Privacy Policy
Last updated 29 September 2026
This explains what Bright Side Streams collects, why, who else processes it, and how to get it deleted. It is written to be read, not to be survived.
This policy covers the Bright Side Streams website, the studio, and our text message (SMS) program. Our phone app has its own privacy policy.
1. The short version
We set no cookies and run no advertising or analytics trackers. There is no tracking pixel on this site and no ad network. We have never sold personal data and we do not intend to start.
QR codes: when someone scans a code a member saved, we send them to its link and add one to that code's count. We don't record who they are.
We do count visits, in one line a day. For each page view we add one to a daily total for that page's path and for the site you came from — its name only, never the page you were reading. No cookie, no IP address, no identifier, nothing traceable to you.
What we hold is the account you created, the shows you recorded, and the billing record Stripe keeps for us. You can delete it from inside the studio, and deletion means deletion.
2. Who we are
Bright Side Streams is operated by Charles Hines of 3367 Moss Bridge Lane, Myrtle Beach, SC 29579. For anything in this policy, write to support@brightsidestreams.com. We are the data controller for the information described here.
3. What we collect
Because you gave it to us
- Account details — a username, an email address, and a password. If you sign in with Apple or Google, we receive an identifier and the email you chose to share, and no password exists for that account.
- Show content — recordings, transcripts, show notes, clips, plus any banners, logos and branding you upload.
- Streaming connections — when you connect a destination such as a YouTube channel, we store the authorisation needed to stream there. You can disconnect it at any time, which revokes our access.
- Support messages — what you send us, and our replies.
- Mobile phone number — if you are a podcast host, or a guest a host has booked into a session, and you tick the box agreeing to text notifications in the studio, or text START to resume texts after replying STOP. We keep a record of that agreement — when it happened, the exact words you agreed to, and the account or session it was given for — and of any STOP you send. See Text messages (SMS).
Because the product produced it
- Usage records — studio hours and relay hours consumed, plan and billing status, when a show started and stopped. This is how metering works; without it we cannot bill correctly.
- Technical logs — errors and diagnostic events, kept briefly so we can find and fix faults.
- A visit count — one row a day holding how many times each page path was opened and which sites sent people here (hostnames such as google.com, never a full address). It is a tally, not a record of you: nobody's visit is stored separately, so there is nothing in it to link to a person, and there is nothing to delete.
What we deliberately do not collect
- No cookies, no advertising identifiers, no cross-site tracking, no analytics SDK.
- No card numbers. Payments go directly to Stripe; we never see or store your card.
4. Recordings, and the people in them
A recording usually contains other people — guests, co-hosts, callers. That makes it different from the rest of your data, so it gets its own rules.
- Recordings belong to the host who made them. We store them so you can download and publish them, and for no other purpose.
- We do not use your recordings to train AI models, ours or anyone else's, and we do not licence them onward.
- Transcripts, show notes, clips, covers and dubbed audio are produced by sending the audio, video, frames or transcript to the service providers listed in section 6. They process it to return the result. The AI service provider that writes show notes and picks clips does not train on it.
- Everyone in a room sees a REC indicator while recording is running, and guests are asked to acknowledge recording before they join.
If you are a guest and want a recording deleted, ask the host first — it is theirs. If that goes nowhere, write to us and we will act on it.
5. Why we are allowed to hold it
Where the GDPR or UK GDPR applies to you, our lawful bases are:
- Performing our contract — your account, your shows, your billing. We cannot provide the studio without these.
- Legitimate interests — keeping the service secure, preventing abuse, fixing faults.
- Consent — for optional things you switch on, such as connecting a streaming destination. You can withdraw consent at any time.
- Legal obligation — tax and accounting records we are required to retain.
6. Who else processes it
We use other companies to run the studio. Each receives only what it needs for its job, and none may use your data for their own purposes.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database and accounts | Account details, show sign-ups, and texts sent to a show's number |
| Cloudflare | Storage, video and image delivery | Recordings, clips, uploaded images, our records of text-message consent, and the nightly backups of our database (in private storage) |
| LiveKit | Live audio and video in the studio | Your live stream while a room is open |
| Stripe | Payments and subscriptions | Email, billing details, payment method |
| Resend | Transactional email | Email address and message content |
| Telnyx | Delivering text messages (SMS), only to people who opted in | Mobile number and message content |
| An AI service provider | Show notes, titles, clip and cover choices, and Miles in the editor | The show content being processed |
| A speech-to-text service | Transcripts and captions | The show's audio |
| An image service | Covers and thumbnails | Frames from the show, and any photo you give it |
| A voice service | Dubbed audio in another language | The translated transcript |
| Google (YouTube) | Streaming to your channel, Google sign-in | Your stream, and your channel authorisation |
| Apple | Sign in with Apple | An account identifier |
YouTube API Services
Bright Side Streams uses YouTube API Services so that you can stream to, and publish on, a YouTube channel you own. We ask for one permission scope, youtube.force-ssl, and we use it only to create and end your live broadcasts, upload your own recordings and clips to your own channel, set the cover image on those uploads, read your channel’s name so we can show you which account is connected, and read the live chat on your own broadcast so it can appear in the studio. We do not read, collect or analyse anyone else’s YouTube data.
