L2MR Cast Privacy Policy

Effective date: September 13, 2026

Policy version: 2026-09-13.1

L2MR Cast is provided by MediaHosting Ltd. This policy describes the L2MR Cast website, mobile applications, Backend3 service, and Live Team feature for radio managers, DJs, and approved listeners. It updates the technical descriptions in our August 27 and August 29 policies. Older app versions may still link to those historical documents; this page describes current service data handling.

Station access and identity

Station controls and live production

Backend3's standard live path mixes and relays contribution audio in transient buffers and is not configured to record or archive the microphone or live mix. Audio is associated with station, show, membership, and session identities to authorize routing. Selected audio files are not uploaded merely because they were selected; starting their contribution sends the audio into the live path.

Selected files and saved playlists

Mobile files selected for a queue may be copied into private app storage. On iOS, temporary queue imports and explicitly saved playlists are separate copies, and new temporary imports require successful backup exclusion. Saved playlists remain in the device's shared station library when a temporary queue is cleared or stations are switched or removed. Deleting a saved playlist removes its app-owned copies, not the original phone files or other playlists. The current iOS version requests backup exclusion for saved playlists but does not check whether it succeeds. Saved copies may therefore remain in device backups; local deletion does not establish removal from an existing backup.

Who receives live audio

The mixed program is delivered to the source endpoint selected for the station and can then be heard by its listeners. The station owner, hosting provider, Icecast or SHOUTcast operator, downstream relay, or listeners may independently record, relay, log, or archive the stream. Their practices are outside Backend3's non-recording configuration. Contact the applicable station or hosting operator about its retention and deletion practices. L2MR Cast does not use live audio for advertising or cross-app tracking.

Safety, diagnostics, and service operations

Backend3 can store report reasons and optional details, participant blocks, manager moderation decisions, and related audit records for abuse response, security, and legal or store-policy obligations. A separately authenticated service-operator dashboard can display accounts, stations, live sessions, participant roles, and connection state. It does not reveal Centova, source, DJ, or user passwords.

Servers can receive IP address, request time, remote port, method, URI, host, User-Agent, rate-limit events, and security or error details. Application container logs rotate by size, generally up to three 10 MB files per container; this is not a guaranteed time-based retention period. Depending on platform and consent, Google advertising, consent-management, analytics, and crash-diagnostic SDKs can process device identifiers, approximate IP-derived location, app interactions, crashes, performance, and advertising data under their own policies. These SDK activities are separate from the live audio contribution.

Security and transport

Web and app account, safety, control, and Live Team connections to Backend3 use encrypted transport. The connection from Backend3 or a mobile device to a radio source is separate and may be cleartext when the selected server does not support TLS. In that case, source credentials and audio can be observed or changed in transit. L2MR Cast does not place source passwords in listener URLs or analytics events.

Server-side credential encryption keys are protected separately from credential database records. Managed PostgreSQL backups can contain encrypted credential envelopes without those key values. Full filesystem or project backups are a separate scope and may contain additional protected material. No system can guarantee absolute security. Use unique credentials and “Forget station access” when persistent Centova access is no longer needed.

Retention, deletion, and choices

Identity, Terms, show-control, safety, audit, and related service records are distinct from transient audio and can persist in PostgreSQL and backups. They support service operation, abuse prevention, security, dispute handling, and legal obligations. Expiring an authentication token or stopping output does not itself delete historical service records or the saved station profile.

A database-backup expiry policy has been approved, but enforcement and coverage of all copies are not yet fully verified. We do not promise deletion of every copy by a particular date. A deletion from the live database does not establish removal from existing backups, and backup expiry does not establish deletion of all live service or recovery records. Database backups are not a microphone or live-mix recording mechanism.

A successful server logout revokes the current session but does not delete the account or all durable records. An offline or failed logout can clear local access without confirmed server revocation. “Forget station access” removes the active remembered Centova credential, not the separate station output profile or existing backups. You may request access, correction, or deletion by emailing privacy@listen2myradio.com or admin@listen2myradio.com. We may request proof of identity and retain records required for security, legal claims, or law. A pending request is not confirmation that cleanup is complete.

You can decline microphone permission, turn availability or Ready off, return backstage, stop a broadcast, clear imported media, remove saved playlists, avoid remembered access, block another participant, or report live content. Current Terms, safety, presence, and preflight checks govern contribution admission and starting output.

User content and contact

You must have the rights needed to broadcast your microphone, music, and other content and follow the Live Audio Terms and User Policy (2026-08-26.1). Managers can mute, return backstage, or remove contributors. Live Team provides reporting and participant-blocking controls.

Privacy matters: MediaHosting Ltd., P.O. Box 3220, Acre 24132, Israel — privacy@listen2myradio.com.