Privacy Policy
How Streamliner collects, uses, stores, and shares information when you use streamliner.tv and related products.
Effective date: September 27, 2026
Streamliner (“Streamliner,” “we,” “us,” or “our”) operates streamliner.tv, a studio for live-stream graphics (stingers, frames, alerts, and related tools). This Privacy Policy describes how we handle information when you visit our website, create an account, use the editor, publish browser-source overlays, connect third-party services, use optional Premium features, or use companion software such as the Streamliner Music Magic browser extension or the Streamliner Stream Deck integration.
By using Streamliner, you agree to this Privacy Policy. If you do not agree, do not use the service.
1. Summary
- We collect information needed to run your account, store your projects, render exports, serve live overlays, and operate integrations you choose to enable.
- We do not sell your personal information and we do not share it with third parties for their own marketing or advertising.
- We use Google Cloud Platform and Firebase (authentication, database, file storage, server functions, and product analytics) to host and measure the product. When you connect optional services, limited data is exchanged with those providers only as needed for the feature you turned on (for example Streamlabs alerts or Spotify now playing).
- Some overlay URLs and assets are public by design so broadcasting software can load them. Treat published overlay links like shareable capability URLs.
2. Scope
This policy applies to:
- The Streamliner website and signed-in studio (projects, gallery, account, Music Magic, Premium checkout, and documentation).
- Live overlay pages served at paths such as
/o/[token]. - Server APIs used by the site, browser extension, Stream Deck plugin, and external trigger tools.
- The Streamliner Music Magic Chrome extension (when installed and paired to your account).
It does not govern third-party websites or apps you link to from Streamliner (for example Streamlabs, Spotify, Stripe checkout, or Google Fonts). Those services have their own policies.
3. Information we collect
3.1 Account and profile
When you register or sign in, we use Firebase Authentication (hosted at auth.streamliner.tv) with either:
- Google sign-in (Google provides your account identifier, email, display name, and profile photo URL to Firebase), or
- Email and password (you provide email and password; Firebase stores authentication credentials).
After sign-in, we create or update a profile record in Cloud Firestore under your user id, typically including:
- Email address (when available from your auth provider)
- Display name (up to 80 characters)
- Profile photo URL (HTTPS link only, when provided)
- Account creation and update timestamps
We use this information to identify your account, show your profile in the studio, and associate your projects and settings with you.
3.2 Projects, palettes, and user content
When you use the studio, we store data you create or upload, including:
- Project metadata (name, timestamps, owner id).
- Composition documents (canvas settings, colors, animation parameters, text, layout, and other design settings you configure in the editor).
- Color palettes you save.
- Image library entries and project assets (for example logos and graphics), stored in Firebase Cloud Storage with metadata in Firestore.
- Project poster images (WebP previews) in Cloud Storage.
- Trigger set definitions (names, project references, and key order for Stream Deck workflows), when you use that feature.
This content is your data. We process it to save your work, render previews, enforce plan limits, and publish overlays you choose to publish.
3.3 Local storage on your device
Before or alongside cloud sync, the browser may use:
- IndexedDB (
streamliner) to hold projects locally when you are not signed in or during migration. - localStorage for small flags (for example one-time migration of local projects to your account, or throttling poster uploads).
We do not use these mechanisms for cross-site tracking.
3.4 Published overlays and public reads
When you publish an element or frame as a browser source, Streamliner generates an overlay token and stores a document in the overlays collection that includes:
- Your composition and image references needed to draw the overlay.
- Optional live alert fields (for example donor name, amount, message, subscription tier) when alerts are triggered.
- Optional now playing music fields (title, artist, album, artwork URL, playing state) for Premium music features.
- Optional Streamlabs socket token reference when you connect Streamlabs (see below).
- Owner id and project id for your account management.
Anyone who knows the overlay URL can load that page and receive live updates (for example via Firestore listeners). Overlay image files under overlays/{userId}/{token}/… in Cloud Storage are world-readable so OBS, Streamlabs, and similar tools can fetch them without signing in.
Stream Deck counters: If your composition includes a counter with a Stream Deck element id, the counter value is stored in Firestore. The id acts as a capability: clients that know the id (including the Stream Deck plugin, without a Streamliner login) may increment or read the counter through our HTTP API, subject to our rules.
3.5 Streamlabs integration (optional)
If you connect Streamlabs from your account:
- We run an OAuth flow with Streamlabs and request the
socket.tokenscope. - We exchange an authorization code for access, then obtain a Streamlabs socket token.
- We store that socket token in Firestore on your account (
integrations/streamlabs) and may copy it onto your published overlay documents so the overlay player can subscribe to alert events.
When alerts fire, Streamlabs sends event payloads to the overlay player in your browser (for example donor display name, amounts, messages, follow/subscription details). Streamliner maps those events into on-screen alert graphics. We do not use Streamlabs data for advertising. Disconnecting Streamlabs removes the stored token from your account settings (overlay documents are updated accordingly).
