STREAMSAFE · LEGAL
Privacy Policy
Effective September 6, 2026 · Version 2026-09-06
Your video buffer stays local. Account, licensing, billing, and operational information support the service.
1. Scope and responsibility
This Privacy Policy explains how StreamSafe, the operator of streamsafe.io and its desktop application, handles personal information. It describes data practices; it is not a waiver of privacy rights or liability. The Service is intended for adults 18 and older. If you believe a child has provided information, contact us so we can investigate and take appropriate action.
2. Account, sign-in, and payment information
We process your email address, account identifier, verification status, and authentication and session information. Amazon Cognito handles account authentication. If you choose a social login, the provider shares identifiers and authorized profile information, such as an email address or display name. StreamSafe does not receive the password for your social account. Some provider connections use our server to exchange temporary authorization codes and retrieve your profile.
Stripe processes subscription payments. We associate your account with Stripe customer and subscription identifiers, billing status, access period, and relevant payment events. Payment information you enter in Stripe checkout is handled by Stripe; our application does not store your full payment-card number. Information you voluntarily send in a support or privacy request is also processed to respond.
3. Desktop configuration, video, and activity reports
Video is buffered locally on your computer and sent from that computer to destinations you configure. Our account service is not designed to receive or store your video or audio. Local buffer files can remain until cleaned up; StreamSafe does not promise secure erasure or recovery. Your streaming destinations independently receive and process the content you send.
Broadcast configuration, including destination URLs and stream keys, is sent over HTTPS to our licensing API to validate settings and issue a signed authorization ticket. License validation does not intentionally persist those destination credentials in the account database or application logs. If you connect Twitch or Kick as an output, our server exchanges a temporary authorization code and reads your channel and streaming destination. YouTube output connection is currently paused. Stream keys from a connection are encrypted in a temporary database record for up to five minutes and deleted when your signed-in desktop retrieves them; expired records may remain encrypted until database cleanup runs. Twitch/Kick access and refresh tokens, granted scopes and channel identity are retained encrypted on our server for up to 90 days from connection or reconnection, for explicit channel metadata/category requests and opt-in Twitch clipping. Use or refresh does not extend that retention. Tokens are not sent to the desktop or intentionally logged. Connecting does not automatically create a broadcast or publish a clip. Settings and login tokens are saved locally using operating-system credential encryption where available. Local encoder configuration or diagnostic files may contain sensitive settings; protect access to your computer and inspect diagnostics before sharing them.
While signed in, the desktop app periodically reports its version, whether it is running a broadcast, a broadcast identifier, and the time of the report. We also process broadcast start/end and expiry information, dump allowance or usage records, license status, and administrative account actions. These support entitlement enforcement and an administrator dashboard showing account and activity counts. They do not prove that a platform actually received a stream.
4. Optional public Twitch clips
Public Twitch clipping is optional and requires an explicit enabled output setting, disabled by default in desktop versions offering it, and a consent-bearing API request. New Twitch output connections request clip-creation permission, but granting that permission does not enable publishing. When requested after a local save or dump snapshot, our server asks Twitch to create a public clip of content already aired on Twitch, not the private local buffer or dumped footage. We do not upload local video or audio. Timing and duration may differ from the local save; Twitch controls availability and publication. Kick clipping is unsupported.
We retain an account-bound clip request record with event, broadcast and channel identifiers, requested duration, explicit consent, timestamps, operation and provider clip identifiers, result state, validated public URL and sanitized error for one day. Rate and public-clip allowance records expire one day after the last new creation. Physical database cleanup may occur later; expiration is enforced by the API. These records prevent duplicate publishing and enforce allowances and abuse limits. Uncertain requests are not automatically recreated. Disabling the output setting stops future requests but cannot recall a dispatched request. Public clips remain on Twitch under its rules until removed there; expiration or deletion of StreamSafe records does not remove them. Output-account deletion blocks access immediately, while clip records age out under their one-day retention.
5. Optional Discord activity
Desktop versions with Discord Rich Presence can send a generic activity state and StreamSafe logo to the locally running Discord client. This setting is enabled by default in those versions and can be disabled in Stream setup. It does not include your email, stream keys, destinations, or video. Your visibility is also controlled by Discord’s activity-sharing settings. The activity uses the account signed into your local Discord application, which may differ from your StreamSafe sign-in account.
6. Cookies, technical data, and purposes
We use session and login-security cookies and temporary authentication records to keep you signed in, validate redirects, prevent cross-site attacks, and complete social sign-in. Website, network, hosting, and security providers may process IP addresses, request metadata, browser information, and operational logs to deliver and protect the Service. We use Google Analytics with analytics and advertising cookie storage disabled to send cookieless signals about visits to public pages and the account page, selected navigation and button clicks, sections viewed, checkout handoffs and errors, and time the page is visible. We do not send payment amounts, Stripe session IDs, or payment URLs. A page becoming hidden may mean switching tabs rather than leaving the site. These signals can include browser and device information; Google receives network information such as IP addresses when processing requests. This does not provide precise unique-visitor counts. You can disable these signals through Analytics preferences, and existing opt-outs remain honored. We do not send account IDs, email addresses, form contents, or sign-in tokens to Analytics. Advertising features are disabled.
We use information to operate accounts, verify licenses, deliver downloads, process subscriptions, provide support, detect abuse, troubleshoot failures, and meet legal obligations. Where a legal basis is required, these purposes rely on performing our agreement with you, legitimate interests in operating and securing the Service, legal obligations, or consent where required. You can block cookies in your browser, but sign-in may stop working.
7. Recipients and international processing
Service providers include AWS for hosting, authentication, database storage, secrets, and email; Cloudflare for domain, DNS, and configured network services; Stripe for payments; and the social providers you choose for authentication. They process information under their applicable terms and privacy policies. Administrators can access account and license information for operations and support. We do not sell personal information or share it for cross-context behavioral advertising.
We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or security, or carry out a business transfer subject to applicable safeguards and notice requirements. Our AWS application infrastructure is in the United States. Providers may process data in other countries; applicable transfer requirements still apply.
8. Retention and security
Account, license, and billing-link records are retained while needed to provide the Service and for legitimate accounting, security, dispute, or legal needs afterward. Latest activity and broadcast records may remain stored after they stop counting as active; expiration from a dashboard does not mean deletion. Temporary social-login records have short validity windows and are scheduled for expiry, but physical database deletion may occur later. Local files remain subject to your computer’s storage and cleanup behavior.
We use measures such as HTTPS, access controls, operating-system encryption for saved desktop credentials, and managed secret storage. No security measure or transmission method is infallible. We do not promise absolute security. We retain information only as reasonably needed for the purposes described and applicable obligations; request deletion through the contact below.
9. Your choices, requests, and changes
You can manage billing from your account, sign out, disable Discord activity, and revoke social-provider permissions through that provider. Revoking a provider or uninstalling StreamSafe does not cancel a subscription or delete server records. Contact us to request access, correction, export, or deletion of your information, or to ask about other rights available where you live. We may verify your identity and retain information required for legal, accounting, fraud-prevention, or dispute purposes. We will explain applicable limits and respond within legally required periods.
Depending on your jurisdiction, you may also have rights to restrict or object to processing, withdraw consent where processing relies on it, appeal a decision, or complain to a data-protection authority. We will not unlawfully discriminate for exercising a protected right. Material policy changes will be notified through the Service or email where appropriate, and the date above will be updated. Changes do not authorize previously undisclosed uses where additional permission is required.
Contact StreamSafe
For legal, privacy, deletion, or billing questions, use our contact form. Do not send passwords, stream keys, or payment-card numbers.