Privacy Policy
This policy describes the information Stream Rituals handles to run creator dashboards, overlays, widgets, alerts, integrations, and related stream-production services.
Scope
This Privacy Policy explains how Fintrics Pty Ltd, trading as Stream Rituals, collects, uses, shares, retains, and protects information when you use our websites, creator dashboard, overlay and alert tools, widgets, APIs, browser-source pages, and related services. Fintrics Pty Ltd is based in Australia and is the operator of Stream Rituals.
Stream Rituals is built for creators and stream operators. The service may process account details, workspace settings, connected-platform data, OAuth tokens, overlay configuration, viewer-facing event data, generated or uploaded assets, analytics, and technical logs so creators can prepare and run stream experiences.
Information You Provide
We collect information you choose to provide, such as name, email address, login details, workspace names, channel names, brand settings, overlay text, alert copy, uploaded files, generated or customized assets, support messages, billing details, and configuration values such as Rumble URLs or channel-specific settings.
If you invite team members or configure public widgets, we may process the information needed to make those features work, including role assignments, shared workspace settings, public page slugs, browser-source URLs, and widget state.
Connected Platforms and OAuth
When you connect a platform such as Twitch, YouTube, Rumble, or another streaming or creator service, we receive information authorized through that platform. This can include account identifiers, channel metadata, profile images, stream status, event data, chat or audience signals, subscription or supporter events, and tokens that allow Stream Rituals to operate selected features.
We use connected-platform data only to provide, secure, troubleshoot, and improve the features you enable. You can disconnect integrations through Stream Rituals where available or through the connected platform's account settings. Disconnecting may stop overlays, alerts, analytics, or dashboard features that depend on that integration.
Platform-Specific Data
Stream Rituals uses YouTube API Services. When you use a YouTube-connected feature, Stream Rituals' handling of information received from YouTube is governed by this Privacy Policy, the YouTube Terms of Service, the Google Privacy Policy, and the Google API Services User Data Policy.
For YouTube connections, Stream Rituals may request permission to identify the creator's channel; read creator-owned broadcasts, live-chat messages, author avatars and available member, owner, moderator, or verification indicators; retrieve active channel-member names, profile images, membership levels, and membership tenure; and display private channel, video, audience, revenue, monetized-playback, and advertising-performance reports. These permissions support the connected creator's unified chat, alerts, Playground, analytics, and live-publishing features.
When a creator expressly chooses to prepare or manage a YouTube Live destination, Stream Rituals uses the authorized YouTube connection to create and bind a YouTube broadcast and ingestion stream, apply the creator-selected title, description, privacy and audience settings, check broadcast state, and manage the Prepare, Live, Stop, and Complete lifecycle. Stream Rituals does not provide general-purpose access to manage or delete the creator's other YouTube videos, and it does not send or moderate chat unless the creator separately enables a feature that requires and clearly identifies that access.
Video and audio are sent directly from the creator's paired OBS installation to YouTube over YouTube's supported streaming transport. Stream Rituals does not ingest, relay, record, or store that broadcast media. Publishing credentials and ingestion details are encrypted and kept server-side, are not exposed in browser responses, and are released only to the paired OBS device through a short-lived, one-time, device-bound credential lease needed to publish the selected broadcast.
Use of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements. OAuth credentials are encrypted and kept server-side. Verification-only member and analytics responses are fetched on demand and are not retained as raw Google payloads.
To disconnect and delete locally stored YouTube API Data, open Account, choose Connections, find YouTube, and select Disconnect and delete YouTube data. Stream Rituals will stop YouTube collectors, attempt to revoke the Google token, remove local credentials, and delete stored YouTube API Data associated with the connection as soon as possible and no later than seven calendar days. You may also request deletion at [email protected]. Deleting data from Stream Rituals does not delete videos, live streams, comments, messages, or other content held by YouTube.
You may separately revoke Stream Rituals' access from your Google Account connections page. Stream Rituals checks active YouTube authorization at least daily. If Google-side revocation is detected, related stored YouTube API Data is deleted as soon as possible and no later than 30 calendar days after revocation.
For Twitch, TikTok, and Kick, the permissions requested depend on the connection and may include basic account or channel identity, chat, subscriptions, supporter activity, follower information, or event subscriptions. Rumble connections may use a creator-provided live API URL. Stream Rituals does not control a platform's own collection, retention, or use of information.
Google Privacy PolicyYouTube Terms of ServiceManage or revoke Google Account connectionsGoogle API Services User Data Policy
Information Collected Automatically
We collect technical information when you use Stream Rituals, including IP address, device and browser details, pages viewed, referring URLs, session identifiers, error reports, request logs, feature usage, approximate location derived from network information, and performance data for dashboards, overlays, widgets, and APIs.
Browser-source pages and public widgets may log load events, runtime errors, event delivery status, and configuration identifiers so creators can verify that live surfaces are working. At launch, cookies, local storage, and similar technologies are used for authentication, preferences, security, and service diagnostics. We will update this policy and introduce any controls required by law before adding optional analytics or advertising technologies.
How We Use Information
We use information to create accounts, authenticate users, operate workspaces, connect third-party platforms, prepare and manage creator-requested live broadcasts, deliver publishing details to paired OBS devices, deliver overlays and alerts, save presets, customize assets, sync events, provide analytics, prevent abuse, troubleshoot issues, and communicate about the service. If paid features are introduced, we will also process the information needed for billing and payment support.