Short-lived HTTP-only cookies (sl_state, and temporarily sl_socket) may be set during OAuth to prevent CSRF and complete the connection flow.
3.6 Spotify and Music Magic (optional, Premium)
Spotify (Premium): Music Magic can use your own Spotify developer application. You enter a Client ID and Client Secret in the studio. We store those credentials and, after you authorize Spotify, OAuth refresh and access tokens in server-only Firestore paths (secrets/spotify). We store non-secret status in integrations/spotify (for example connected state, Spotify display name, subscription product type, client id).
With your authorization, our servers call Spotify’s Web API to read playback state, playlists, and search, and to control playback when you use those controls. Scopes include reading email/profile, playback state, currently playing track, modifying playback, and private playlists.
Browser tab source (Premium): Alternatively, you can pair the Streamliner Music Magic Chrome extension:
- You generate a short pairing code in Music Magic.
- The extension submits the code to our API and receives an opaque device token.
- The extension stores the token in Chrome local storage and sends now playing metadata (title, artist, album, artwork URL, playing state) from the audible browser tab to our API over HTTPS.
We hash device tokens at rest, maintain a server session mapping, and write the latest track to your account (music/nowPlaying) and to overlay documents you configure. The extension does not send your Streamliner email to our servers; it only uses the pairing token.
You can disconnect Spotify or the browser reader from Music Magic or the extension popup.
Short-lived HTTP-only cookies (sp_state) may be used during Spotify OAuth.
3.7 Stream Deck integration (optional)
When you pair a Stream Deck device:
- The plugin obtains a pairing code and poll token from our API, which you approve in the signed-in studio.
- We issue a device token; only a hash of that token is stored (
deckDevices,deckSessions). - You may assign a device name for display on your account page.
The plugin uses the token to call APIs (for example listing triggers, firing actions, session management). You can revoke devices from your account.
3.8 HTTP triggers (optional)
Third-party tools (including Stream Deck and custom scripts) may call our trigger HTTP API with:
- A counter id (increment, set, reset, or read), or
- An overlay token and alert action (for example
tip,subscription,arrival,redemption) plus text fields such as name, amount, and message, or - A track action with now playing fields for Premium overlays.
Request parameters may appear in query strings or form bodies. Our servers validate tokens and update Firestore overlay or counter state. Do not embed secrets in URLs you share publicly.
3.9 Premium payments (Stripe)
When you purchase Premium, checkout is handled by Stripe (hosted checkout at checkout.stripe.com). We pass your Firebase user id and, when available, your email to prefill checkout. Payment card numbers are collected by Stripe, not by Streamliner.
After a successful payment, our Cloud Functions record:
- Premium entitlement flags on your account (
billing/premium). - A Stripe event id and related metadata (event type, live/test mode, checkout session id, optional Stripe customer id) in a server-only
stripeEventscollection for idempotency and support.
We do not store full payment instrument details on our servers.
3.10 Video renders (Cloud Functions)
When you request a WebM render, you upload frame images to Cloud Storage; a Cloud Function encodes video (using ffmpeg) and writes output to renders/{userId}/{jobId}/…. We create notification documents so the studio can show encode status. Render files are readable only by you (authenticated as the owner).
3.11 Notifications
We write in-app notifications (for example render ready or failed) to Firestore under your user id. You can mark them read in the studio.
3.12 Administrative access
A small set of administrator accounts (Firebase custom claim admin) can list user profiles and Premium flags to operate the service (for example support and manual entitlement adjustments in non-production admin tools). Admin tools are not exposed on the public production site.
3.13 Server and security logs
Like most hosted applications, our infrastructure on Google Cloud and Firebase App Hosting may automatically log IP addresses, request paths, timestamps, user agents, and error diagnostics. We use these logs to secure the service, debug failures, and prevent abuse. Log retention follows Google Cloud/Firebase defaults and our operational practices.
3.14 Cookies and similar technologies
We use cookies only where needed for core functionality, principally:
| Cookie / storage | Purpose | Duration |
|---|---|---|
| Firebase Auth session | Keep you signed in | Per Firebase / browser session |
sl_state, sp_state | OAuth CSRF protection for Streamlabs / Spotify | Short (minutes) |
sl_socket | Complete Streamlabs socket token handoff during connect | Very short |
Chrome extension local storage | Music Magic pairing token | Until you disconnect |
_ga, _ga_* | Google Analytics: distinguish browsers and measure site usage | Up to 2 years |
We do not deploy third-party advertising cookies on streamliner.tv.
