# Privacy Policy

> Privacy policy for Vistacast (iOS), Vistacast Receiver (Fire TV, Google TV, Android TV), and this website.

Last updated: 2026-09-09
Canonical: https://vistacast.app/privacy

---

Vistacast mirrors your iPhone's screen to a Fire TV, a Google TV device, or an Android TV. This page describes what data the apps touch, and above all what data they do not collect. It also covers this website, which is a separate matter from the apps and is addressed in its own section below.

## What the apps don't collect

Vistacast has no server or backend of its own. There are no user accounts, no analytics, and no tracking inside either app, and we don't share information with third parties. The apps never send your content to the internet: your screen's video and audio travel directly from your iPhone to your own TV, over your local Wi-Fi network, without passing through any intermediate server.

## What is stored locally on your device

A few preferences are stored only on your iPhone, and never sent anywhere:

- The name of the TV you last selected, so it is remembered.
- Whether you have already seen the welcome screen.
- Your Vistacast Pro purchase status, so the app knows whether your daily limit is unlocked.

This information lives in the app's own storage (an App Group shared between Vistacast and its broadcast extension) and is deleted if you uninstall the app.

## In-app purchases

Vistacast Pro purchases, whether the lifetime unlock or a subscription, are processed entirely through Apple and StoreKit. Vistacast never sees or stores your payment information; Apple handles that directly, under its own privacy policy.

## How your screen travels to the TV

Your screen never leaves your local network. It is sent straight from the iPhone to the TV over your own Wi-Fi.

We want to be precise about encryption rather than vague, because the honest answer has a caveat. Vistacast attempts an encrypted (TLS) connection to the receiver. Some TV chipsets fail that handshake, and on those devices the app falls back to an unencrypted connection on your local network so that mirroring still works. Vistacast also does not currently verify the receiver's identity, which means that on a network you do not control (a shared, public, or workplace Wi-Fi), another device on that same network could in principle present itself as a receiver. On your own home network this is not a practical concern. We would rather state this plainly than claim the stream is encrypted end to end when it is not always so.

## The TV receiver

The receiver app that runs on your Fire TV, Google TV, or Android TV does not collect data, has no ads, and does not connect to the internet. It uses the local network only to announce itself to your iPhone (via the Bonjour/NSD discovery protocol) and to receive the video and audio stream directly from it.

A scoped exception existed during pre-release testing and has since ended. Closed-testing builds, never the public versions on the Play Store or Amazon Appstore, could send a technical diagnostics report containing the TV model, Android version, dropped video frames, audio latency, and whether the connection was encrypted. That report never included the sending device's name, any passwords, or the content being streamed. Collection of these reports was closed on 3 September 2026, the endpoint now rejects all submissions, and the public builds are compiled without it entirely.

## Permissions the app asks for, and why

**Local network.** So your iPhone can find the TV, and vice versa, on your Wi-Fi. Without this permission the app cannot function; it is its core purpose.

**Screen recording (ReplayKit).** This is what lets the app capture your screen in order to stream it. It is explicitly activated every time you tap to start mirroring, with a confirmation shown by iOS itself. Vistacast does not request microphone access and does not capture microphone audio.

## Protected content

Because of a restriction in Apple's operating system (FairPlay), Vistacast cannot mirror content from apps such as Netflix or Disney+, or any other app that uses copy protection. This is not a limitation specific to Vistacast; no third-party app can do it.

## This website

This website is separate from the apps, and it is only fair to describe it on its own terms rather than let the apps' "no analytics" answer stand in for it.

vistacast.app uses Vercel Web Analytics to count page views. It is cookieless: it sets no cookies, uses no persistent identifiers, and does not track you across sites or sessions. Visits are counted using a hash derived from the incoming request, and the result is aggregate traffic data that cannot be traced back to you. Because no cookies or similar identifiers are stored on your device, no consent banner is required, and you will not find one here.

This site uses no advertising, no third-party tracking scripts, and no tag manager. Fonts are served from this site's own domain rather than a third-party font CDN, so loading a page does not disclose your IP address to another company. The site is hosted by Vercel, which processes standard server request logs as part of delivering it.

## Changes to this policy

If this policy changes, the "last updated" date above will change with it. Significant changes will also be reflected in the app's description on the App Store, Play Store, and Amazon Appstore.