1. Controller and scope
Multistream.id ("Multistream," "we") is responsible for the information described in this policy. It covers our website, accounts and dashboard, stream relay, platform connections, OBS chat dock, support, and legacy beta form. Contact [email protected] for privacy requests.
2. Information we process
- Account and security: email, name or profile image if available, account ID, authentication sessions, login times, accepted legal document versions, and technical or security records.
- Streaming configuration: destination names and labels, RTMP/RTMPS addresses, destination stream keys encrypted at rest, their final characters for identification, session status, start/end times, forwarded bytes, and relay region. Ingest and operational logs may process your IP address and connection information.
- YouTube and Twitch connections: channel or account IDs, names/handles, connection status and permissions, encrypted access and refresh tokens, expiry, stream metadata needed for the selected features, and connection errors.
- Chat dock: chat message content, sender name and ID, source platform or channel, time, badges, emotes, and connection status. Pairing codes, hashed session verifiers/tokens, expiry and revocation status, and technical data needed to keep the dock connected are also processed.
- Website and communications: information you send to support or the legacy form, plus visit metrics from Plausible if production analytics are enabled and Google Analytics on the public marketing site only after you allow it.
3. How the chat dock works and its limits
The read-only dock starts with a single-use pairing code that expires after 10 minutes. After you confirm it from the dashboard, the dock receives a dedicated session using an HttpOnly cookie; the session's server-side permissions are limited to OBS features. It lasts up to 30 days and can be revoked. YouTube/Twitch tokens and stream keys are not sent to the OBS page. New messages are delivered through a server-sent events (SSE) connection. The chat pane is read-only and does not send messages or change moderation. Separately, an optional stream control panel may request title or category changes after you grant separate stream-control permission to that provider. A chat-only pairing does not grant that permission, so the panel is unavailable for that session.
To restore the view after a connection interruption, the in-memory replay queue is limited to 5,000 events per account; entries remain until displaced by newer events or the process ends. With Redis, replay excludes events older than one hour, and the stored list expires one hour after the latest event. This is not a permanent account chat archive or history. Live processing may also use temporary process memory; platform and infrastructure providers may keep their own logs under their policies. Chat and stream control are separate paths; stream control requires its own connection and authorization.
YouTube and Google services
A chat-only YouTube connection requests the read-only https://www.googleapis.com/auth/youtube.readonly scope to retrieve the live chat needed for the dock. Optional stream control requires separate consent and requests https://www.googleapis.com/auth/youtube.force-ssl; Google's consent screen describes this broader scope as permission to view, edit, and permanently delete YouTube videos, ratings, comments, and captions. With a separately authorized stream-control connection, Multistream reads relevant live stream information and can update a title or category you ask it to change. We do not call the API to delete videos, ratings, comments, or captions. Twitch chat uses chat:read; optional Twitch stream control separately requests channel:manage:broadcast.
API calls and live status checks are scheduled with applicable quota limits in mind; we do not use quota to circumvent Google's limits. Multistream's use of Google data complies with the Google Privacy Policy, Google API Services User Data Policy, including Limited Use requirements, and YouTube Terms of Service. To revoke Google access, visit app permissions in your Google Account. Revoke Twitch access separately in Twitch Connections settings. Removing a connection in Multistream deletes our local copy but does not by itself revoke the grant on the platform.
YouTube, Google, and Twitch operate their own services, set their own policies and processing, and are not affiliated with Multistream. Connecting an account does not transfer control of your account or content to us.
5. Purposes and legal bases
We process information to create and secure accounts, authenticate users, store configuration, relay streams, provide requested chat or control features, measure usage, prevent abuse, improve the service, respond to support requests, meet legal obligations, and send beta communications if you opt in. Depending on applicable law, processing may be based on providing the service you request, your consent, legitimate interests in security and operations, or legal obligations. Consent to the legacy waitlist only allows us to contact you and is separate from consent to use the dashboard.
6. Streams, cookies, and analytics
Video and audio are forwarded from your device through a relay to destinations you choose. The Multistream control plane does not store broadcast recordings as a current feature; relays, networks, or destination platforms may process and log traffic under their own systems. Necessary cookies support login, pairing, and request security. The website may use Plausible for visit metrics if configured. On the public marketing site, Google Analytics stays off until you choose Allow Google Analytics; after you allow it, Google may use analytics cookies. Your choice is stored in your browser's local storage and can be declined or changed through Privacy settings on the site. Your browser also communicates directly with providers needed to display the site.
When you open a referral link such as /ref/Code, we may store the code, UTM campaign parameters, click time, and a temporary HttpOnly referral cookie for up to 30 days so a new registration can be attributed to the correct source. We may process anonymized risk signals, such as device or payment patterns, to prevent self-referrals and abuse. Click, attribution, and reward-adjustment records are retained as needed for program audits, support, and legal obligations, then deleted or anonymized under our retention practices.
7. Providers and international processing
Information may be processed by authorized personnel and providers for website/API hosting, databases, relays/VPS, Redis when enabled, email, Plausible when configured, Google Analytics after consent, Google/YouTube, Twitch, and the destinations you choose. The actual vendors depend on deployment configuration and may change. They may process information in other countries and are subject to their own policies and safeguards. We may share data as needed to provide a feature you request, comply with valid legal process, protect safety, or investigate abuse. We do not sell your account tokens or stream keys.
8. Retention and deletion
We keep data as needed to provide the service, maintain security, offer support, resolve disputes, or meet legal obligations. OBS sessions last up to 30 days unless revoked earlier; pairing codes expire after 10 minutes. The in-memory chat replay queue holds up to 5,000 events until displaced or process shutdown. With Redis, replay excludes events older than one hour and its list expires one hour after the latest event. We have not set a single fixed deletion deadline that applies to every request or all copies in provider logs and backups.
You can remove connections and configuration in the dashboard, then separately revoke grants at Google or Twitch. Request account deletion or access/correction through our data deletion instructions. Some data may be retained when required by law or strictly needed for security, fraud prevention, disputes, or backup recovery. Deletion by third-party providers follows their systems and policies.
9. Security and privacy choices
We use safeguards such as encryption of stored credentials, access controls, hashed session tokens, and separation of dock authorization. Service components that perform a feature must be able to use decrypted credentials; no system is risk-free. You may contact us to request access, correction, deletion, withdraw consent, or exercise other rights available under applicable law. Withdrawing permission needed for a feature may disable that feature.
10. Changes to this policy
We may update this policy as the service or law changes. The effective date and version appear above. For material changes that require renewed consent, we will request it before dashboard access continues.