Privacy Policy
Last updated: July 30, 2026
1. What we collect
When you create a TeraPlay account, we collect your email address, a securely hashed version of your password, and an optional display name. If you add an xAPIverse API key, it is encrypted before being stored and is never shown back to you or anyone else in full — only a masked preview.
We also store the TeraBox links you resolve, basic file metadata returned by the resolver (name, duration, quality, thumbnail), and your watch progress, favourites, saved items, and folders, so your library works across sessions.
2. How we use it
Your data is used solely to operate your account: authenticating you, resolving links on your behalf using your own API key, and keeping your history and library in sync. We do not sell your data or use it for advertising.
3. Third-party processors
To resolve TeraBox links, your request (using your own encrypted, decrypted-in-memory-only API key) is sent to xAPIverse's TeraBox Pro API. Review xAPIverse's own privacy practices at their site for details on how they process that request. Our hosting provider and database processor may also incidentally process data as part of running the service.
4. Your rights
You can update or remove your API key at any time from your Profile page. To request deletion of your account and all associated data, use the Contact page.
5. Security
Passwords are hashed with bcrypt. API keys are encrypted at rest with AES-256-GCM. All traffic should be served over HTTPS in production.
6. Changes
We may update this policy from time to time. Continued use of TeraPlay after changes constitutes acceptance of the updated policy.