Stream Director

Last updated 20 September 2026

Privacy Policy

Stream Director ("we", "us", or "our") operates the Stream Director service. This policy describes how we collect, use, and protect your information.

1. Information we collect

Account information. When you register, we collect your email address, display name, and a hashed password. We never store your password in plain text.

YouTube & Twitch data. If you connect an account, we store encrypted OAuth access/refresh tokens and the platform data needed to provide the integration. For YouTube this includes channel/broadcast identifiers and live-chat data, and the authorization can also be used for the posting and moderation actions you explicitly initiate or enable.

Stream session data. During active ingestion we store chat messages and related moderation/display metadata needed to operate Stream Director. YouTube API data is subject to a maximum 30-calendar-day lifecycle regardless of subscription plan. Non-YouTube Stream Director data may be retained for the session-history period included with your plan.

Billing information. Payments are processed by Stripe. We do not store your card number or payment details. We store a Stripe customer reference ID to link your account to your subscription.

Technical data. We collect standard server logs including IP addresses and request timestamps for security and debugging purposes. These are retained for 30 days.

🎬

YouTube API Services — Specific Disclosures

Stream Director uses YouTube API Services provided by Google. By connecting your YouTube account, you also agree to Google's Privacy Policy. This section explains exactly how we interact with YouTube data. Before Stream Director redirects a workspace Owner to Google OAuth, it displays its own consent page describing the requested scopes, data use, manual YouTube actions, automatic moderation controls, and data lifecycle, and requires an explicit confirmation.

What data we access from YouTube

Stream Director requests access to your YouTube account using the https://www.googleapis.com/auth/youtube.readonly and https://www.googleapis.com/auth/youtube.force-ssl OAuth scopes. These scopes allow Stream Director to read the data listed below and to perform the live-chat posting/deletion actions that you explicitly initiate or separately enable:

  • Live chat messages — read in real time from your active YouTube Live broadcasts using the liveChatMessages.list API endpoint
  • Live broadcast information — the title and ID of your current or scheduled live broadcasts, used to let you select which broadcast to monitor
  • Channel information — your channel name and ID, used solely to identify your account within Stream Director

What we do NOT access

  • We do not read, access, or store your YouTube videos, playlists, subscriptions, or account settings
  • We do not upload, edit, or delete your YouTube videos, playlists, subscriptions, captions, ratings, or general account settings through Stream Director
  • We do not perform unrelated YouTube account-management actions outside the live-chat management features described below

Live-chat actions we perform on your behalf

  • Posting — authorised workspace users can post messages and saved announcements to the connected YouTube Live Chat from Stream Director.
  • Moderation deletion — when an authorised workspace user chooses Delete from YouTube for a YouTube message in Stream Director, Stream Director requests deletion of that message from YouTube Live Chat.
  • Automatic moderation — blocked messages can be automatically deleted from YouTube only when the Workspace Owner explicitly enables the automatic YouTube deletion setting. It is disabled by default.
  • These actions use the authorisation granted by the owner of the connected YouTube channel. Workspace owners control which team members are authorised to operate the Director Console.

How YouTube data is stored

  • OAuth tokens — your access token and refresh token are encrypted using ASP.NET Data Protection and stored in our database. They are never logged or transmitted to third parties.
  • Live chat messages — while YouTube ingestion is active, Stream Director stores the live-chat messages returned by the YouTube API so they can be moderated, queued, searched, displayed, and processed by enabled rules. Raw and identifying YouTube API data is automatically deleted after a maximum of 30 calendar days.
  • Broadcast metadata — the title and ID of your connected broadcast is stored while ingestion is active and cleared when you stop or disconnect.

Data deletion and revocation

You can revoke Stream Director's access to your YouTube account at any time through either of these methods:

  • Within Stream Director — go to the YouTube page and click Disconnect & revoke access. Stream Director programmatically revokes the Google OAuth grant, stops ingestion, deletes stored OAuth tokens, and deletes locally stored YouTube API data.
  • Via Google — visit myaccount.google.com/permissions, find Stream Director, and click Remove Access. This revokes our OAuth tokens at the Google level.

You can also use Delete stored YouTube data on the YouTube page without disconnecting. This deletes Stream Director's locally stored YouTube API data and does not delete content stored by YouTube. Account deletion also removes data associated with the account and revokes any YouTube grant authorised by that account.

YouTube API Terms compliance

Stream Director's use of YouTube API Services complies with the YouTube API Services Terms of Service and YouTube API Developer Policies. We do not sell, transfer, or use YouTube data for advertising, user profiling, or any purpose beyond providing the Stream Director service to the authenticated user.

Google Privacy Policy

By using YouTube features in Stream Director, your use is also subject to Google's Privacy Policy. Stream Director is not affiliated with Google or YouTube.

3. How we use your information

  • To provide, operate, and maintain the Stream Director service
  • To authenticate you and manage your account and workspace
  • To process subscription payments via Stripe
  • To send transactional emails such as team invitations (no marketing emails without your consent)
  • To detect and prevent abuse, spam, and security incidents
  • To improve the service based on aggregated, anonymised usage patterns

4. Data sharing

We do not sell your personal data. We share data only with:

  • Stripe — for payment processing. Subject to Stripe's privacy policy.
  • Google / YouTube — OAuth authorization and the YouTube Data API to discover your broadcasts, ingest live chat, and carry out the posting/deletion actions you authorise.
  • Twitch — OAuth authentication and chat integration using Twitch APIs.
  • Anthropic — when AI classification is enabled and included in your plan, Stream Director sends the chat message text and platform identifier needed to classify that message. Anthropic does not receive your Google OAuth tokens from Stream Director.
  • Law enforcement — only when required by law or valid legal process.

Team members you invite to your workspace can see messages in your show queue and overlay history. Workspace owners control who has access.

5. Data retention

YouTube API data: raw and identifying YouTube API data is retained only as long as needed to provide the service and for no longer than 30 calendar days unless refreshed as permitted by YouTube policy. Stream Director runs an automated lifecycle process at least every six hours and uses a 29-day scheduled purge threshold to maintain a safety margin below the 30-day policy ceiling. It also periodically reconfirms authorization.

Other session data: non-YouTube Stream Director session history may be retained for the period specified by your subscription plan (7 days on Free, up to 5 years on Agency).

Revocation: when you disconnect YouTube in Stream Director, we programmatically revoke the Google OAuth grant and delete the locally stored YouTube API data immediately. If Google-side revocation is detected during periodic authorization checks, the associated YouTube API data is deleted as soon as detected.

Billing records are retained for 7 years for legal and financial compliance.

6. Your rights

You have the right to access, correct, or delete your personal data at any time. Most of this is self-service through your Account Settings page. For requests that can't be handled in-app, contact us at the address below.

If you are located in the European Economic Area, you have additional rights under the GDPR including the right to data portability and the right to lodge a complaint with your local supervisory authority.

7. Security

We use industry-standard security practices including encrypted storage of OAuth tokens, hashed passwords, HTTPS for all data in transit, and role-based access controls. No system is perfectly secure — if you discover a security issue, please disclose it responsibly by contacting us directly.

8. Cookies

We use only essential cookies: a session cookie to keep you signed in, and an anti-forgery token cookie for form security. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Changes to this policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect. Continued use of Stream Director after changes are effective constitutes acceptance of the updated policy.

10. Contact

For privacy questions or data requests, contact us at privacy@streamdirector.app.