Privacy Policy
This Privacy Policy explains how the TulipTv applications, tuliptv.net website and related account and licensing services process information. It should be read with our Terms of Use.
1. Who is responsible
The controller responsible for the processing described here is Ginger Cat Works, Verdunplein 17, G9053, 5627 SZ Eindhoven, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42139363, VAT number NL005527559B44. In the Microsoft Store, the publisher is shown as Ginger Cat. Privacy, account-deletion and data-rights requests can be sent to contact@gingercatworks.com.
2. Data kept only on your device
The Windows application stores the following locally so its features work:
- source names, M3U/M3U8 and XMLTV addresses, provider server details and supported credentials; credentials are encrypted for the current Windows user;
- catalogue and guide caches, favourites, hidden groups, recent activity, playback progress, app settings, parental-control settings and a salted parental PIN hash;
- recordings and downloads you choose to create;
- cached trial status and the TulipTv Pro status reported by the Microsoft Store;
- the TulipTv Pro reminder state and, for the one-time Microsoft Store rating request, a local tally of total playback time, the number of days you watched and whether recent sessions failed (never titles or sources); and
- the version and UTC time of your Terms acceptance (the version also identifies the Privacy Policy presented), plus your separate error-reporting choice made in Settings.
TulipTv does not send your playlist URLs, provider credentials, catalogue, favourites, viewing history, playback progress, recordings or downloads to the TulipTv account service. Removing the app may not remove recordings or other files you saved outside the app-data folder; you control those files.
In Windows builds using notice version 2026-10-07, error reporting is optional and off until you enable it separately in Settings. Accepting the Terms or viewing this Policy does not enable it. While it is on, the app keeps a separate random reporting ID, a bounded queue of technical reports, records of its recent process sessions and, after a crash, a small crash-report file that the next start adds to the queue. Pending reports, session records and crash-report files expire after 7 days for reporting purposes. Expired local files are removed when the app next processes reporting data and may remain on the device while the app is closed. The queue holds at most 100 reports and 1 MiB. The reporting ID stays until you turn reporting off. Local diagnostic logs remain local.
3. Direct connections to your sources
When you add, refresh or play a source, your device contacts the provider, guide server, stream host and any artwork host identified by that source. Those parties receive the network information needed for the request, which can include your IP address, device or player headers, requested addresses and the credentials required by the provider. They process that information under their own policies. TulipTv does not proxy these requests. Connection security is controlled by the provider, so you are responsible for choosing a provider and connection method appropriate for your needs.
4. Accounts and authentication
Your TulipTv account is a Ginger Cat Works account. Our apps, such as TulipTv and TasteMate, share one account per email address: if you use the same email address in another of our apps, it is the same account, with the same password and sign-in methods. You still sign in to each app separately; signing in to one app does not sign you in to another. The account holds only what every app needs to sign you in: your email address; your sign-in details (password-verification material, which does not let us read your password, and, if you use Google Sign-In, the identifier that links your Google account); technical account records, such as when the account was created and last used; and which of our apps you use, with any role you have in each. The Ginger Cat Works privacy policy describes the shared account.
Everything TulipTv keeps beyond that stays with TulipTv: your TulipTv membership and its status, linked devices, and trial and licence records. Our other apps cannot read it, and TulipTv does not read their data.
If you choose Google Sign-In, Google shares your email address, a Google account identifier, your name and your profile picture with us. We use the email address and the identifier only to sign you in. We do not store your Google name or profile picture: they are removed when the sign-in is saved. Account emails, such as sign-up confirmations and password resets, are sent from no-reply@gingercatworks.com.
Necessary session cookies keep you signed in on the website. We do not use advertising, behavioural analytics or marketing cookies. An external sign-in provider processes the information required for its sign-in flow under its own privacy terms.
5. Device, trial and licence data
TulipTv is distributed only through the Microsoft Store and is free to download there, and each device gets a 30-day TulipTv Pro trial, with no account needed. After the trial the free version keeps every playback feature with one usable playlist at a time; TulipTv Pro, a one-time Microsoft Store purchase, unlocks the other saved playlists and the choice of theme.
