← StreamStudio Community Pro

Privacy Policy

Last updated: 9 July 2026 · Version: 3.0

This Privacy Policy explains what personal data StreamStudio Community Pro ("StreamStudio", the "Service") collects, why, how it is used and shared, and the rights you have. It applies to everyone who uses the Service worldwide. Please read it together with our Terms of Service, our Data Processing Addendum (Section 1.4), our Cookie/Storage Policy, and our Disclaimer.


1. Who we are (data controller)

The Service is operated by [Operator legal name — individual sole proprietor / 屋号: __________] (the "Operator", "we", "us", "our"), a sole proprietor based in Japan. For the personal data described in this Policy, the Operator is the data controller (in Japan, the business handling personal information / 個人情報取扱事業者).

We publish the controller's legal name and a postal contact address directly in this Policy (not only "on request"). The Operator's full registered details, including telephone number, also appear on our 特定商取引法に基づく表記 page (see Section 15). The "disclosure on request" concession under the 特定商取引法 applies only to the sole-proprietor items on that page and does not replace the identification given here.

1.1 EU/EEA and UK representatives (Article 27)

Because the Operator is established outside the Union and the UK and offers the Service to individuals in the EU/EEA and the UK on a regular, ongoing basis, we have appointed representatives under Article 27 GDPR and Article 27 UK GDPR:

You may contact either representative on all issues relating to the processing of your personal data and to exercise your rights. These appointments are a launch precondition for the EU/EEA and UK; the Service will not be offered to those regions until both are in place.

1.2 Data Protection Officer

We have carried out and documented an assessment of whether a Data Protection Officer ("DPO") is required under GDPR Article 37 (given that our core activity includes processing audio/video, recordings, and viewer chat that may reach large scale and may include special-category data). [If required: DPO name and contact details are: __________.] [If not required: no DPO is legally mandated; our privacy contact point (privacy@[service-domain]) handles all privacy matters, and the reasoned assessment is retained on file.]

1.3 Controller/host split

For your account, billing, authentication, and YouTube-connection data, the Operator is the controller. For the content you broadcast or record — including the personal data of your guests and of viewers (for example live chat and Super Chat) that passes through the Service — you (the Host) are the controller under the GDPR/UK GDPR, and the Operator acts as your processor. As the Host, you are responsible for having a lawful basis for that content and for giving your guests and audience any notices and obtaining any consents required by law (including any Article 9 explicit consent — see Section 3.3 — and recording-consent laws — see Section 11).

Japan (APPI) — no processor shield. Japan's APPI does not recognise a controller/processor split. Regardless of the allocation above, the Operator itself remains an 個人情報取扱事業者 for all personal data it handles — including guest and viewer data passing through the Service — and independently complies with its APPI duties (利用目的の特定・通知公表, 安全管理措置, 委託先の監督, 開示等請求対応, and 漏えい等報告). The Host bears its own APPI obligations in addition; the arrangement does not transfer the Operator's APPI duties to the Host.

1.4 Data Processing Addendum (where you are the controller)

Where you use the Service to process Guest or Viewer personal data as a controller, our Data Processing Addendum ("DPA") at [URL] applies and forms part of our Terms of Service. The DPA contains the full Article 28(3) processor terms, under which we commit to:


2. Who this Policy covers


3. Data we collect and why (with GDPR lawful bases)

Where the EU/UK GDPR applies, we rely on the lawful bases shown. "Contract" = necessary to provide the Service you signed up for; "Legitimate interests" = our or a third party's legitimate interests, balanced against your rights; "Consent" = your freely given consent, which you may withdraw at any time; "Legal obligation" = required by law.

