Legal

Privacy Policy

Your stream keys stay encrypted. Your data stays yours. We don’t sell it.

Last updated July 29, 2026

1. Who we are

SlimCast is operated by AbstraScapes LLC, a Florida, USA limited liability company (“SlimCast,” “we,” “us”). This policy explains what data we collect when you use the SlimCast website, dashboard, and OBS plugin, why we collect it, and the choices you have.

2. The short version

We collect only what’s needed to run the service and bill you correctly. We do not sell your personal information, and we never will. Your platform stream keys and OAuth tokens are encrypted at rest and are never shared with the rented GPUs that transcode your video.

3. Information we collect

We collect the following categories of information:

  • Account information: your email address, authentication credentials (handled by our auth provider, Supabase), and account preferences (output resolution, orientation, portrait-crop settings).
  • Platform connections: if you connect Twitch, YouTube, or Kick via OAuth, we store the access/refresh tokens needed to fetch your stream key. If you paste a stream key manually (e.g. TikTok), we store that key. All keys and tokens are encrypted at rest with AES-256-GCM and decrypted only to configure your stream. When you use the SlimChat dock or stream-info sync, we also use these connections to read and send chat messages, perform moderation actions you invoke, and update the stream title and tags you set. For YouTube specifically, we request manage access to your YouTube account (the youtubescope) solely to create and manage the live broadcast SlimCast streams to on your behalf, retrieve its ingestion URL and stream key, read and send messages in that broadcast’s live chat when you use SlimChat, and update that broadcast’s title and tags when you set them in SlimCast. We do not access your other videos, playlists, subscriptions, or any YouTube data beyond that live broadcast.
  • Billing information:we use Stripe to process payments and manage memberships. We store your Stripe customer/subscription IDs and credit balance — we do not see or store your full card number. To keep the one-time free trial one-time, we also store the fingerprint Stripe derives from a saved card: an opaque identifier that cannot be used to charge the card and does not reveal its number.
  • Usage and session data: stream session start/end times, duration, platforms streamed to, and credits deducted, so we can bill accurately and show you your history.
  • Scheduled media:when you choose scheduled streaming, we collect the MP4 or MOV file you upload, its original filename, the start time you select, the destinations you enable, and limited technical metadata needed to validate and deliver it (such as codec, dimensions, duration, and byte size). The dashboard displays your browser’s time zone for confirmation, but the scheduled record stores the resulting UTC time. We do not use uploaded media for advertising or model training.
  • Technical and connection data: IP address (for abuse prevention and rate limiting), device/API key identifiers used by the OBS plugin, stream health metrics (bitrate, dropped frames) used to render the connection graph in the dock, and technical error reports when something in the app breaks (so we can fix it). Error reports are designed not to include stream content, private Storage URLs, filenames, stream keys, or OAuth tokens.

4. How we use your information

  • To operate the service: provisioning a GPU, configuring outputs, and delivering your stream to the platforms you’ve connected.
  • To store, validate, schedule, transmit, cancel, and delete media you submit for a scheduled broadcast.
  • To bill you correctly for credits consumed and manage your membership.
  • To detect and prevent abuse, fraud, and violations of our Terms of Service.
  • To provide support when you contact us.
  • To send you service-related notices (billing receipts, low-balance warnings, security alerts). We do not send marketing email without your consent.

5. What we don’t do

  • We do not sell, rent, or trade your personal information to data brokers or advertisers.
  • We do not use third-party advertising trackers or ad-network cookies. Site analytics run on Vercel Analytics and Speed Insights, which are privacy-respecting and do not build cross-site ad profiles.
  • We do not send your stream keys or OAuth tokens to the rented GPUs that transcode your video — those credentials stay on our trusted relay infrastructure.

6. Google API Services User Data

SlimCast’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube data only to create and manage the live broadcast you start through SlimCast and to retrieve its stream key; we do not use it to serve advertising, and we do not allow it to be read by humans except where necessary for security purposes, to comply with applicable law, or with your consent.