By connecting a channel you also agree to the YouTube Terms of Service. Google’s handling of any data it receives is described in the Google Privacy Policy.
How to revoke our access. Disconnecting the channel in the studio deletes the stored authorisation from our database immediately. You can also revoke it from Google’s side at any time, without us, at myaccount.google.com/permissions — that withdraws the permission from Bright Side Streams for good.
Some of these operate in the United States. Where we transfer personal data out of the UK or EEA, we rely on the providers' Standard Contractual Clauses.
We will also disclose information if the law genuinely requires it — a valid court order or binding legal demand. We will tell you when that happens unless we are forbidden from doing so.
7. Text messages (SMS)
Bright Side Streams sends text messages only to podcast hosts and the guests a host books into a session, and only to those who ask for them by ticking the box in the studio: hosts under Settings › General › Text notifications, and guests on the invite link their host sends for one session. Ticking it is optional, and it is never a condition of recording, joining a session or buying anything. Enter only your own number. There is no public sign-up page; our text notifications page shows both screens and explains how it works.
- What we send — to a guest, a show reminder with the join link for the session they were booked into; to a host, a notice with the download link when their recorded video is ready. We do not send marketing texts.
- How often — Message frequency may vary. Standard Message and Data Rates may apply.
- Stopping — reply STOP at any time; we will confirm once and then send no further messages. A host can also turn texts off in the studio's Settings, and a guest on their invite. Reply HELP for help, or email support@brightsidestreams.com.
- What we keep — your mobile number; a record of when you agreed, the exact words you agreed to, and the account or session you agreed from (and, for a guest, the name you gave); the IP address and browser that submitted it; and any opt-out. A guest's name and number stay on their invite only until 12 hours after the session starts. We keep the record so we can honour your choice and show that you gave consent.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. All the categories in section 6 exclude text messaging originator opt-in data and consent. Information sharing to subcontractors in support services is permitted, and only to run this program: Telnyx delivers our text messages and Cloudflare stores our record of your consent, both on our behalf and under contract, and neither may use it for anything else.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account details | Until you delete the account |
| Recordings (Creator and above) | 12 months, then deleted |
| Recordings (Starter) | 7 days, then deleted |
| A published episode you delete | Deleted straight away, with its recording, audio, clips and transcript |
| A recording you delete before it was ever published | 30 days, so it can be recovered if the delete was a mistake, then deleted |
| Technical logs | Up to 30 days |
| Billing and tax records | As long as tax law requires, typically 6–7 years |
| Mobile number and text-message consent record | While you are opted in, and for 4 years after you opt out (by replying STOP, or turning texts off in the studio or on your invite), so we can prove consent and keep honouring your opt-out; after that we keep only the fact that this number opted out. If you delete your account, or ask us to delete your data, we keep only that fact straight away, so we never text that sign-up again. |
Your browser also keeps a local backup of shows you record. That copy is on your own device, not ours, and clearing your browser data removes it.
When you delete your account we remove your account and recordings. Billing records survive because we are legally required to keep them. Our nightly database backups are kept in private storage with no public address, and backups roll off on their own cycle within 30 days.
9. How it is protected
- Passwords are hashed with scrypt and a random per-account salt, compared in constant time, and stored in a table separate from public profile data. Nobody at Bright Side can read your password, including us.
- Everything travels over HTTPS.
- Card details never touch our servers — Stripe handles them directly.
- Nightly backups of our database are kept in a private storage bucket with no public address; only our own server's keys can read them.
No service can promise perfect security, and we will not pretend otherwise. If a breach affects you we will tell you promptly and tell you plainly what happened.
10. Your rights, and how to use them
Wherever you live, you may ask us to: give you a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere in a portable format.
Most of this you can do yourself — delete a recording, delete the account. For anything else, email support@brightsidestreams.com and we will respond within 30 days. Exercising these rights costs nothing and we will not degrade your service for asking.
If you are in California: you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. There is nothing to opt out of, because we do not sell or share personal data as those terms are defined by the CCPA, and we have not done so in the past 12 months. We will not discriminate against you for exercising any of these rights.
If you are in the UK or EEA: you may complain to your data protection authority. In the UK that is the Information Commissioner's Office. We would rather you came to us first so we can fix it.
11. Children
The studio is not intended for children under 13, and you must be at least 13 to hold an account. In the EEA the minimum is 16 unless your country sets it lower. We do not knowingly collect data from children under those ages; if we discover we have, we delete it.
12. Changes
If we change this policy we will update the date at the top. For anything that meaningfully affects your rights we will email you before it takes effect, rather than quietly editing the page.
13. Contact
Questions, requests, or complaints: support@brightsidestreams.com. A real person reads it.