Privacy Policy
Last updated: 13 September 2026
This policy covers the Castario website, the mobile sender apps, native television receivers and the Google Cast receiver route. Castario does not operate a cloud media proxy that receives and forwards your private screen or media. Hosted software, Google Cast, app stores and third-party content services have separate data flows described below.
In short
- Castario has no product account, no first-party advertising system and no first-party product analytics.
- A paired native Castario receiver carries screen, sound, selected media and control traffic directly between the phone and television on the local network. Castario does not receive those private media bytes in a cloud service.
- The website at castario.de consists of static files. Page requests reach our web server and its hosting provider and are recorded in short-lived operational logs. The pages load nothing from other providers and store nothing in your browser except a language choice you make yourself.
- The Custom Web Receiver at castario.de/cast/ is not opened by website visitors: a Google Cast device loads it at the start of a Cast session, and it loads Google's Cast framework.
- Google Cast is a separate platform route. Google's sender and receiver software and services process Cast session and diagnostic data under Google's terms; Castario does not describe that route as a purely local native-receiver connection.
- Websites, search engines, YouTube, IPTV providers and app stores receive data when you choose to use their services. Their own privacy terms apply.
Who is responsible
The legal operator for the first-party processing described here is Castario · Mahmoud Khawatmi · Einzelunternehmer. Privacy enquiries go to privacy@castario.de.
Website and hosting
castario.de is a static website hosted on a server rented from Hetzner Online GmbH in Germany. Every page, script, style sheet and image it uses is served from castario.de itself.
- The web server necessarily processes the requesting IP address, date and time, requested path, response status and size, referrer if supplied, and user-agent information in order to deliver and secure the service.
- The live nginx configuration records those fields in access logs. Logs rotate daily and are retained for up to 14 days for operation, fault investigation and security, then deleted by rotation.
- The website uses no analytics, no advertising or marketing trackers, no marketing cookies and no third-party scripts. It loads no Google Fonts or other externally hosted web fonts; text appears in fonts already installed on your device.
- The website sets no cookies. The only thing it stores in your browser is the language preference described in the next point.
- When you switch the language by hand, the website stores the key castario-language with the value de or en in your browser's localStorage. When you open the English start page, it reads that key and, if it says de, opens the German version; it is used for nothing else. It contains no user identifier and is not sent to our server with your requests. It is not used for tracking, profiling, analytics or advertising and serves only to keep the language you chose. Storing and reading it is strictly necessary for this function you asked for (Section 25(2) no. 2 of the German TDDDG), so no consent is requested. You can remove it at any time by clearing this site's data in your browser.
- The website does not read your browser's language setting and does not choose a language by location or IP address. Without a stored choice the start page stays in English, and the language switch opens the German version.
- Where the website shows a link to the App Store, it is an ordinary link. No Apple image, script or other resource is loaded before you click it; the Apple logo on the button is drawn by the page itself. Only after you click does your browser contact Apple, and Apple's privacy policy applies from there.
Receiver software on castario.de
The same server also delivers software to televisions. Visitors to the website do not load it.
- A Google Cast device loads the Castario Custom Web Receiver from castario.de/cast/ when a Cast session starts. That request comes from the television and appears in the server logs described above.
- The Custom Web Receiver loads the Google Cast Application Framework from www.gstatic.com and, when needed, the Shaka player from ajax.googleapis.com. Those requests expose the Cast device's public IP address and ordinary request metadata to Google. The website's own pages load neither.
- A television receiver that was installed by hand can ask castario.de whether a newer version exists and download it, but only when somebody presses the update control on the television. A receiver installed from the Amazon Appstore or from Google Play never asks us; its store updates it, and that entry does nothing.
The receiver host serves software files. It is not a media relay: your mirrored screen, photos, videos and audio are not uploaded to castario.de for forwarding to the television.
Local native receiver traffic
On the native Castario receiver route, a new phone is confirmed on the television. The phone and receiver then use an encrypted connection pinned to the identities established at pairing. Depending on the selected feature, the local connection carries control messages, a live screen and permitted app audio, selected media, or addresses the receiver should open.
This traffic stays between the devices on the local network unless the selected item itself requires an internet service. A web page or IPTV stream is fetched from its own provider, not from a Castario cloud media proxy.
Compatible standard TV routes
A DLNA or UPnP television is reached through the local-network protocol it advertises. This route does not use Castario pairing and is not the encrypted native Castario receiver session. The phone can offer only the media capabilities the television announces. The television vendor controls what the set stores, logs or reports, and its privacy terms apply to the device.
Google Cast and Chromecast
When you choose a Google Cast device, the iOS sender uses Google Cast SDK 4.8.6 to discover the device, start a Cast session, launch the Castario Custom Web Receiver and control playback. Google Cast is for selected content and receiver commands in Castario; it does not carry Castario screen mirroring.
- A Cast device downloads the Castario receiver software from castario.de/cast/ at session start. That request appears in the server logs described above.
- Selected local media is served from the phone to the Cast device on the local network. Web pages and IPTV streams are requested from their respective internet hosts. For supported credential-protected HLS, the iPhone may perform the temporary local relay described below instead of handing the provider address directly to the Cast device. The private media bytes are not uploaded to castario.de.
- Google's Cast SDK privacy materials say the SDK automatically processes diagnostic data. The embedded SDK privacy manifest declares non-linked device ID, other diagnostic data and product interaction for analytics and app functionality, with no tracking. This data goes to Google, not to Castario's own analytics system.