Data categoryExamplesPurposeGDPR lawful basis
Account dataEmail address; optional phone numberCreate and manage your account; contact you about the ServiceContract
Authentication dataOne-time login codes (via email/SMS); passwords stored only as a scrypt hash; session tokens (30-day expiry)Verify identity; deliver the login code you request; keep you signed in securelyContract (secure authentication you requested); Legitimate interests (account security). Delivery of a login code you request is necessary for the login you asked for — it is not based on consent and cannot be "withdrawn" without breaking login.
Google/YouTube OAuth tokensAccess/refresh tokens for your YouTube channel(s)Schedule/start/stop broadcasts, upload thumbnails, read & display live chat and Super Chat — only on your instructionContract (to deliver the YouTube feature you connected). Connecting is your voluntary authorisation to access your Google account; you can disconnect or revoke at any time (Section 4).
Content you upload or createVideo/audio clips, music, images, logos, avatars, thumbnails; studio scenes and settings; recordings saved to your LibraryStore, process, and transmit to the destinations you choose; provide the DJ Mixer, Groovebox, and Recording featuresContract
Broadcast/room dataCamera, microphone, display names of Host and guests routed in real time (WebRTC)Enable live production and broadcastingContract (for you as Host); you are controller for guests/viewers
Viewer chat & Super ChatPublic YouTube live-chat messages, author names, Super Chat amounts, retrieved for display in the studioShow live audience interaction to the HostYou (Host) are controller; we process on your instruction
Billing dataStripe customer ID, subscription ID, plan, subscription status, trial/renewal dates. We never receive or store card numbers (PCI DSS SAQ-A)Manage subscription and billingContract; Legal obligation (tax/accounting). For card and payment data, Stripe acts as an independent controller — see Section 5.
Server logs / technical dataIP address, browser/user-agent, timestamps, error and diagnostic logsSecurity, abuse/fraud prevention, debugging, service reliabilityLegitimate interests; Legal obligation where applicable

3.1 Sensitive personal information (California)

Account log-in credentials (email + password) are "sensitive personal information" (SPI) under the CPRA (Cal. Civ. Code §1798.140(ae)). We use them solely to authenticate you — a permitted business purpose under §1798.140(e). We do not use or disclose SPI to infer characteristics about you. Because our use is limited to that permitted purpose, the CPRA "right to limit the use of sensitive personal information" does not require us to offer an opt-out link (see Section 8).

3.2 Automated decision-making

Except for automated fraud- and abuse-prevention checks (including risk scoring performed by our payment processor, Stripe Radar, and automated checks on our server logs), we do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you. Where a payment or account action is affected by such a check, you may contact us to request human review.

3.3 Special-category data (Article 9)

Live video and audio, recordings, and displayed chat/Super Chat can incidentally reveal special-category data — for example data about health, racial or ethnic origin, religious or political beliefs, sexual orientation, or biometric/facial data — of Hosts, guests, and viewers.


4. Google / YouTube API data (mandatory disclosures)

The Service uses the YouTube Data API v3 and Google OAuth. By connecting your YouTube account you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy).

What we access and why. With your authorization we access your YouTube channel(s) only to provide features you request: schedule and create live broadcasts, start and stop streams, upload thumbnails, and read and display live chat and Super Chat. We request the minimum scopes needed for these functions.

How we use, store, and share it. OAuth tokens are stored encrypted at rest with restricted key access, and are used only to perform actions on your instruction. We never see your Google password. We do not sell Google user data, do not use it for advertising, and do not transfer it to third parties except as needed to provide the feature you requested. Humans do not read your Google user data except: (a) with your consent for specific messages; (b) as necessary for security purposes (for example, investigating abuse or a vulnerability); (c) to comply with applicable law; or (d) where the data is aggregated and anonymized and used for internal operations in compliance with applicable law.

Limited Use. StreamStudio Community Pro's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

30-day refresh-or-delete (YouTube API requirement). As required by the YouTube API Services Terms and the YouTube API Services Developer Policies: except for OAuth authorization tokens (which we retain only while your YouTube account stays connected), we do not store any YouTube API Data for longer than 30 calendar days without refreshing it from the YouTube Data API. Any stored YouTube API Data that is not refreshed within 30 days is deleted. In practice, live-chat and Super Chat data is held only transiently to display live interaction and is not retained after the session. All YouTube API Data and OAuth tokens are deleted promptly when you disconnect YouTube, delete your account, or on request.

How to revoke access. You can (a) disconnect YouTube inside the Service at any time, and/or (b) revoke access via your Google account at https://myaccount.google.com/permissions. On disconnect or account deletion, stored Google/YouTube tokens and any cached chat data are deleted promptly.


5. Processors, sub-processors, and recipients

We share personal data only with the providers below, each acting under contract and only as needed to run the Service. We do not sell your personal data and do not share it for cross-context behavioral advertising.

