Privacy-First IPTV Playlist Editor

M3U playlists contain sensitive subscription hashes. Exposing these tokens can lead to account bans or stolen credentials. A private editor is mandatory.

Local file processing boundary

When you select a local file, FileReader loads its text into browser memory. Editing, analysis, comparison, conversion, and export happen in that client-side workspace, and the playlist is not intentionally posted to an M3U Studio application server. Refreshing the page clears the in-memory playlist unless you downloaded an export.

Import by URL is not purely offline: the browser requests the supplied address. The stream checker also requests each tested URL. The destination servers can observe normal connection data, so do not test or import URLs you are not authorized to use.

Block Dangerous Protocols

Our editor sanitizes incoming links and blocks unsafe injection protocols (like javascript: or file:), protecting your device from local exploits.

Security Auditing Guidelines

Separate playlist handling from the surrounding website. M3U Studio includes Google Analytics and Google AdSense code, and the hosting platform may retain access/security logs. The Privacy Policy explains those services. The application does not intentionally send locally parsed playlist contents to them for analytics or advertising.

Safely Storing Local State

The playlist workspace is held in browser memory and is discarded on refresh. Theme and language choices are saved in localStorage. To preserve playlist changes, export a new file before closing or refreshing the tab; keep the original separately so cleanup operations are reversible.

Threat model for a browser editor

Local parsing reduces one risk: sending the complete file to an application server. It does not protect a compromised device, browser extension, destination host, or copied export. Website scripts and network tools also create a broader data boundary than the in-memory editor alone.

Use a trusted browser profile, avoid sharing screenshots containing tokens, prefer local-file selection over URL import when possible, and rotate exposed credentials through the legitimate provider.

Frequently Asked Questions

Can other users see the files I upload?

No, because the files are parsed locally on your device and are never sent to a database.

Do URL imports stay entirely local?

No. Your browser must contact the supplied host to retrieve the URL, and that host may log the request. M3U Studio does not intentionally store the imported playlist as application data.

Interactive Tool Workspace