Xelvo legal

Privacy policy

Xelvo is built for media you already have. Local media stays on your device by default, while optional Google services are kept separate from the core playback task.

Last updated: August 17, 2026

At a glance

  • Xelvo does not require an account and has no approved Xelvo backend.
  • Local media is not uploaded by default.
  • Ads, Ad privacy options, usage and crash diagnostics, remote configuration, and purchases use Google services only when their feature, configuration, and consent requirements allow.
  • Android Clear storage or uninstall removes Xelvo's app-local records and settings, not source media.

1. Scope

This policy explains how the Xelvo Android app handles information during local playback, user-requested network playback, advertising, telemetry, remote configuration, Google Play purchases, and support. In this policy, "Xelvo," "we," and "us" refer to the provider of the Xelvo app.

Third-party services and websites have their own privacy practices. Their policies apply when they process information.

2. Information handled on your device

With Android permission or a file selection you make, Xelvo can read local media needed to browse and play it. The app can keep app records such as playback activity and progress, favorites and playlists, settings, local diagnostics, and data waiting for an eligible telemetry request.

Media filenames, titles, folders, paths, URIs, media content, subtitles, lyrics, artwork, search terms, playlist names, bookmarks, and exact playback positions are not sent as Xelvo telemetry. Local media is not uploaded to an Xelvo server by default, and Xelvo does not currently provide an account or cloud sync.

If you explicitly open an HTTP or HTTPS media address, Xelvo connects to the host you selected so it can request that media. The host and network providers may receive normal connection information such as your IP address. Xelvo does not save URL credentials, cookies, tokens, or custom authentication headers.

3. Google services

Availability and collection depend on the released app build, configuration, region, consent status, and the service's own rules. Local playback remains available when these services or the network are unavailable.

Advertising and consent

Google AdMob and User Messaging Platform (UMP)

When ads are enabled and a request is permitted, Google may process device or other identifiers, app and ad interactions, approximate location derived from network information, and related technical data to deliver and measure ads, apply Ad privacy options, prevent abuse, and meet legal requirements. UMP provides Ad privacy options where applicable. Xelvo remains fully usable whichever option you choose; ads may become non-personalized, limited, or unavailable.

If a Google ad cannot be requested or is unavailable, the library may instead show a bundled Xelvo message about ad-free options. That local message does not create an AdMob request or record a House impression or click. Opening the in-app options does not by itself send House interaction data; a later Google Play purchase or rewarded-ad choice uses the applicable Google service under its own rules.

Product telemetry

Firebase Analytics

When Analytics is enabled and consented, Xelvo may report app lifecycle activity, whether a feature was used, workflow results, and closed technical categories such as container, codec, failure stage, and compatibility fallback result. These reports are designed not to include media identity, media content, user-entered text, or raw error messages. When Analytics collection is allowed, it uses app-instance or installation identifiers and may use the Advertising ID for acquisition attribution; AdMob may use it for ads. Where required, Google UMP privacy options manage both advertising consent and Analytics storage through Google Consent Mode. Xelvo does not show a second Analytics prompt or keep a duplicate consent record. Outside those regions, Analytics may run as ordinary app operation. With Analytics storage declined, advanced Consent Mode may still send limited, non-persistent consent and activity signals without Advertising ID, cookies, or Analytics persistent identifiers. Xelvo also keeps a global switch to stop collection remotely. Analytics never affects local playback.

Reliability

Firebase Crashlytics

In production builds, Crashlytics is enabled by default for reliability and security. Google may process crash logs, ANR information, diagnostics, and app or device technical information. Xelvo limits explicit reports to sanitized categories and does not intentionally attach media names, paths, URLs, content, user input, screenshots, or raw exception text. Every user can turn crash reporting off under Privacy & legal → Data collection. The change fully applies after Xelvo restarts, when reports waiting to be sent are deleted. Reports already uploaded cannot be recalled. Xelvo also keeps a global emergency switch.

Configuration

Firebase Remote Config

When enabled, Xelvo can fetch approved app configuration from Firebase. Firebase may handle app-instance and technical app or device information for that request. Remote configuration cannot grant consent, bypass UMP or the Crashlytics user setting, or make core local playback depend on the service; telemetry switches can only stop their corresponding collection.

Purchases

Google Play Billing

Google Play processes subscriptions and one-time purchases. Google may handle payment, purchase history, account, device, and transaction information under its own policy. Xelvo receives the product and entitlement status needed to provide ad-free access; Xelvo does not require a separate account or receive full payment-card details.

Learn more in Google's Privacy Policy and Firebase Privacy and Security.

4. Support communications

If you email support, we receive the email address and message content you choose to send so we can understand and respond to the request. Do not send media files, filenames, paths, URLs, subtitles, lyrics, playlists, credentials, payment-card details, or other private content. See the support page for safer diagnostic details to include.

5. Data Xelvo does not use for telemetry

Xelvo telemetry is not designed to collect or report:

  • Media filenames, titles, directories, paths, URIs, URLs, audio, video, subtitles, lyrics, artwork, or screenshots.
  • Artist or album names, search terms, playlist or bookmark names, clipboard content, or other user-entered text.
  • Exact playback positions, complete queues, item-level history, file-operation targets, or full app databases.
  • Passwords, tokens, cookies, authentication headers, raw exception messages, or unsanitized logs.
  • Android ID, IMEI, MAC address, SSID, or hardware serial number as Xelvo-defined telemetry fields.

6. Ad privacy, usage data, and app storage

Media access
Android permissions and the system file picker control which media Xelvo can access. Revoking access can limit browsing or playback.
Ad privacy options
Where UMP makes them available, Ad privacy options let you review or update advertising and Analytics storage choices. Xelvo remains fully usable whichever option you choose. Depending on your choice, region, and service availability, ads may be non-personalized, limited, or unavailable. A change applies to eligible future processing; it does not promise deletion of provider history. With Analytics storage declined, Google may still receive limited, non-persistent consent and activity signals without Advertising ID, cookies, or Analytics persistent identifiers.
Usage and crash diagnostics
Analytics follows the Google privacy choice described above. Crashlytics is separately enabled by default for reliability, and every user can turn it off under Data collection. Turning it off fully applies after Xelvo restarts and deletes reports still waiting to be sent; uploaded reports cannot be recalled. Local playback is never affected.
Android Clear storage and uninstall
Android system Clear storage and uninstall can remove Xelvo's app-local records and settings, subject to Android behavior. These system actions do not delete source media or provider-held service history.
Explicit media-file deletion
A delete operation you explicitly confirm for selected media is a separate device-file action. When Android authorization and the source allow it, that action can delete the selected source media.

No remote deletion service: Xelvo has no account or approved backend and cannot identify or delete provider-held AdMob, Firebase, or Google Play records on your behalf.

7. Retention and deletion limits

Local app records remain in Xelvo's app storage until changed or removed through Android system Clear storage or uninstall, subject to Android behavior. Those system actions remove app-local records and settings, not source media. An explicit delete operation for selected media is a separate device-file action.

Google services apply their own retention and deletion rules. Xelvo does not promise deletion of provider-held information, including information already received that Xelvo cannot identify as belonging to a particular person or device. Use the relevant Google account, service, and privacy controls for provider-held information.

8. Age

Xelvo is intended for people aged 18 and over. It is not directed to children.

9. Changes to this policy

This policy may be updated when Xelvo's features, service configuration, or release requirements change. The updated page will show a new "Last updated" date. Material differences must be reflected in the app and store disclosures where required.

10. Contact

For privacy or support questions, contact:

xelvo.support@gmail.com