For the trial, the app creates a pseudonymous device identifier: a one-way hash computed on the device from hardware identifiers. Raw hardware identifiers are not sent to the service. When the trial starts, the app sends that identifier and the platform (Windows) to the account and licensing service; later trial checks send the identifier. Newer Windows app versions do not collect or send your computer name. Older clients may still include it in a request, but the updated service ignores it and clears earlier stored names. Requests also carry a marker naming the Microsoft Store version, and the service records when it first saw the device from that version so the trial is counted from then. The service stores the identifier with the platform and these first-seen times and the latest trial, status or linking request time, and uses them to provide the trial, limit repeated trials and apply the inactivity retention period in section 11. This request time does not record what you watch or every use of the app. Current Store builds do not link devices to tuliptv.net accounts; the service still supports account links from earlier clients. Trial starts and checks are rate-limited with a short-lived hash of the requesting IP address.
These pseudonymous records are kept to prevent repeated free trials (see section 11). The app also keeps local trial and TulipTv Pro information so it can continue during temporary outages.
6. TulipTv Pro purchases
TulipTv Pro is a Microsoft Store add-on sold through the Microsoft Store, where Microsoft is the merchant. Microsoft processes store accounts, purchases, promotional-code redemptions, payment, taxes, refunds and licence information under its own policies. TulipTv reads the licence status made available to the installed app but does not receive your payment details from the Microsoft Store.
7. Security and operational data
Website hosting and account services may process standard connection and error information for delivery, security and troubleshooting. Temporary security and abuse-prevention records are retained only for short periods.
If you contact support, we receive your email address and whatever diagnostic or other information you choose to send. Do not send playlist credentials.
Export diagnostics saves a ZIP locally; it does not upload it. If you choose to attach that ZIP to a support message, we receive diagnostic logs and build or machine details, including Windows version and graphics-adapter information. Logs may also contain content titles, recent app actions and local file information. Export applies redaction, but review the archive before sending it. This manual support flow is separate from optional error reporting.
8. Optional error reporting
Windows builds using notice version 2026-10-07 capture and send limited technical error reports only after you accept the current Terms and make a separate choice to enable Error reporting in Settings, General. Reporting is off by default, including when an older build had enabled it automatically. You can withdraw this consent there at any time; an update does not opt you in. Earlier builds using the 2026-10-04 notice may report automatically after legal acceptance until you turn reporting off or update. There are no usage analytics or launch heartbeats. Turning reporting off does not prevent playback or change your licence.
Reports are sent for app crashes, start-up errors and playback failures (a stream that does not open, fails while playing or is given up on). They contain a random reporting-installation ID, event ID, occurrence time, error category, exception type and error code, up to 12 method identifiers, up to 12 codes for the app actions just before the error (for example that a channel was being opened, never which channel, film or source), app version and build ID, development/test/production environment, Windows version and the vendor and device ID numbers of the graphics adapter (not its name). Native crash reports can include an allowlisted module basename and version, exception code and relative fault offset. Supabase also assigns a receipt time. We use these fields to group recurring faults and compare affected installations, releases and graphics hardware. The reporting ID is pseudonymous and is separate from account, licence and hardware identifiers.
On a later start, the app may read recent Windows Application Error 1000 records matching this installation's process sessions recorded while reporting was on, and the current Windows user. Matching uses the process ID, creation time and consent interval locally. Raw Windows event XML, Windows user identifiers and paths are never retained in reporting data or uploaded. Reports contain no playlist or stream URLs, passwords, tokens, content names, personal file paths, exception messages, raw logs or memory dumps. Missing Windows records or not reopening the app can prevent a crash from being reported.
Reporting captures at most 100 new reports per day and retries earlier undelivered reports in the background for up to 7 days. Expired reports are no longer eligible for delivery; local cleanup occurs when the app processes reporting data, as described in section 2. As with any network connection, Supabase receives connection metadata such as the source IP address. The error table does not store IP addresses; temporary hashed IP rate-limit records are cleared within about 20 minutes under the existing cleanup schedule.
Turn reporting off in Settings to stop capture and sending and clear pending reports, crash-report files, process sessions and the local reporting ID. Already-sent requests cannot be recalled. Settings lets you select and copy the ID before turning reporting off for support or deletion requests; a copy remains visible for that app session after turning off. Sent reports are not linked to your account, so account deletion cannot identify them without that reporting ID.
9. Why we process data
- Contract: to create accounts, authenticate users, provide trials and respond to support;
- Consent: to capture and send optional technical error reports, including the local crash-event processing in section 8. You can withdraw it in Settings without affecting playback, accounts or entitlement.
- Legitimate interests: to protect accounts and service availability, prevent repeated-trial and licence abuse, retain app-scoped ban and consumed-key markers, and handle support correspondence. These interests are balanced against your rights through limited data, app isolation and the retention and objection controls described below; and
- Legal obligations: to comply with binding law, valid legal process, accounting and consumer-protection duties.
