Xone.build

MPFX privacy policy

9 October 2026

Developer: xone.build / xdev143
Privacy and support contact: hello@xone.build

This policy covers MPFX's portable and Microsoft Store editions. The Store edition uses package LocalState as described below and ships no personal artwork, media, accounts or keys.

Privacy and local data

MPFX Portable stores its settings and library data in its own folder. It does not require an account. Give the folder write access if you want settings, library details, and playback positions to persist.

The MSIX edition stores these same data locations under %LOCALAPPDATA%\Packages\<MPFX package family>\LocalState, separate from its installed files. For the reserved Store identity the family is xdev143.MPFX_z1agw6nq6e8wa; isolated test packages have a different family. The relative locations below apply within that data folder. Screenshots are saved outside package data in your Pictures folder, with Desktop as a fallback. Windows package removal manages package user data; back up data you want to keep before uninstalling.

What stays on this computer

Use Options → Data or File → Local data to review and confirm a specific action. Clear playback history stops playback, removes saved positions and automatic resume records, and clears recent TV channels. Clear temporary caches removes cached movie details, scan/probe caches and TV logos; folders, favorites, personal keys and the internal cover collection remain. Remove movie data keys removes your personal keys and disables online details, including private service defaults. Remove a TV source removes that saved sign-in and its catalog, guide and associated channel choices. These actions preserve your media files and the internal cover collection. Saved screenshots and diagnostics are separate; review them before sharing or removing them manually.

MPFX stops relevant background producers before removal and rejects older TV save snapshots and logo writes. Failure is reported; a partial removal is not reported as success. A new refresh or new playback can create fresh data afterwards. Do not share your whole portable folder without reviewing personal state.

Optional online movie data

Automatic cover lookup checks the local collection before contacting the online movie details service and makes no provider request for a matching cover. Explicit title correction or metadata refresh can still request online details.

Manage online lookups in Settings → Library. Enter your own API key for the movie details service. Get an API key opens that service's registration page in your browser. MPFX has no shared or bundled movie-data keys. Existing keys from an older version are ignored until you explicitly enter and save a key in Settings.

Your saved key is protected with Windows DPAPI in the state/library folder, together with a record confirming your explicit save. Protection uses the current Windows account; enter the key again when moving to another computer or account. Code running as your account can access it. Saving removes the primary legacy plaintext key. A fallback key is never used.

Disable online details stops provider lookups across restarts while keeping your key. Enable online details restores only an already confirmed key; saving your own key enables lookups. Removing it also removes its confirmation.

When a key is configured and the library needs movie details, MPFX sends HTTPS requests to the online movie details service associated with your key. The request URL contains your key and the movie title, year, or IMDb ID being looked up. The service can therefore see those queries and the usual connection information. MPFX also downloads a cover from the HTTPS poster URL returned by the service. That image host can vary and receives a request from your computer. Cached results can be reused without another lookup. Without a key, local artwork and the MPFX default cover work offline.

The IMDb reviews and Rotten Tomatoes actions open an IMDb page or a Bing search in your default browser when you click them. Get a key opens the movie details service's registration page in your browser. These services and your browser have their own terms and privacy practices.

IPTV connections

Sources are added by you. Testing or refreshing contacts that source's server, and may fetch its channel categories, Movies/Series catalog and XMLTV guide. Opening a series requests its episodes if they are not cached. Visible channel logos are fetched from addresses in the catalog and stored internally. Playing contacts the selected stream and may follow the stream's media requests; only one MPFX player is used. Your provider can see your login, selections and normal connection information. HTTP sources transmit their login and streams without TLS encryption; use the provider's HTTPS endpoint when it offers one.

New or edited HTTP connections show their transport warning and require an explicit acknowledgment before testing or saving. MPFX does not silently change your provider address. Provider/catalog requests reject cross-server/port redirects and HTTPS downgrades; some redirect-based services may therefore fail and need a direct address from the provider. Stream playback uses playback engine's network backend, verifies TLS certificates, and can follow provider media redirects and playlist references. The catalog redirect restriction does not establish the same restriction for every stream segment; no blanket secure-transport claim is made for HTTP or a provider's nested media requests.

Playback addresses are passed through the existing IPC pipe, not through process command-line arguments. They remain in memory and can be recovered by software with access to that process. Ordinary playback labels, copied reports and errors use channel names or opaque identities. Streams do not create playback engine watch-later records or saved bookmarks. Personal sources, IPTV catalogs and test fixtures are excluded from release packages.

Contact: hello@xone.build · https://xone.build