StreamNexus Privacy Policy
StreamNexus is a Windows desktop app for Twitch and YouTube stream monitoring, notifications, and multiview playback. This Privacy Policy explains what information StreamNexus handles and how YouTube API Services data is used.
1. Scope
This policy applies to the StreamNexus desktop app, release distribution through the public StreamNexus release repository, and Twitch, Google, and YouTube integrations. StreamNexus shows a policy confirmation screen before users start initial setup or connect Twitch or YouTube.
2. Information StreamNexus handles
StreamNexus may handle the following information and uses it only for the purposes listed below.
- Twitch and YouTube channel IDs, channel names, profile image URLs, live stream status, thumbnails, titles, scheduled or actual live times, watch URLs, and other public video metadata needed to show stream lists, notifications, history, and multiview playback.
- The user's YouTube subscriptions returned by YouTube API Services after OAuth consent, so the user can choose which channels to monitor.
- User-selected tracked channels, notification settings, multiview layout settings, audio settings, app preferences, and policy confirmation state.
- If the contact form is used, the name, reply email address, inquiry category, message, optionally attached screenshots or diagnostic logs, and minimal technical information needed for abuse prevention and troubleshooting, such as User-Agent and Cloudflare Ray ID.
- YouTube OAuth access and refresh tokens issued by Google after user consent. These tokens are used only to call authorized YouTube API Services, refresh access, or revoke access.
- Local logs and health information needed for troubleshooting, such as app version, local runtime state, and non-secret diagnostic messages.
StreamNexus is designed not to intentionally store API keys, OAuth client secrets, or OAuth tokens in Git.
3. YouTube API Services
StreamNexus uses YouTube API Services. By using YouTube integration in StreamNexus, users also agree to the YouTube Terms of Service and Google Privacy Policy.
StreamNexus requests the read-only Google OAuth scope:
https://www.googleapis.com/auth/youtube.readonly
StreamNexus uses this scope to:
- Display the user's YouTube subscriptions inside StreamNexus.
- Check live stream status for tracked YouTube channels.
- Display public video metadata needed for stream monitoring, notifications, and multiview playback.
StreamNexus does not:
- Upload, delete, or edit YouTube videos.
- Post comments or manage playlists or channels.
- Sell YouTube API Services data.
- Use YouTube API Services data for advertising, credit scoring, unrelated profiling, or AI model training.
4. Device storage, cookies, and similar technologies
StreamNexus is a desktop app and stores information on the user's device. This includes encrypted OAuth tokens, local SQLite data, local settings files, Electron session data, localStorage, and troubleshooting logs.
When users open Google OAuth pages, YouTube pages, YouTube embedded players, Twitch pages, or update/support pages, those third-party services may place, access, or recognize cookies, localStorage, session storage, device identifiers, or similar technologies in their own browser or WebView contexts. StreamNexus does not use these technologies for advertising or unrelated tracking.
5. Storage, retention, and protection
YouTube OAuth tokens are stored locally by StreamNexus and encrypted before being saved in app settings. Tracked YouTube channels and public stream metadata may be stored locally while needed to provide monitoring, notification, history, and multiview features. YouTube API Services data that is displayed or stored by StreamNexus is refreshed, updated, or deleted within 30 days where required by the YouTube API Services Developer Policies. Users can also delete locally stored YouTube authorized data at any time from StreamNexus settings. Information submitted through the contact form is used for support, replies, abuse prevention, and record review, and is retained only as long as needed for those purposes. Optional attachments are stored in non-public object storage and are automatically deleted no later than 90 days after submission, regardless of inquiry status.
StreamNexus uses security procedures to protect the confidentiality of Google user data handled by the app.
- YouTube OAuth access and refresh tokens are stored on the user's Windows device and encrypted before persistence.
- Local app data is protected by the user's Windows account and local file-system permissions.
- OAuth tokens are transmitted only to Google OAuth and YouTube API endpoints when needed for token exchange, token refresh, token revocation, and authorized YouTube API calls.
- StreamNexus uses HTTPS for communication with Google OAuth, YouTube API, update, and support endpoints.
- StreamNexus is designed not to intentionally store API keys, OAuth client secrets, OAuth tokens, or other sensitive credentials in Git.
- Local logs and health information are used for troubleshooting. Users should not publicly share logs that may contain personal data, account identifiers, tokens, or other sensitive information.
- Before attaching a screenshot or diagnostic log to an inquiry, users should confirm that it does not contain authentication tokens, cookies, passwords, or unnecessary personal information.
StreamNexus does not operate a production server that sells or redistributes YouTube API Services data.
6. Sharing
StreamNexus does not sell Google or YouTube user data. Information is shared only when required by user actions, app update delivery, video playback through the relevant platform, troubleshooting, security, or legal obligations.
7. Deletion, disconnect, and revocation
Users can disconnect YouTube from StreamNexus settings. StreamNexus programmatically revokes the stored Google OAuth token and then clears locally stored YouTube OAuth tokens. If revocation fails because of a network or server error, StreamNexus keeps the local token so the user can retry revocation.
Users can also use the local YouTube Authorized Data deletion control. This removes locally stored YouTube tracked channels, stream history, watch sessions, stream notes, claim history rows, and YouTube OAuth tokens. It does not delete the user's YouTube account, videos, comments, playlists, channels, or YouTube-side subscriptions.
Users can revoke StreamNexus access from Google's third-party app access page. To remove all local StreamNexus data, users should disconnect YouTube, use the authorized-data deletion control, and delete StreamNexus local app data from Windows.
8. Changes
StreamNexus may update this policy when app functionality, API usage, or compliance requirements change. Material changes will be reflected on this page and, when appropriate, in release notes or the app UI.
9. Contact
For privacy questions, YouTube API Services data questions, data deletion assistance, app support, or security reports, contact:
- General contact: info@stream-nexus.com
- Privacy / YouTube API Services data / data deletion: privacy@stream-nexus.com
- App support: support@stream-nexus.com
- Security and vulnerability reports: security@stream-nexus.com
- GitHub support: StreamNexus support repository