STREAM DIRECTOR

Last updated 27 July 2026

Privacy Policy

Stream Director ("we", "us", or "our") operates the Stream Director service. This policy describes how we collect, use, and protect your information.

1. Information we collect

Account information. When you register, we collect your email address, display name, and a hashed password. We never store your password in plain text.

YouTube & Twitch data. If you connect a YouTube or Twitch account, we store OAuth access tokens (encrypted) to read your live chat. We do not store full chat histories beyond what is shown in your session history, and we never access your account beyond what is necessary to read live chat messages from your own broadcasts.

Stream session data. We record anonymised statistics about your stream sessions — message counts, duration, and engagement metrics. We store the text of chat messages you choose to display on screen for the duration of your plan's session history retention period.

Billing information. Payments are processed by Stripe. We do not store your card number or payment details. We store a Stripe customer reference ID to link your account to your subscription.

Technical data. We collect standard server logs including IP addresses and request timestamps for security and debugging purposes. These are retained for 30 days.

🎬

YouTube API Services — Specific Disclosures

Stream Director uses YouTube API Services provided by Google. By connecting your YouTube account, you also agree to Google's Privacy Policy. This section explains exactly how we interact with YouTube data.

What data we access from YouTube

Stream Director requests access to your YouTube account using the https://www.googleapis.com/auth/youtube.readonly OAuth scope. This grants read-only access. We access only the following:

  • Live chat messages — read in real time from your active YouTube Live broadcasts using the liveChatMessages.list API endpoint
  • Live broadcast information — the title and ID of your current or scheduled live broadcasts, used to let you select which broadcast to monitor
  • Channel information — your channel name and ID, used solely to identify your account within Stream Director

What we do NOT access

  • We do not read, access, or store your YouTube videos, playlists, subscriptions, or account settings
  • We do not post comments, messages, or any content to YouTube on your behalf
  • We do not modify or delete any data on your YouTube account
  • We do not access any YouTube data beyond what is necessary to read live chat from your own broadcasts

How YouTube data is stored

  • OAuth tokens — your access token and refresh token are encrypted using ASP.NET Data Protection and stored in our database. They are never logged or transmitted to third parties.
  • Live chat messages — messages you choose to display on screen are stored in your session history for the duration of your plan's retention period (7 days on Free, up to 5 years on Agency). Messages you do not select are not stored.
  • Broadcast metadata — the title and ID of your connected broadcast is stored while ingestion is active and cleared when you stop or disconnect.

Data deletion and revocation

You can revoke Stream Director's access to your YouTube account at any time through either of these methods:

  • Within Stream Director — go to the YouTube page in your account and click Disconnect channel. This immediately deletes your stored OAuth tokens and stops all data ingestion.
  • Via Google — visit myaccount.google.com/permissions, find Stream Director, and click Remove Access. This revokes our OAuth tokens at the Google level.

To delete all your data including stored chat history, delete your Stream Director account from Account Settings → Danger Zone → Delete my account. All your data including any YouTube chat history is permanently and irreversibly deleted within 24 hours.

YouTube API Terms compliance

Stream Director's use of YouTube API Services complies with the YouTube API Services Terms of Service and YouTube API Developer Policies. We do not sell, transfer, or use YouTube data for advertising, user profiling, or any purpose beyond providing the Stream Director service to the authenticated user.

Google Privacy Policy

By using YouTube features in Stream Director, your use is also subject to Google's Privacy Policy. Stream Director is not affiliated with Google or YouTube.

3. How we use your information

  • To provide, operate, and maintain the Stream Director service
  • To authenticate you and manage your account and workspace
  • To process subscription payments via Stripe
  • To send transactional emails such as team invitations (no marketing emails without your consent)
  • To detect and prevent abuse, spam, and security incidents
  • To improve the service based on aggregated, anonymised usage patterns

4. Data sharing

We do not sell your personal data. We share data only with:

  • Stripe — for payment processing. Subject to Stripe's privacy policy.
  • Google / YouTube — OAuth authentication only, using the YouTube Data API.
  • Twitch — OAuth authentication only, using the Twitch EventSub API.
  • Law enforcement — only when required by law or valid legal process.

Team members you invite to your workspace can see messages in your show queue and overlay history. Workspace owners control who has access.

5. Data retention

Session history is retained for the period specified by your subscription plan (7 days on Free, up to 5 years on Agency). You can delete your account at any time from Account Settings, which permanently removes all your data.

OAuth tokens are deleted immediately when you disconnect a YouTube or Twitch channel.

Billing records are retained for 7 years for legal and financial compliance.

6. Your rights

You have the right to access, correct, or delete your personal data at any time. Most of this is self-service through your Account Settings page. For requests that can't be handled in-app, contact us at the address below.

If you are located in the European Economic Area, you have additional rights under the GDPR including the right to data portability and the right to lodge a complaint with your local supervisory authority.

7. Security

We use industry-standard security practices including encrypted storage of OAuth tokens, hashed passwords, HTTPS for all data in transit, and role-based access controls. No system is perfectly secure — if you discover a security issue, please disclose it responsibly by contacting us directly.

8. Cookies

We use only essential cookies: a session cookie to keep you signed in, and an anti-forgery token cookie for form security. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Changes to this policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect. Continued use of Stream Director after changes are effective constitutes acceptance of the updated policy.

10. Contact

For privacy questions or data requests, contact us at privacy@streamdirector.app.