Privacy Policy
Last updated 1 August 2026
This explains what Bright Side Streams collects, why, who else processes it, and how to get it deleted. It is written to be read, not to be survived.
⚠️ Website only, and not yet reviewed by a lawyer. The operator name and address are now the real ones. This policy covers this website and the studio — the Bright Side phone app collects considerably more and needs its own policy, which both app stores require.
1. The short version
We set no cookies and run no advertising or analytics trackers. There is no tracking pixel on this site and no ad network. We have never sold personal data and we do not intend to start.
What we hold is the account you created, the shows you recorded, and the billing record Stripe keeps for us. You can delete it from inside the studio, and deletion means deletion.
2. Who we are
Bright Side Streams is operated by Charles Hines of 3367 Moss Bridge Lane, Myrtle Beach, SC 29579. For anything in this policy, write to support@brightsidestreams.com. We are the data controller for the information described here.
3. What we collect
Because you gave it to us
- Account details — a username, an email address, and a password. If you sign in with Apple or Google, we receive an identifier and the email you chose to share, and no password exists for that account.
- Show content — recordings, transcripts, show notes, clips, plus any banners, logos and branding you upload.
- Streaming connections — when you connect a destination such as a YouTube channel, we store the authorisation needed to stream there. You can disconnect it at any time, which revokes our access.
- Support messages — what you send us, and our replies.
Because the product produced it
- Usage records — studio hours and relay hours consumed, plan and billing status, when a show started and stopped. This is how metering works; without it we cannot bill correctly.
- Technical logs — errors and diagnostic events, kept briefly so we can find and fix faults.
What we deliberately do not collect
- No cookies, no advertising identifiers, no cross-site tracking, no analytics SDK.
- No card numbers. Payments go directly to Stripe; we never see or store your card.
4. Recordings, and the people in them
A recording usually contains other people — guests, co-hosts, callers. That makes it different from the rest of your data, so it gets its own rules.
- Recordings belong to the host who made them. We store them so you can download and publish them, and for no other purpose.
- We do not use your recordings to train AI models, ours or anyone else's, and we do not licence them onward.
- Transcripts, show notes and clips are produced by sending the audio or video to the AI providers listed in section 6. They process it to return the result and do not retain it for training under our agreements with them.
- Everyone in a room sees a REC indicator while recording is running, and guests are asked to acknowledge recording before they join.
If you are a guest and want a recording deleted, ask the host first — it is theirs. If that goes nowhere, write to us and we will act on it.
5. Why we are allowed to hold it
Where the GDPR or UK GDPR applies to you, our lawful bases are:
- Performing our contract — your account, your shows, your billing. We cannot provide the studio without these.
- Legitimate interests — keeping the service secure, preventing abuse, fixing faults.
- Consent — for optional things you switch on, such as connecting a streaming destination. You can withdraw consent at any time.
- Legal obligation — tax and accounting records we are required to retain.
6. Who else processes it
We use other companies to run the studio. Each receives only what it needs for its job, and none may use your data for their own purposes.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database and accounts | Account details |
| Cloudflare | Storage, video and image delivery | Recordings, clips, uploaded images |
| LiveKit | Live audio and video in the studio | Your live stream while a room is open |
| Stripe | Payments and subscriptions | Email, billing details, payment method |
| Resend | Transactional email | Email address and message content |
| Anthropic, OpenAI | Transcripts, show notes, clip selection | The show content being processed |
| Google (YouTube) | Streaming to your channel, Google sign-in | Your stream, and your channel authorisation |
| Apple | Sign in with Apple | An account identifier |
Some of these operate in the United States. Where we transfer personal data out of the UK or EEA, we rely on the providers' Standard Contractual Clauses.
We will also disclose information if the law genuinely requires it — a valid court order or binding legal demand. We will tell you when that happens unless we are forbidden from doing so.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account details | Until you delete the account |
| Recordings (Creator and above) | 12 months, then deleted |
| Recordings (Starter) | 7 days, then deleted |
| Technical logs | Up to 30 days |
| Billing and tax records | As long as tax law requires, typically 6–7 years |
Your browser also keeps a local backup of shows you record. That copy is on your own device, not ours, and clearing your browser data removes it.
When you delete your account we remove your account and recordings. Billing records survive because we are legally required to keep them, and backups roll off on their own cycle within 30 days.
8. How it is protected
- Passwords are hashed with scrypt and a random per-account salt, compared in constant time, and stored in a table separate from public profile data. Nobody at Bright Side can read your password, including us.
- Everything travels over HTTPS.
- Card details never touch our servers — Stripe handles them directly.
No service can promise perfect security, and we will not pretend otherwise. If a breach affects you we will tell you promptly and tell you plainly what happened.
9. Your rights, and how to use them
Wherever you live, you may ask us to: give you a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere in a portable format.
Most of this you can do yourself — delete a recording, delete the account. For anything else, email support@brightsidestreams.com and we will respond within 30 days. Exercising these rights costs nothing and we will not degrade your service for asking.
If you are in California: you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. There is nothing to opt out of, because we do not sell or share personal data as those terms are defined by the CCPA, and we have not done so in the past 12 months. We will not discriminate against you for exercising any of these rights.
If you are in the UK or EEA: you may complain to your data protection authority. In the UK that is the Information Commissioner's Office. We would rather you came to us first so we can fix it.
10. Children
The studio is not intended for children under 13, and you must be at least 13 to hold an account. In the EEA the minimum is 16 unless your country sets it lower. We do not knowingly collect data from children under those ages; if we discover we have, we delete it.
11. Changes
If we change this policy we will update the date at the top. For anything that meaningfully affects your rights we will email you before it takes effect, rather than quietly editing the page.
12. Contact
Questions, requests, or complaints: support@brightsidestreams.com. A real person reads it.