Privacy Policy
Last updated: 9 July 2026 · Version: 3.0
This Privacy Policy explains what personal data StreamStudio Community Pro ("StreamStudio", the "Service") collects, why, how it is used and shared, and the rights you have. It applies to everyone who uses the Service worldwide. Please read it together with our Terms of Service, our Data Processing Addendum (Section 1.4), our Cookie/Storage Policy, and our Disclaimer.
1. Who we are (data controller)
The Service is operated by [Operator legal name — individual sole proprietor / 屋号: __________] (the "Operator", "we", "us", "our"), a sole proprietor based in Japan. For the personal data described in this Policy, the Operator is the data controller (in Japan, the business handling personal information / 個人情報取扱事業者).
- Legal name of controller: [Operator legal name] — stated here in full to satisfy GDPR/UK GDPR Art. 13(1)(a) and APPI/consumer-law identification duties.
- Postal contact address: [Registered business postal address in Japan]
- Privacy, security, and rights-request contact: privacy@[service-domain] (monitored dedicated mailbox). A copy is also received at marcelo.r198500@gmail.com during transition.
- Copyright/DMCA and breach reports: legal@[service-domain] and security@[service-domain].
We publish the controller's legal name and a postal contact address directly in this Policy (not only "on request"). The Operator's full registered details, including telephone number, also appear on our 特定商取引法に基づく表記 page (see Section 15). The "disclosure on request" concession under the 特定商取引法 applies only to the sole-proprietor items on that page and does not replace the identification given here.
1.1 EU/EEA and UK representatives (Article 27)
Because the Operator is established outside the Union and the UK and offers the Service to individuals in the EU/EEA and the UK on a regular, ongoing basis, we have appointed representatives under Article 27 GDPR and Article 27 UK GDPR:
- EU/EEA representative (Art. 27 GDPR): [Representative name, postal address in an EU/EEA Member State, email].
- UK representative (Art. 27 UK GDPR): [Representative name, UK postal address, email].
You may contact either representative on all issues relating to the processing of your personal data and to exercise your rights. These appointments are a launch precondition for the EU/EEA and UK; the Service will not be offered to those regions until both are in place.
1.2 Data Protection Officer
We have carried out and documented an assessment of whether a Data Protection Officer ("DPO") is required under GDPR Article 37 (given that our core activity includes processing audio/video, recordings, and viewer chat that may reach large scale and may include special-category data). [If required: DPO name and contact details are: __________.] [If not required: no DPO is legally mandated; our privacy contact point (privacy@[service-domain]) handles all privacy matters, and the reasoned assessment is retained on file.]
1.3 Controller/host split
For your account, billing, authentication, and YouTube-connection data, the Operator is the controller. For the content you broadcast or record — including the personal data of your guests and of viewers (for example live chat and Super Chat) that passes through the Service — you (the Host) are the controller under the GDPR/UK GDPR, and the Operator acts as your processor. As the Host, you are responsible for having a lawful basis for that content and for giving your guests and audience any notices and obtaining any consents required by law (including any Article 9 explicit consent — see Section 3.3 — and recording-consent laws — see Section 11).
Japan (APPI) — no processor shield. Japan's APPI does not recognise a controller/processor split. Regardless of the allocation above, the Operator itself remains an 個人情報取扱事業者 for all personal data it handles — including guest and viewer data passing through the Service — and independently complies with its APPI duties (利用目的の特定・通知公表, 安全管理措置, 委託先の監督, 開示等請求対応, and 漏えい等報告). The Host bears its own APPI obligations in addition; the arrangement does not transfer the Operator's APPI duties to the Host.
