Privacy Policy
Last updated: September 23, 2026
Effective: September 23, 2026
The short version
We run streaming infrastructure, not an advertising business. We collect what we need to run your server, bill you, and keep the thing online. We do not sell your personal information. We do not watch your streams. We do not use your video, audio, or chat to train machine learning models. We do not track your location.
The rest of this page is the detail.
1. Who this covers
This policy explains how [LEGAL ENTITY] ("CueIRL", "we", "us") handles personal information across cueirl.com and its subdomains, the CueIRL iOS and Android apps, the browser studio, and the cloud OBS servers we run for you.
For the personal information of your own viewers that flows through CueIRL (chat messages, for example), you are the controller and we act as your processor. For your account, billing, and device information, we are the controller.
2. What we collect
Account information
- Email address
- A hashed password, if you sign up with email (we never store the password itself)
- Your Twitch or Google account identifier, display name, and email, if you sign in that way. We ask for the narrowest scopes we can and we do not read your Google or Twitch data beyond what sign-in and publishing need.
- Account creation date, last sign-in, and which plan you are on
Billing information
Payments are processed by Stripe. Your full card number never reaches our servers.
We store: the card brand, last four digits, and expiry date so you can recognize it; your billing email, country, and postal code; your invoice history and amounts; and Stripe's identifiers for your customer and subscription records. For Custom plans we may also hold a company name, billing contact, and purchase order reference.
Your streaming setup
Scene names and layouts, overlay configuration, ingest feed names, audio mixer settings, destination names, and the server region you are assigned. Stream keys and platform credentials are stored encrypted, and we treat them as secrets.
Platform connections
When you connect Twitch, Kick, or YouTube, we store the access and refresh tokens needed to publish your stream and, if you turn it on, to read chat. You can disconnect a platform at any time from the app, which revokes our token.
Video and audio
Your live video and audio pass through our servers so they can be decoded, composited, encoded, and published. In normal operation that content is processed in memory and in short-lived transport buffers, and it is not retained after the session.
Video and audio are stored only when you use cloud recording (Pro and Custom plans) or when you save a local recording on your own device, which stays on your device.
We do not review, transcribe, analyze, or monetize your stream content.
Chat
When unified chat is enabled, messages from Twitch, Kick, and YouTube pass through your server so the app and your overlay can display them. We hold them transiently for the length of your session and do not build a searchable archive of them. Those messages are your viewers' content, and the platform each message came from is also handling it under its own privacy policy.
Technical and connection data
To keep streams alive and to debug them, we collect: bitrate, packet loss, RTT, dropped frames, resolution and codec, connection type (cellular or WiFi), device battery level as reported by the app, IP addresses of connecting encoders and of your control sessions, device model, OS version, and app version.
Session logs
Your server keeps a rolling session log, and you can export the last 24 hours from the app. Logs contain the technical data above and the actions taken in your session, such as scene cuts and destination toggles. Logs do not contain your video or audio.
Push notifications
If you allow alerts, we store a push token from Apple (APNs) or Google (FCM) so we can notify you when your stream needs attention.
Support and sales
Emails you send us, and anything you fill in on the Contact Sales form (name, email, company or channel, what you are looking for, camera and budget ranges, city or region, and what you tell us about your stream).
Website analytics
We use privacy-respecting, aggregated analytics on cueirl.com to see which pages people read. We do not run advertising trackers, ad pixels, or cross-site profiling.
3. What we do not collect
- Precise location. We never ask for GPS and we do not track where you are. The app shows cellular and WiFi strength from your device's own radios. We can infer a rough region from an IP address for routing and fraud checks, which is not the same as tracking you.
- Your contacts, photo library, calendar, or messages.
- Biometrics or face recognition. Face detection for autofocus, if your phone does it, happens on your phone and never leaves it.
- Advertising identifiers. We do not use IDFA or GAID, and we do not build ad profiles.
- Full card numbers or bank credentials.
4. Device permissions the app asks for
| Permission | Why | If you refuse |
|---|---|---|
| Camera | To capture video in camera mode | Camera mode cannot capture |
| Microphone | To capture audio | Your stream has no sound |
| Notifications | Stream alerts when something needs attention | No alerts, everything else works |
| Local network | To find USB and external cameras and local encoders | External sources may not be found |
| Photos / storage | Only to save a local recording you asked for | Local recordings cannot be saved |
| Background activity | To keep streaming with the screen off | The stream ends when you leave the app |
You can change any of these in your phone's settings at any time.
5. Why we use it
- To run the service. Provision your server, route your feeds, publish to your destinations, show chat and stats, send alerts. Legal basis: performance of our contract with you.
- To bill you. Subscriptions, ingest feeds, trials, invoices, tax. Legal basis: contract, and legal obligation for tax records.
- To keep things secure and working. Detect abuse, investigate incidents, stop fraud and trial abuse, diagnose failures. Legal basis: legitimate interests.
- To support you. Answer your emails and, when you ask us to, look at your server or logs. Legal basis: contract and legitimate interests.
- To tell you things you need to know. Trial ending in three days, failed payment, incident notice, changes to these documents. Legal basis: contract.
- To improve CueIRL. Aggregated, de-identified usage and reliability figures. Legal basis: legitimate interests. This never involves reading your stream content.
