Privacy Policy
This Privacy Policy explains how Mestrio Stream Server (the “App”) handles information. The App is provided by Robin Wang under the Mestrio brand (“Mestrio,” “we,” “us,” or “our”).
1. Scope
This Policy applies to the Android App and the official documentation website at mestrio-stream-server.web.app. It does not govern media servers, cameras, signaling services, storage providers, playback clients, or other endpoints that you choose to connect to the App.
2. Privacy summary
- The media server and media processing run on your Android device.
- We do not operate a cloud relay for your streams and do not intentionally receive your media content.
- Files, recordings, HLS output, configuration, access tokens, and TLS identities are stored locally or through document locations you select.
- The App uses Firebase Analytics and Firebase Crashlytics by default for limited product analytics and stability diagnostics.
- The App does not intentionally include media content, stream URLs, app/stream names, passwords, access tokens, or certificate contents in analytics events.
- You decide which network listeners to enable, which remote endpoints to contact, and which clients may connect.
3. Information handled by the App
Information stored locally
Depending on the features you use, the App stores or references:
- server listener ports, TLS and access-control settings, preferred host values, and runtime preferences;
- theme, language, preferred playback protocol, monitor refresh interval, and interactive-guide progress;
- recordings, imported media copies, generated HLS VOD playlists and segments, server web cache, temporary files, and logs;
- persistable Android document grants and metadata for external files or folders you explicitly select;
- TLS identities, certificate metadata, and encrypted or app-protected access credentials;
- media task configuration and operational state for pull, republish, RTP, SRT, WebRTC, GB28181, recording, and file-distribution workflows.
- the last verified Pro entitlement time and a one-way digest of the purchase token, when a store purchase is used.
This information is used to provide the requested feature, restore settings, show task state, generate addresses, and manage app-owned storage. It remains on the device unless you transmit it to an endpoint, export it, include it in an email, back up the device, or another system service processes it.
Information you provide when contacting us
If you email support, we receive your email address, message, and any attachments or diagnostics you choose to include. The App can prepare basic diagnostics such as app version, Android version, device manufacturer/model, and current engine state. It sends nothing by email until you complete the action in your email application.
Purchases and entitlements
In a compatible store build, the App asks the store for product details and purchase status. Google Play Billing may process your store account, payment, transaction, device, and fraud-prevention information under Google’s terms and privacy policy. The App receives a product identifier, purchase state, acknowledgement state, signed purchase data, signature, and purchase token needed to validate and restore access. It does not receive your full payment-card details. Purchase signatures are verified locally using the App’s Google Play licensing public key. The raw purchase token is not sent to an application-operated server or retained in App preferences; the App stores only the last successful verification time and a one-way token digest for offline entitlement recovery.
Documentation website data
The documentation website is hosted on Firebase Hosting. The pages do not use a custom analytics script, advertising cookies, account login, or contact form. Google may process standard hosting and security logs, such as IP address, request time, requested path, browser or device information, and network diagnostics, to deliver and protect the website.
4. Media, file, and network data
Local media server
When you start the server, the App opens the listeners you configured. Other clients may send media, signaling, authentication values, or control requests directly to your Android device. Playback clients may receive media directly from it. This traffic is not routed through a Mestrio-operated media backend.
You are responsible for the network on which the server is reachable, the clients that connect, the strength and secrecy of access tokens, certificate trust, firewall or VPN configuration, and whether you have authority to process the media.
Remote endpoints you select
Pull, republish, RTP, SRT, WHIP/WHEP, WebRTC signaling, and GB28181 features contact the hostnames, IP addresses, ports, and URLs that you configure. Those endpoint operators can observe the connection and receive the data required by the protocol. Their privacy practices are governed by their own policies and your relationship with them.
Files and recordings
The App accesses only files and folders you select through Android's system picker or files created in app-managed storage. When you choose copying, the App creates a private managed copy. When you choose linking and the document provider permits it, the App retains a system grant. Publishing, serving, recording, previewing, or exporting a file makes the relevant data available to the client or destination you selected.
Credentials and certificates
Access tokens, GB28181 registration credentials, SRT passphrases, and TLS private-key material are used locally to establish or protect the connections you request. The App does not intentionally include their values in analytics or support diagnostics. However, a client or remote service necessarily receives or validates protocol credentials involved in its connection.
5. Firebase Analytics and Crashlytics
The App uses Google Firebase services in the main UI process and the isolated media-engine process as described below.
Firebase Analytics
Analytics helps us understand feature usage and product reliability. Events can include:
- app session start and screen category;
- server start/stop requests and success or coarse failure category;
- coarse operation names such as pull, republish, RTP, SRT, WebRTC, recording, media import, storage cleanup, or guide navigation;
- app version, version code, build type, distribution channel, packaged architecture group, Android API-level bucket, memory-tier bucket, locale, orientation, and an app-session UUID.
