Cookie & Local-Storage Policy
Last updated: 9 July 2026 · Version 2.0
1. About this Policy
This Cookie & Local-Storage Policy explains how StreamStudio Community Pro ("StreamStudio", "the Service", "we", "us") uses cookies, browser local storage, session storage, and similar technologies when you use our browser-based live-streaming studio.
It should be read together with our Privacy Policy and Terms of Service. Defined terms (Operator, Host, Guest, Viewer) have the same meaning as in those documents.
Who is responsible (data controller). The Service is operated by a sole proprietor, who is the data controller for the storage described here:
- Operator / controller legal name: [full legal name of the sole proprietor — to be completed before publication]
- Business postal address: [business/registered address in Japan — to be completed before publication]
- General contact: marcelo.r198500@gmail.com
- Privacy & data-rights requests: privacy@ [service domain]
- Security & breach reports: security@ [service domain]
- Copyright / DMCA notices: dmca@ [service domain]
We publish the controller's legal name and a business address directly (not only "on request"), because several laws (including GDPR Art. 13, Japan's APPI, and consumer-transaction rules) require the controller to be identified affirmatively. We monitor the dedicated mailboxes above so time-critical notices are not missed; the personal Gmail address remains available as a general contact.
The short version: we use one essential first-party cookie to keep you signed in, plus browser local storage to remember preferences you set (language and studio layout). We run no advertising cookies, no cross-site tracking, and no analytics of our own. Some third-party features (payments, YouTube, live video) can set their own cookies — for users in the EU/EEA and UK we block the non-essential ones until you opt in.
2. What are cookies and local storage?
- Cookies are small text files a website asks your browser to save and send back on later requests. A cookie can be marked HttpOnly (unreadable by page JavaScript), Secure (sent only over HTTPS), and SameSite (restricted on cross-site requests) — settings we use to protect your session.
- Local storage and session storage (the browser's built-in "Web Storage" APIs) let a website save small pieces of data on your device. This data is not automatically sent to a server with every request; it stays in your browser until cleared.
- Similar technologies include short-lived tokens or state held in memory during a session.
In this Policy, "storage" covers all of the above. StreamStudio uses one essential first-party cookie (your sign-in session) together with local storage and session storage for preferences and short-lived state.
3. What we store, and why
The table below lists what we set on our own domain. Each item is classified as either Strictly necessary (no consent required) or Functionality (stored only after you take an explicit action, such as choosing a language or configuring your studio).
| # | Item stored | Type & class | Purpose | How long it lasts |
|---|---|---|---|---|
| 1 | Sign-in / session cookie | First-party cookie, HttpOnly + Secure + SameSite. Strictly necessary. | Keeps you securely signed in so you don't re-enter a one-time code or password on every page, and identifies your authenticated session. Because it is HttpOnly, page scripts (including third-party embeds) cannot read it, which reduces the risk of session theft. Sessions are revocable on our servers, so a lost or expired session can be invalidated. | Until you sign out, we revoke it, or it expires — up to 30 days. |
| 2 | Language / locale preference | Local storage. Functionality (set after you pick a language). | Remembers which of the 10 UI languages you chose so the app opens in your language. | Until you change or clear it, up to a maximum of 12 months, then refreshed by your continued use. |
| 3 | Studio & layout preferences | Local storage. Functionality (set only inside your logged-in session, after you configure the studio). | Remembers studio settings you set up — scene/stage layout, selected camera/microphone, DJ Mixer and Groovebox settings, and UI options — so your workspace is the way you left it. | Until you change or clear it, up to a maximum of 12 months, then refreshed by your continued use. |
| 4 | Temporary session state | Session storage / in-memory. Strictly necessary. | Holds short-lived state needed while a page or broadcast is open (for example, in-progress form or connection state). | Cleared automatically when you close the tab. |
A note on classification. We treat only the session cookie (item 1) and temporary session state (item 4) as strictly necessary. Items 2 and 3 are functionality storage: they are not required to deliver the Service, but they are set only after you explicitly act (choosing a language, arranging your studio) and only to render the authenticated Service you asked for. We do not treat broad preference persistence as "strictly necessary," and we do not keep it indefinitely.