ProviderRoleWhat it handlesRegionPolicy
[Cloud hosting & storage provider — e.g. name]Cloud hosting, compute, and media/object storage (sub-processor)Server hosting; storage at rest of account data, encrypted OAuth tokens, studio settings, and your recordings/Library[e.g. US / EU region][policy URL]
[Media/CDN store, if separate]Object storage / CDN for recordings & uploadsStorage and delivery of recorded and uploaded media[region][policy URL]
LiveKitReal-time media (WebRTC) infrastructure (sub-processor)Live audio/video routing for rooms and broadcasts[US/EU]https://livekit.io/legal/privacy-policy
Google / YouTubeBroadcast platform & APIOAuth tokens; broadcast, thumbnail, chat/Super Chat operationsUShttps://policies.google.com/privacy
StripePayment processing — Stripe acts as an independent/separate data controller for payment, fraud-prevention, and legal-compliance purposes under its own privacy policyCheckout, Customer Portal, subscription/customer IDs; card data (handled solely by Stripe)US/EUhttps://stripe.com/privacy
ResendTransactional email (sub-processor)Delivery of login codes and account emailsUS/EUhttps://resend.com/legal/privacy-policy
TwilioSMS delivery (sub-processor)Delivery of one-time login codes by SMS (if you provide a phone number)UShttps://www.twilio.com/legal/privacy

Stripe as controller. For card and payment data, Stripe determines its own purposes and means (payment processing, fraud prevention, and regulatory compliance) and acts as an independent controller; Stripe's privacy policy applies directly to that processing.

A current list of sub-processors is available at [URL]; we will give notice of new sub-processors before they process your data. We may also disclose data where required by law, to enforce our Terms, to prevent fraud or harm, or in connection with a business transfer, subject to this Policy.


6. International data transfers

We and our providers operate in the United States, the EU, Japan, and other countries, so your data may be transferred and processed outside your home country, including outside the EEA/UK.

Which providers are outside the EEA/UK. Google/YouTube, Stripe, LiveKit, Twilio, Resend, and our cloud hosting/storage provider are, or may be, located in the United States. The Operator is in Japan.

EU/EEA and UK transfers.

Japan (APPI) transfers. SCCs and the UK IDTA are not valid bases under the APPI, and the United States is not an APPI-designated adequate country (only the EEA and UK are). For transfers of personal data from Japan to providers in third countries (including the US), we rely on the APPI Article 28 bases: either (a) your prior consent obtained at signup, after we provide the destination country name, information about that country's data-protection regime, and the recipient's protective measures; or (b) the 基準適合体制 route (a recipient that has established equivalent standards), with ongoing verification and provision of the prescribed information on request. The APPI 委託 (outsourcing) exemption does not exempt these foreign transfers, so we do not rely on it for cross-border provision.


7. Retention

We keep personal data only as long as needed for the purposes above or as required by law:


8. Your rights

Depending on where you live, you may have some or all of the rights below. We honor the strongest applicable protections regardless of your location.

EU/UK (GDPR / UK GDPR): access; rectification; erasure ("right to be forgotten"); restriction; objection (including to processing based on legitimate interests); data portability; and the right to withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office (ICO), https://ico.org.uk/make-a-complaint/; in the EU, your national Data Protection Authority.

California (CCPA/CPRA): the right to know/access, delete, and correct your personal information; the right to opt out of sale/sharing; the right to limit use of sensitive personal information; and the right to non-discrimination for exercising your rights. This section is our notice at collection; the categories we collect and disclose are listed in Sections 3 and 5, and the sensitive personal information we collect (login credentials) and its purpose are described in Section 3.1.

Japan (APPI): you may request disclosure, correction, addition, deletion, or suspension of use of your personal data (including 開示等請求), and raise complaints, using the contact in Section 14. Our contact point also handles grievances.

Other regions: if you are covered by another law (for example Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, South Korea's PIPA, Switzerland's FADP, or US state laws such as Virginia's VCDPA or Colorado's CPA), you may have additional local rights. Contact us and we will honor them as required. Where a recognized opt-out preference signal such as GPC applies under those laws, we will treat it as a valid request; because we do not sell or share personal information, there is currently nothing for such a signal to opt you out of.

How to exercise your rights. Email privacy@[service-domain]. We may need to verify your identity. We will respond without undue delay and in any event within one month of receiving your request; where a request is complex or you have made a number of requests, we may extend this by up to two further months and will tell you within the first month, explaining why. For California residents, we will respond within the 45-day period the CCPA allows, which we may extend by a further 45 days for complex requests, with notice. Exercising these rights is free unless a request is manifestly unfounded or excessive.


