Privacy Policy
Last updated: October 3, 2026 (version 2.0.0)
Overview
M3U8/HLS Player with Custom Controls is a free, open-source browser extension. It does not collect, transmit or sell any personal data. It contains no analytics or tracking.
Data Stored Locally
The following is kept in your browser's local extension storage and never leaves your device:
- Settings: player preferences such as volume, playback speed and subtitle style.
- Watch history: stream URLs, titles and playback positions, used for resume. You can turn history off or clear it on the options page.
- DRM settings (optional): license URLs, request headers and robustness values you choose to remember, stored per stream host.
- Site headers (optional): request headers such as
RefererandOriginfor a stream host, either entered by you or, if you turn on Remember the page a stream link was opened from (off by default), saved from the page a stream link was clicked on. You can edit or remove any entry on the options page.
Stream Detection (Off by Default)
If you turn on Detect streams on pages, the browser asks you for permission to read request headers. While it is on, the extension notices when a page requests an .m3u8 or .mpd file and keeps:
- the stream URL
- the request headers the page sent with it, which can include cookies and authorization tokens
This is kept in memory only (storage.session), for that tab, and is cleared when the tab navigates, closes, or the browser exits. It is never written to disk and never sent anywhere except back to the same stream host when you choose to play that stream. Turning the switch off removes the permission and deletes everything detected.
Network Requests
The extension only contacts:
- the stream URLs you open, to play them
- DRM license servers you configure yourself
When it plays a stream, the extension adds the site headers or detected headers above to requests made by its own player tab only. Pages you visit are never modified.
Permissions
- storage: save settings and history locally
- webNavigation: detect navigation to
.m3u8/.mpdURLs so they open in the player - declarativeNetRequestWithHostAccess: open
.m3u8/.mpdURLs in the player, and send site headers from the player tab - webRequest (optional): stream detection, only after you turn it on
- Host permissions / content script: detect stream links on pages and load streams from any host you open
Third-Party Services
The extension does not integrate with any third-party analytics, advertising, or tracking services. The canonical policy is PRIVACY.md in the repository.
Open Source
This extension is fully open source. You can review the entire source code on GitHub to verify these claims yourself.
Contact
If you have any questions about this privacy policy, please open an issue on our GitHub repository or contact Bishal Dahal.