Privacy Policy
Last updated: 4 August 2026
This Privacy Policy explains how Norva (“Norva”, “we”, “us”) collects, uses, stores and deletes information when you use the Norva apps (Android phone/tablet and Android TV) and the Norva web app at norva.tv (together, the “Service”).
Norva is a media player, not a content provider. Norva does not supply, sell or host any channels, movies, series or streams. You connect a compatible media source that you own and are authorized to use. Any credentials or playlist links you add are used only to connect the Service to your source on your behalf.
1. Information we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, display name, password (stored hashed by our auth provider) | Create and secure your account, sign you in |
| Media source settings | Provider host/username/password (Xtream), playlist (M3U) and TV-guide (EPG) URLs you choose to add | Connect the Service to the source you are authorized to use |
| Usage & preferences | Watch history and playback progress, favorites, audio/subtitle/genre preferences | Resume playback across your devices and personalize the experience |
| Devices & pairing | Trusted-device records, device tokens, pairing codes | Let your TV and phone share one account and sync playback |
| Sign-up context | Whether sign-up was completed in a web browser or the Android mobile app, the Norva journey used (account, subscription or TV pairing), sign-in method, and an approximate country/region/city supplied by Cloudflare at the network edge and handed on by the Norva client. This is an indicative analytics signal, not proof of residence. Norva does not retain the raw IP address in this record. | Understand onboarding, provide support and improve the multi-device experience |
| Entitlement / subscription | Subscription status and the store/provider that granted it (e.g. Google Play, Apple, Stripe) | Verify Norva access; we do not store card numbers |
| Norva Partners membership, referral & access credit | Partner membership status, accepted programme terms, opaque referral code and claim, pseudonymized attribution, commission and counter-entry ledger, server-issued access-credit quote, redemption and Norva access-grant status. These core records do not require or contain a Didit identity result. | Join the programme, attribute valid referrals, calculate and mature commissions, prevent abuse and convert available commission into Norva access |
| Optional Partner cash payout | Only after Norva's server confirms that your account is in the current cash cohort and you choose a cash transfer: your explicit payout country; the minimum normalized Didit identity, age, country and capacity result; hashed transaction references; exact amount paid, tax and currency/exponent; payout status; required tax-profile fields; and tokenized payout-provider references. An account outside that cohort is not asked for payout country, KYC, tax or banking information. Norva does not store identity-document images, biometric captures, a full KYC response, raw Google Play purchase token, buyer address, bank credentials or card number. | Assess cash-payout readiness, reconcile and pay valid individual commissions, and meet applicable tax, accounting and transfer obligations |
| Partners operations analytics | Aggregated counts and financial totals by day, payment rail and currency, including referral claims, attributions, verification outcomes, holds, refunds, chargebacks and commission processing. These aggregates exclude names, emails, public referral codes, payment identifiers and raw KYC or payment-provider payloads. | Monitor the programme, reconcile its ledger and detect operational or fraud-control failures without exposing individual records |
| Technical | IP address, app version, device/model, basic logs and crash data | Deliver streams from your network, secure the Service, fix bugs |
| Analytics & advertising (web, with consent) | Cookies and identifiers set by Google Analytics, Google Ads and Meta Pixel when you accept them | Measure how the Service is used and how our ads perform |
| Downloads (on device) | Media you download is encrypted and stored only on your device | Offline viewing; this content is not uploaded to us |
2. How we use information
- To provide, maintain and secure the Service and your account.
- To connect the Service to the compatible source you choose to add.
- To sync playback progress, history and preferences across your devices.
- To verify your Norva access/subscription status.
- When you choose to join Norva Partners, to create and operate your membership and link, attribute valid referrals, calculate and mature commissions, prevent fraud and let you convert available commission into Norva access.
- Only after the server confirms cash-pilot eligibility and you choose a cash payout, to collect your explicit payout country, verify the individual payout requirements, collect the applicable tax profile, validate a supported corridor and administer the transfer.
- To understand which Norva sign-up journey and device type were used and improve onboarding.
- To diagnose problems and improve reliability.
- With your consent, to measure audience and the performance of our advertising (web app only).
We do not sell your personal information. With your consent, we use analytics and advertising cookies on the web app to measure usage and how our ads perform — see Cookies, analytics & advertising below. You can decline or withdraw this at any time.