9. Cookies, local storage, and opt-out signals

The Service uses only essential cookies and browser storage (for example your sign-in/session token and your language and studio preferences). We do not use advertising, tracking, or analytics cookies. Third parties embedded to run the Service — such as LiveKit, Stripe (including Stripe's fraud-detection cookies under its own policy), and any YouTube embeds — may set their own cookies under their policies. Because we do not sell or share personal information, there is nothing for a Global Privacy Control (GPC) or similar opt-out preference signal to opt you out of; if our practices ever change, we will treat a recognized GPC signal as a valid opt-out request. See our separate Cookie/Storage Policy for details.


10. Subscriptions, free trial, and recurring billing (定期購入)

Paid plans (Community ¥6,000 / Pro ¥12,000 / Studio ¥24,000 per month; yearly ~30% off) include a 7-day free trial that, unless cancelled, automatically converts to a paid subscription and auto-renews until you cancel. In line with the 改正特定商取引法 (Art. 12-6 display duty and Art. 15-4 rescission right), before you subscribe we present a dedicated 最終確認画面 (final confirmation screen) — in Japanese for consumers in Japan — that clearly shows:

The same recurring-purchase terms appear in Terms clause 6 and on our 特定商取引法に基づく表記 page. We do not rely solely on Stripe's generic checkout screen for these statutory disclosures.


11. Guests and viewers


12. Children

The Service is intended for adults (18+ or the age of majority where you live) and is not directed to children under 13 — or under the applicable age of digital consent in your country (up to 16 in parts of the EU).

We do not knowingly collect personal information (including camera, microphone, or recordings) from anyone under that age. This applies to the Operator directly: because we ingest, route (via LiveKit), and may store or record Guest camera, microphone, and display name, if we become aware that a Guest or other individual under the applicable age has had personal data collected through the Service, we will delete it and may suspend or terminate the responsible Host account (see Terms clause 14.2). Hosts must not bring a known under-age Guest into a room. If you believe a child has provided us data, contact us and we will delete it.


13. Security and breach notification

We use reasonable technical and organizational measures to protect personal data, including:

Because the Service uses Google restricted/sensitive OAuth scopes, we maintain the security posture Google's API Services User Data Policy requires for such scopes, including encryption of that data at rest and, where applicable, the annual restricted-scope security assessment (CASA). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

外的環境の把握 (APPI). Some personal data is stored or processed on servers located in [list actual countries — e.g. the United States and/or the EU]. Our safeguards take into account those countries' data-protection regimes. Further detail about where specific data is stored is available on request.

Breach notification. Our duties depend on our role:

We maintain incident-response and logging capabilities intended to meet these deadlines.


14. Contact

Questions, requests, or complaints about privacy: privacy@[service-domain] (rights requests and grievances). Security/breach reports: security@[service-domain]. Copyright/DMCA notices: legal@[service-domain]. EU/EEA and UK users may also contact the Article 27 representatives named in Section 1.1. The Operator's legal name and postal address appear in Section 1; its telephone number and further registered details appear on the 特定商取引法に基づく表記 page.


15. 特定商取引法に基づく表記 (Japan)

For consumers in Japan, our 特定商取引法に基づく表記 page sets out all mandatory 通信販売 items, including: 販売価格・消費税 (tax-included JPY prices); 追加手数料等; 支払方法と支払時期 (first charge at trial end; monthly/yearly thereafter); 役務の提供時期 (決済完了後直ちに); 返品・キャンセルに関する特約 (digital service — no refunds/returns except as required by law, matching Terms clause 6.6); 事業者の氏名・住所・電話番号 (with the sole-proprietor on-request disclosure method clearly stated and answered 遅滞なく through a monitored channel); 運営統括責任者名; and 申込みの有効期限. See the recurring-purchase block in Section 10.


16. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified in-app and/or by email, and the "Last updated" date above will change. Continued use after changes take effect means you accept the updated Policy.


This document is a template provided for convenience and does not constitute legal advice. Data-protection, consumer, and copyright laws differ by country and change over time. Before launch, the Operator should have this Privacy Policy — together with the appointment of the EU/EEA and UK Article 27 representatives, the Data Processing Addendum, the APPI cross-border consent/verification mechanics, the 特定商取引法 disclosures and 最終確認画面, and the sub-processor and encryption-at-rest arrangements referenced above — reviewed and finalised by qualified legal counsel in the relevant jurisdictions.