L2MR Cast Privacy Policy
Effective date: August 27, 2026
Policy version: 2026-08-27.2
L2MR Cast is provided by MediaHosting Ltd. This policy explains the data used by the L2MR Cast mobile applications, including direct Icecast/SHOUTcast broadcasting and the optional Live Team feature for radio owners, DJs, and approved listeners.
Data used to provide the service
- Station and account data. The app uses the station address, account identifier, role, and credentials supplied by you or your radio provider. Saved app credentials are kept in device-protected storage. Source passwords are remembered only when you choose that option.
- Live Team account and production data. Backend3 stores the email address, display name, password hash, user and station identifiers, membership role and status, device and authentication-session identifiers, session expiry and revocation records, refresh and invitation token digests, and request or idempotency digests. It also stores show state, routing commands, participant and presence timestamps, microphone consent, detailed preflight results, Ready and on-air times, Terms acceptance, and security audit events needed to authenticate users and operate a show. Redis copies of some live state expire, but these PostgreSQL records are durable and currently have no automatic purge schedule.
-
Passwordless Live Team verification. If the optional passwordless owner
exchange is enabled, the app sends the current Centova panel username and administrator
password over TLS to Backend3 solely to verify that the current user owns that station.
Backend3 transmits those credentials as form fields over TLS only to the exact
Listen2MyRadio Centova
/api.phporigin selected by the saved station: first forserver.authenticate, then forserver.getaccount. The documented Centova API does not provide a signed owner assertion. The credentials therefore exist transiently in Backend3 memory and outbound request bodies, are excluded from PostgreSQL, files, audit metadata, and application logs, and are discarded after the verification attempt. Backend3 stores the provider key, identifiers derived from the authoritative Centova username, station title, verification time, a random installation identifier, and keyed digests of device/session secrets. DJs and approved listeners instead use a manager-created, single-use, role-bound code and display name; the plaintext code is not stored. The reserved@identity.invalidaddress used internally for a new passwordless identity is not a real contact address. - Live Team output profile. To send the Backend3 mix to a station, an output profile can contain the source server address, protocol, port or mount, source username, and source password. The profile is stored server-side in an access-controlled host secret file mounted only into the media-egress service; it is not stored in PostgreSQL. Backend3 uses it to establish the station output selected by the radio owner.
- Microphone audio. Microphone access begins only after permission and an explicit in-app consent. Direct broadcasts send encoded audio to the source server chosen for the station. Live Team sends microphone audio over an encrypted WebRTC connection to Backend3, where it is associated in real time with station, show, membership, and authentication-session identities needed to authorize routing, then mixed and sent to the configured station output. L2MR Cast and Backend3 do not intentionally record or archive microphone audio or the live mix.
- Selected music and audio files. Files chosen for a direct broadcast may be copied into private app storage for the active queue, excluded from device backup, and removed when the queue or Go Live context is cleared, the account changes, or the app is deleted. The encoded program is transmitted to the configured station source server.
- Safety information. Live Team can store report reasons and optional report details, participant blocks, owner moderation decisions, and related audit records. These records protect users, investigate abuse, and meet legal or store-policy obligations.
- Technical and diagnostic data. Servers can receive IP address, request time, remote port, request method, URI, host, User-Agent, and security or error details. Backend3 container access logs rotate by size, with up to three 10 MB files per container; this is not a guaranteed time-based retention period. Depending on platform and consent, Google advertising, consent-management, analytics, and crash-diagnostic SDKs can process device identifiers, approximate IP-derived location, app interactions, crashes, performance, and advertising data under their own policies.
Who receives live audio
Live audio is delivered to the radio source endpoint selected by the station and can then be heard by that station's listeners. The radio owner, hosting provider, Icecast/SHOUTcast operator, or downstream relay may log, relay, record, or archive a stream under its own policy. Contact the applicable station or hosting operator for its retention and deletion practices. L2MR Cast does not use live audio for advertising or cross-app tracking.
Security and transport
Connections from the app to Backend3 for account, safety, and Live Team media use encrypted transport. The later connection from Backend3 to the configured radio source is separate and may be cleartext. When a Backend3 output profile has TLS disabled, its source username and password and the mixed audio are transmitted from Backend3 to that station without transport encryption. The current Backend3 demo Icecast, SHOUTcast 1, and SHOUTcast 2 output profiles are configured without TLS.
Passwordless owner verification is disabled by default. When enabled, Backend3 accepts only the 12 fixed Listen2MyRadio panel hosts configured by the operator, requires the complete current public A and AAAA address sets to match reviewed pins, validates the TLS hostname, pins the chosen network address, accepts no client-supplied URL, and follows no redirect. Private, loopback, link-local, documentation, benchmark, multicast, malformed, or unapproved addresses are rejected. This flow means Backend3 briefly receives the Centova administrator password during each owner verification. It never requests or stores the station source password as part of Live Team authentication.
Some legacy Centova, Icecast, or SHOUTcast servers selected for direct broadcasting also support only cleartext HTTP/source connections. The app identifies cleartext source transport before a direct broadcast and requires explicit approval because credentials and audio could otherwise be observed or changed in transit. L2MR Cast does not place source passwords in listener URLs or analytics events.
Retention, deletion, and choices
Live audio handled by Backend3 is processed for real-time delivery and is not intentionally written to a recording or archive by Backend3; transient media buffers exist only for delivery. Account, membership, Terms, show-control, safety, report, block, and audit records are retained for service operation, abuse prevention, security, dispute handling, and legal obligations.
Full PostgreSQL backups contain non-audio account, membership, Terms, show-control, safety, report, block, and audit data. They do not intentionally contain microphone audio or the live mix. These backups are access-controlled, but an approved retention and deletion schedule has not yet been finalized; a deletion request may therefore not immediately remove data from existing backup copies.
Backend3 currently has no account-deletion API or automatic purge worker. Logging out revokes the current session but does not delete durable expired or revoked session rows or other account records. A database operator view can identify records that could be deletion candidates, but live retention timestamps are unset and no manual deletion execution process has been verified. Changing or deleting a stored station output credential requires manual replacement of its access-controlled secret bundle. You may request access, correction, or deletion by emailing privacy@listen2myradio.com or admin@listen2myradio.com. We may request proof of identity and may retain records that are required for security, legal claims, or law.
You can decline microphone permission, keep Live Team availability off, leave Ready off, return backstage, stop a broadcast, clear imported media, disable remembered source passwords, block another participant, or report live content. Escalating a participant or starting output is blocked when current Terms, safety, presence, or preflight checks are not satisfied.
User content and acceptable use
Users must have the rights needed to broadcast microphone, music, and other content and must follow the current Live Audio Terms and User Policy (version 2026-08-26.1). Report and participant-blocking controls are available in Live Team. Radio owners can mute, return backstage, or remove contributors.
Contact
Privacy matters: MediaHosting Ltd., P.O. Box 3220, Acre 24132, Israel — privacy@listen2myradio.com.