Ellipse · VR Player

Privacy Policy

Effective date: September 8, 2026

This policy covers the Android app VR Player (package app.ellipse.vrplayer), published by Ellipse. It explains what stays on your device, what the app's advertising provider collects, and the choices you have. Questions: ellipseapps@gmail.com.

The short version

Data that stays on your device

The following is processed and stored only on your phone, in the app's private storage. None of it is transmitted to Ellipse:

Advertising data (Google AdMob)

The free version shows one banner ad in the launcher and an optional rewarded ad that unlocks both interactive phone and headset VR playback for a video. Ads are provided by Google AdMob (the Google Mobile Ads SDK). When ads are shown or requested, Google automatically collects and shares with its partners:

Google uses this data for advertising, analytics, and fraud prevention. This transfer is protected with TLS encryption. See Google's Privacy Policy and how Google uses data in AdMob.

Your choices: in the European Economic Area, the UK, and certain US states, the app shows a consent form before ads and you can reopen it any time from the app's privacy options to change your choice. You can reset or delete your advertising ID in Android settings. Purchasing Premium removes ads entirely, which stops AdMob requests from this app.

Analytics (Google Analytics for Firebase)

The Google Play version reports a small, fixed set of usage events, so we can see which features are used and where people get stuck. Each event records what kind of thing happened — never what you watched:

The optional purchase feedback accepts no typed response. Its choices are limited to price, not using VR enough, a missing feature, a technical problem, preferring the ad option, not purchasing today, or skipping the question.

No file names, media titles, folder paths, web addresses, typed feedback, or playback error text are included in any event. Events are grouped by a Firebase installation identifier for this app on this device. Analytics also marks the installation as free or Premium so existing owners can be excluded from Premium campaigns. Analytics data may be associated with the Android advertising ID when permitted by your privacy choices.

We use these events to understand feature use, playback and purchase drop-off, and to measure or build audiences for app-promotion campaigns. When Analytics, AdMob, and Google Ads are linked, audience and conversion data can be shared between those Google services, subject to your consent and Google's eligibility thresholds. Google processes this data under the Google Privacy Policy; see also Firebase privacy and security.

Analytics is present only in the Google Play build. Builds distributed outside Google Play contain no analytics SDK at all.

Rewards accounts and verification

If you choose rewarded unlocks, Google sign-in creates a Firebase Authentication account. Google/Firebase processes the sign-in identity, email address, profile information supplied by Google, IP address, and authentication tokens. We use it for account access and fraud prevention, not to identify you in Analytics.

Our Firebase/Google Cloud service receives a hash of the selected media address, an account identifier derived from your Google identity, random reward reservation identifiers, server timestamps, and AdMob reward transaction identifiers. A hash is pseudonymous data, not guaranteed anonymous. Raw video addresses, titles, and video contents are not sent. The service enforces two rewarded video unlocks per Google account per UTC day and verifies AdMob-signed completion callbacks. Firebase App Check with Play Integrity checks app authenticity.

Each reward covers the current viewing session in both interactive phone and headset VR, with one hour to reopen the same video. Failed or declined ads do not consume completed unlocks; a completed ad may retain a slot while verification is pending.

Purchases

Premium is available as a monthly auto-renewing subscription or a one-time lifetime purchase through Google Play Billing. Google handles payment; Ellipse does not receive payment-card or bank details. Existing lifetime purchases retain their access.

The app retains the signed lifetime receipt locally. Lifetime and subscription purchase tokens are sent over HTTPS to our verification service, which queries Google Play for current access and acknowledgement. Raw tokens are processed for verification and are not written to our database or application logs. For purchases Google has canceled or revoked, including chargebacks, we retain a one-way hash of the purchase token and reversal metadata for as long as needed to prevent the reversed purchase from restoring access. These records contain no email address or payment-card details and are separate from optional rewards accounts. A confirmed lifetime reversal is also stored on the device. Valid lifetime receipts continue to work offline; a temporary verification outage does not remove lifetime access. The app caches a signed subscription entitlement for at most 24 hours, never beyond the verified paid or grace-period expiry. Rebooting requires online subscription verification. Limited infrastructure request metadata may be processed by Google Cloud for security and operation.

When Firebase is linked to Google Play, Analytics can record the product identifier, currency, and purchase value. These records do not include payment-card details. Manage or cancel a subscription from the Premium page or the Google Play subscription center.

