Updated 11 October 2026. This notice covers Kensat Player and its device, setup and support services. Contact Player support for privacy questions.
Device access and recovery
The player sends its App MAC, Device Key, device model, authentication token and activation checks over HTTPS to verify access and synchronise its playlist. The service and its hosting providers also process connection information such as IP addresses and request times. Device records and playlists are private and require authentication.
The App MAC is an identifier used by the player. Android Beta 10 and later derive a recovery proof from the app-scoped Android ID; only a hash of that proof is stored on the server. This can recover the same App MAC, Device Key, activation and managed playlist after reinstalling the same signed app on the same Android profile, once recovery has been linked online. Factory resets, another Android profile or a different signing key can change identity. The app does not read your hardware MAC, IMEI, contacts, location, camera or microphone.
The App MAC and Device Key let you access your device playlist manager. A reseller you give these details to can save verified access without administrator assignment. A separate playlist PIN, if set, still protects editing. Changing a Device Key invalidates previously verified reseller access.
Playlists and content providers
Personal playlist links, provider credentials and imported files are stored in the encrypted library on your device. Managed playlist details are stored securely by the Player service and sent to the authorised device over HTTPS. Devices do not share playlists. Saved DNS profiles may be reused by the management service without publishing individual playlist credentials.
Your chosen content provider receives the IP address, access credentials and catalogue, artwork and playback requests needed to deliver its content. It has its own privacy practices. Kensat Player includes no channels or subscriptions.
Support and setup forms
Support requests store your name, reply address, optional device reference and the information you submit so the support team can respond. Setup requests store the device details, contact number and optional photo you submit; device codes and setup photos are encrypted. Do not include passwords or payment details in support messages. If you choose to scan a QR on the setup webpage, your browser asks for camera permission; scanning happens on your device.
Local storage and website use
The Android app uses Android Keystore encryption for playlists and device credentials; the Windows player uses protection provided by Windows for its stored credentials. Favourites, history and preferences remain in app storage. The Android app disables Android backup and uses a bounded artwork cache. The apps do not include advertising or analytics SDKs.
The website uses essential session cookies for device, reseller and administrator access. Public pages do not use advertising or third-party analytics. Search engines can read public help and product information. Account pages, device codes, playlists and support submissions are excluded from public indexing and protected by the relevant access controls. Data is used to operate, secure and support the service; it is not sold.
Retention and deletion
Local app data remains until you remove it, reset the app or uninstall. Server device and activation records are retained for access management until removal is requested. Support records are retained to handle requests. Necessary financial, security or fraud-prevention records may need to be retained; the reason and applicable period will be explained when a deletion request is processed.
Use the data deletion instructions to request removal of Player-held records. Ownership is verified before deletion. Your content provider handles requests about its own records.