Our legal bases depend on the purpose: performance of our contract for account, playback, subscription and the optional Partners agreement; compliance with tax, accounting and other applicable legal obligations; and our legitimate interests in service security, fraud prevention, support and reliability, balanced against your rights. Optional analytics and advertising use consent. Didit's document, selfie, liveness and face-match verification is used only if you choose the optional cash-payout path. Norva requests separate explicit consent before redirecting you to the hosted capture. You may stop before capture or withdraw that consent from the Partners page; Support remains available if the in-app control cannot be used. Withdrawal blocks any new biometric verification and all cash transfers while consent remains withdrawn. It never ends Partners membership, deactivates a referral link, cancels attribution, stops commission accrual or maturation, or prevents conversion of available commission into Norva access. It also does not affect your ordinary Norva subscription or the lawfulness of earlier processing. Withdrawal does not itself erase an already completed verification or records that must be kept for a legal claim, tax, accounting or anti-fraud obligation; those records remain subject to the retention limits in section 5.
Didit uses automated systems to assess document integrity, liveness, face match and fraud signals. Norva then applies the programme's configured age, country, legal-capacity and account rules to the normalized result. An unsuccessful result can prevent cash-payout readiness and a transfer, but it cannot prevent Partners membership, a referral link, attribution, commission maturation or a Norva access-credit conversion and does not affect ordinary access to Norva. From the Partners page you can contest an unsuccessful payout-verification result and request a human review. A Risk operator reviews the relevant result in Didit's secured console through an access that requires MFA, authorization and an audited justification; the Norva Admin page does not expose identity documents, biometric captures or the raw provider response. The review may uphold the result or make a fresh verification available. This description explains the actual workflow and does not predetermine whether any particular data-protection-law provision on solely automated decisions applies to an individual case.
An access-credit redemption records an irreversible conversion of available commission into a Norva-only access entitlement at the server-issued quote. The entitlement cannot be transferred, used to pay another person or redeemed for cash, and Norva does not present it as a bank/payment account or general-purpose payment instrument. This factual description does not predetermine its legal classification under applicable law. The ledger also records any later refund, chargeback, reversal, duplicate correction or recovery due so that Norva does not silently alter the financial history. Access-credit records contain no biometric data or payout destination.
3. Cookies, analytics & advertising
The first-party sign-up context described in section 1 is an operational account record, not a Google Analytics, Google Ads or Meta cookie. It remains available when optional analytics cookies are declined, and is kept separate from billing country and your chosen catalogue region.
On the Norva web app we use cookies and similar technologies. Analytics and advertising technologies are not loaded until you accept them: a consent banner appears on your first visit, and nothing is set or sent to these providers unless you choose “Accept”.
- Strictly necessary — needed for the site to work (sign-in, security and remembering your consent choice). Always active; no marketing use.
- Analytics — Google Analytics 4, to understand how the Service is used so we can improve it.
- Advertising — Google Ads and Meta Pixel, to measure how our ads perform (for example a sign-up or purchase that follows an ad).
You can change or withdraw your choice at any time from Settings → Privacy & legal → Manage cookies, which reopens the consent banner. If you decline, these analytics and advertising tools are not loaded. These providers process data under their own policies: Google and Meta.
4. Sharing and processors
We share data only with providers used to operate the Service or, where applicable, to measure analytics and advertising after consent:
- Hetzner — hosting of Norva's self-hosted application, authentication, database and operational services on infrastructure located in the European Union. Norva operates the Supabase software on this infrastructure; Supabase does not host this Norva deployment.
- Cloudflare — DNS, security, web hosting and content delivery, including the approximate network-edge location signal described in section 1.
- Resend — transactional and security email delivery, including authentication messages, support communications and Norva Partners access-review decisions. Resend receives the destination email address, the minimum message content and delivery metadata needed to send and troubleshoot those messages.
- Didit — hosted individual identity, age, country and capacity verification only when a Norva Partner chooses a cash payout and that payout-verification provider is enabled for the jurisdiction. Didit is not used to join, create a referral link, attribute referrals, accrue or mature commission, or convert available commission into Norva access. Didit acts as Norva's processor for the checks Norva configures and also describes itself as an independent controller for limited security, abuse-prevention, legal-compliance, audit-logging and legal-claims purposes. Before redirecting you, Norva links the Didit Verification Privacy Notice and Didit End User Terms for Identity Verification and requests explicit confirmation for document, selfie, liveness and face-match capture. Verification data may be processed outside the country where the flow starts; where required, Didit states that it uses safeguards such as adequacy decisions, standard contractual clauses or another recognized transfer mechanism. Norva retains only the minimum normalized outcome and provider reference needed for payout audit and does not copy identity-document images or biometric captures into the Norva database.
- Telegram — delivery of operational new-sign-up notifications to a restricted administrator chat. These notifications may include a display name, masked email, sign-in method, whether sign-up used the web browser or Android mobile app, the Norva journey used, approximate region/country, and an Admin link whose destination may contain an internal account identifier. They do not include the raw IP address or city. Norva marks messages as protected against forwarding and saving where supported by Telegram, but this cannot prevent screenshots or manual copying and does not delete a delivered message.
- Google (Analytics, Ads) and Meta (Pixel) — audience measurement and advertising performance on the web app, only after you consent (see section 3).
