HL Player Privacy Policy

Published and effective: July 20, 2026

HL Player is an app that provides local video playback, highlight/tag/playlist management, subtitle generation and translation, backup and restore, and PC subtitle generation assistance. By default, users' original video/audio files and most app data are processed on the user's device or on the PC connected by the user. HL Player does not store users' full video/audio files in Firebase, does not sell personal information, and does not use personal information for personalized advertising through third-party advertising SDKs.

This revision clarifies the actual PC subtitle session lifetime and deletion delay, service-specific Firebase retention and overseas processing, detailed backup package contents and their unencrypted nature, user-selected external services, and change-notice procedures.

This English version is provided for convenience. In case of any discrepancy between the Korean and English versions, the Korean version shall prevail to the extent permitted by applicable law.Korean original

1. Controller and Contact

Questions about HL Player's processing of personal information, or requests for access, correction, deletion, or suspension of processing, may be submitted using the contacts below.

Privacy controller and privacy operations contact Pangaeha, HL Player operator
Privacy inquiries and deletion requests privacy@hlplayer.app
General support support@hlplayer.app

HL Player is currently provided through an individual developer account before business registration and without in-app purchases. The Google Play developer name is Pangaeha. If business registration is completed or paid features/advertising are introduced, the controller information, terms, Play Console information, and Play Data Safety responses will be updated together.

