Stream Ease
Sign in

Privacy Policy

Effective 18 August 2026

Who we are

Stream Ease is operated by Mile End Media Limited, a company registered in England & Wales under company number 17030248, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the data controller for the personal data described in this policy, and we are registered with the Information Commissioner’s Office under registration reference ZC187020.

For any privacy question or request, contact privacy@streamease.co.uk.

What we collect and why

The personal data Stream Ease holds, where each item comes from, and why we hold it.
DataWhere it comes fromWhy we hold it
Email address, name and profile pictureYour Google account, when you sign inTo create your account and show who is in a broadcast
YouTube authorisationGoogle, when you connect your channelTo create and control broadcasts on your behalf
Show details — title, schedule, statusYouTo run and display your broadcasts
Scene layouts and uploaded imagesYouTo compose what your viewers see
Participant display namesYou and your guestsTo label people in the studio and on screen
Chat messages and display names of viewersYouTube live chat, during a broadcastTo show chat on your broadcast and power features that use it during the show
A one-way identifier derived from a viewer’s YouTube channelYouTube live chat, during a broadcastSo each viewer is counted once in a poll
Server logs, including IP address and request metadataAutomatically, as you use the serviceSecurity, debugging and service reliability

Our lawful basis is performance of a contract with you — we cannot provide the service without this data — except for server logs, which we keep on the basis of our legitimate interest in operating a secure and reliable service.

Google user data and Limited Use

When you connect your YouTube channel, we request a single OAuth scope: https://www.googleapis.com/auth/youtube.force-ssl. We use it only to create a broadcast and a stream on your channel, bind them together, tell YouTube to start and stop the broadcast around your show, read your broadcast’s live chat while it is running, and delete a broadcast we created if it fails to start.

Stream Ease’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising, it is not used to train artificial intelligence or machine learning models, and it is not read by any person except with your explicit consent, where necessary for security purposes, or where we are required to do so by law.

Your Google authorisation is stored as an encrypted refresh token in Supabase Vault. It is never sent to your browser and never written to our logs.

How we protect your data

These protections are properties of how Stream Ease is built rather than promises about how we behave. The first of them is that we hold very little in the first place: your broadcast is never recorded, your YouTube stream key is never stored, and viewer chat is deleted an hour after the show ends.

  • Your Google authorisation is encrypted and held apart from everything else. The refresh token that lets us act on your YouTube channel is stored in Supabase Vault, encrypted at rest and kept out of our ordinary application tables. It can be read only by a dedicated database function, and only by a privileged server-side key that never leaves our server and is never sent to a browser. The token is not written into any page, API response or log.
  • Your YouTube stream key is never written down anywhere. YouTube issues it when a broadcast starts; it is passed straight to the encoder that needs it and held only for the life of that broadcast. It reaches no database, no log and no response body.
  • Encryption in transit. The site is served over HTTPS only, with HTTP Strict Transport Security set for two years and including subdomains, so a browser will not connect to us unencrypted. Live audio and video between participants and our streaming servers travel over WebRTC, which is encrypted by the standard and cannot be turned off.
  • Encryption at rest. Our database and file storage are hosted by Supabase on Amazon Web Services in London, and are encrypted at rest by the provider.
  • One customer cannot reach another’s data. Every table enforces row-level security inside the database, denying access by default and permitting it only to members of the workspace that owns the row. Because the rule is enforced by the database rather than by application code, a mistake in the application cannot step around it. We maintain automated tests whose only purpose is to prove that one workspace cannot read another’s data.
  • Least privilege. We request a single Google permission, and use it only against the channel you connected. Joining a live room requires a short-lived token issued by our server for one room and one role, so a browser never holds a credential that would work anywhere else.
  • Hardened in the browser. We serve a Content Security Policy that restricts what a page may load and where it may send data, refuse to be embedded in other sites, stop browsers guessing file types, and allow camera, microphone and screen capture only on our own pages while blocking location access entirely.
  • Credentials are kept out of our source code. They live in an encrypted configuration store, never in the code repository. That repository is scanned automatically for credentials, and a push containing one is blocked rather than merely reported; a further check runs before any change is committed.
  • We keep the software patched. Our dependencies and our own source code are scanned automatically for known vulnerabilities, and a failing security or test check prevents a release reaching production.
  • We never handle your password. Signing in is delegated to Google, so no password for your account is seen, received or stored by us.
  • If something goes wrong. Where a personal data breach occurs, we will report it to the Information Commissioner’s Office within 72 hours where the law requires it, and tell affected users directly where the risk to them is high.

