StreamRoute · Veeloris
StreamRoute Privacy Policy
Last updated: August 17, 2026.
This Privacy Policy explains how the StreamRoute app processes personal data. StreamRoute is a product of Veeloris, a company currently being incorporated and responsible for the decisions regarding the processing described in this document.
Privacy and support contact: callegari.cf@gmail.com.
1. Who this policy applies to
This policy applies to people who use StreamRoute, including without creating an account. The catalog and search can be used without logging in. An account is required to sync the My List feature across devices.
2. Data we process
2.1. Account and authentication data
When an account is created or accessed, we may process:
- internal user identifier;
- email address and email confirmation status;
- authentication credentials processed by Supabase;
- name and profile photo provided by Google, when Google sign-in is chosen;
- session tokens required to keep the user authenticated.
StreamRoute does not receive or store the Google account password. For email sign-up, authentication is processed by Supabase, and the application does not keep passwords in plain text.
2.2. My List
To sync My List, we store:
- user identifier;
- TMDB title identifier;
- content type, such as movie or series;
- title, image path, release year, and date added.
Each authenticated user can only view, add, or remove their own items through the access rules configured in the database.
2.3. Catalog and searches
When the catalog, search, or details page is used, the app sends our Supabase service the required route and parameters such as search term, category, region, genre, and page. The service forwards only the permitted queries to TMDB.
These queries do not include the account name or email. Providers may, however, process technical data associated with the connection, such as IP address, timestamp, network information, and request logs, according to their own policies and retention settings.
2.4. Data stored on the device
The app may keep session tokens, technical preferences, and image cache locally for authentication and performance. Android app data backup is disabled. Local data may be removed when signing out, clearing the app data, or uninstalling it, depending on the data type and the operating system behavior.
2.5. Data we do not currently collect
StreamRoute does not currently use its own SDK for advertising, analytics, behavioral tracking, location, contacts, or crash monitoring. If this changes, this policy and the applicable disclosures will be updated before the new processing is activated.
3. Why we use data
We use data to:
- create, authenticate, and protect accounts;
- enable email or Google sign-in;
- sync and display My List;
- search and present movies, series, anime, cartoons, and availability on streaming services;
- respond to support, privacy, and deletion requests;
- prevent abuse, investigate failures, and maintain the security and operation of the service;
- comply with legal obligations and exercise rights in administrative, judicial, or extrajudicial proceedings, when necessary.
Depending on the activity, processing may rely on the performance of the service requested by the user, compliance with a legal or regulatory obligation, the regular exercise of rights, the legitimate interest related to the security and operation of the service, or consent, where that is the applicable basis. Where processing relies on consent, it may be withdrawn through the channels indicated in this policy, without affecting prior processing carried out legitimately.
4. Third-party services and sharing
We share data only to the extent necessary to operate the app:
- Supabase: authentication, database, server functions, and account deletion. Receives account, session, My List data, catalog queries, and technical request data;
- Google: optional authentication. When chosen, it provides the sign-in flow with basic account data authorized by the user, such as identifier, email, name, and photo;
- TMDB (The Movie Database): catalog, images, search, details, and availability data. Receives catalog queries forwarded by our proxy, without the account name or email;
- JustWatch via TMDB: source of the availability data presented by TMDB. StreamRoute does not maintain a direct account integration with JustWatch;
- Google Play: app distribution and technical or purchase data processed by the platform, when the app is made available on it.
These providers may process information in other countries. In such cases, the processing and international transfer occur according to the terms, security measures, and legal mechanisms adopted by the respective providers and applicable law.
Relevant policies:
We do not sell personal data. We also do not share data for behavioral advertising.
5. Retention and deletion
Account and My List data are kept while the account is active or while necessary to provide the service. When you delete the account through the app, we request the user's removal in Supabase, and the associated My List items are automatically deleted from the main database.
A request made by email will be processed after the measures necessary to confirm ownership. We aim to complete verified requests within 30 days, unless a different deadline is required or allowed by law.
Technical logs are kept according to the provider's plan and settings, only for the period necessary for security, diagnostics, and operation. Residual copies may remain temporarily in backups until they are replaced according to the provider's retention cycle. Information may be kept beyond these periods when necessary to comply with a legal obligation, prevent fraud, protect rights, or respond to an order from a competent authority.
Support messages and the records needed to demonstrate that a request was handled may be kept for as long as necessary to complete the handling and safeguard rights.
6. How to delete your account
In the app, go to Profile > Delete my account and confirm the presented steps. Deletion ends the session, removes the account in Supabase, and deletes the associated My List items from the main database. With Google sign-in, the app also requests disconnection of the authorization used by StreamRoute.
If you cannot access the app, send a request to callegari.cf@gmail.com with the subject StreamRoute account deletion. Do not send a password, access token, or personal document in the first contact. We may ask for a proportional confirmation to prevent the improper deletion of another person's account.
Before publication on Google Play, a public web deletion page accessible without installing the app will also be made available.
7. Data subject rights
Under the Brazilian General Data Protection Law (LGPD), the data subject may, where applicable, request:
- confirmation of the existence of processing;
- access to and correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
- portability, subject to regulation and the protection of commercial and industrial secrets;
- information about sharing and about the possibility of refusing or withdrawing consent;
- deletion of data processed with consent, except for legal retention scenarios;
- objection to processing carried out in non-compliance with the LGPD;
- review of decisions made solely on the basis of automated processing, if any.
StreamRoute does not currently make decisions that produce legal or significant effects solely through automated processing.
To exercise rights, write to callegari.cf@gmail.com. We may request information strictly necessary to confirm the identity and legitimacy of the request. The data subject may also file a petition with the Brazilian National Data Protection Authority (ANPD), under applicable terms.
8. Security
We adopt measures compatible with the stage and risks of the service, including HTTPS communication, blocking of HTTP traffic on Android, Row Level Security rules for My List, separation of server credentials, limitation of the routes accepted by the TMDB proxy, and session validation before account deletion.
No system is completely secure. In the event of a relevant incident, the technical, administrative, and communication measures required by applicable law will be adopted.
9. Children and adolescents
StreamRoute is not specifically directed at children under 13 and does not knowingly seek to collect their data. Minors should use the service with the supervision of their parents or guardians, as applicable by law. The target audience declared in the stores must remain consistent with this information and with the actual app experience.
If we become aware of improper processing of a child's or adolescent's data, the responsible party may request review and deletion through the contact email.
10. Changes to this policy
This policy may be updated to reflect changes in the app, providers, or legislation. The current version will indicate the date of the last update. Relevant changes will be communicated by appropriate means before they take effect when required by law.
11. Contact
Current controller: Veeloris, a company currently being incorporated and responsible for the StreamRoute app.
Privacy and support email: callegari.cf@gmail.com.