SAM PLAY / INFORMATION
Privacy Policy
Last updated: October 2, 2026
About this policy
This policy describes the SAM PLAY website as it is currently implemented. The website does not provide user accounts or a contact form. Questions about privacy: support@samplay.net.
Information handled by the website
The Worker reads request paths and, when you use remote playlist setup, receives the six-digit pairing code and playlist details you submit. D1 stores a keyed hash of the app's random installation identifier, the Android app version and device model, and keyed hashes of the pairing code and polling token. Pairing-only device metadata may be removed after 30 days of inactivity when no unexpired pairing session remains. Devices with app-entitlement or license-binding records are retained separately so cleanup cannot reset an existing trial or paid-device binding. Pairing session status and lifecycle timestamps are stored until session cleanup. Expired sessions are cleaned up by a scheduled task; other terminal session records may remain for up to seven days before cleanup.
Playlist details, which may include provider URLs, usernames, passwords, or device addresses, are sent from your browser to SAM PLAY over HTTPS and relayed to the app that requested the pairing session. The temporary relay payload is encrypted with AES-GCM in the active D1 database and can be read only by the app holding that session's secret polling token. It stays encrypted until the app confirms that it has saved the playlist on the device, and is deleted from the database at that point; if the app never confirms, it is deleted when the pairing session expires (10 minutes after the code was created). Do not submit details unless you want them added to that app. Pairing tokens are sent in authorization headers and are not placed in API query strings.
After delivery, the Android app adds the playlist setup to its persistent on-device app storage. The app database is excluded from Android cloud backup and device-to-device transfer by the current app configuration. Uninstalling the app removes its private app data.
Deleting a relay payload from the active D1 database does not immediately erase earlier encrypted database states from Cloudflare recovery history. Cloudflare documents D1 Time Travel history for up to 7 days on Free plans or 30 days on Paid plans; the applicable account retention period applies. Historical states contain the encrypted payload, not its plaintext.
The website does not provide SAM PLAY user accounts, a contact form, or newsletter signups. It does not use advertising, analytics, or tracking scripts.
License purchases
Payments are handled on Stripe's hosted checkout page (test mode in this pre-release implementation); card and payment details are entered on Stripe and never reach SAM PLAY. Stripe processes your payment and the information you give it (such as your email address and billing country) under its own privacy policy. SAM PLAY stores a purchase record: the plan, price and currency, payment status, timestamps, payment-event records and Stripe's session and payment references. If a payment is fully refunded or a dispute is lost, SAM PLAY records that reversal (payment reference, amount, currency, reason and time) and the license is revoked. Your license key is stored only as a one-way hash, plus an encrypted copy that can be unlocked only with the private link of your purchase confirmation page.
When you activate a license, either with the code shown on your device at samplay.net/activate or by entering the key in the SAM PLAY license screen on the device, the license is linked to that device's keyed installation hash (the same pseudonymous device record used for pairing). Licensed device records are kept for as long as the license binding exists, so the app can confirm its license. Promo code redemptions store a hash of the code, the issued license and a timestamp.
For the free trial, the app registers a device entitlement record: the hashed installation identity, a hashed installation authorization secret, the trial start and end and validation timestamps. These minimal records are kept to preserve trial and non-transferable device-binding history; they do not contain provider credentials. The Android entitlement cache and installation proof are encrypted with Android Keystore and excluded from backup and device transfer.
Cookies and browser storage
The public website does not set cookies or use browser storage for analytics, advertising, or visitor profiles. The site's own administrators receive a strictly necessary sign-in cookie when they use the private admin area.
Technical requests and hosting
Your browser and network send technical request information when loading or using this service. Cloudflare, which hosts and delivers this website, may process or log technical request information as part of providing its services. The Worker is configured to sample invocation logs at 10% and redact query strings. Request bodies, which can contain playlist credentials, are not written to application logs by this Worker. This policy does not specify Cloudflare's separate practices or retention periods.
Changes
If website features change, this policy may be updated to describe the information those features handle. The date above indicates when this version was prepared.