We also use information to improve reliability, understand feature adoption, develop new creator tools, enforce terms, protect users and viewers, comply with legal obligations, and maintain records needed for security, billing, and dispute handling.
Public and Viewer-Facing Features
Some Stream Rituals features are designed to be public or viewer-facing, including overlays, alerts, leaderboards, fan missions, rewards, stream screens, browser-source pages, and shared links. Information you place in those surfaces may be visible to viewers, moderators, team members, or anyone with access to the relevant URL.
You should avoid placing private information in overlay copy, alert messages, uploaded assets, public page slugs, or widget configuration. Treat unlisted browser-source URLs and workspace links as sensitive if they can control or expose stream content.
Retention and Deletion
We generally keep OAuth tokens until you disconnect the platform or delete the account; workspace, loadout, creator-configuration, and creator-selected broadcast metadata while the account remains active or as needed to provide the feature; non-YouTube live-event and routine technical logs for up to 12 months; and security or audit logs for up to 24 months. Short-lived publishing credential leases expire after their limited delivery window and are not retained as reusable browser credentials.
Stream Rituals deletes stored YouTube API Data no later than 30 days after collection. This hard limit covers YouTube live events, chat, channel metadata, API-derived analytics snapshots, audience data, and provider state; newly retrieved data replaces or supplements only data that is still inside that 30-day window. Payload-free deletion receipts may be retained for audit and security purposes.
You may request deletion of your account or personal information by emailing [email protected]. Verified requests to delete stored YouTube API Data are completed as soon as possible and no later than seven calendar days. Other verified privacy requests are normally completed within 30 days where practical. Deleted non-YouTube media and residual backup copies may take 30 to 90 days to be removed through normal backup and storage cycles. We may retain limited records where required or permitted for security, fraud prevention, legal compliance, billing, dispute resolution, and legitimate business records, but those exceptions are not used to retain YouTube API Data contrary to YouTube's policies.
Generated and AI-Assisted Content
Stream Rituals may include pre-generated or AI-assisted images, animations, templates, and other assets prepared for the service. Selecting or using one of those library assets does not by itself send your account information or content to the tool that was used to prepare it.
Stream Rituals does not currently offer a customer-facing feature that sends your prompts or uploads to an AI provider to generate new content. Before enabling such a feature, we will identify or document the material provider, the information sent, relevant retention and processing locations, and any choices available to you.
Stream Rituals does not use customer uploads or workspace content to train its own models. If customer-facing generation is introduced, we will select provider terms and account settings intended to prevent customer inputs and outputs from being used to train general-purpose models, and we will update this policy before the feature is enabled. Do not submit confidential or sensitive personal information to a generated-content feature unless it expressly requires that information.
Your Choices and Rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. Stream Rituals may need to verify the request and may retain information where permitted or required for security, legal compliance, fraud prevention, disputes, and backups.
You can also manage information by updating account or workspace settings, removing uploaded media, disconnecting platforms, revoking access in the connected platform, and controlling browser cookies or local storage. The exact controls available depend on the feature and connection involved.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted transport, logging, and separation of sensitive credentials where appropriate. No internet service can guarantee perfect security.
You can help protect your workspace by using strong credentials, limiting team access, disconnecting unused integrations, rotating exposed browser-source URLs or tokens where supported, and reviewing connected-platform permissions periodically.
International Use
Stream Rituals is operated in Australia by Fintrics Pty Ltd and may be made available internationally except where use is prohibited by Australian law, sanctions, export controls, or applicable local restrictions. We primarily manage the service from Australia. Some service providers and connected platforms may process personal information outside Australia, including in the United States. Those countries may have privacy laws that differ from Australian law or the law where you live.
Where Australian privacy law applies, before disclosing personal information to an overseas service provider we take reasonable steps appropriate to the circumstances to assess and manage how the recipient handles that information. Connected platforms also process information under their own terms and privacy policies. We maintain a record of material providers and the countries in which they are reasonably likely to process personal information. You may request current information about those locations at [email protected].
If local law gives you rights to access, correct, delete, export, restrict, or object to processing of personal information, you may contact us to exercise those rights. We may need to verify your identity and may decline requests where permitted by law.
Children
Stream Rituals is not directed to children under 13 and is available only to people aged 13 or older. Users under 18 must have a parent or legal guardian review and agree to the service terms where required by applicable law. If you believe a child under 13 has provided personal information to Stream Rituals, contact [email protected] so we can review and take appropriate action.
Changes and Contact
We may update this Privacy Policy as Stream Rituals, laws, platform rules, or data practices change. When updates are material, we will use reasonable efforts to provide notice through the site, dashboard, or account communications.
Questions, privacy requests, deletion requests, correction requests, and integration-data concerns can be sent to [email protected]. Include enough detail for us to identify the relevant account, workspace, integration, URL, asset, or event. We may ask for information needed to verify that a request relates to you or an account you are authorized to manage.
If you make a privacy complaint, explain what happened and the outcome you are seeking. We aim to acknowledge and respond to privacy complaints within 30 days. If you are not satisfied after giving us a reasonable opportunity to respond, you may contact the Office of the Australian Information Commissioner at oaic.gov.au. Other complaint rights available under applicable law are not excluded.
