L2MR Cast Privacy Policy

Effective date: August 27, 2026

Policy version: 2026-08-27.2

L2MR Cast is provided by MediaHosting Ltd. This policy explains the data used by the L2MR Cast mobile applications, including direct Icecast/SHOUTcast broadcasting and the optional Live Team feature for radio owners, DJs, and approved listeners.

Data used to provide the service

Who receives live audio

Live audio is delivered to the radio source endpoint selected by the station and can then be heard by that station's listeners. The radio owner, hosting provider, Icecast/SHOUTcast operator, or downstream relay may log, relay, record, or archive a stream under its own policy. Contact the applicable station or hosting operator for its retention and deletion practices. L2MR Cast does not use live audio for advertising or cross-app tracking.

Security and transport

Connections from the app to Backend3 for account, safety, and Live Team media use encrypted transport. The later connection from Backend3 to the configured radio source is separate and may be cleartext. When a Backend3 output profile has TLS disabled, its source username and password and the mixed audio are transmitted from Backend3 to that station without transport encryption. The current Backend3 demo Icecast, SHOUTcast 1, and SHOUTcast 2 output profiles are configured without TLS.

Passwordless owner verification is disabled by default. When enabled, Backend3 accepts only the 12 fixed Listen2MyRadio panel hosts configured by the operator, requires the complete current public A and AAAA address sets to match reviewed pins, validates the TLS hostname, pins the chosen network address, accepts no client-supplied URL, and follows no redirect. Private, loopback, link-local, documentation, benchmark, multicast, malformed, or unapproved addresses are rejected. This flow means Backend3 briefly receives the Centova administrator password during each owner verification. It never requests or stores the station source password as part of Live Team authentication.

Some legacy Centova, Icecast, or SHOUTcast servers selected for direct broadcasting also support only cleartext HTTP/source connections. The app identifies cleartext source transport before a direct broadcast and requires explicit approval because credentials and audio could otherwise be observed or changed in transit. L2MR Cast does not place source passwords in listener URLs or analytics events.

Retention, deletion, and choices

Live audio handled by Backend3 is processed for real-time delivery and is not intentionally written to a recording or archive by Backend3; transient media buffers exist only for delivery. Account, membership, Terms, show-control, safety, report, block, and audit records are retained for service operation, abuse prevention, security, dispute handling, and legal obligations.

Full PostgreSQL backups contain non-audio account, membership, Terms, show-control, safety, report, block, and audit data. They do not intentionally contain microphone audio or the live mix. These backups are access-controlled, but an approved retention and deletion schedule has not yet been finalized; a deletion request may therefore not immediately remove data from existing backup copies.

Backend3 currently has no account-deletion API or automatic purge worker. Logging out revokes the current session but does not delete durable expired or revoked session rows or other account records. A database operator view can identify records that could be deletion candidates, but live retention timestamps are unset and no manual deletion execution process has been verified. Changing or deleting a stored station output credential requires manual replacement of its access-controlled secret bundle. You may request access, correction, or deletion by emailing privacy@listen2myradio.com or admin@listen2myradio.com. We may request proof of identity and may retain records that are required for security, legal claims, or law.

You can decline microphone permission, keep Live Team availability off, leave Ready off, return backstage, stop a broadcast, clear imported media, disable remembered source passwords, block another participant, or report live content. Escalating a participant or starting output is blocked when current Terms, safety, presence, or preflight checks are not satisfied.

User content and acceptable use

Users must have the rights needed to broadcast microphone, music, and other content and must follow the current Live Audio Terms and User Policy (version 2026-08-26.1). Report and participant-blocking controls are available in Live Team. Radio owners can mute, return backstage, or remove contributors.

Contact

Privacy matters: MediaHosting Ltd., P.O. Box 3220, Acre 24132, Israel — privacy@listen2myradio.com.