Effective 13 August 2026

Privacy

TMPlayer runs on your Android TV and talks directly to the services needed to play media from your own Telegram account. There is no TMPlayer account or developer-operated backend.

What stays on your TV

Telegram's TDLib stores your signed-in session, cached chat information, thumbnails, and downloaded media inside TMPlayer's private app storage. TMPlayer also stores your settings, favourites, Continue watching positions, and a temporary update APK when you choose to download an update.

Other apps cannot normally read this data. Anyone with control of the TV or a rooted device may still be able to access it, so treat the TV as a signed-in device.

Services TMPlayer contacts

  • Telegram handles sign-in, chat and channel lists, file metadata, media downloads, and Telegram-provided sponsored messages where applicable.
  • GitHub is checked for a newer TMPlayer release. An APK is downloaded only after you choose to update.
  • Your TV's speech-recognition provider receives audio only when you deliberately start voice search.
  • Sentry receives a crash report, and only if you have switched crash reporting on in Settings. It is off until then and nothing is contacted. See below for what a report contains.

TMPlayer does not send filenames, viewing history, or media to a developer-operated service.

What TMPlayer does not include

TMPlayer has no developer-operated server, no analytics SDK, no advertising SDK and no cross-app tracking. Nothing measures how you use the app, and the developer does not receive your Telegram credentials, chat list, filenames, viewing history, or media.

There is one exception, and it is off until you switch it on: crash reporting. See below.

Crash reporting, if you turn it on

Off on a fresh install, and off again after signing out. With the switch off, nothing about crash reporting is started: no library is initialised and no server is contacted. Turning it on is the only thing in TMPlayer that ever sends anything anywhere other than Telegram and GitHub.

With it on, a crash sends the stack trace, the TMPlayer version, the Android version and the device model to Sentry, which stores it on the developer's behalf in its European region. That is the whole report.

What a report deliberately does not carry: no chat names, no filenames, no search terms, no viewing history, no breadcrumb trail of what you were doing, no session or usage measurement, no IP address kept as personal data, and no identifier that ties two reports to the same person or device. The automatic trail Sentry would otherwise collect is switched off in code rather than merely left unused, because that trail is exactly where the name of the video you were watching would otherwise appear.

Switch it off in Settings and reporting stops immediately. The setting lives on your device, and signing out clears it back to off along with everything else.

Your controls

Settings lets you delete the downloaded video, clear Continue watching, clear favourites, and sign out. Signing out removes TMPlayer preferences and asks TDLib to log out and clear its local account database. Uninstalling TMPlayer removes its app data through Android.

This website

The static website sets no cookies. It counts page views using Vercel Web Analytics, which is served from this domain rather than from a third party, stores no cookie and no identifier that follows you between visits, and records only the page, the referrer and coarse device and country information. There is no advertising script, no tag manager and nothing that can recognise you on another website.

The pages that show release information ask the public GitHub API for it when you open them, which means GitHub sees that request. Hosting and network providers may keep ordinary connection logs under their own policies.

Questions

Email nevilnicks4321@gmail.com with a privacy question. Material changes to this page will update the effective date above.