1.4 Data Processing Addendum (where you are the controller)
Where you use the Service to process Guest or Viewer personal data as a controller, our Data Processing Addendum ("DPA") at [URL] applies and forms part of our Terms of Service. The DPA contains the full Article 28(3) processor terms, under which we commit to:
- process such content only on your documented instructions;
- ensure personnel are bound by confidentiality;
- apply the Article 32 security measures summarised in Section 13;
- engage only the sub-processors listed in Section 5 (including our cloud hosting and media-storage provider), with prior authorisation and advance notice of any change;
- assist you with data-subject requests and with your Article 32–36 duties (security, breach notification, DPIAs, prior consultation);
- notify you without undue delay of any personal-data breach affecting your content;
- delete or return the content on termination; and
- make available information needed to demonstrate compliance and allow audits/inspections.
2. Who this Policy covers
- Hosts / account holders — registered, paying users who run broadcasts.
- Guests — people a Host invites into a room; they share camera, microphone, and a display name from their own device. See Section 11.
- Viewers — the audience on YouTube. Viewers are not our users, but their chat/Super Chat data may flow through the Service; see Section 11.
3. Data we collect and why (with GDPR lawful bases)
Where the EU/UK GDPR applies, we rely on the lawful bases shown. "Contract" = necessary to provide the Service you signed up for; "Legitimate interests" = our or a third party's legitimate interests, balanced against your rights; "Consent" = your freely given consent, which you may withdraw at any time; "Legal obligation" = required by law.
| Data category | Examples | Purpose | GDPR lawful basis |
|---|---|---|---|
| Account data | Email address; optional phone number | Create and manage your account; contact you about the Service | Contract |
| Authentication data | One-time login codes (via email/SMS); passwords stored only as a scrypt hash; session tokens (30-day expiry) | Verify identity; deliver the login code you request; keep you signed in securely | Contract (secure authentication you requested); Legitimate interests (account security). Delivery of a login code you request is necessary for the login you asked for — it is not based on consent and cannot be "withdrawn" without breaking login. |
| Google/YouTube OAuth tokens | Access/refresh tokens for your YouTube channel(s) | Schedule/start/stop broadcasts, upload thumbnails, read & display live chat and Super Chat — only on your instruction | Contract (to deliver the YouTube feature you connected). Connecting is your voluntary authorisation to access your Google account; you can disconnect or revoke at any time (Section 4). |
| Content you upload or create | Video/audio clips, music, images, logos, avatars, thumbnails; studio scenes and settings; recordings saved to your Library | Store, process, and transmit to the destinations you choose; provide the DJ Mixer, Groovebox, and Recording features | Contract |
| Broadcast/room data | Camera, microphone, display names of Host and guests routed in real time (WebRTC) | Enable live production and broadcasting | Contract (for you as Host); you are controller for guests/viewers |
| Viewer chat & Super Chat | Public YouTube live-chat messages, author names, Super Chat amounts, retrieved for display in the studio | Show live audience interaction to the Host | You (Host) are controller; we process on your instruction |
| Billing data | Stripe customer ID, subscription ID, plan, subscription status, trial/renewal dates. We never receive or store card numbers (PCI DSS SAQ-A) | Manage subscription and billing | Contract; Legal obligation (tax/accounting). For card and payment data, Stripe acts as an independent controller — see Section 5. |
| Server logs / technical data | IP address, browser/user-agent, timestamps, error and diagnostic logs | Security, abuse/fraud prevention, debugging, service reliability | Legitimate interests; Legal obligation where applicable |
3.1 Sensitive personal information (California)
Account log-in credentials (email + password) are "sensitive personal information" (SPI) under the CPRA (Cal. Civ. Code §1798.140(ae)). We use them solely to authenticate you — a permitted business purpose under §1798.140(e). We do not use or disclose SPI to infer characteristics about you. Because our use is limited to that permitted purpose, the CPRA "right to limit the use of sensitive personal information" does not require us to offer an opt-out link (see Section 8).
3.2 Automated decision-making
Except for automated fraud- and abuse-prevention checks (including risk scoring performed by our payment processor, Stripe Radar, and automated checks on our server logs), we do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you. Where a payment or account action is affected by such a check, you may contact us to request human review.