All of the above are first-party. None contain advertising identifiers, and none are shared with advertisers or data brokers.
4. What we do NOT do
- We do not use advertising or marketing cookies of our own.
- We do not use cross-site or cross-context behavioural tracking, ad-profiling pixels, or fingerprinting for advertising.
- We do not embed third-party analytics products (such as Google Analytics) in the app. Our servers keep basic technical logs (IP address, browser type, timestamps) as described in the Privacy Policy, but those are server-side records, not trackers placed on your device.
- We do not sell or "share" (as the CCPA/CPRA uses that term) any information gathered through storage for cross-context behavioural advertising.
We do not claim that every cookie connected with the Service is exempt from consent. Some third-party features can set non-essential cookies (see Section 5), and where they do we handle consent as described in Section 6 rather than disclaiming responsibility for them.
5. Third-party / processor storage
Several StreamStudio features load services operated by our processors. When those features run, the providers can set their own cookies or storage on their own domains, under their own policies. Some of what they set is strictly necessary (for example, to route a payment or a video stream); some — particularly for embedded YouTube players — can include advertising/tracking cookies that are NOT strictly necessary.
Because we choose to embed these services, we accept that we are jointly responsible, together with the provider, for obtaining consent for any non-essential cookies those embeds set (consistent with CJEU Fashion ID and UK ICO guidance). We do not treat third-party cookies as "purely the provider's problem." Concretely:
- YouTube / Google — where we show a YouTube player, we use the privacy-enhanced
youtube-nocookie.comembed. For Google sign-in / OAuth and any player that still sets non-essential (e.g. DoubleClick) cookies, those cookies are blocked for EU/EEA/UK users until you opt in (Section 6).
Privacy: https://policies.google.com/privacy · Cookies: https://policies.google.com/technologies/cookies
- Stripe — used for subscription Checkout, the Customer Portal, and payment-fraud prevention. Cookies strictly necessary for secure payment and fraud detection are set when you actually enter a payment flow; any Stripe cookies that are not strictly necessary are held behind the consent gate for EU/EEA/UK users.
Privacy: https://stripe.com/privacy · Cookies: https://stripe.com/legal/cookies-policy
- LiveKit — provides the real-time WebRTC audio/video connection for the studio and may set storage needed to establish and maintain that connection (strictly necessary once you join a room).
Privacy: https://livekit.io/privacy
You can review each provider's policy to understand and manage what they set. Disabling storage that is genuinely required by Stripe, YouTube/Google, or LiveKit may prevent payment, YouTube connection, or the live studio from working.
6. Consent — when we ask, and when we don't
Strictly-necessary storage does not require consent. Under the EU ePrivacy Directive ("Cookie Law") and the UK PECR, consent is not required for storage that is strictly necessary to provide a service you have explicitly requested. Our session cookie and temporary session state (Section 3, items 1 and 4) fall within that exemption, so we do not ask for consent for them.
Functionality storage (language and studio/layout preferences, items 2 and 3) is set only after your explicit action and lasts a defined maximum period. We rely on that functional basis and keep the scope and duration limited, in line with EDPB/CNIL guidance.
Non-essential third-party cookies — we obtain prior opt-in. For users in the EU/EEA and the UK, any non-essential cookies that our embeds (YouTube/Google, Stripe) could set are blocked by default and are only set after you give consent through our consent banner. The banner:
- asks before any non-essential storage is placed;
- gives a genuine choice (accepting and rejecting are equally easy — no pre-ticked boxes, no "reject" buried);
- lets you withdraw consent later as easily as you gave it (see Section 7); and
- records your choice so we can honour it.
Where you do not opt in, we fall back to the privacy-enhanced (youtube-nocookie) embed and to strictly-necessary processing only.
Users in California, Japan, and other regions. We use only essential and functionality storage of our own and do not sell or "share" personal information for advertising, so there is no advertising opt-out to exercise on our side. Japan-specific transmission disclosures are in Section 7 below. Your broader data-protection rights are described in the Privacy Policy.
