Privacy Policy — RX PRULE
Version: 2.1 · Effective from: June 2026
This Privacy Policy describes, in accordance with the General Data Protection Regulation (GDPR — EU), the Brazilian General Data Protection Law (LGPD — Law nº 13.709/2018), and international best practices, how RX PRULE collects, uses, stores, protects, and shares user information.
By using RX PRULE, the user declares to have read, understood, and agreed to the terms below.
1. Controller identification and product nature
RX PRULE (also referred to as "RX Purple", the "application", or the "platform") is a digital media player software, provided as a neutral technological tool. Operations comprise: the player application, the per-device licensing system, the web management panel, and tools to organize media sources inserted by the user.
RX PRULE does not provide, host, distribute, index, recommend, or commercialize any audiovisual content, channel, live broadcast, movie, series, sporting event, ready-made playlist, or content distribution service. All content played is, without exception, inserted by the user from external sources of their own choice.
2. Data collected
In the ordinary course of the service, the following data is collected exclusively:
Device technical data (required for license validation and fraud prevention):
- Hardware MAC address
- Device model, platform, and operating system version
- Application firmware and SDK version
- Access IP, used for approximate country/region identification and audit of sensitive operations
- Browser identification (User-Agent), collected exclusively in public features (such as Temporary DNS Code generation) for audit and prevention of automated abuse
Data voluntarily provided by the user:
- Playlist URL (m3u, m3u8, or similar) inserted in the application
- Playlist name set by the user
- External server credentials (DNS code, username, password) when the user opts for this login method: in these cases, credentials remain stored exclusively on the user's own device; in our infrastructure we only keep the device↔DNS code binding and the server reference (host)
- Optional four-digit PIN, for local playlist protection
Specific case — temporary codes generated on the home page: some optional features let the user generate a short-lived code from their own list. Depending on the feature, we may store only the server (scheme and host, for example `http://server.com`) or, in the case of the list-connection code, the URL provided — which may contain an embedded username and password — temporarily and strictly tied to the code, for at most 24 hours. These codes are single-use: once redeemed on a device, the list is transferred to that device and the code is invalidated. The URL (with any credentials) is deleted as soon as the code is used or expires; afterwards we keep only non-sensitive metadata (no URL, no credentials) for up to 30 days, for statistics. For abuse prevention, we also log the IP and browser identifier (User-Agent) of whoever generated the code.
We do not collect personal documents, biometric data, precise geolocation, contacts, calendar, photos, microphone, or camera. We do not track user activity outside the application.
3. Purpose of processing
Collected data is processed exclusively for the following purposes:
- Unique identification of the licensed device
- Validation and renewal of the software license
- Generation of aggregated and anonymized statistics (without personal identification)
- Technical fraud prevention (MAC cloning, unauthorized access)
- Technical support, when requested by the user
- Compliance with legal and regulatory obligations
4. Data sharing
RX PRULE does not sell, rent, or share personal data with third parties for commercial or advertising purposes.
For essential product functions, we rely on certified technical operators:
- IP geolocation provider, for country identification
- Payment processing provider, when applicable
- Infrastructure, CDN, and attack protection provider
None of these operators receives playlists, credentials, or user content. They act under formal agreements ensuring a level of protection equivalent to this Policy.
Data may be provided to competent authorities upon reasoned judicial order or formal legal request.
5. Storage and security
Data is stored on certified infrastructure provider servers, with international redundancy. We adopt technical and organizational measures to protect against unauthorized access, loss, alteration, or destruction:
- Always encrypted traffic (HTTPS / TLS 1.3)
- Periodic encrypted backups
- Strict infrastructure access control
- Passwords stored with bcrypt hash
- Access logs for auditing
6. Retention
Data is retained for the periods below, being securely discarded thereafter:
- Device data: while the license is active
- Technical access logs: 90 days
- Payment history: for the period required by applicable tax law
- User playlists: until removed by the user or account cancellation
- Temporary codes generated on the home page (including the list-connection code, which stores the provided URL): at most 24 hours, with automatic and final removal at the end of the period or right after use
7. Data subject rights
Under GDPR, LGPD, and other applicable laws, the data subject may, at any time and upon request via the Contact channel:
- Confirm the existence of processing of their data
- Access the data processed
- Correct incomplete, inaccurate, or outdated data
- Request anonymization, blocking, or deletion of unnecessary or non-compliant data
- Request portability of data in readable format
- Revoke consent, subject to legal exceptions
- File a complaint with the national data protection authority
Requests are addressed within fifteen business days.
8. Cookies and local storage
RX PRULE uses exclusively essential cookies and local storage to: (i) preserve language, theme, and session preferences; (ii) record the personal list of devices and codes registered by the user in this browser (MAC addresses, management tokens, and activation history), so the user can access this data only from their own browser; and (iii) enable encrypted backup of this information in a personal local file (`.rxbk` format, encrypted with AES-GCM 256 and a user-defined password). This data remains exclusively on the user's device and is not sent to our servers without their explicit action. We do not use tracking cookies, advertising profiles, or invasive analytics tools.
9. Children and adolescents
The service is not intended for users under thirteen years of age. If processing of a minor's data without parental consent is identified, the data is immediately removed.
10. International transfer
Data may be processed or stored in jurisdictions other than the user's, exclusively at providers ensuring a level of protection compatible with the LGPD and GDPR.
11. Changes to this Policy
Any relevant change to this Policy will be communicated at least fifteen days in advance through the application. The effective date at the top always identifies the current version.
12. Officer and contact
The Data Protection Officer (DPO) is available through the official channels listed on the Contact page. Privacy-related requests should be directed there.
RX PRULE