Xelvo legal
Privacy policy
Xelvo is built for media you already have. Local media stays on your
device by default, while optional Google services are kept separate
from the core playback task.
Last updated: August 17, 2026
At a glance
- Xelvo does not require an account and has no approved Xelvo backend.
- Local media is not uploaded by default.
-
Ads, Ad privacy options, usage and crash diagnostics, remote
configuration, and purchases use Google services only when their
feature, configuration, and consent requirements allow.
-
Android Clear storage or uninstall removes Xelvo's app-local records
and settings, not source media.
1. Scope
This policy explains how the Xelvo Android app handles information
during local playback, user-requested network playback, advertising,
telemetry, remote configuration, Google Play purchases, and support.
In this policy, "Xelvo," "we," and "us" refer to the provider of the
Xelvo app.
Third-party services and websites have their own privacy practices.
Their policies apply when they process information.
2. Information handled on your device
With Android permission or a file selection you make, Xelvo can read
local media needed to browse and play it. The app can keep app records
such as playback activity and progress, favorites and playlists,
settings, local diagnostics, and data waiting for an eligible
telemetry request.
Media filenames, titles, folders, paths, URIs, media content,
subtitles, lyrics, artwork, search terms, playlist names, bookmarks,
and exact playback positions are not sent as Xelvo telemetry. Local
media is not uploaded to an Xelvo server by default, and Xelvo does
not currently provide an account or cloud sync.
If you explicitly open an HTTP or HTTPS media address, Xelvo connects
to the host you selected so it can request that media. The host and
network providers may receive normal connection information such as
your IP address. Xelvo does not save URL credentials, cookies, tokens,
or custom authentication headers.
3. Google services
Availability and collection depend on the released app build,
configuration, region, consent status, and the service's own rules.
Local playback remains available when these services or the network
are unavailable.
Advertising and consent
Google AdMob and User Messaging Platform (UMP)
When ads are enabled and a request is permitted, Google may
process device or other identifiers, app and ad interactions,
approximate location derived from network information, and
related technical data to deliver and measure ads, apply Ad
privacy options, prevent abuse, and meet legal requirements. UMP
provides Ad privacy options where applicable. Xelvo remains fully
usable whichever option you choose; ads may become
non-personalized, limited, or unavailable.
If a Google ad cannot be requested or is unavailable, the library may instead show a bundled Xelvo message about ad-free options. That local message does not create an AdMob request or record a House impression or click. Opening the in-app options does not by itself send House interaction data; a later Google Play purchase or rewarded-ad choice uses the applicable Google service under its own rules.
Product telemetry
Firebase Analytics
When Analytics is enabled and consented, Xelvo may report app
lifecycle activity, whether a feature was used, workflow results,
and closed technical categories such as container, codec, failure
stage, and compatibility fallback result. These reports are
designed not to include media identity, media content, user-entered
text, or raw error messages. When Analytics collection is
allowed, it uses app-instance or installation identifiers and
may use the Advertising ID for acquisition attribution; AdMob
may use it for ads. Where required, Google UMP privacy options
manage both advertising consent and Analytics storage through
Google Consent Mode. Xelvo does not show a second Analytics
prompt or keep a duplicate consent record. Outside those
regions, Analytics may run as ordinary app operation. With
Analytics storage declined, advanced Consent Mode may still
send limited, non-persistent consent and activity signals
without Advertising ID, cookies, or Analytics persistent
identifiers. Xelvo also keeps a global switch to stop collection remotely.
Analytics never affects local playback.
Reliability
Firebase Crashlytics
In production builds, Crashlytics is enabled by default for
reliability and security. Google may process crash logs, ANR information,
diagnostics, and app or device technical information. Xelvo
limits explicit reports to sanitized categories and does not
intentionally attach media names, paths, URLs, content, user
input, screenshots, or raw exception text. Every user can turn
crash reporting off under Privacy & legal → Data
collection. The change fully applies after Xelvo restarts, when
reports waiting to be sent are deleted.