- Google's services also handle receiver registration, session infrastructure and the Google-hosted Cast framework. Google's privacy policy and Cast terms apply to that processing.
Websites, search engines and IPTV providers
- A website opened in the phone browser or on a supported receiver gets ordinary web requests, including the requesting device's IP address, headers, cookies for that session where enabled by that route, and anything you submit to the site.
- A search typed into the address bar is sent to the search engine you selected as an ordinary web search.
- A YouTube video is handed to the television as the video identifier alone and plays in YouTube's own embedded player inside the receiver. No stream is extracted or downloaded, and no watch address, playlist, search term or account of yours travels with it; the player on the television is signed out. YouTube and Google receive the television's own request and apply their own terms. On the Google Cast route that player is loaded from youtube-nocookie.com.
- An IPTV provider receives the request for a playlist and the selected channel from the phone or television route that fetches it. Provider access data is sent only to the matching provider host under Castario's URL and redirect rules.
- Direct playback remains the normal IPTV route. For supported HLS that needs provider credentials which a non-native television route cannot carry, the iPhone sender can issue a short-lived local address to that television, fetch the provider resources with the credentials held on the phone, rewrite the HLS resource addresses and relay the response bytes across the local network. The phone app must remain available or playback stops. This relay runs on the phone for that session; it is not a Castario-operated internet proxy or cloud media service.
- The mobile browser's ad and tracker filter is applied on the device. The native receiver and Google Cast routes have different blocking capabilities; Google Cast does not offer the same request-level filter over a framed third-party page.
Castario does not control these parties. Their privacy terms, retention and international-transfer rules apply to the services you choose to reach.
App stores and purchases
The current iPhone and iPad sender uses StoreKit. Apple handles the Apple Account, payment, subscription, renewal, cancellation and refund infrastructure. Castario reads the verified entitlement on the device and operates no purchase-history backend of its own.
Android Mobile is not a public download and the current development build contains no Google Play Billing integration. If it is released with Play Billing, the policy and Google Play Data Safety form must be updated before that release. Native TV receiver builds and the Google Cast receiver route contain no separate purchase.
iPhone and iPad sender
- The sender keeps bookmarks, optional browser history, playlists, pairings and settings on the device. IPTV credentials and the private device-identity key are kept in the iOS keychain.
- The Apple photo picker grants access only to the selected items; Castario does not request general photo-library access.
- Screen mirroring starts only after you confirm it in the iOS broadcast picker. The recording indicator remains visible. The microphone is not used; app audio depends on iOS and the source app allowing capture.
- Apple may receive crash and diagnostic reports through the iOS system setting you control. Castario has no crash-reporting backend of its own.
- The app's own privacy manifest declares no first-party collected data or tracking. The separately embedded Google Cast SDK manifest and disclosures still apply to the Google Cast route as described above.
Android Mobile development build
Android Mobile is part of the Castario product family but is not currently distributed as a public app. The present development build stores pairings, bookmarks, playlists and settings in app-private storage; IPTV credentials are encrypted with a key held in AndroidKeyStore. It currently requests internet access for local discovery and for browser and playlist requests. It does not yet implement screen capture, app-audio capture or Play Billing, so this policy does not claim those unfinished flows.
Native television receivers
Native receiver apps keep the television identity, paired-sender trust records, language and player preferences, and a small local watch-progress history where the receiver supports continue-watching. The receiver's temporary web mode clears its page, cookies, cache and history when the session ends as supported by the platform. Receiver data stays on the television until it is cleared in the app or system, or the receiver is uninstalled; the precise system controls differ between Fire OS, Vega OS, Android TV and Google TV.
Support reports and messages
The iPhone and iPad sender can create a diagnosis report after you request it. It contains a fixed set of versions, states and counts, not installation identifiers, network addresses, television names, playlist or file names, or viewing history. It remains on the device until you choose to copy or send it. If you contact support, the message and anything you deliberately attach are processed to answer you and retained according to the support process established before launch.
Retention and deletion
- Web access logs are retained for up to 14 days under the live server configuration and then deleted by rotation.
- Sender and receiver data remains on the relevant device until you remove it through the app or system, clear the app's data, or uninstall the app. Available deletion controls depend on the platform and data type.
- Castario keeps no cloud copy of private screen or media content because it operates no cloud media proxy.
- Third parties such as Google, Apple, websites, search engines, IPTV providers and television vendors apply their own retention rules.
Children
Castario is not directed at children. It includes unrestricted web access and user-supplied playlists, so the applicable store age rating and the device's parental controls matter. Castario does not knowingly create accounts for or market to children because it creates no product accounts at all.
Security
- Native Castario receiver connections are encrypted and pinned to identities confirmed at pairing.
- Google Cast and DLNA use their respective platform and standard security models; they are not represented as the native pairing channel.
- Public IPTV sources are required to use HTTPS. A narrowly confirmed local-network source may use plain HTTP where the route supports it, which means other parties on that local network may be able to observe the traffic.
- No security measure is absolute. A network, television or third-party service you do not control can introduce its own risks.
Your rights
Where the GDPR or comparable law applies, you may have rights of access, rectification, erasure, restriction, objection and data portability, and a right to complain to a supervisory authority. Most Castario product data is under your direct control on your own devices. Privacy requests concerning web logs or support communications go to privacy@castario.de; identity verification may be necessary before disclosing information tied to an IP address or message.
Changes and contact
This policy changes when the product, SDKs, hosting or legal requirements change. The date at the top identifies the current version. Privacy questions go to privacy@castario.de; legal operator: Castario · Mahmoud Khawatmi · Einzelunternehmer.