3.3 Special-category data (Article 9)
Live video and audio, recordings, and displayed chat/Super Chat can incidentally reveal special-category data — for example data about health, racial or ethnic origin, religious or political beliefs, sexual orientation, or biometric/facial data — of Hosts, guests, and viewers.
- Hosts (as controllers of content): you must ensure you have a valid Article 9 condition — normally the explicit consent of each affected individual — before broadcasting or recording content that may capture such data.
- The Operator: we do not intentionally process special-category data for our own purposes. Where such data is contained in content we handle on your instruction, we rely on you having obtained the required explicit consent.
- See the recording-consent obligations in Section 11 and in Terms clauses 9.4 and 11.1.
4. Google / YouTube API data (mandatory disclosures)
The Service uses the YouTube Data API v3 and Google OAuth. By connecting your YouTube account you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy).
What we access and why. With your authorization we access your YouTube channel(s) only to provide features you request: schedule and create live broadcasts, start and stop streams, upload thumbnails, and read and display live chat and Super Chat. We request the minimum scopes needed for these functions.
How we use, store, and share it. OAuth tokens are stored encrypted at rest with restricted key access, and are used only to perform actions on your instruction. We never see your Google password. We do not sell Google user data, do not use it for advertising, and do not transfer it to third parties except as needed to provide the feature you requested. Humans do not read your Google user data except: (a) with your consent for specific messages; (b) as necessary for security purposes (for example, investigating abuse or a vulnerability); (c) to comply with applicable law; or (d) where the data is aggregated and anonymized and used for internal operations in compliance with applicable law.
Limited Use. StreamStudio Community Pro's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
30-day refresh-or-delete (YouTube API requirement). As required by the YouTube API Services Terms and the YouTube API Services Developer Policies: except for OAuth authorization tokens (which we retain only while your YouTube account stays connected), we do not store any YouTube API Data for longer than 30 calendar days without refreshing it from the YouTube Data API. Any stored YouTube API Data that is not refreshed within 30 days is deleted. In practice, live-chat and Super Chat data is held only transiently to display live interaction and is not retained after the session. All YouTube API Data and OAuth tokens are deleted promptly when you disconnect YouTube, delete your account, or on request.
How to revoke access. You can (a) disconnect YouTube inside the Service at any time, and/or (b) revoke access via your Google account at https://myaccount.google.com/permissions. On disconnect or account deletion, stored Google/YouTube tokens and any cached chat data are deleted promptly.
5. Processors, sub-processors, and recipients
We share personal data only with the providers below, each acting under contract and only as needed to run the Service. We do not sell your personal data and do not share it for cross-context behavioral advertising.
| Provider | Role | What it handles | Region | Policy |
|---|---|---|---|---|
| [Cloud hosting & storage provider — e.g. name] | Cloud hosting, compute, and media/object storage (sub-processor) | Server hosting; storage at rest of account data, encrypted OAuth tokens, studio settings, and your recordings/Library | [e.g. US / EU region] | [policy URL] |
| [Media/CDN store, if separate] | Object storage / CDN for recordings & uploads | Storage and delivery of recorded and uploaded media | [region] | [policy URL] |
| LiveKit | Real-time media (WebRTC) infrastructure (sub-processor) | Live audio/video routing for rooms and broadcasts | [US/EU] | https://livekit.io/legal/privacy-policy |
| Google / YouTube | Broadcast platform & API | OAuth tokens; broadcast, thumbnail, chat/Super Chat operations | US | https://policies.google.com/privacy |
| Stripe | Payment processing — Stripe acts as an independent/separate data controller for payment, fraud-prevention, and legal-compliance purposes under its own privacy policy | Checkout, Customer Portal, subscription/customer IDs; card data (handled solely by Stripe) | US/EU | https://stripe.com/privacy |
| Resend | Transactional email (sub-processor) | Delivery of login codes and account emails | US/EU | https://resend.com/legal/privacy-policy |
| Twilio | SMS delivery (sub-processor) | Delivery of one-time login codes by SMS (if you provide a phone number) | US | https://www.twilio.com/legal/privacy |
Stripe as controller. For card and payment data, Stripe determines its own purposes and means (payment processing, fraud prevention, and regulatory compliance) and acts as an independent controller; Stripe's privacy policy applies directly to that processing.
