Legal
Privacy Policy
What the Opixo Studio service and the Opixo Player TV app collect, why, and how to have it deleted.
Last updated 7 September 2026
Who we are
Opixo is a digital-signage product operated by Astorion Mediacomm Solutions LLP, Silvassa, Dadra and Nagar Haveli, India. This policy covers the Opixo Studio web application and the Opixo Player app for Android TV.
Questions about anything here: tech@amsads.in.
The short version
Opixo Player is a screen, not a person. It is paired once to a business account and then plays that account's content. It has no user accounts, no sign-in on the television, and no advertising. We do not sell data, and we do not share it with data brokers or advertising networks.
What the TV app sends us
Everything below is sent so that the screen can be operated remotely by the business that owns it. All of it is required for the product to function; none of it is optional analytics.
-
Device and network identifiers — an Android-generated device identifier
(
ANDROID_ID), the screen's pairing code, its local network IP address, and the device model, manufacturer and Android version. These identify which screen is which, and the pairing process is built on them. We do not read the hardware MAC address, and we do not use an advertising identifier. - Device health — free and total storage, memory use, and display resolution, so an operator can tell whether a screen is failing before it goes dark.
- Screen usage measurement — for each hour: whether the screen was on, whether Opixo was the app in the foreground, whether it had internet, and whether content was playing. This is what lets an owner see that a screen in another city is actually showing their content. It records that another app was in front, never which app, and never anything about it.
- Diagnostic logs — the app's own log lines (errors, content loads, connection events), kept on the device and uploaded so support can diagnose a screen without visiting it.
- A picture of what the screen is showing — the app can capture an image of its own rendered output and send it, so an operator can confirm remotely that the right content is on screen. This happens when an operator asks for a status update, and after a command is carried out. It captures the Opixo app's own content only. It is not a continuous recording, and it does not capture other applications.
Signing in on the television
Screens are normally paired with a six-digit code and no credentials are ever typed on the television. There is also a fallback sign-in screen where an operator can enter the e-mail address and password of their Opixo Studio account instead. When that path is used, those credentials are sent to us over HTTPS to authenticate the screen. The password is not stored on the television; only the resulting access token is.
What the TV app does not collect
- No names, phone numbers or postal addresses. No e-mail address either, unless an operator chooses the fallback sign-in described above.
- No location data. The app does not request or use location permissions.
- No contacts, calendar, photos, microphone or camera access.
- No financial or payment information.
- No health data.
- No advertising identifier, and no advertising or analytics SDKs.
- No browsing history or activity in other apps.
Contact details belonging to our customers — the business signing up for Opixo Studio — are collected in the web application when an account is created, not by the television app.
Encryption in transit
Every channel between a screen and our servers is encrypted. Content, media, logs, usage
reports and configuration travel over HTTPS. The realtime messaging link a
screen uses to report that it is online and to receive operator commands — which carries
the screen's identifier, its online/offline state, and commands such as "refresh your
content", and no personal data — runs over MQTT inside a TLS WebSocket
(wss://). Each screen presents its own short-lived credential on that link,
and the server refuses connections that do not.
Until 8 September 2026 that messaging link used plaintext MQTT. It carried no personal data then either; we record the change here rather than quietly rewrite the history.
How long we keep it, and how to have it deleted
Removing a screen in Opixo Studio stops further collection immediately: the screen's credential is revoked, it is unbound from your account, and it stops reporting.
It does not, by itself, erase what was already collected. Usage history, uploaded diagnostic logs and captured screen images are retained on our systems after a screen is removed, and there is no automatic purge today. We would rather say so than imply a deletion that does not happen.
To have that retained data deleted, write to tech@amsads.in from an address associated with the account, and we will delete it and confirm when it is done. You can use the same address to ask for a copy of what we hold about your screens.
Who processes it for us
- Amazon Web Services — application servers and databases.
- Cloudflare R2 — storage and delivery of media files and app updates.
- Google Play — distribution of the Android TV app, where installed from Play.
These providers process data on our instructions in order to run the service. We do not sell data to anyone, and there are no advertising partners.
Children
Opixo is a business product. It is not directed at children and is not designed for use by them.
Changes
If this policy changes materially we will update the date below and, where the change affects existing customers, tell them directly.