2. Personal Information Processed, Purposes, and Retention

Category Items processed Purpose Retention and deletion
App activity information App launch, major feature usage, guide display/click events, and similar app interaction events when the user allows anonymous usage statistics in the first-run prompt or Settings. The app is designed not to send local file names, paths, video titles, or subtitle text as event values. The current release disables Google Analytics Advertising ID collection, and Play Store referrer values are used only as campaign-level reference signals. Service quality improvement, feature usage analysis, and error cause analysis Collection is off by default, and users may allow, deny, or change it in the first-run prompt or Settings. Retention is subject to Firebase Analytics settings and Google/Firebase retention policies. Users may reset device-side identifiers by deleting the app, deleting app data, or using platform privacy settings.
Diagnostic information Crashlytics crash logs, stack traces, app/device diagnostic information, and redacted non-fatal error context. Release builds filter sensitive local content information such as file names, local paths, video titles, and subtitle text. Non-fatal custom keys are limited to values such as app area, operation, error code, and severity. App error analysis, stability improvement, and incident response Firebase states that crash stack traces, processed minidumps, and associated identifiers are kept for 90 days before removal from live and backup systems begins. Local debug logs are not automatically collected as release artifacts; only crash/non-fatal reports and Crashlytics logs/custom reasons sent to Crashlytics are filtered and transmitted.
Support diagnostics When the user opens feedback/support, the app may prepare app version, operating system name/version, Android SDK version, manufacturer, model, and app language for a support email or copied report. Android ID, serial number, fingerprint, board, bootloader, hardware, hardware ID, codename, local file names, paths, video titles, and subtitle text are restricted from this diagnostic set. Helping the user include basic app/device environment information in a support inquiry selected by the user The app does not upload this automatically. If the user sends the email or copies the content, it is handled according to the user's selected email app, clipboard, email provider, and the HL Player support mailbox policies.
Remote app configuration and notices Requests to https://hlplayer.app/app-config/android.json, config version, cache max age, update notice build numbers, notice title/body/URL, notice display period, feature flags, local cache, and local notice/recommended-update dismissal state Providing important notices, forced/recommended update messaging, temporary feature gating, and launch safety controls The config JSON may be cached on the device according to a 1-72 hour max age, defaulting to 24 hours, and is removed by app data deletion. During the request, Firebase Hosting access logs may record ordinary HTTPS request metadata such as IP address, User-Agent, requested URL, and timestamp. Firebase states that Hosting IP data is retained for a few months.
Anonymous authentication and security information Firebase Anonymous Auth UID, authentication tokens, Firebase App Check tokens, and verification information Creating PC subtitle generation sessions, protecting Firebase requests, and preventing abuse Deleting app data or reinstalling the app may reset authentication state stored on the device, but is not guaranteed to automatically delete the anonymous user record on Firebase servers. Firebase Authentication information may remain until the operator initiates deletion for that user, and Firebase states that removal from live and backup systems may take up to 180 days after deletion starts. Server-side deletion requests may be sent to privacy@hlplayer.app, and an additional verification process may be provided to identify the requested record.
PC subtitle generation connection metadata Session ID, created/updated/expires timestamps, SDP offer/answer, ICE candidates, connection status, progress status, selected model information, audio size, language tag, and batch job count Establishing WebRTC connections and syncing subtitle generation progress between the mobile app and the user's PC browser/local engine A session is valid for up to approximately 6 hours from creation. The parent session becomes eligible for Firestore TTL deletion after expiration; Firebase states that TTL deletion is typically completed within 24 hours after expiration but is not immediate. The app attempts to delete ICE-candidate subcollection documents during normal cleanup; candidates with expiration timestamps are also eligible for their own TTL; and server cleanup runs when the parent session is deleted. Abnormal termination, network failure, or asynchronous cleanup may delay deletion.
Request limiting information Hash-based rate limit counters, time keys, and expiration timestamps created from a Firebase UID or request IP Preventing abuse of PC subtitle generation link creation and protecting the service Configured to be deleted after about 3 days through Firestore TTL. The original IP address is not stored in rate limit documents and is used only as a hash input.
Model download information Selected model URL, model ID, model size, SHA-256, and network metadata sent during download requests such as IP address and User-Agent Downloading user-selected local subtitle models and verifying integrity Model files are stored on the user's device or PC and may be removed through the app model management screen, PC engine management features, file manager, app data deletion, or app deletion. External storage request logs are subject to each provider's policy.
Subtitle translation SDK and model information Device and app information, SDK/API configuration, app- or installation-level identifiers, performance metrics, error codes, feature events, feature input/output size, model download events, and source/target language settings that may be processed by Google ML Kit Translate SDK. The content of subtitle text to be translated and translation results are designed to be processed on the device. On-device subtitle translation, translation model download, and performance/error diagnostics Translation models are stored on the device and may be removed through app features or app data deletion. ML Kit SDK diagnostics and usage analytics data are subject to Google's policies.
Notification and background processing information Playback, media processing, model download, subtitle generation, compact video generation progress status, and Android notification permission/channel settings Showing task progress and ensuring stable background playback and long-running processing Processed on the device by default. Users can control this through Android notification settings, stopping tasks in the app, deleting app data, or deleting the app.
Local media and generated data Video/audio/subtitle files selected or authorized by the user, thumbnails, highlights, tags, playlists, multiview presets, subtitle generation results, compact videos, trash items, search/sort/view settings, and temporary files or progress state created during on-device FFmpeg/FFprobe media processing Local video playback, organization, highlight management, subtitle display/generation, FFmpeg/FFprobe compatibility processing, compact video generation, trash/restore, and preserving user settings Stored on the user's device by default. Users may remove data through in-app deletion, emptying trash, resetting settings, deleting app data, using a file manager, or deleting the app. Original video files created or owned by the user are not deleted merely by resetting app data.
Profile and backup/restore data Profile name/color and backup identifiers, app language, per-profile settings, achievement state, backup location and folder-access information, and data that may be included in a backup package (.hlbk): file name, path and last-known path, hash, size, duration, media-store identifier, playback/trash/missing state and timestamps, playback position/speed/A-B loop/display and subtitle selection/sync settings, highlights, tags, playlists, multiview presets, generated subtitle content/files/model/language information, user-selected thumbnails, and identifiers/modification times used for merge and deletion decisions Profile switching, preserving app language/settings, backup creation, restore, and moving data between devices Stored by default on the user's device or in a user-designated storage location. Original video files are not included in the package. A .hlbk package includes integrity checksums but is not guaranteed to be password-protected or encrypted. Backup discovery may inspect a designated folder and subfolders and may retain folder access where the operating system permits. Users may directly delete backup files or delete related data through the app's backup/restore and reset features.
Sharing and export data Highlights, subtitles, compact videos, backup files, and metadata required for share link processing when the user chooses sharing or export. Share links may include file name, part of a file hash, file size/length, tag name/color, highlight time, title, description, repeat settings, and, if a file hash is unavailable, part of the original path. Sharing, exporting, or opening in another app or browser as selected by the user After a share link or export file is created, it may be processed according to the user's selected storage location, receiving app, browser, Firebase Hosting access logs, or external service policies. Users should review the target and contents before sharing. Share links are not permanent storage and existing links may stop opening if the domain, hosting, or share web page is discontinued.