7. Japan — Disclosure of External Transmission (外部送信に関する公表 / 電気通信事業法第27条の12)
For users in Japan, the following discloses information transmitted from your device to third parties when you use features that embed external services, as required by the 改正電気通信事業法 外部送信規律 (Telecommunications Business Act, Art. 27-12).
| 送信先事業者<br>(Recipient) | 送信される情報の内容<br>(Information transmitted) | 利用目的<br>(Purpose) |
|---|---|---|
| Stripe, Inc. | IP address, device/browser information, cookie identifiers, and payment-flow interaction data | Processing subscription payments securely and detecting/preventing fraud |
| Google LLC / YouTube | IP address, device/browser information, and (unless blocked) cookie/player identifiers | Displaying the YouTube player/embed and enabling Google sign-in / OAuth for your channel |
| LiveKit, Inc. | IP address, device/network (WebRTC/ICE) information, and connection state | Establishing and maintaining the real-time audio/video studio connection |
Links to each recipient's privacy and cookie policies are provided in Section 5. Where you are in the EU/EEA or UK, non-essential transmissions above are additionally gated behind the consent banner (Section 6).
8. How to see, control, or clear your stored data
You are always in control of storage on your device. You can:
- Sign out of StreamStudio — this ends and clears your session cookie.
- Change your consent choice (EU/EEA/UK) via the "Cookie settings" link in the app footer, at any time.
- Clear site data for StreamStudio in your browser. In most browsers: Settings → Privacy → "Cookies and site data" / "Clear browsing data", or use the padlock/site-information menu next to the address bar and clear cookies and site data for this site.
- Use your browser's developer tools (Application → Storage) to inspect and delete individual cookie, local-storage, and session-storage items.
- Block or limit cookies/storage through your browser settings, or use private/incognito mode.
Please note: clearing or blocking essential storage will sign you out and reset your language and studio preferences, and may stop parts of the Service from working. Managing third-party cookies (Section 5) may also affect payment, YouTube, or live-connection features.
To manage or revoke the YouTube/Google connection itself (separate from browser cookies), disconnect inside StreamStudio or visit https://myaccount.google.com/permissions.
9. Related disclosures in other documents
Some matters that people ask about are handled where they legally belong, not in this cookie-focused Policy. For completeness:
- Recurring subscription & free trial (定期購入). Details of the 7-day free trial, the first-charge date at trial end, the renewal amount and billing cycle, and the one-step cancellation path are presented on the final confirmation screen (最終確認画面) during signup and are set out in Terms cl. 6 and on our 特定商取引法に基づく表記 page, consistent with the 改正特定商取引法 (Art. 12-6).
- Statutory commercial disclosures (特商法表記). Price and consumption tax, additional fees, payment method and timing, timing of service provision (決済完了後直ちに), return/cancellation terms (返品特約), the operating manager's name (運営責任者), and offer validity are enumerated on that page.
- Children. The Service is for adults. Handling of any personal information (including camera, microphone, and recordings) relating to individuals under 13 (or the applicable age of digital consent) — including our deletion backstop — is described in Privacy Policy Section 11 and Terms clause 14.
These references are provided so nothing is silently omitted; the operative text lives in the documents named.
10. Changes to this Policy
We may update this Policy from time to time — for example, if we add a feature that uses new storage. We will change the "Last updated" date above and, for material changes (such as introducing any new non-essential technology), provide notice in-app or by email and, where required, request your consent before the change takes effect.
11. Contact
Questions about this Policy or about cookies and storage in StreamStudio:
StreamStudio Community Pro (Operator — sole proprietor)
- Legal name / business address: as stated in Section 1 (to be completed before publication)
- Privacy & data-rights: privacy@ [service domain]
- Security & breach: security@ [service domain]
- Copyright / DMCA: dmca@ [service domain]
- General: marcelo.r198500@gmail.com
This document is a template provided for general informational purposes only and does not constitute legal advice. Cookie, storage, and privacy requirements vary by country and change over time. Before launch, the Operator should have this Policy — and the related Privacy Policy, Terms, and 特定商取引法に基づく表記 page — reviewed and adapted by qualified legal counsel in the relevant jurisdictions (including the EU/EEA, UK, Japan, and California), and should confirm that the engineering implementation (HttpOnly session cookie with server-side revocation, youtube-nocookie embeds, and the EU/EEA/UK consent gate described above) matches what this Policy states.