Privacy
This page describes what the Ember application stores, what it deliberately does not store, and how to have your data deleted. It is written from the actual code and database, not from a template.
Last updated 8 September 2026 · RUSCUS LLC
What Ember is
Ember is a media player. It contains no channels, films or series and it sells no subscription to any. Whatever you watch comes from a playlist you or your reseller supplies. We are not the source of that content and we do not host it.
We do not record what you watch
There is no watch history, no viewing profile and no per-title analytics anywhere in the system. This was a deliberate design decision, not an omission. Your reseller cannot see what you watch either, because we never collect it.
What we store
Device record
A device identifier generated by the app on first launch — it is not a hardware serial or advertising identifier. Alongside it: platform, OS version, device model, interface language, the country derived from your IP address, the last IP address seen, and the time you were last online. This is what makes a licence belong to a device rather than to a person.
Licence and playlists
Your licence period and where it came from, plus the playlists defined for the device: name, type and address. For Xtream playlists the username is stored and the password is stored encrypted. Your device PIN is stored as a hash, never in plain text.
Health measurements
When a playlist was last refreshed, how many entries it returned, any error it reported, the round-trip latency to our server, and the timestamps of your first and last playback. Timestamps only — never what was played. This exists so a reseller can tell “their internet is down” from “the playlist is broken” without calling you.
Failed content reports
One exception to the paragraph above, and we would rather state it than hide it: when a stream fails to open, the app reports the item’s name and section so the provider can find the broken entry. Successful playback is never reported, and each item is recorded at most once per device per day. It is a fault report, not a history.
Advertising
Only if you choose it
Ember can extend your trial when you choose to watch a rewarded advertisement. Advertisements appear only on the setup screen, never during playback, never over content, and never without you tapping a button first. If you never tap it, no advertisement is requested and the advertising SDK is not even started.
Google AdMob
Advertisements are served by Google AdMob, which may process your device’s advertising identifier and IP address under Google’s own terms. In the European Economic Area and the United Kingdom you are asked for consent first; on iOS you are additionally asked for tracking permission. Declining either is fine — the app keeps working and advertisements simply become non-personalised.
The rest
Who can see it
If a reseller set up your device, they can see its record, its licence and its playlists, and can attach a private note to it. We can see the same. Nobody else does: we do not sell, rent or share this data, and there is no third-party analytics or tracking SDK in the app.
How long we keep it
The device record lives as long as the device is registered. Health measurements are overwritten as new ones arrive. Failed-content reports are kept while they are useful to the provider.
Deleting your data
Ask your reseller to delete the device, or write to us at hello@ruscus.net with the device identifier shown on the app’s home screen. Deleting the device removes its record, playlists, measurements and reports. It also ends any licence attached to it, so ask only when you mean it.
Children
Ember is not directed at children and we do not knowingly collect data from them. The app has an adult-content lock, off by default, which a parent can enable with a PIN.
Contact
RUSCUS LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States. Questions about this page or about your data: hello@ruscus.net. We answer data requests within 30 days.