- Marketing email. Only if you opt in, and every message has an unsubscribe link. Legal basis: consent.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We use these categories of service providers, under contracts that limit them to processing data on our instructions:
| Provider | What for | What it sees |
|---|---|---|
| Stripe | Payments and subscriptions | Your card, billing email, address, amounts |
| Cloud and colocation providers | Hosting your server and our platform | Encrypted data at rest, network traffic |
| Apple APNs, Google FCM | Push notifications | Push token and alert content |
| Email delivery provider | Transactional email | Your email address and message content |
| Error and uptime monitoring | Crash and failure diagnostics | Technical data, app version, error traces |
| Twitch, Kick, YouTube, and destinations you configure | Publishing your stream and reading chat | Your stream, your platform account |
We will publish a current list of subprocessors on request to [email protected].
We also disclose information:
- When the law requires it. We review every request, push back on ones that are overbroad, and tell you unless we are legally barred from doing so.
- To protect people. Where there is a credible risk of serious harm, or in a child-safety case, which we report to the appropriate authority.
- In a business transfer. If we are acquired or merge, we will tell you before your information moves, and this policy or something at least as protective will keep applying.
7. Where your data lives
Your cloud OBS server runs in the region you are assigned, close to you (current regions: [LIST REGIONS, e.g. FRA-04 Frankfurt]). Account, application, and configuration data are stored with [HOSTING/DATABASE PROVIDER] in [REGION, e.g. US-East]. Payment data is held by Stripe in the United States. Transactional email is sent through [EMAIL PROVIDER] in [REGION].
For transfers out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK Addendum where it applies, and adequacy decisions where they exist. Ask [email protected] if you want a copy of the transfer mechanism we use for a specific provider.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account record | While your account exists |
| Scenes, ingests, destinations after cancellation | 30 days, then deleted |
| Cloud recordings | While your plan includes storage, or 30 days after it stops |
| Session logs | 30 days rolling (24 hours exportable by you) |
| Technical and connection metrics | Up to 90 days in identifiable form, then aggregated |
| Chat messages | Length of the session, not archived |
| Invoices and tax records | 7 years, as tax law requires |
| Support emails | 2 years |
| Contact Sales submissions | 2 years, or until you ask us to delete them |
| Security and abuse investigation records | Up to 2 years |
Backups roll off on their own schedule, and a deleted item can sit in a backup for up to 35 days before it is gone for good.
9. Your rights
Wherever you live, you can ask us to:
- See what we hold about you
- Get a copy in a portable format
- Correct anything wrong
- Delete your account and your data
- Stop marketing email
- Object to or restrict a particular use
- Withdraw consent you gave earlier
Email [email protected]. We verify that the request is really from you, and we reply within 30 days. We do not charge for this and we will not treat you worse for asking.
Some things we have to keep even after you ask us to delete, mainly invoices and tax records, and records tied to an open abuse or security investigation. We will tell you if that applies.
If you are in the EEA or the UK: we are the controller for your account data, you can complain to your local supervisory authority, and you have the rights in Articles 15 to 22 of the GDPR. [APPOINT AN EU/UK REPRESENTATIVE IF YOU HAVE EEA/UK CUSTOMERS AND NO ESTABLISHMENT THERE, AND LIST THEM HERE.]
If you are in California: you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA as amended. We do not sell or share personal information, and we do not use or disclose sensitive personal information for anything beyond providing the service. An authorized agent can make a request for you with written proof.
We treat a Global Privacy Control (GPC) signal from your browser as a valid request to opt out of sale or sharing. You can also use the Your privacy choices link at the bottom of our website.
If you are in Colorado, Connecticut, Virginia, Texas, or another US state with a privacy law: you have equivalent rights, including the right to appeal if we refuse a request. Appeal to [email protected] with "Appeal" in the subject.
10. Security
We use TLS for everything in transit, encryption at rest for stream keys and platform tokens, hashed passwords with a modern algorithm, least-privilege access with logging for staff who can reach production, and separation between customer servers.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the relevant regulator within the time the law requires, and we will explain what happened and what to do about it.
You have a part in this too: use a strong, unique password, turn on two-factor authentication with your Twitch or Google account if you sign in that way, do not paste your stream keys into other tools, and remove team seats when people leave.
11. Cookies
We use a small number of cookies, and none of them are for advertising:
- Essential. Keeping you signed in, CSRF protection, remembering your plan toggle. These cannot be turned off without breaking the site.
- Preferences. Small things like your last selected view.
- Aggregated analytics. Which pages get read. No cross-site tracking, no ad pixels, no fingerprinting.
You can block cookies in your browser. If you block the essential ones, sign-in will not work.
12. Children
CueIRL is not for children under 13, and not for anyone under 16 in the EEA or the UK. We do not knowingly collect their information. If you believe a child has created an account, email [email protected] and we will delete it.
If minors appear in your stream, that is on you. Get the consent you need under the law that applies where you are filming.
13. Your viewers
If you use unified chat or a chat overlay, your viewers' messages and usernames flow through your server. Those viewers are your audience, and you decide what to display and what to record. Under GDPR terms, you are the controller and we are your processor for that data. If you need a Data Processing Addendum, email [email protected] and we will send you one to sign.
14. Changes to this policy
We will update this page when our practices change. For material changes we will email you and post a notice at least 30 days before they take effect, and the "Last updated" date at the top always tells you the current version. We keep previous versions available on request.
15. Contact
Privacy questions, requests, and complaints: [email protected]
[LEGAL ENTITY]
[BUSINESS ADDRESS]
