Privacy Policy

Last updated 8 July 2026

This policy explains what Stream Repeater collects, why, and your choices. By using the service you agree to it.

Information we collect

  • Account data — your name, email, and password (stored hashed).
  • Stream configuration — workspaces, streams, and destinations you create. Destination credentials are encrypted at rest. If you sign in with Twitch or Kick to set up a destination, we use that connection only to read your channel's ingest URL and stream key so we can create the destination for you; the key is then stored encrypted like any other destination credential.
  • Operational data — relay status, throughput and viewer metrics, stream health and stability diagnostics (e.g. detecting a source that keeps dropping so we can flag an unstable connection), and security/audit logs.
  • Recordings — if you turn on recording for a stream, we store the recorded media on our infrastructure for a limited, plan-based retention period (then auto-delete it). Recording is off by default and you control it per stream.
  • Branding assets — any logo you upload for a public watch page, and (if you enable it) the custom domain name you point at your watch page.
  • Viewer lead data — if a workspace owner turns on lead capture for a public watch page, the name and email a viewer enters to unlock that stream. The workspace owner who enabled the feature is the data controller for those details; we only process them on the owner's behalf so the owner can grant access and export their leads.
  • Connected-platform tokens — if you connect a destination account (e.g. YouTube or Twitch) for unified viewer analytics, the authorisation token for that account, stored encrypted, used only to read aggregate viewer counts.
  • Integration & automation data — if you use Integrations (a higher-plan feature), the credentials, webhook URLs or device details you enter for each connected service (e.g. a Twitch OAuth token, a Govee API key, a Discord or custom webhook URL), all stored encrypted at rest; the automation rules you build; and a short, rolling log of the live events that drive them (e.g. a Twitch follow or a TikTok gift, with the small amount of context each event carries, such as a display name or amount). Twitch events are received via Twitch EventSub webhooks.
  • Local Agent data — if you run our optional Local Agent on your own computer, a pairing record and a per-agent signing key. The agent runs on your machine and forwards events to your workspace; we receive only the events it sends, not your device contents.
  • Safety reports — report category, details, reporter contact details if provided, content snapshots, moderation decisions, and a hashed IP address for abuse prevention.
  • Technical data — IP address and request metadata, used for security and rate limiting.

How we use it

To operate the service — authenticate you, run and supervise your relays, show you metrics, take payment, and keep the platform secure. We do not sell your personal data.

Support access. Our administrators may securely access or sign in to your account to provide support, investigate issues, or enforce these terms. Such access is restricted to staff, recorded in our audit trail, and used only for those purposes.

Legal bases (GDPR)

  • Contract — to provide the service you sign up for (account, streams, relays, billing).
  • Legitimate interests — security, abuse prevention, and service improvement, balanced against your rights.
  • Legal obligation — retaining invoices and financial records as required by law.
  • Consent — optional marketing emails (opt in/out anytime in Settings, or via any email's unsubscribe link).

Who we share data with

We use a small set of processors to run the service, each under their own data-protection terms:

  • Hetzner — hosting (EU data centres).
  • Amazon Web Services (S3) — encrypted off-site backups, stored in the UK (London, eu-west-2).
  • Amazon SES — transactional & account emails.
  • Stripe — payment processing (we never store full card details).
  • Cloudflare — bot/abuse protection (Turnstile) and, where enabled, CDN/edge delivery and web-application firewalling for the control plane.
  • Google, Twitch & Kick — only if you choose to sign in with, or connect, one of these accounts; each then handles your data under its own privacy policy.

Cookies

We use strictly-necessary cookies (such as your login session and a CSRF security token) to operate the platform. With your consent, we also load analytics tools (Google Analytics and our self-hosted tracking system) to help us measure site traffic and improve performance. You can choose to accept or decline these optional cookies via our cookie consent banner. We do not use advertising cookies.

Our custom analytics tracking is hosted at https://tracking.zurg.co.uk/ and handles data in a privacy-respecting, GDPR-compliant manner.

International transfers

Your data is hosted in the EU (Germany), with encrypted backups stored in the UK. Where a processor handles data outside the EU/UK, it is covered by appropriate safeguards (e.g. Standard Contractual Clauses).