A current list of sub-processors is available at [URL]; we will give notice of new sub-processors before they process your data. We may also disclose data where required by law, to enforce our Terms, to prevent fraud or harm, or in connection with a business transfer, subject to this Policy.
6. International data transfers
We and our providers operate in the United States, the EU, Japan, and other countries, so your data may be transferred and processed outside your home country, including outside the EEA/UK.
Which providers are outside the EEA/UK. Google/YouTube, Stripe, LiveKit, Twilio, Resend, and our cloud hosting/storage provider are, or may be, located in the United States. The Operator is in Japan.
EU/EEA and UK transfers.
- To the Operator in Japan: the EU and the UK have each recognised Japan (private sector) as providing adequate protection, so transfers from the EEA/UK to the Operator rely on those adequacy decisions (with the supplementary rules those decisions require).
- To US-based providers: we rely, for each recipient, on the EU-US Data Privacy Framework and the UK Extension where that provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum and appropriate supplementary measures.
- You may request copies of these safeguards using the contact in Section 14.
Japan (APPI) transfers. SCCs and the UK IDTA are not valid bases under the APPI, and the United States is not an APPI-designated adequate country (only the EEA and UK are). For transfers of personal data from Japan to providers in third countries (including the US), we rely on the APPI Article 28 bases: either (a) your prior consent obtained at signup, after we provide the destination country name, information about that country's data-protection regime, and the recipient's protective measures; or (b) the 基準適合体制 route (a recipient that has established equivalent standards), with ongoing verification and provision of the prescribed information on request. The APPI 委託 (outsourcing) exemption does not exempt these foreign transfers, so we do not rely on it for cross-border provision.
7. Retention
We keep personal data only as long as needed for the purposes above or as required by law:
- Account, authentication, and studio settings — for the life of your account.
- Google/YouTube OAuth tokens — retained (encrypted) only while your YouTube account stays connected; deleted promptly on disconnect, account deletion, or request.
- Cached YouTube chat / Super Chat — held only transiently to display live interaction; not retained after the broadcast/session, and in no case beyond 30 days without a refresh from the YouTube API (Section 4).
- Uploaded media and recordings (Library) — until you delete them or your account, subject to your plan's storage limits; you can delete media at any time.
- Billing records — retained as long as required by tax and accounting law (typically up to 7 years in Japan), then deleted or anonymized.
- Server logs (including IP addresses and diagnostics) — retained for 30–90 days for security and abuse prevention, and for up to 12 months where needed to investigate a specific security incident or to meet a legal obligation, after which they are deleted or irreversibly anonymised.
- Account deletion — on request to the contact in Section 14, we delete or anonymize your personal data. Data is removed from live systems within 30 days and purged from encrypted backups within [X days] as backups rotate, except data we must retain by law. Token and cached-chat deletion follows Section 4.
8. Your rights
Depending on where you live, you may have some or all of the rights below. We honor the strongest applicable protections regardless of your location.
EU/UK (GDPR / UK GDPR): access; rectification; erasure ("right to be forgotten"); restriction; objection (including to processing based on legitimate interests); data portability; and the right to withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office (ICO), https://ico.org.uk/make-a-complaint/; in the EU, your national Data Protection Authority.
California (CCPA/CPRA): the right to know/access, delete, and correct your personal information; the right to opt out of sale/sharing; the right to limit use of sensitive personal information; and the right to non-discrimination for exercising your rights. This section is our notice at collection; the categories we collect and disclose are listed in Sections 3 and 5, and the sensitive personal information we collect (login credentials) and its purpose are described in Section 3.1.