The App's analytics layer does not intentionally attach media frames, media filenames, source URLs, stream names, remote IP addresses, messages sent over DataChannel, credentials, tokens, or certificate contents. Firebase may independently process device or app instance identifiers, IP-derived information, and other data described in Google's Privacy Policy and Firebase documentation.
Firebase Crashlytics
Crashlytics receives crash reports and stability diagnostics from the UI and media-engine processes. Reports may include stack traces, thread state, app and process information, app version, Android version, device model, available memory or storage indicators, timestamps, and identifiers used to group crashes. Native crash reports may include symbolicated call stacks. We use this information to reproduce and fix defects.
We do not intentionally attach media content, passwords, access tokens, or certificate private keys to crash reports. A crash report can nevertheless contain incidental values that were present in a system exception, native stack, or operating-system diagnostic. Do not put secrets into filenames, stream names, or URLs where avoidable.
Purpose and legal basis
We process limited analytics and crash data to operate, secure, understand, and improve the App, including our legitimate interests in reliability and abuse prevention where that basis is available. Where applicable law requires another basis, we rely on the basis required for that processing. Android, Google Play, or Firebase settings may provide additional controls depending on your account, device, and region.
6. Android permissions and system capabilities
| Permission or capability | Why it is used |
|---|---|
| Internet and network state | Accept client connections, contact user-selected endpoints, perform signaling, and detect network availability. |
| Wi-Fi multicast state | Support network discovery or media scenarios that rely on multicast on compatible networks. |
| Foreground service and special-use foreground service | Keep the user-visible server running while the App UI is backgrounded. |
| Notifications | Show the foreground-service notification and its Stop action on Android versions that require permission. |
| Wake lock | Reduce interruption of active server and media tasks while the device is awake or the UI is backgrounded. |
| Modify audio settings | Support audio playback and WebRTC audio routing. |
| System document grants | Read only the media files or folders you select through Android's file picker. |
The App does not request broad all-files storage access, camera capture, microphone capture, contacts, precise location, or SMS permissions for the described product features.
7. When information is shared
We do not sell personal information. Information may be disclosed only in these contexts:
- Service provider: Google processes Firebase Analytics, Crashlytics, and Hosting data on our behalf and under its applicable terms.
- App-store provider: Google Play or another distribution provider processes product, transaction, account, and entitlement data when you request a purchase or restore.
- Your configured endpoints and clients: media, signaling, credentials, addresses, or control messages flow to parties you choose through the requested protocol.
- Your chosen apps: Android shares a copied address, exported file, or support email only when you initiate that action.
- Legal and safety reasons: we may disclose information if reasonably necessary to comply with law, protect rights and safety, investigate abuse, or defend legal claims.
- Business transition: information may transfer as part of a merger, acquisition, reorganization, or asset transfer, subject to applicable law and continued protection.
8. Retention and your controls
- Local settings remain until changed, cleared, or the App's data is removed.
- Recordings, imported copies, and generated output remain until you delete them, clean the applicable category, clear app data, or uninstall the App.
- Linked external files remain under the control of their document provider; removing a link from the library does not necessarily delete the original.
- Active network data exists for the duration required by the protocol and any local recording or cache settings.
- Support emails are retained as reasonably necessary to answer the request, maintain support history, protect against abuse, and meet legal obligations.
- Firebase data is retained according to our Firebase configuration and Google's service rules. Aggregated or de-identified information may remain longer.
You can stop the server, stop individual tasks, disconnect sessions, revoke document access through Android or the provider, delete managed media, clean supported storage categories, clear app data, or uninstall the App. To request access, correction, deletion, restriction, or another right available under your local law for information held by us, contact us using the address below. We may need enough information to verify and locate the request.
9. Security
We use reasonable technical and organizational measures appropriate to this App, including Android app-private storage, explicit document grants, TLS options, access controls, process separation, and transport security provided by Firebase. No device, network listener, storage system, or Internet transmission is completely secure.
Enabling a listener makes the service reachable according to your device and network configuration. A self-signed certificate encrypts traffic but may not authenticate the device to a client that has not established trust. You should enable only necessary listeners, use strong unique tokens and credentials, protect private keys, keep Android updated, and prefer trusted networks or VPNs.
10. International processing
Firebase and email providers may process information in countries other than where you live. Those countries may have different data-protection laws. Google describes its transfer and protection mechanisms in its service documentation and privacy materials.
11. Children's privacy
The App is a technical media-server tool and is not directed to children under 13 or the minimum age required by local law. We do not knowingly request children's personal information. If you believe a child has provided personal information to us, contact us so we can take appropriate action.
12. Changes to this Policy
We may update this Policy to reflect product, provider, legal, or security changes. The effective and last-updated dates identify the current version. Material changes may also be communicated through the App or its distribution listing when appropriate.
13. Contact
Provider and data contact: Robin Wang, Mestrio.
Email: robinxdroid@gmail.com
Product: Mestrio Stream Server · Android application ID com.github.zlmedge