Media content

Stream Repeater relays your live streams to the destinations you configure. By default we do not retain stream media — it passes through and is delivered onward. Two optional features change this, and only when you turn them on:

  • Recording — if enabled for a stream, we store the recorded media on our infrastructure for a limited, plan-based retention window, after which it is automatically deleted. You can delete recordings yourself at any time.
  • Public watch page — if enabled, that stream becomes viewable by anyone who has the link (and via any site where you embed it). Disable it and the link stops working.

We may also generate a short-lived still preview thumbnail of a live stream to show in your dashboard; it is cached briefly and automatically replaced or expired.

Third-party destinations (e.g. YouTube, Twitch) handle delivered content under their own policies. If you configure outbound webhooks or an alert URL, we send stream event metadata (not media) to the endpoint you specify.

Watch-page protection, leads & connected platforms

These optional features are off by default, available only on the plans that include them, and controlled by you per stream:

  • Watch-page password. If you password-protect a watch page, we store only a one-way hash of the password (never the password itself) and a short-lived access cookie on each viewer's browser so they don't have to re-enter it on every request.
  • Lead capture. If a workspace owner requires viewers to enter a name and email before watching, that workspace owner is the data controller for those details and we act as their processor: we collect them solely to grant access and to make the leads available to the owner for export. We do not market to those viewers or use their details for our own purposes. At the point of collection the viewer is told their details go to the stream owner, not to us. A viewer can ask us to forward a deletion request to the owner, the owner can delete a lead at any time, and the records are removed when the watch page is deleted.
  • VOD clips. A clip you create from a recording is stored and retained on the same plan-based basis as the underlying recording, and is deleted when you delete it or its parent recording.
  • Custom domain. If you point your own domain at a watch page, we store that hostname and perform DNS lookups and issue a TLS certificate for it (via a certificate authority such as Let's Encrypt) so the page loads securely. Remove the domain and we stop using it.
  • Unified viewer analytics. If you connect a destination account, we use its API only to read aggregate concurrent-viewer counts to show you a combined audience figure. We store the access token encrypted, never post on your behalf, and you can disconnect the account at any time to revoke our access.

Integrations & automations

Integrations let you connect third-party platforms and devices and run rules that react to live events. They are off by default, available only on the plans that include them, and entirely under your control:

  • Connecting a service. When you connect Twitch or Kick we store the OAuth token it issues (encrypted) and register the event subscriptions or webhooks needed to receive your channel events (e.g. follows, subscriptions, cheers, raids); for other services we store the API key, webhook URL or device details you provide (encrypted). You can disconnect any integration at any time, which removes its stored credentials and tears down any subscriptions we created.
  • YouTube (Google) data. If you connect YouTube, you grant us access to your own channel (the youtube.force-ssl scope). We use it only for things you ask us to do, and only on your own channel: (1) reading your live chat — chat messages, Super Chats and new-member events — so they can trigger the automation rules you set up and appear in your moderation feed; (2) acting in your live chat when you choose to — sending the replies you write and carrying out the moderation you initiate (deleting a message, or timing out or banning a viewer) in your own live chat; and (3) setting up restreaming to YouTube — when you choose to, we create a live broadcast and its ingest endpoint/stream key on your channel so the platform can relay your stream to YouTube. It is one grant used for these features; reconnecting refreshes it. We do not read, modify or delete your existing videos, captions, playlists or other channel content; the only changes we make are the live broadcasts you ask us to create and the live-chat replies and moderation actions you choose to take, and we never touch any channel other than your own. Stream keys and OAuth tokens are stored encrypted. Chat content is kept only briefly: it is used to evaluate your rules, and a copy of each event (including the message) appears in your own private activity log so you can see and debug what fired — that log is automatically deleted after 7 days. You can revoke this access at any time from your Google account or by disconnecting YouTube in your workspace. Limited Use. Stream Repeater's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we do not use Google user data for advertising, do not sell it, do not use it to train generalised AI/ML models, and do not transfer it to others except as needed to provide these features to you, for security, or to comply with law.
  • Unified chat & engagement. If you connect chat-capable platforms (Twitch, Kick, YouTube, or TikTok via the Local Agent), we capture recent chat messages — the author's public display name and the message text — into a moderation feed you can read, reply to, moderate and show on a stream overlay. Messages are retained only for the live moderation window and are removed when you delete them, when a participant is removed, or as the feed rolls over; moderating a message soft-deletes it so it drops out of your feed and overlay. Audience-engagement tools (giveaways, polls and chat commands) store only the public chat names of participants for the duration of that giveaway or poll, and are cleared when you end it.
  • Data we send to your connected services. When a rule fires, we send the action you configured to the destination you chose — for example a message to your Discord webhook, a request to a custom webhook URL you entered, or a command to your lights. Those third parties process what they receive under their own privacy policies. We send only what the action needs; we never sell or repurpose this data.
  • TikTok & the Local Agent. TikTok has no official live API, so TikTok events are gathered by the Local Agent running on your own machine and forwarded to your workspace over a signed connection. Running it, and connecting any account or device, is your choice and your responsibility under those platforms' terms.
  • Event log. We keep a short, rolling activity log so you can see and debug your automations: inbound events (the small amount of context each carries) are automatically deleted after about 7 days, and rule-run records after about 30 days.

