Last updated 20 September 2026
Stream Director ("we", "us", or "our") operates the Stream Director service. This policy describes how we collect, use, and protect your information.
Account information. When you register, we collect your email address, display name, and a hashed password. We never store your password in plain text.
YouTube & Twitch data. If you connect an account, we store encrypted OAuth access/refresh tokens and the platform data needed to provide the integration. For YouTube this includes channel/broadcast identifiers and live-chat data, and the authorization can also be used for the posting and moderation actions you explicitly initiate or enable.
Stream session data. During active ingestion we store chat messages and related moderation/display metadata needed to operate Stream Director. YouTube API data is subject to a maximum 30-calendar-day lifecycle regardless of subscription plan. Non-YouTube Stream Director data may be retained for the session-history period included with your plan.
Billing information. Payments are processed by Stripe. We do not store your card number or payment details. We store a Stripe customer reference ID to link your account to your subscription.
Technical data. We collect standard server logs including IP addresses and request timestamps for security and debugging purposes. These are retained for 30 days.
Stream Director uses YouTube API Services provided by Google. By connecting your YouTube account, you also agree to Google's Privacy Policy. This section explains exactly how we interact with YouTube data. Before Stream Director redirects a workspace Owner to Google OAuth, it displays its own consent page describing the requested scopes, data use, manual YouTube actions, automatic moderation controls, and data lifecycle, and requires an explicit confirmation.
Stream Director requests access to your YouTube account using the
https://www.googleapis.com/auth/youtube.readonly and https://www.googleapis.com/auth/youtube.force-ssl
OAuth scopes. These scopes allow Stream Director to read the data listed below and to perform the live-chat posting/deletion actions that you explicitly initiate or separately enable:
liveChatMessages.list API endpointYou can revoke Stream Director's access to your YouTube account at any time through either of these methods:
You can also use Delete stored YouTube data on the YouTube page without disconnecting. This deletes Stream Director's locally stored YouTube API data and does not delete content stored by YouTube. Account deletion also removes data associated with the account and revokes any YouTube grant authorised by that account.
Stream Director's use of YouTube API Services complies with the YouTube API Services Terms of Service and YouTube API Developer Policies. We do not sell, transfer, or use YouTube data for advertising, user profiling, or any purpose beyond providing the Stream Director service to the authenticated user.
By using YouTube features in Stream Director, your use is also subject to Google's Privacy Policy. Stream Director is not affiliated with Google or YouTube.
We do not sell your personal data. We share data only with:
Team members you invite to your workspace can see messages in your show queue and overlay history. Workspace owners control who has access.
YouTube API data: raw and identifying YouTube API data is retained only as long as needed to provide the service and for no longer than 30 calendar days unless refreshed as permitted by YouTube policy. Stream Director runs an automated lifecycle process at least every six hours and uses a 29-day scheduled purge threshold to maintain a safety margin below the 30-day policy ceiling. It also periodically reconfirms authorization.
Other session data: non-YouTube Stream Director session history may be retained for the period specified by your subscription plan (7 days on Free, up to 5 years on Agency).
Revocation: when you disconnect YouTube in Stream Director, we programmatically revoke the Google OAuth grant and delete the locally stored YouTube API data immediately. If Google-side revocation is detected during periodic authorization checks, the associated YouTube API data is deleted as soon as detected.
Billing records are retained for 7 years for legal and financial compliance.
You have the right to access, correct, or delete your personal data at any time. Most of this is self-service through your Account Settings page. For requests that can't be handled in-app, contact us at the address below.
If you are located in the European Economic Area, you have additional rights under the GDPR including the right to data portability and the right to lodge a complaint with your local supervisory authority.
We use industry-standard security practices including encrypted storage of OAuth tokens, hashed passwords, HTTPS for all data in transit, and role-based access controls. No system is perfectly secure — if you discover a security issue, please disclose it responsibly by contacting us directly.
We use only essential cookies: a session cookie to keep you signed in, and an anti-forgery token cookie for form security. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect. Continued use of Stream Director after changes are effective constitutes acceptance of the updated policy.
For privacy questions or data requests, contact us at privacy@streamdirector.app.