- We do not sell your personal information and do not share it for cross-context behavioral advertising, and we use sensitive personal information only for permitted business purposes (authentication and security). Because of this, there is no "Do Not Sell or Share My Personal Information" link and no "Limit the Use of My Sensitive Personal Information" mechanism to exercise — no action is needed on your part. If our practices ever change, we will provide the required links and honor opt-out preference signals, including Global Privacy Control (GPC).
- Authorized agents. California residents may use an authorized agent to submit access, deletion, correction, or opt-out requests. We may require the agent to provide proof of authorization and may verify your identity directly.
Japan (APPI): you may request disclosure, correction, addition, deletion, or suspension of use of your personal data (including 開示等請求), and raise complaints, using the contact in Section 14. Our contact point also handles grievances.
Other regions: if you are covered by another law (for example Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, South Korea's PIPA, Switzerland's FADP, or US state laws such as Virginia's VCDPA or Colorado's CPA), you may have additional local rights. Contact us and we will honor them as required. Where a recognized opt-out preference signal such as GPC applies under those laws, we will treat it as a valid request; because we do not sell or share personal information, there is currently nothing for such a signal to opt you out of.
How to exercise your rights. Email privacy@[service-domain]. We may need to verify your identity. We will respond without undue delay and in any event within one month of receiving your request; where a request is complex or you have made a number of requests, we may extend this by up to two further months and will tell you within the first month, explaining why. For California residents, we will respond within the 45-day period the CCPA allows, which we may extend by a further 45 days for complex requests, with notice. Exercising these rights is free unless a request is manifestly unfounded or excessive.
9. Cookies, local storage, and opt-out signals
The Service uses only essential cookies and browser storage (for example your sign-in/session token and your language and studio preferences). We do not use advertising, tracking, or analytics cookies. Third parties embedded to run the Service — such as LiveKit, Stripe (including Stripe's fraud-detection cookies under its own policy), and any YouTube embeds — may set their own cookies under their policies. Because we do not sell or share personal information, there is nothing for a Global Privacy Control (GPC) or similar opt-out preference signal to opt you out of; if our practices ever change, we will treat a recognized GPC signal as a valid opt-out request. See our separate Cookie/Storage Policy for details.
10. Subscriptions, free trial, and recurring billing (定期購入)
Paid plans (Community ¥6,000 / Pro ¥12,000 / Studio ¥24,000 per month; yearly ~30% off) include a 7-day free trial that, unless cancelled, automatically converts to a paid subscription and auto-renews until you cancel. In line with the 改正特定商取引法 (Art. 12-6 display duty and Art. 15-4 rescission right), before you subscribe we present a dedicated 最終確認画面 (final confirmation screen) — in Japanese for consumers in Japan — that clearly shows:
- 分量: that the plan renews automatically until you cancel, and the billing cycle (monthly or yearly);
- 対価・販売価格: the amount charged after the trial (tax included, JPY);
- 支払時期・方法: the first charge occurs at the end of the 7-day trial, then on each monthly/yearly renewal, via the payment method on file;
- 申込みの撤回・解除に関する事項: the exact, one-step cancellation path (via the Stripe Customer Portal / your account settings), including that cancelling during the trial avoids any charge.
The same recurring-purchase terms appear in Terms clause 6 and on our 特定商取引法に基づく表記 page. We do not rely solely on Stripe's generic checkout screen for these statutory disclosures.
11. Guests and viewers
- Guests. When a Host invites you into a room, your camera, microphone, and display name are shared with the room and may be broadcast and/or recorded. You control your own device (you can mute, disable your camera, or leave). The Host — not the Operator — is responsible for telling you when YouTube broadcasting or recording is happening, for obtaining any consent required by law (including two-party/all-party recording-consent laws and any Article 9 explicit consent), and for complying with its own controller duties.
- Viewers. Public YouTube live-chat messages and Super Chat data may be retrieved and displayed to the Host inside the studio. The Operator processes this on the Host's instruction; the viewer's primary relationship is with YouTube under YouTube's and Google's policies.
