Privacy

What Momnt knows about you, and what it cannot

Most privacy pages describe how carefully a company handles your data. This one mostly describes data that was never collected, because the app has no account system, no server holding your credentials and no analytics carrying what you watch.

Momnt account
Does not exist
Your IPTV credentials
iOS Keychain only
Streams proxied by us
Never
What you watch
Never sent to us

The short version

  • No Momnt account, no sign-up, no email address required
  • No IPTV service supplied, sold or resold by us
  • Your streams are never proxied through our servers
  • IPTV credentials held in the iOS Keychain on your device
  • Analytics that record how much played, never what played
  • Ad tracking refused by default until you say otherwise

Point by point

Every line below is checkable against the shipping app, not a statement of intent.

Your IPTV credentials
Stored in the iOS Keychain on your device and sent only to the server address you configured. We operate no server that could receive them, and no proxy that streams sit behind.
Your account with us
There isn’t one. Momnt IPTV has no sign-up, no email address to hand over and no password to choose. Nothing in the app is tied to an identity we hold.
What you watch
Never leaves the device in identifiable form. Channel names, film and episode titles, programme names, categories, provider identity, server addresses, stream URLs and search text are never sent to us.
What we do measure
Anonymous, categorical product usage: which screens are opened, how long playback ran, whether a stream failed. No user identifier is ever attached, so a report cannot be traced back to a person.
Crash diagnostics
When the app crashes we receive a stack trace and device model so it can be fixed. Crash reports carry no catalogue data and no credentials.
Advertising
The app is free and carries advertising. Before any ad is requested, iOS asks whether apps may track you across other companies’ apps and websites. Declining is fully supported and limits no feature.
Provider codes
Stored only as a salted SHA-256 hash, never in plain text. A code identifies a configuration, not a person, and grants access to nothing.
This website
Served from Cloudflare’s edge with no advertising, no third-party embeds, no fingerprinting and no cross-site tracking. See “This website” in the policy below for exactly what measurement is enabled.

Privacy policy

Effective 25 August 2026. This policy covers the Momnt IPTV app and momnt.tv.

Who this covers

This policy covers the Momnt IPTV app for iPhone and iPad, published by Lewis Halliday, and the website at momnt.tv. It does not cover your IPTV provider, whose own privacy policy governs everything you do with their service.

Momnt IPTV is a media player. It supplies no channels, streams, playlists or subscriptions, and it has no relationship with your provider beyond the requests your device makes to the address you entered.

What stays on your device

The following never reaches us, because the app has nowhere to send it:

  • IPTV server addresses, usernames and passwords — held in the iOS Keychain.
  • Your channel, movie and series catalogue, and the programme guide fetched from your provider.
  • Favourites, My List, watch history and playback positions.
  • Programme reminders, which iOS schedules locally on the device.
  • Downloaded films and episodes, stored in the app’s container, excluded from iCloud backup and protected until first device unlock.
  • Every app setting and preference.

Deleting the app removes all of it. There is no server-side copy for us to delete, because one was never made.

What the app measures

Momnt IPTV sends anonymous product-usage events through Google Analytics for Firebase. The question these answer is how much is watched, of what kind, and how well it played — never what was watched, or whose service it came from.

The following are never sent, and the app contains an enforced denylist plus tests that fail the build if any of them appear in an event:

  • Channel, movie, series, episode, programme, playlist or category identifiers and titles.
  • Provider identity, provider codes, credentials, server addresses, stream or download URLs.
  • Raw search text, notification payloads and push tokens.
  • Any user identifier or user property. The analytics layer has no identity surface at all.

One opaque identifier does exist: a randomly generated session ID that stitches together the events of a single playback session. It is not derived from the content, the provider or the device, and it is discarded when the session ends.

The app also reports crashes and non-fatal errors through Firebase Crashlytics, so that faults can be diagnosed. These carry a stack trace, the app version and the device model.

Advertising

The app is free to download and is supported by advertising served by Google AdMob. Before any ad request is made, the app runs Google’s User Messaging Platform consent flow and, on iOS, Apple’s App Tracking Transparency prompt.

If you decline tracking, personalised advertising and the advertising identifier are not used. Non-personalised ads may still be shown. Nothing else in the app changes: no feature is withheld, degraded or gated behind consent.

You can change this decision at any time — in iOS Settings under Privacy & Security → Tracking, and from the privacy options row inside the app’s own settings.

When you contact us

If you send a message from the app’s contact form, or email us, we receive what you chose to write: your name, your email address and the contents of the message. We use it to answer you and to fix what you reported, and for nothing else. It is never used for advertising, never sold, and never combined with analytics.

Provider codes and configuration

A provider code is a lookup key for a configuration document — a provider’s name, colours, artwork, login wording and server list. It is not a credential and unlocks no content.

Codes are stored only as a salted SHA-256 hash, so the raw code exists nowhere in our systems. When the app resolves a code it receives that provider’s public configuration and nothing else; the request carries no identity, and no record is kept linking a code to a person or a device.

Third parties in the app

These are the only third parties the app communicates with:

  • Google Firebase — anonymous analytics, crash reporting, remote configuration and the function that resolves provider codes.
  • Google AdMob and the User Messaging Platform — advertising and the consent flow described above.
  • The Movie Database (TMDb) — artwork and synopses for films and series, matched by title. TMDb is not endorsed or certified by us, and we send it no information about you.
  • Your IPTV provider — every catalogue request and every stream goes from your device directly to the address you configured.

This website

momnt.tv is server-rendered at Cloudflare’s edge. It carries no advertising, no third-party embeds, no social widgets, no fingerprinting and no cross-site tracking, and it asks for no personal information.

Cloudflare processes the request in order to serve it and keeps standard operational logs, including IP address, for security and abuse prevention.

Measurement is configured per deployment. In the default configuration Google Analytics runs with storage denied under Consent Mode v2: no analytics cookies and no client-side identifiers are written to your browser, which is why you are not asked to dismiss a cookie banner. If a deployment is switched to cookie-based measurement, nothing is measured until you choose, and a consent control is shown before anything is stored.

Children

Momnt IPTV is rated 4+ on the App Store, but it is a general-audience tool that plays whatever service you connect. It is not directed at children and we do not knowingly collect personal information from them. The content available through your provider is your provider's responsibility and yours.

Retention

Anonymous analytics events are retained by Google Analytics under the retention period configured for the property, after which they are deleted. Crash reports are retained for as long as they remain useful for diagnosis. Messages you send us are kept while your question is open and for a reasonable period afterwards, then deleted.

Because we hold no account and no user identifier, there is no profile of you to retain, export or sell — none is ever created.

Your rights

Depending on where you live you may have rights to access, correct, export or delete personal information held about you, and to object to certain processing. The only personal information we can hold is what you sent us directly, so a request about it is straightforward: email privacy@momnt.tv from the address you wrote to us from.

To remove everything held on your device, delete the app. To reset advertising consent, use iOS Settings → Privacy & Security → Tracking, or the privacy options row in the app’s settings.

Changes to this policy

When the app’s data behaviour changes, this page and the App Store privacy labels are updated together. Material changes are noted in the app release notes rather than published quietly.

Contact

Privacy questions: privacy@momnt.tv. Anything else: support@momnt.tv.