whether data is shared, and the purpose of collection:

Data Type Collected / Shared Purpose Protection
Personal Info (Name, Email, Phone) Collected / Never Sold Account Authentication & Customer Support TLS 1.3 Encrypted
Financial Info (Transaction IDs) Collected via Gateway Subscription Billing & Entitlement Verification PCI-DSS Gateway (eSewa, Khalti, Stripe)
Device or Other IDs (Hashed Device Hash) Collected (Hashed) Concurrent Stream Limits & Anti-Fraud Binding One-way SHA-256 Hash Only
App Info & Performance (Security Logs) Collected Anti-Piracy, Jailbreak Detection & DRM Enforcement Encrypted Server Telemetry
Auth Credentials (JWT Tokens) Stored Locally Persistent Secure User Login Android Keystore / iOS Keychain (flutter_secure_storage)

3 Package & Technical Dependency Declarations

To ensure 100% transparency with Google Play Reviewers, below is the declaration of technical packages utilized in filmithila_app:

  • flutter_secure_storage (^9.2.2): Used exclusively to store authentication JWT tokens inside hardware-backed Android Keystore and iOS Keychain. Raw tokens are never stored in plain text or SharedPreferences.
  • device_info_plus (^10.1.0) & crypto (^3.0.3): Reads hardware model and OS version to create a one-way cryptographic SHA-256 hash. Used to enforce multi-device subscription stream limits (1-4 screens) and prevent unauthorized account reselling. Raw hardware serials are never collected.
  • flutter_jailbreak_detection (^1.10.0): Inspects OS integrity to detect rooted/jailbroken environments. Used strictly for Digital Rights Management (DRM) telemetry to protect copyrighted media.
  • dio (^5.4.3+1): HTTPS-only network client. All API traffic is encrypted via TLS 1.3.
  • flutter_inappwebview (^6.1.5) & webview_flutter (^4.10.0): Embedded browser engines used to render secure payment gateway interfaces (eSewa, Khalti, Stripe) and account authentication flows.
  • video_player (^2.8.6) & chewie (^1.8.1): High-performance HLS video playback rendering engine for licensed movie streaming.
  • youtube_player_iframe (^6.0.2): Embeds official public film trailers and promotional teasers.
  • url_launcher (^6.3.2): Triggers external system handlers to send email (`info@techprocod.com.np`) or call support (`+977 9805916598`).

4 Information We Collect

We collect information to provide, secure, and personalize our streaming services:

  • Account & Identity: Full name, email address, phone number, and bcrypt-hashed password (work factor 12).
  • Billing Details: Subscription plan type, billing status, transaction IDs from certified payment providers. We never store credit card numbers.
  • Device Telemetry: Model, OS version, app version, IP address, and a one-way hashed device identifier.
  • Playback & Resume Data: Watch history, timestamp progress, audio language selection, and playback heartbeats (every 30 seconds).

5 How We Use Your Information

  • Authenticate user accounts and verify subscription entitlements.
  • Enforce concurrent stream caps tied to your subscription plan.
  • Synchronize watch progress seamlessly across mobile, web, and TV devices.
  • Prevent piracy, unauthorized account reselling, and copyright infringement.
  • Provide customer support via email and phone.

6 DRM & Anti-Piracy Protections

Filmithila incorporates technical security controls:

  • Android FLAG_SECURE: Blocks screenshots and screen recording at the OS layer.
  • iOS Screen Capture Detection: Detects system isCaptured events and blanks video rendering.
  • Signed & Expiring URLs: Video stream URLs are signed with HMAC tokens and expire in 15 minutes.
  • DRM Encryption: Widevine and FairPlay studio DRM integrations for licensed titles.

7 Account & Data Deletion Rights

In compliance with Google Play User Data policies and Apple App Store Guideline 5.1.1, Filmithila provides all users with the direct right to delete their account and purge all personal data.

In-App Account Deletion

  1. Open Filmithila App (filmithila_app).
  2. Go to Account SettingsSecurity & Privacy.
  3. Tap Delete Account and confirm password.

Direct Contact Requests

Email info@techprocod.com.np or call +977 9805916598. Upon request, profile data and device bindings are permanently purged within 30 days.

8 Data Sharing & Third Parties

We NEVER sell, rent, or trade your personal data. Data is shared only with payment gateways (eSewa, Khalti, Stripe) and cloud infrastructure (AWS/Cloudflare) under confidentiality contracts.

9 Security & Retention

Bank-grade security: TLS 1.3 transit encryption, bcrypt password hashing, and Android Keystore token storage. Playback telemetry logs auto-expire in 12 months.

10 Contact & Support Channels

For support or Google Play reviewer inquiries:

Support Email info@techprocod.com.np
Contact Phone +977 9805916598