YouTube API Services

Stream Repeater uses YouTube API Services to provide its YouTube features (reading and acting in your live chat, and setting up restreaming to your channel). By connecting your YouTube account and using these features you also agree to the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.

  • What we access. With your explicit consent we use the single https://www.googleapis.com/auth/youtube.force-ssl scope, on your own channel only, to: (1) read your live chat (messages, Super Chats, new-member events); (2) send the chat replies and carry out the moderation (delete / timeout / ban) that you initiate; and (3) when you ask, create a live broadcast plus its ingest endpoint and stream key so we can relay your stream to YouTube. We never read, modify or delete your existing videos, playlists, captions or any other channel content, and we never touch any channel but your own.
  • How we store it. Your OAuth tokens and stream keys are stored encrypted at rest. Live-chat content is used to run the automations and moderation you set up, and a copy of each event appears only in your own private activity log.
  • How we delete it (data-deletion policy). Google user data is deleted automatically and on request: your activity-log copies of YouTube data are auto-deleted after 7 days; live-chat messages we display in your dashboard and overlays are automatically deleted after at most 30 days (and immediately when you moderate them), in line with the YouTube API Services requirement that stored data is not kept beyond 30 days; disconnecting YouTube in your workspace immediately deletes the stored tokens and stream keys and stops all access; and deleting your account removes all associated YouTube data. You can also ask us to delete your data at any time via a data request.
  • How to revoke access. You can revoke Stream Repeater's access to your YouTube data at any time: from Settings → Privacy → Connected accounts (a dedicated “Revoke access” button), by disconnecting YouTube on your workspace's Integrations page, or through the Google security settings at https://security.google.com/settings/security/permissions (also reachable at myaccount.google.com/permissions). Revoking immediately deletes the stored token and stops all access.
  • Limited Use. Stream Repeater's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we do not use Google user data for advertising, do not sell it, do not use it to train generalised AI/ML models, and do not transfer it to others except as needed to provide these features to you, for security, or to comply with law.

Twitch & Kick

If you connect Twitch or Kick, you grant us access to your own channel to power the same chat, moderation and restreaming features described above, and we store the OAuth token each issues encrypted at rest. Your use of those connections is also subject to each platform's own terms and privacy policy: the Twitch Terms of Service and Twitch Privacy Notice, and the Kick Terms of Service and Kick Privacy Policy. You can revoke our access at any time from Settings → Privacy → Connected accounts or your workspace's Integrations page, which deletes the stored token immediately; you can also review and revoke third-party access in each platform's own account/connections settings.

Retention

Account and configuration data are kept while your account is active. Recordings are kept only for your plan's retention window and then auto-deleted (sooner if you delete them or your storage fills). Operational logs are pruned on a rolling basis. Invoices are retained as long as the law requires, even after account closure (pseudonymised). Safety reports, and account-moderation records (strikes and the reason for a suspension or ban), are retained while needed for moderation, legal, and audit purposes.

Your rights

Under GDPR you can access, correct, export, restrict, object to, or delete your personal data. Logged-in users can download a copy of their data and delete their account directly from Settings → Privacy & your data. For anything else, or if you don't have an active login, make a data request (we respond within one month). You also have the right to complain to your local data-protection authority (in the UK, the ICO).

Contact

Questions about this policy, our use of YouTube API Services, or to exercise your rights? Email us at [email protected] or get in touch. Stream Repeater is operated by Joe Taylor (United Kingdom).