We use Google Analytics, initialized through the Firebase JavaScript SDK, to measure how the website and signed-in studio are used (pages viewed, approximate device and browser, and — when you are signed in — your Firebase user id). Analytics is not loaded on live overlay pages (/o/…), so browser sources in broadcasting software are not counted as visits. Advertising features and ad personalization signals are turned off in the app. We do not send project contents, alert payloads, or email addresses to Analytics.
3.15 Fonts
If you choose a Google Font in the editor, your browser loads font files from Google Fonts (fonts.googleapis.com / font.gstatic.com). Google may receive your IP address and font request metadata under its policies. We also host a font catalog JSON on our origin for the font picker.
4. Information we do not collect
We designed Streamliner to minimize collection. Unless you provide it or enable a feature that requires it, we do not intentionally collect:
- Sale of personal information to data brokers or ad networks.
- Precise geolocation, government identifiers, or health data.
- Your streaming platform passwords (Twitch, YouTube, etc.).
- Raw audio or video from your broadcasts or desktop.
- Full browsing history from the Music Magic extension (only metadata from the single audible tab when paired).
- Page contents beyond media-session metadata in that tab.
- Payment card numbers or bank account details (Stripe processes payments).
- Streamlabs or Spotify passwords (OAuth is used instead).
If you do not connect Streamlabs, Spotify, Music Magic, or Stream Deck, we do not receive data from those integrations.
5. How we use information
We use the information described above to:
- Provide, maintain, and improve Streamliner.
- Authenticate you and secure your account.
- Store and sync your projects, assets, and settings.
- Publish and update live overlays and counters you configure.
- Operate optional integrations you enable.
- Process Premium purchases and enforce plan limits.
- Encode and deliver render jobs.
- Respond to support requests and protect against fraud or abuse.
- Measure use of the website and studio.
- Comply with law and enforce our terms.
We do not use your project content or alert payloads for targeted advertising.
6. How we share information
We do not sell personal information. We do not share it with third parties for their independent marketing purposes.
We disclose information only in these circumstances:
| Recipient | Why data is shared |
|---|---|
| Google Cloud / Firebase (Auth, Firestore, Cloud Storage, Cloud Functions, App Hosting) | Host the application, store your account and content, run server logic |
| Google Analytics (via Firebase) | Receive usage measurements for the website and studio (page views, device and browser data, and Firebase user id when signed in). Overlay pages are excluded |
| Stripe | Process Premium payments you initiate |
| Streamlabs | When you connect Streamlabs, to obtain a socket token and receive alert events in your browser |
| Spotify | When you connect your Spotify app, to read/control playback per your OAuth scopes |
| Google Fonts | When your browser loads fonts you select |
| The public or anyone with a link | Published overlay URLs, public overlay assets, and counter ids you embed in tools |
| Legal and safety | When required by law or to protect rights, safety, and integrity of the service |
Service providers process data under their terms and our instructions only as needed to provide the service. We remain responsible for our platform’s handling of your data as described in this policy.
7. Your choices and controls
- Account: Sign out at any time. Email/password users manage credentials through Firebase Auth flows.
- Integrations: Disconnect Streamlabs, Spotify, or the Music Magic browser reader from Account or Music Magic. Revoke Stream Deck devices from Account.
- Overlays: Unpublish or delete overlay documents from the studio to stop public serving. Rotate overlay tokens by republishing if a URL leaks.
- Premium: Premium status is stored on your account; payment history details live primarily with Stripe.
- Local data: Clear site data in your browser to remove IndexedDB/localStorage for streamliner.tv.
Account deletion: The studio does not yet offer a one-click delete-everything control. To request deletion of your account and associated cloud data, contact us (Section 12). Some logs or backups may persist for a limited period as described by our infrastructure providers.
8. Data retention
We retain account and project data while your account is active and as needed to provide the service. Server-only records (OAuth secrets, hashed device tokens, Stripe event ids) are kept while the related feature is enabled or as required for billing and security. You may delete individual projects, assets, and integrations from the product where those controls exist.
9. Security
We use industry-standard measures appropriate to a hosted web application, including HTTPS, Firebase security rules, server-side storage of sensitive tokens, hashed device tokens, and scoped OAuth flows. No method of transmission or storage is completely secure; use a strong password and protect overlay URLs and Stream Deck counter ids.
10. Children’s privacy
Streamliner is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
11. International users
Streamliner is operated from the United States. If you access the service from other regions, your information may be processed in the United States and other countries where Google Cloud operates data centers. By using Streamliner, you consent to that transfer to the extent permitted by law.
Depending on where you live, you may have rights to access, correct, delete, or restrict certain processing of your personal information, and to object to processing or request portability. California residents: we do not sell personal information as defined by the CCPA/CPRA. To exercise rights, contact us (Section 12). We may need to verify your request via your signed-in account or email.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be noted in the product. Continued use after changes means you accept the updated policy.
13. Contact
Questions about this Privacy Policy or our data practices:
Email: privacy@streamliner.tv
Website: https://streamliner.tv