3. Local Video, Audio, Subtitles, AI, and Translation Processing

4. Processors, Platforms, and User-Selected External Services

HL Player does not sell personal information and does not provide it to a third party for the operator's independent purposes. Google/Firebase and Google ML Kit are used as processors or technical service providers for app functionality, security, analytics, and error response. Hugging Face, GitHub, Google Play, and user-selected sharing destinations are external services that the user's device contacts directly following the user's download, distribution, or sharing choice, or that process information independently as platforms. They are included below for transparency.

Provider Role Items processed Retention and management standards
Google / Firebase Analytics, Crashlytics, Anonymous Auth, App Check, Firestore, Cloud Functions, Hosting, STUN App activity, crash/diagnostics, anonymous UID, App Check verification information, PC session metadata, WebRTC network metadata, remote app config requests, Firebase Hosting access logs, and share link URL/path metadata Subject to Firebase settings, Firestore TTL, session cleanup logic, Firebase privacy and security standards, and the Google Privacy Policy.
Google ML Kit On-device subtitle translation, translation model download, SDK diagnostics, and usage analytics Device/app information, SDK/API configuration, app- or installation-level identifiers, performance metrics, error codes, feature events, feature input/output size, model download events, and source/target language settings. Translation input content and output results are processed on the device. Translation models are stored on the device. SDK diagnostics and usage analytics data are subject to Google ML Kit terms and privacy standards.
Hugging Face Downloading user-selected whisper.cpp model files Model download request URL, IP address, User-Agent, and other network metadata Model files are stored on the user's device or PC, and request logs are subject to the Hugging Face Privacy Policy.
GitHub Providing download paths for models, open-source components, or release files when used Download request URL, IP address, User-Agent, and other network metadata Downloaded files are stored on the user's device or PC, and request logs are subject to the GitHub Privacy Statement.
Google Play App distribution and updates Google account, installation, and update information independently processed by the Play Store. HL Player currently does not accept in-app payments. Subject to the Google Privacy Policy, Google Play policies, and the user's Google account settings.
User-selected sharing destination Sharing, exporting, and opening in another app User-selected highlights, subtitles, compact videos, backup files, and share link metadata After sharing, the receiving app, storage location, or external service policies apply.

5. Overseas Transfer and Processing

Firestore and Cloud Functions for PC subtitle session documents use the asia-northeast3 region in Seoul, so storage of those session documents in the designated region is not an overseas transfer from Korea. Firebase Authentication, Analytics, Crashlytics, App Check, Hosting, STUN, ML Kit, and external download services selected by the user may nevertheless process network metadata or service data outside Korea. Transfers below are based on the user's optional choice under Article 28-8(1)(1) of the Korean Personal Information Protection Act or processing/storage necessary to perform the service contract under Article 28-8(1)(3), and occur through encrypted communications when the relevant feature is used or a network request occurs.