Reports already uploaded cannot be recalled. Xelvo also keeps
a global emergency switch.
Configuration
Firebase Remote Config
When enabled, Xelvo can fetch approved app configuration from
Firebase. Firebase may handle app-instance and technical app or
device information for that request. Remote configuration cannot
grant consent, bypass UMP or the Crashlytics user setting, or
make core local playback depend on the service; telemetry
switches can only stop their corresponding collection.
Purchases
Google Play Billing
Google Play processes subscriptions and one-time purchases.
Google may handle payment, purchase history, account, device, and
transaction information under its own policy. Xelvo receives the
product and entitlement status needed to provide ad-free access;
Xelvo does not require a separate account or receive full
payment-card details.
Learn more in
Google's Privacy Policy
and
Firebase Privacy and Security.
4. Support communications
If you email support, we receive the email address and message content
you choose to send so we can understand and respond to the request.
Do not send media files, filenames, paths, URLs, subtitles, lyrics,
playlists, credentials, payment-card details, or other private
content. See the support page for safer
diagnostic details to include.
5. Data Xelvo does not use for telemetry
Xelvo telemetry is not designed to collect or report:
-
Media filenames, titles, directories, paths, URIs, URLs, audio,
video, subtitles, lyrics, artwork, or screenshots.
-
Artist or album names, search terms, playlist or bookmark names,
clipboard content, or other user-entered text.
-
Exact playback positions, complete queues, item-level history,
file-operation targets, or full app databases.
-
Passwords, tokens, cookies, authentication headers, raw exception
messages, or unsanitized logs.
-
Android ID, IMEI, MAC address, SSID, or hardware serial number as
Xelvo-defined telemetry fields.
6. Ad privacy, usage data, and app storage
- Media access
-
Android permissions and the system file picker control which media
Xelvo can access. Revoking access can limit browsing or playback.
- Ad privacy options
-
Where UMP makes them available, Ad privacy options let you review
or update advertising and Analytics storage choices. Xelvo
remains fully usable whichever option you choose. Depending on
your choice, region, and service availability, ads may be
non-personalized, limited, or unavailable. A change applies to
eligible future processing; it does not promise deletion of
provider history. With Analytics storage declined, Google may
still receive limited, non-persistent consent and activity
signals without Advertising ID, cookies, or Analytics
persistent identifiers.
- Usage and crash diagnostics
-
Analytics follows the Google privacy choice described above.
Crashlytics is separately enabled by default for reliability,
and every user can turn it off under Data collection. Turning it
off fully applies after Xelvo restarts and deletes reports still
waiting to be sent; uploaded reports cannot be recalled. Local
playback is never affected.
- Android Clear storage and uninstall
-
Android system Clear storage and uninstall can remove Xelvo's
app-local records and settings, subject to Android behavior.
These system actions do not delete source media or provider-held
service history.
- Explicit media-file deletion
-
A delete operation you explicitly confirm for selected media is a
separate device-file action. When Android authorization and the
source allow it, that action can delete the selected source media.
No remote deletion service: Xelvo has no account or
approved backend and cannot identify or delete provider-held AdMob,
Firebase, or Google Play records on your behalf.
7. Retention and deletion limits
Local app records remain in Xelvo's app storage until changed or
removed through Android system Clear storage or uninstall, subject to
Android behavior. Those system actions remove app-local records and
settings, not source media. An explicit delete operation for selected
media is a separate device-file action.
Google services apply their own retention and deletion rules. Xelvo
does not promise deletion of provider-held information, including
information already received that Xelvo cannot identify as belonging
to a particular person or device. Use the relevant Google account,
service, and privacy controls for provider-held information.
8. Age
Xelvo is intended for people aged 18 and over. It is not directed to
children.
9. Changes to this policy
This policy may be updated when Xelvo's features, service
configuration, or release requirements change. The updated page will
show a new "Last updated" date. Material differences must be reflected
in the app and store disclosures where required.