- Google Play — Android subscription entitlement and, only for an attributed Partners account, the Orders API fields needed to record the exact paid total, tax, currency and refund state. Norva hashes transaction references and does not copy the raw purchase token or buyer address into the Partners ledger.
- RevenueCat — delivery and normalization of subscription lifecycle events used to maintain entitlement and initiate server-side financial reconciliation.
- Revolut — web subscription checkout and authoritative settled, refund and chargeback events where that payment rail is used; Revolut Business also executes individual Norva Partners payouts in supported corridors. Under the initial manual workflow, Norva keeps the unique payout reference, exact amount/currency, masked destination, provider beneficiary token, a keyed beneficiary fingerprint and mapping-proof hash, opaque transaction identifier and hashes, and normalized statement status needed for reconciliation. The keyed fingerprint is produced outside the database and cannot reveal the underlying bank details by itself. Norva does not retain the raw bank statement or unrelated statement transactions.
- Your media source — when you ask the Service to connect, requests are made to the host you configured. You are responsible for that source and its terms.
We may disclose information if required by law or to protect the rights, safety and security of users and the Service.
Revolut Business is the initial individual payout provider for supported Norva Partners corridors. Availability remains jurisdiction- and currency-specific and is shown before a payout profile can become active. Beneficiary details are managed in Revolut; Norva stores the provider token, masked destination and opaque transfer identifier needed to prepare and reconcile the payout, but not the beneficiary's full bank-account details.
5. Data retention
We keep account and usage data while your account is active. When you delete your account (see below) we delete or anonymize your personal data, except where we must retain limited records to comply with legal obligations. Downloaded media lives only on your device and is removed when you delete it or uninstall the app.
If a Partners payout, return, recovery or required financial review is still open, account deletion is placed in a temporary financial-closure state instead of discarding or anonymizing the records needed to resolve it. Norva does not expose the amount in the public deletion response. The user is directed to Support, and deletion can complete once the account-specific financial obligations are resolved.
For sign-up context, city and region stop being available to administrators at 90 days and are physically erased by a retention job within the following 15 minutes. Country and product-origin fields may remain while the account is active so we can compare onboarding trends over time; they are deleted with the account.
Deleting your Norva account does not automatically or retroactively remove a sign-up notification that has already been delivered to the restricted Telegram administrator chat. Telegram-side retention depends on that chat's settings. Norva recommends a short automatic deletion period and restricted chat membership, but does not claim that a delivered message is erased by the account-deletion flow.
Partners referral claims expire if they are not consumed within the published attribution window. Attribution, commission, access-credit redemption, grant, reversal and payout records may be retained for the period required by tax, accounting, anti-fraud and dispute-resolution law even after a Norva account is closed. For users who choose a cash payout, KYC provider references and normalized outcomes are retained only for as long as necessary for those obligations. Identity-document images and biometric captures are not copied into Norva's database. Once Norva has safely committed an accepted terminal Didit verification, it stores only the normalized minimum needed for eligibility and audit, then requests deletion of the hosted verification session; a deletion failure is retried and blocks successful webhook acknowledgement. Before any live France-pilot collection, Didit's application-level retention must also be set to a maximum of one month and evidenced in the private approval record, subject only to a documented applicable legal hold. Norva reassesses this period before any broader release.
6. Your rights & deleting your account
You can access or update your information in the app, and you can request deletion of your account and associated data at any time:
- In the app: Settings → Account → Delete account.
- On the web: norva.tv/delete-account.html.
Depending on where you live, you may also have rights to access, correct, port or restrict processing of your data. To exercise them, contact us using the details below.
7. Security
Traffic to Norva’s cloud is encrypted in transit (HTTPS). Passwords are stored hashed by our auth provider. Offline downloads are encrypted on your device with a hardware-backed key where available. No system is perfectly secure, but we work to protect your data.
8. Children
Norva is not directed to children under 13 (or the minimum age in your country) and we do not knowingly collect their personal data.
9. International transfers
Your data may be processed in countries other than your own by the providers listed above, with appropriate safeguards in place.
10. Changes
We may update this policy. We will revise the “Last updated” date and, for material changes, provide a more prominent notice.
11. Contact & data controller
Data controller / operator: Norva is a trading name of
Adrien Hernandez, sole trader (entrepreneur individuel) registered in
France under RCS Paris 824 852 081, business address
270 rue de Vaugirard, 75015 Paris, France.
Email: [email protected]
Full legal notice: mentions légales.
Norva has not officially designated a Data Protection Officer (DPO). Privacy and data-subject requests may be sent to the contact above; this statement does not limit any right to contact a competent supervisory authority.
If you are in the EEA/UK, you may lodge a complaint with your local data-protection authority. In France this is the CNIL.