What we do not do

  • We do not record your broadcasts. Audio and video pass through our streaming infrastructure in real time and are composed into the picture sent to YouTube. No part of Stream Ease writes the audio or video from your broadcast to storage. YouTube may keep its own recording of the finished broadcast on your channel, governed by YouTube’s terms rather than ours.
  • Uploaded media is stored, until you delete it. Files you choose to upload to your media library — video, audio and images — are stored in our Supabase file storage in London (eu-west-2) until you delete them. Deleting a file removes it.
  • We never store your YouTube stream key. It is passed directly to the streaming service that needs it and is not saved to any database, log or response.
  • We do not sell your personal data, and we do not use it for advertising.
  • We do not use analytics, advertising or third-party tracking services.

Who processes data for us

  • Supabase — database, authentication, file storage and encrypted secret storage. Your data is held in the London (eu-west-2) region.
  • LiveKit — real-time audio and video transport, and composing your scene into the broadcast picture.
  • Vercel — application hosting.
  • Hetzner — hosting, in Germany, for the service that reads your broadcast’s live chat.
  • Google / YouTube — sign-in, and the destination your broadcast is sent to.

Some of these providers may process data outside the United Kingdom. Where they do, the transfer is covered by the provider’s standard contractual clauses or an equivalent safeguard.

How long we keep it

We do not delete data automatically. Your account, workspace, shows and scenes are kept until you ask us to delete them or to close your account. Your YouTube authorisation is held until you revoke access at Google or ask us to delete it. If you ask us to erase your data, we will do so within 30 days.

Links to images you upload are time-limited and expire after 12 hours, but the images themselves stay in your workspace until you delete them.

Chat messages captured from a YouTube broadcast are different: we delete them an hour after the broadcast ends. YouTube keeps its own record of live chat on the video’s replay, so Stream Ease is not the system of record for it and has no reason to hold it. Deletion is performed by a scheduled job, not by hand.

The one-way identifier we derive for polls is deleted at the same time, an hour after the broadcast ends, together with the random value that poll used to derive it. That random value is unique to a single poll and is never reused, so once it is gone the identifier cannot be worked back to a YouTube channel. We never hold the channel itself: the identifier is calculated as a chat message is read and it is the only form we store.

The results of a poll are kept, and are not deleted on that timetable: the question, the options and the running totals stay with your show, so a series of polls can be compared over a season. Once the votes and that random value have been deleted, those results are counts and averages with nothing in them that identifies a viewer.

How to revoke our access to your YouTube channel

You can withdraw our access at any time:

  • Remove Stream Ease at myaccount.google.com/permissions. This revokes the authorisation at Google directly and immediately stops us being able to create or control broadcasts on your channel.
  • Email privacy@streamease.co.uk and we will disconnect the destination and delete the stored authorisation.

Your rights

Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. To exercise any of these, email privacy@streamease.co.uk.

If you are not satisfied with our response, you can complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk.

Cookies

We set only the cookies the service needs to work: a session cookie that keeps you signed in, and a short-lived cookie that protects the YouTube connection flow against cross-site request forgery. We do not use analytics, advertising or tracking cookies, so we do not ask for cookie consent.

Children

Stream Ease is not intended for anyone under 18, and you must be 18 or over to create an account.

Changes to this policy

If we change how we handle personal data we will update this page and change the effective date above. If the change is significant, we will tell account holders by email.

© 2026 Mile End Media Limited. Registered in England & Wales, company number 17030248.

PrivacyTerms