10. Service providers and disclosure
We use service providers only for the functions described here:
- Supabase for account authentication, data hosting, trials and error reporting;
- Vercel for website hosting and delivery;
- Resend for account emails, and Zoho Mail for support correspondence;
- Cloudflare Workers and R2 for sample-clip downloads and credits; requests include connection metadata such as your IP address;
- Google for Google Sign-In, only if you choose it; and
- the Microsoft Store, for distribution, purchases and licensing.
These providers receive only the information needed for their role and process it under their own terms and safeguards. We do not sell personal data or viewing data and do not share it for cross-context behavioural advertising. We may disclose information when required by law, to protect rights and security, or as part of a business transfer with appropriate notice and safeguards.
11. Retention and deletion
- Local app data remains until you clear it, uninstall the app or delete saved files, except the bounded reporting queue and session records described in section 8.
- Received error reports are deleted after 30 days on the next daily cleanup, normally within about 31 days of the server-assigned receipt time. Client occurrence times do not extend this period.
- Your TulipTv membership and active device associations remain while you use them and are removed when you leave TulipTv. The shared Ginger Cat Works account remains while you use any of our apps.
- Unlinked device identifiers, platform and trial timestamps are deleted after 12 months without a trial, status or linking request, on the next daily cleanup. A linked record remains while its account association exists; an unexpired pending link is kept until it expires. Earlier stored computer names are cleared.
- Consumed licence-key records remain marked used to prevent reuse; their account reference is cleared when you leave. A minimal TulipTv ban record may remain tied to a shared account to prevent rejoining, until the ban is lifted or the shared account is deleted.
- Temporary security and abuse-prevention records are short-lived.
- Support correspondence is kept only as long as reasonably needed to resolve and document the request.
To leave TulipTv, email us from the account's address. Leaving removes your TulipTv membership, active device associations and link credentials, and clears account references from consumed licence keys. Limited device, consumed-key and ban records can remain as described above. It removes TulipTv from your Ginger Cat Works account; the account and your data in our other apps stay. Leaving the last of our apps also deletes the account itself, including your email address and sign-in details. To delete the whole account from every app at once, say so in your email. We may need to confirm that you control the address. Neither can erase local data on your devices or data held independently by source providers and stores.
Deletion from active systems does not immediately erase earlier backup or archive copies. Their removal depends on the applicable backup process; we do not promise a fixed production or archive expiry period here. Contact us about data retained in those copies. Sent error reports are separate from accounts; provide the reporting ID for a targeted deletion request.
12. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing; withdraw consent without affecting processing already lawfully done; receive portable data; and complain to a data protection authority, including the Dutch Autoriteit Persoonsgegevens. You may also clear local history and favourites, delete local sources, and turn optional error reporting off. Send requests to contact@gingercatworks.com. We may need to verify that you control the relevant account.
Your right to object
You may object at any time, for reasons relating to your particular situation, to processing based on our legitimate interests, including anti-abuse device records and support or security processing. We will stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or need it to establish, exercise or defend legal claims. Email the contact address above. This right is separate from withdrawing consent to optional error reporting in Settings.
13. International processing
Our Supabase account and application databases are hosted in Frankfurt, Germany. Providers and their subprocessors may also process information in the United States or other countries, including for support, email and delivery. Hosting in the EU does not mean every provider operation stays there. Your chosen media provider makes its own international-processing arrangements.
Supabase, Resend and Cloudflare publish data-processing terms that incorporate the European Commission's Standard Contractual Clauses for applicable restricted transfers. See the Supabase data-processing addendum, Resend data-processing addendum and Cloudflare data-processing addendum. Vercel's hosting information is in its privacy notice. You can request information about the safeguard applicable to your data and a copy of the relevant clauses from our contact address; confidential unrelated information may be removed. Google Sign-In and Microsoft Store processing is also described in their own privacy notices.
14. Security
We use reasonable administrative, organisational and technical safeguards appropriate to the nature of the information and the risks involved. No system is perfectly secure. You are responsible for protecting your Windows account, TulipTv account, provider credentials and source connections.
15. Children
The Service is not directed to children and we do not knowingly create accounts for or collect personal data directly from children who cannot legally consent. A parent or guardian should contact us if they believe a child provided personal data. Source catalogues and age ratings come from third parties and may be missing or inaccurate.
16. Changes
We may update this Policy when the product, providers or law changes. The version date below identifies the current notice. Material changes may be presented again in the app alongside renewed Terms acceptance. Optional error reporting still requires its separate Settings choice.
Version: 2026-10-07. Last updated: 2026-10-07