12. Children
The Service is intended for adults (18+ or the age of majority where you live) and is not directed to children under 13 — or under the applicable age of digital consent in your country (up to 16 in parts of the EU).
We do not knowingly collect personal information (including camera, microphone, or recordings) from anyone under that age. This applies to the Operator directly: because we ingest, route (via LiveKit), and may store or record Guest camera, microphone, and display name, if we become aware that a Guest or other individual under the applicable age has had personal data collected through the Service, we will delete it and may suspend or terminate the responsible Host account (see Terms clause 14.2). Hosts must not bring a known under-age Guest into a room. If you believe a child has provided us data, contact us and we will delete it.
13. Security and breach notification
We use reasonable technical and organizational measures to protect personal data, including:
- Encryption in transit (TLS) for data moving between you, the Service, and our providers;
- Encryption at rest for personal data, including Google/YouTube OAuth tokens (stored encrypted with restricted key access) and recordings in your Library;
- storage of passwords only as scrypt hashes;
- restricted access to OAuth tokens, keys, and secrets; and
- reliance on PCI-DSS-compliant Stripe for all card handling (we never store card numbers).
Because the Service uses Google restricted/sensitive OAuth scopes, we maintain the security posture Google's API Services User Data Policy requires for such scopes, including encryption of that data at rest and, where applicable, the annual restricted-scope security assessment (CASA). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
外的環境の把握 (APPI). Some personal data is stored or processed on servers located in [list actual countries — e.g. the United States and/or the EU]. Our safeguards take into account those countries' data-protection regimes. Further detail about where specific data is stored is available on request.
Breach notification. Our duties depend on our role:
- Where we are the controller (account, billing, authentication, YouTube-connection data): we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach likely to result in a risk to rights and freedoms (GDPR Art. 33); and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to them (GDPR Art. 34).
- Where we act as a processor for a Host (guest/viewer content, recordings): we will notify the Host (controller) without undue delay after becoming aware of a breach (GDPR Art. 33(2)), so the Host can meet its own obligations.
- Under Japan's APPI: we will report to the Personal Information Protection Commission (個人情報保護委員会) and notify affected individuals as and when the APPI requires (including a prompt preliminary report and a final report).
We maintain incident-response and logging capabilities intended to meet these deadlines.
14. Contact
Questions, requests, or complaints about privacy: privacy@[service-domain] (rights requests and grievances). Security/breach reports: security@[service-domain]. Copyright/DMCA notices: legal@[service-domain]. EU/EEA and UK users may also contact the Article 27 representatives named in Section 1.1. The Operator's legal name and postal address appear in Section 1; its telephone number and further registered details appear on the 特定商取引法に基づく表記 page.
15. 特定商取引法に基づく表記 (Japan)
For consumers in Japan, our 特定商取引法に基づく表記 page sets out all mandatory 通信販売 items, including: 販売価格・消費税 (tax-included JPY prices); 追加手数料等; 支払方法と支払時期 (first charge at trial end; monthly/yearly thereafter); 役務の提供時期 (決済完了後直ちに); 返品・キャンセルに関する特約 (digital service — no refunds/returns except as required by law, matching Terms clause 6.6); 事業者の氏名・住所・電話番号 (with the sole-proprietor on-request disclosure method clearly stated and answered 遅滞なく through a monitored channel); 運営統括責任者名; and 申込みの有効期限. See the recurring-purchase block in Section 10.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified in-app and/or by email, and the "Last updated" date above will change. Continued use after changes take effect means you accept the updated Policy.
This document is a template provided for convenience and does not constitute legal advice. Data-protection, consumer, and copyright laws differ by country and change over time. Before launch, the Operator should have this Privacy Policy — together with the appointment of the EU/EEA and UK Article 27 representatives, the Data Processing Addendum, the APPI cross-border consent/verification mechanics, the 特定商取引法 disclosures and 最終確認画面, and the sub-processor and encryption-at-rest arrangements referenced above — reviewed and finalised by qualified legal counsel in the relevant jurisdictions.