Websites and streams you choose

If you enter a stream URL, browse a website in the in-app browser, or connect to a network share, your device communicates directly with that server. The operator receives ordinary connection data (such as your IP address) and controls any information you submit to it, under its own privacy policy. Connections you make over HTTPS are encrypted in transit. The player can also, only after showing you an explicit confirmation, play a plain HTTP stream you approve — such traffic is not encrypted. Playback credentials are not silently forwarded to unrelated hosts.

If the app offers View page in VR, it displays the website you chose on a flat virtual screen. The page still communicates directly with its operator; it is not copied to an Ellipse server. Protected or DRM-controlled pages may not render.

Jellyfin servers you choose

Jellyfin is an optional connection to a media server selected by you; it is not an Ellipse service. During sign-in, the app sends the server address, username, and password directly to that server. After a successful sign-in, the password is discarded. The returned access token, username, server details, and a stable random device identifier created separately for that server are stored encrypted on your device.

Jellyfin requests identify the app and device with the device model (used as the client device name), the per-server device identifier, and the app version, and authenticated requests include the access token. Searches send the terms you enter to that server. When playback stops, the app can send the media item identifier and playback position so the server can save your resume point. Ellipse does not receive any of this data.

HTTPS connections are encrypted in transit. Because VR Player also supports media servers on a private or local network, you can choose a plain HTTP server; credentials, tokens, searches, and playback updates sent over HTTP are not encrypted in transit. The server operator controls any server-side logs, retention, access, and deletion. Signing out removes that server's saved token and connection from VR Player, but does not delete data held by the server.

YouTube playback

Recognized YouTube video links can open in YouTube's official embedded player. The app does not download or extract the YouTube media stream. When the player loads, YouTube receives connection and player-use data directly to display the video, determine playability and restrictions, and prevent fraud or abuse.

For YouTube embeds, when supported by the installed Android WebView, Media Integrity sends YouTube attested app metadata (the package name, version number, and signing certificate) and a device-attestation token generated by Google Play services. Google states that this integrity data is encrypted, is not shared with third parties, and is deleted after a fixed retention period. Ellipse does not receive this data.

YouTube playback is governed by YouTube's Terms and Google's Privacy Policy.

Watch parties

A watch party is off unless you start or join one. While one is running, your phone exchanges the current play position — and, with devices that have entered the six-digit code the host displays, the title of what is playing — directly with the other devices in the party over your own local network.

No video is transmitted: every device plays its own copy of the file. There is no account, no relay server, no connection outside your network, and nothing reaches Ellipse. The exchange is encrypted with keys agreed for that party alone, the code authenticates both ends of every join, and everything stops when the party ends or the app closes.

Crash reports

If the app stops unexpectedly, it can keep one local report containing the app version, device model, Android version, and the error. File names, web addresses, network addresses, email addresses, and sign-in tokens are redacted before the report is stored in the app's private files. Nothing is uploaded automatically.

The app offers the report on a later launch so you can read it first. It reaches Ellipse only if you deliberately send it with another app; copying or sending can also expose it to the app you choose. You can turn recording off and delete the stored report from Settings.

Retention and deletion

Local app data remains until you clear the relevant history or browser data, sign out of a media server, delete a crash report, clear VR Player's Android app data, or uninstall the app. Local media data is separate from optional rewards account records.

Delete your rewards account from Premium → Rewards account → Delete rewards account, or request deletion at our account deletion page. Firebase sign-in account data is removed on deletion. Pseudonymous reward and replay-prevention records are scheduled for automatic deletion after eight days; Firestore cleanup is asynchronous and may finish later. This short retention prevents deleting and recreating an account to reset its allowance and allows delayed rewards to be reconciled. Account deletion does not cancel Google Play subscriptions or remove lifetime purchases.

Analytics events are retained by Google for 14 months, after which Google deletes them automatically. Uninstalling VR Player resets the Firebase installation identifier used to group them. Google and the operators of websites, streams, or media servers you choose control their own retention and deletion. Use their account controls or contact them for data held by those services. Premium users can stop future AdMob requests from VR Player; Android also provides controls to reset or delete the advertising ID.

Children

VR Player is a general-audience app and is not directed at children. It is not intended for users under the age required for ad-supported apps in their region.

Security

Sensitive local data (history, browser session state, media-server access tokens, pairing records, and rewarded unlocks) is stored in app-private storage encrypted with keys held in the Android Keystore, and is excluded from device backups. Rewards account and verification data is processed by the Firebase/Google Cloud services described above.

Changes to this policy

If a future version of the app changes what data is handled — for example a new SDK — this page will be updated before that version ships, with a new effective date. Significant changes will be noted in the app's update notes.

Contact

Ellipse — ellipseapps@gmail.com