Blockcast
Privacy Policy
Multicast Gateway (BEACON) is a Chrome extension and Isolated Web App (IWA) that connects Blockcast web applications to native or tunneled multicast gateways.
Effective date: August 27, 2026
Scope
This policy describes information handled by the Multicast Gateway browser extension, its IWA, and the product’s local gateway features. It does not replace the privacy policies of an identity provider, hosting provider, NOP (Network Operator Portal), orchestrator, certificate service, relay, or other service that a deployment configures.
Information the product handles
The product separates information kept on the device from information sent to a service. Depending on the features and deployment you use, it may handle:
- Browser context and routing: the extension reads the requesting tab’s URL to derive its origin, and uses tab and window identifiers to authorize and route a subscription and to open or focus the singleton IWA. The extension has access to pages through its
<all_urls>content-script permission. The setup assistant also fetches Blockcast’s public IWA update manifest and compares its release metadata with the version and immutable build revision reported by the running IWA. - Multicast and player data: a web page can provide a multicast group, source, port, transport mode, optional relay details, and player or bridge diagnostics through
window.multicast. The extension and IWA route this information and the associated multicast packets to the selected local gateway or configured relay. Packets may contain application or media content supplied by the publisher. - Extension diagnostics: the service worker keeps a bounded, session-scoped diagnostic log in Chrome storage. Entries can include timestamps, origins, tab or request identifiers, URLs, and error details emitted while the extension is running. The log is limited to 500 entries and is not an analytics or telemetry upload.
- Optional account and gateway setup: if you register a gateway, the IWA can handle an email address and verification code, access and refresh tokens, gateway name, a location address or coordinates used to derive an H3 cell, hardware/install identifier, network and gateway identifiers, tenant, and gateway JWT. If you choose Google sign-in, a Google access token is exchanged with the configured NOP.
- Local identities and certificates: the IWA creates and stores viewer and BEACON install keypairs, public-key identifiers, gateway certificates, certificate private keys, and bootstrapper credentials needed to authenticate the local gateway and bridge. Viewer and install Ed25519 private keys are stored as non-extractable WebCrypto keys. ACME account keys and bridge TLS private keys are exportable and stored locally in IndexedDB so the bridge can operate. Private key material is not intentionally sent to remote services.
- Local configuration and security state: trusted hosts, discovered bridges, H3-resolution preferences, tuner scan results, certificate-revocation cache entries, and security audit events may be stored locally. An audit event can include an origin, user, IP address, user agent, location, session ID, or event details when that information is supplied by the relevant operation.
How information is used
- to connect an authorized web page to a local IWA or gateway;
- to receive, validate, route, decode, and report multicast or tuner data;
- to authenticate and register an optional gateway and refresh its credentials;
- to validate certificates, trusted hosts, manifests, and revocation status; and
- to diagnose failures and maintain local security and operational logs.
The extension does not intentionally collect arbitrary page contents, browsing history, advertising identifiers, or a person’s activity across unrelated sites. It does not sell personal information and does not include advertising or third-party analytics SDKs.
Where information is sent
Information stays on the device when the feature only needs local routing or local diagnostics. When you use a configured network feature, the following recipients may process the corresponding information:
- NOP and Blockcast services: login, verification, Google sign-in exchange, gateway registration, token refresh, gateway identity, location, public keys, and registration signatures are sent to the NOP URL configured for the deployment.
- Bootstrapper, orchestrator, and certificate services: gateway identity material, challenge responses, certificate-signing requests, certificate data, and protocol or revocation checks may be sent to the configured endpoints.
- Configured gateways and relays: multicast packets, subscription parameters, and connection metadata are sent over the selected native, AMT, MoQ, WebTransport, or WebSocket path.
- Google: Google’s sign-in service is contacted only when you select Google login. The requested sign-in scope is
email profile. If you click the address-resolution control, the entered address is sent to Google Maps Geocoding to obtain coordinates. - Certificate and revocation endpoints: a configured certificate URL, CRL distribution point, or OCSP responder may receive certificate, hostname, and revocation-check requests.
- DNS resolver: AMT relay discovery may send a DNS-over-HTTPS query derived from the requested multicast source address or a discovered relay hostname to the configured resolver. The default resolver is Cloudflare.
- Blockcast Pages and GitHub: this policy page is served from Blockcast’s public Pages site, and the IWA update manifest and signed bundles are also published through GitHub Pages. GitHub may process requests to those sites under the GitHub Privacy Statement.
Each remote service controls its own server-side retention and use under its applicable policy or contract. This product does not define one retention period for data held by those services.
Local storage and retention
- Extension diagnostics are session-scoped and capped at 500 entries.
- The IWA security auditor uses a 90-day age setting when audit-log rotation runs; it does not continuously prune events at 90 days. The archive size is bounded.
- Certificate-revocation results are cached for one hour. The underlying OCSP cache defaults to one hour with a 24-hour maximum; the CRL cache defaults to 24 hours with a seven-day maximum.
- Authentication state, identities, keypairs, certificates, trusted-host settings, discovery state, and preferences remain in the IWA’s local storage until the applicable sign-out, reset, removal, or browser site-data action changes them.
Your choices and deletion
- Gateway registration and Google login are optional. You can choose email login instead of Google where the deployment supports it.
- Location is requested only after you explicitly use a location or address-resolution action. You can decline browser geolocation.
- You can manage trusted hosts and disconnect or unregister a gateway in the IWA controls.
- Signing out clears NOP authentication state. When the IWA’s service-stop hook succeeds, it also stops the NOP-gated connection and removes stored gateway and bootstrapper certificate artifacts. It does not automatically remove viewer/install identities, the ACME account key, audit data, revocation caches, discovery state, or preferences.
- For broader local deletion, remove the extension and clear the IWA’s Chromium app/site data. Those browser actions are the controls that remove the remaining local records and keys.
For questions or requests concerning information held by Blockcast-operated services, email support@blockcast.network. Please do not include passwords, access tokens, private keys, or other sensitive information.
Security
The IWA uses Chromium storage and WebCrypto-backed identities for local credentials and signing. Network features use HTTPS, WebTransport, WebSocket, or other configured protocols as described above. No method of storage or transmission is completely secure, so keep Chromium and the operating system updated and protect access to the device running the gateway.
Children
The product is intended for web application and gateway operators, not for children. We do not knowingly request personal information from children.
Changes to this policy
We may update this policy when the product’s data handling changes. The effective date at the top of this page identifies the current version.