Recipient and contact Country Items and purpose Timing and method Retention Basis, refusal, and effect
Google LLC / Firebase
Privacy inquiry
United States (Firebase Authentication) Anonymous UID, authentication token, IP address, and User-Agent for PC subtitle session authentication and security Sent through the Firebase SDK and HTTPS/TLS when PC subtitles are first used or authentication is refreshed Authentication information may remain until the operator initiates user deletion. Firebase states that authentication IP logs are retained for a few weeks and that removal from live and backup systems may take up to 180 days after user deletion starts. Processing/storage necessary to perform the service contract. Users may refuse by not using PC subtitles or may request deletion; local playback and organization remain available.
Google LLC / Firebase
Privacy inquiry
United States and countries where Google operates data centers Optional app activity; crash/diagnostics; installation/app-instance identifiers; App Check information; Hosting request IP, URL, User-Agent, and time; and STUN/WebRTC network information for analytics, incident response, request protection, and web/connection features Sent via Firebase SDKs, HTTPS/TLS, or WebRTC/STUN when the user enables statistics or when an app error, web access, share-link access, or PC connection occurs Crashlytics removal begins after 90 days; Hosting IP data is retained for a few months; App Check material may be retained for up to 7 days, or used replay-protection tokens for up to 30 days. Analytics follows project retention settings. Analytics is based on the user's optional permission and can be disabled in Settings. Other essential online processing is necessary to perform the service contract. Users may refuse by not using web, sharing, or PC connection features, but those online features may be unavailable.
Google LLC / Google ML Kit
Privacy Policy
United States and countries where Google infrastructure operates Device/app information, SDK/API configuration, installation identifiers, performance/errors, feature input/output size, model download events, and translation-language settings for translation models and SDK diagnostics. Translation text content and results are processed on the device. Sent via ML Kit SDK and HTTPS/TLS when the user uses subtitle translation or downloads a translation model Subject to the ML Kit data disclosure and service-specific Google policies. Processing/storage necessary for the user-selected translation feature. Users may refuse by not using translation or model download, without affecting local playback.
Hugging Face, Inc.
Privacy Policy
United States and countries where the provider operates infrastructure Model download URL, IP address, User-Agent, and network metadata for a user-selected whisper.cpp model Direct HTTPS/TLS request when the user selects an external model download Subject to Hugging Face log and retention policies. Performance of the user-requested model download. Users may refuse by not downloading; the external model will then be unavailable.
GitHub, Inc.
Privacy Statement
United States and countries where the provider operates infrastructure Download URL, IP address, User-Agent, and network metadata for models, open-source components, or release files Direct HTTPS/TLS request when the user selects a GitHub-hosted download Subject to GitHub log and retention policies. Performance of the user-requested download. Users may refuse by not downloading; the external file will then be unavailable.

6. User Rights and How to Exercise Them

Users may submit requests for access, correction, deletion, suspension of processing, or refusal of overseas transfer to privacy@hlplayer.app. Local data may be deleted directly through app features, the device file manager, app data deletion, or app deletion. Deleting the app or app data alone is not guaranteed to automatically delete the anonymous UID on Firebase servers. Users may request deletion of a Firebase anonymous UID or PC-session server data through the same contact. Where available, including the most recent eight-character PC connection code and approximate usage time can help identify the requested record. The operator may provide an additional verification procedure limited to what is necessary. HL Player does not provide email or social login accounts, and the Firebase anonymous UID is used as a technical identifier for PC subtitle generation and security purposes.

7. Destruction Procedures and Methods

8. Security Measures

9. Automatic Collection Tools and Online Behavioral Information

The HL Player app currently does not provide personalized advertising through third-party advertising SDKs. If the user allows anonymous usage statistics, Firebase Analytics may use SDK identifiers such as app instance identifiers for app usage statistics. This collection can be turned off at any time in app Settings. The current release disables Google Analytics Advertising ID collection, and Play Store referrer values are used only as campaign-level reference signals. The PC subtitle generation web page may use browser local storage such as localStorage and IndexedDB for session processing, model cache, and preserving user selections. Users may delete this data in their browser settings.

10. Children's Privacy

HL Player is not primarily directed to children under the age of 14. If processing of personal information of a child under 14 is confirmed, or if a legal representative submits a deletion request, necessary measures will be taken.

11. Automated Decisions

HL Player does not perform fully automated decisions that have a significant effect on users' rights or obligations. Subtitle generation and analysis assistance features are tools that process user-selected content and suggest results, and users should verify the accuracy of those results.

12. Changes to This Privacy Policy

This Policy may be revised due to changes in laws, services, SDKs used, or data processing methods. Ordinary changes will be posted on the official web page before they take effect. Changes that materially affect data-subject rights will, where reasonably possible, be announced through the app or official web page before they take effect with the change, effective date, and reason. Urgent security or legal changes that cannot be announced in advance will be explained promptly afterward. Previous versions may be requested at privacy@hlplayer.app.

13. Remedies for Rights Infringement

If users need counseling or dispute resolution related to privacy infringement, they may use relevant institutions such as the Korean Privacy Portal, the Personal Information Infringement Report Center, or the Personal Information Dispute Mediation Committee.

This Policy applies to the HL Player app, the PC subtitle generation web page, and the PC engine distribution page.