7. Who we share data with

We share data only with the service providers (“subprocessors”) needed to run SlimCast, each bound by their own privacy and security commitments:

  • Supabase — authentication, database hosting, and private object Storage for scheduled videos and custom drop-shield assets.
  • Resend — delivers account email (signup confirmation, password reset) from slimcast.io.
  • Stripe — payment processing and subscription billing.
  • Vercel — application hosting, and privacy-respecting site analytics.
  • Cloudflare — Turnstile bot protection on account signup, login, password recovery, and sensitive password-confirmation forms.
  • Sentry — error monitoring. Receives technical error reports so we can fix failures — never your stream content or credentials.
  • Vast.ai, RunPod, and Hetzner — on-demand cloud GPU and relay infrastructure used to process and deliver live or scheduled media. A scheduled file may be downloaded to isolated relay infrastructure for the broadcast. These providers never receive your destination stream keys.
  • Twitch, YouTube (Google), and Kick — only if you choose to connect an account via OAuth: to fetch your stream key, deliver your stream, sync the stream info you set, and power SlimChat on your behalf.

We may also disclose information if required by law, or to protect the rights, property, or safety of SlimCast, our users, or others.

8. Data retention

We retain account and billing data for as long as your account is active, and for a reasonable period afterward to meet our legal, tax, and fraud-prevention obligations. Stream session history is kept to show you your usage; connection-health metrics are automatically deleted after roughly 24 hours.

A scheduled-upload reservation expires after six hours if it is not submitted. Canceled media is queued for deletion immediately. Media for a completed or failed scheduled broadcast is normally queued for deletion within 24 hours. Deletion failures are retried with bounded backoff and escalated for operator review; the object remains private while cleanup is pending. We may preserve limited scheduling and cleanup metadata after the object is removed, but not the video itself.

You can request deletion of your account and associated data at any time (see Section 10); purchased-credit balances are forfeited or refunded per the process described in our Terms of Service. Account deletion blocks new media creation, cancels scheduled work, inventories your private scheduled and drop-shield objects, and requests their deletion before removing your identity. If a Storage provider is temporarily unavailable, we retain an operator-only deletion record containing the generated bucket/path capability but no original filename; its user reference is removed with the account so cleanup can continue without retaining account ownership data.

One exception: if you claimed the one-time free trial, we keep the opaque card fingerprint tied to that grant even after account deletion — it cannot charge your card or identify you by itself, and it exists solely so the one-time trial cannot be claimed repeatedly with the same card.

9. Security

Stream keys and OAuth tokens are encrypted at rest with AES-256-GCM. Data in transit is encrypted with TLS. Scheduled videos and drop-shield assets are stored in private buckets and accessed through short-lived signed URLs. Browser roles cannot list cleanup records or claim cleanup work.

Scheduled media is validated in a credential-isolated sandbox with network access disabled, then made available only to the relay process that needs it for the requested broadcast. Destination credentials remain on trusted relay infrastructure and are not included with the media download. Access to production data is restricted to what is needed to operate the service. No system is perfectly secure, and we cannot guarantee absolute security.

10. Your rights and choices

You can, at any time:

  • Access or update your account information from the dashboard.
  • Disconnect a platform or revoke an OAuth connection.
  • Rotate or revoke your OBS plugin API key.
  • Request deletion of your account and personal data by contacting us, or using the account-deletion option in your dashboard settings.
  • Cancel a scheduled broadcast from the dashboard while it is upload-pending, queued, starting, or running; cancellation stops or invalidates the job and deletes its stored media.

If you’re located in a jurisdiction with statutory data rights (for example the EU/UK GDPR or the California CCPA/CPRA), you may also have rights to access, correct, port, or restrict processing of your data. Contact us and we’ll honor applicable requests.

11. Children’s privacy

SlimCast is for adults: our Terms require you to be at least 18 to create an account. We do not knowingly collect personal information from anyone under 18 — and certainly not from children under 13. If you believe a minor has provided us with personal information, contact us and we’ll delete it.

12. International users

SlimCast is operated from the United States, and our infrastructure providers may process data in other countries. By using SlimCast, you consent to your information being transferred to and processed in the United States and other countries where our subprocessors operate.

13. Changes to this policy

We may update this policy as the service evolves. We’ll update the “last updated” date above, and for material changes we’ll make a reasonable effort to notify you (e.g. by email or an in-app notice).

14. Contact us

Questions about this policy or your data? Email support@slimcast.io. We’re AbstraScapes LLC, Florida, USA.