L2MR Cast Privacy Policy
Effective date: August 29, 2026
Policy version: 2026-08-29.1
L2MR Cast is provided by MediaHosting Ltd. This policy describes the L2MR Cast website, mobile applications, Backend3 service, and optional Live Team feature for radio managers, DJs, and approved listeners.
Data used to provide L2MR Cast
- Station and account data. L2MR Cast uses station addresses, account identifiers, display names, roles, and the credentials supplied by you or your radio provider. Mobile credentials can be kept in device-protected storage. Web authentication uses secure, HTTP-only cookies; access or refresh tokens and radio credentials are not placed in browser storage. Appearance and language preferences may be saved locally in the browser.
-
Radio-manager verification. A radio manager can sign in with an approved
Centova provider. The browser sends the selected provider key, username, and administrator
password to Backend3 over TLS. Backend3 sends the credentials as form fields over TLS only
to that provider's exact approved and network-pinned
/api.phpendpoint forserver.authenticateandserver.getaccount. Redirects, arbitrary URLs, and private or unapproved network addresses are rejected. - Optional remembered Centova access. When the manager deliberately selects “Keep this station connected,” Backend3 encrypts the verified Centova username and password with AES-256-GCM before storing the encrypted envelope in PostgreSQL. Associated data binds it to the exact station, owner, provider, and verified provider subjects. The browser, DJs, listeners, and service operator dashboard cannot retrieve the plaintext or encrypted envelope. Backend3 decrypts it only in memory when the manager requests station information or a station control through the protected broker. Choosing “Forget station access” deletes the encrypted copy. Reconnecting replaces the previous copy. If remembering is not selected, the credential is used only for verification and is discarded from application memory after that request.
- DJ and listener pairing. A radio manager creates a single-use, role-bound, expiring code. The invited person supplies that code and a display name; they do not receive or enter the station's Centova credential. Backend3 stores a keyed digest rather than the plaintext code and assigns the station and role chosen by the manager.
- Live Team and show data. Backend3 stores user, station, membership, device, authentication-session, presence, readiness, consent, preflight, show, routing, gain, mute, on-air, Terms-acceptance, moderation, and security-audit records needed to operate and protect a show. Some Redis live-state copies expire; related PostgreSQL records are durable and do not currently have a complete automatic purge schedule.
- Station-management data. For a remembered manager connection, Backend3 can retrieve Centova status, public station configuration, listener sessions, recent-song text, playlists, and DJ-account settings. The manager may request audited server, AutoDJ, playlist, DJ-account, or public-configuration changes. Provider responses are filtered before reaching the browser. Source passwords, Centova passwords, DJ passwords, raw provider responses, song titles, and listener details are excluded from broker audit metadata.
- Live audio and selected files. Direct mobile broadcasts send encoded audio to the station source selected by the manager. Live Team sends authorized microphone or selected-playlist audio through an encrypted media connection to Backend3, where permitted sources are mixed and relayed to the configured station. L2MR Cast and Backend3 do not intentionally record or archive microphone audio or the live mix. Selected device files may be copied to private app storage for an active queue and are not uploaded merely because they were selected. Browser microphone contribution remains disabled unless the deployment passes its isolated-media safety checks.
- Safety and operator data. Backend3 can store reports, optional report details, participant blocks, owner moderation decisions, and related audit records. A separately authenticated service-operator dashboard can display accounts, stations, live sessions, and participant roles and connection state for service operations, security, and abuse response. It does not reveal Centova, source, DJ, or user passwords.
- Technical and diagnostic data. Servers can receive IP address, request time, remote port, method, URI, host, User-Agent, rate-limit events, and security or error details. Container access logs rotate by size, with up to three 10 MB files per container; this is not a guaranteed time-based retention period. Depending on platform and consent, Google advertising, consent-management, analytics, and crash-diagnostic SDKs can process device identifiers, approximate IP-derived location, app interactions, crashes, performance, and advertising data under their own policies.
Who receives live audio
Live audio is delivered to the source endpoint selected for the station and can then be heard by that station's listeners. The station owner, hosting provider, Icecast or SHOUTcast operator, or downstream relay may log, relay, record, or archive the stream under its own policy. Contact the applicable station or hosting operator about its retention and deletion practices. L2MR Cast does not use live audio for advertising or cross-app tracking.
Security and transport
Web and app account, safety, control, and Live Team connections to Backend3 use encrypted transport. The connection from Backend3 or a mobile device to a selected radio source is a separate connection and may be cleartext when a legacy Icecast or SHOUTcast server does not support TLS. In that case, source credentials and audio can be observed or changed in transit. L2MR Cast does not place source passwords in listener URLs or analytics events.
Remembered Centova credentials are protected by a server-held encryption key stored separately from the database. Loss of that key makes the encrypted copy unrecoverable. Backups can contain encrypted Centova credential envelopes but not the encryption key when the documented separate backup procedure is followed. No system can guarantee absolute security; use a unique Centova password and choose “Forget station access” when persistent access is no longer needed.
Retention, deletion, and choices
Real-time audio buffers exist only for delivery and are not intentionally written to a Backend3 recording or archive. Account, membership, Terms, show-control, safety, report, block, audit, and encrypted remembered-connection records are retained for service operation, abuse prevention, security, dispute handling, and legal obligations. Full PostgreSQL backups can contain this non-audio data. An approved complete backup-retention and deletion schedule has not yet been finalized, so deletion from the live database may not immediately remove existing backup copies.
Logging out revokes the current web session but does not delete the account or its durable records. Radio managers can delete a remembered Centova credential with “Forget station access.” You may request access, correction, or deletion by emailing privacy@listen2myradio.com or admin@listen2myradio.com. We may request proof of identity and may retain records required for security, legal claims, or law.
You can decline microphone permission, keep Live Team availability or Ready off, return backstage, stop a broadcast, clear imported media, avoid or delete remembered Centova access, block another participant, or report live content. Escalating a participant or starting output is blocked when current Terms, safety, presence, or preflight checks are not satisfied.
User content and acceptable use
Users must have the rights needed to broadcast microphone, music, and other content and must follow the current Live Audio Terms and User Policy (version 2026-08-26.1). Radio managers can mute, return backstage, or remove contributors, and Live Team provides report and participant-blocking controls.
Contact
Privacy matters: MediaHosting Ltd., P.O. Box 3220, Acre 24132, Israel — privacy@listen2myradio.com.