Skip to main content
Legal

Privacy Policy

Last updated: July 21, 2026

This Privacy Policy explains how streamrunnr collects, uses, and protects your personal data when you use our website and service. We take your privacy seriously and process your data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Data Controller

The party responsible for processing your personal data (the "controller" under Art. 4(7) GDPR) is:

  • LL Platforms UG (haftungsbeschränkt)
  • Wuhlestraße 7 a, 12683 Berlin, Germany
  • Email: support@streamrunnr.com

If you have any questions about this policy or wish to exercise your rights, you can contact us at any time using the details above. We currently have not appointed a data protection officer. We review the statutory appointment criteria under Art. 37 GDPR and § 38 BDSG as our organisation and processing activities change.

2. What Data We Collect

Account data

When you create an account, we collect your name, email address, and a securely hashed password (we never store your password in plain text). To verify your email address or reset your password, we generate short-lived one-time codes; these are stored only in hashed form, expire after 15 minutes (verification codes) or 1 hour (password-reset links), and are limited to a small number of attempts. If you choose Google sign-in, Google and Supabase provide us with your Google account identifier, name, email address, basic profile metadata, authentication provider and sign-in timestamps so that we can create, secure and identify your account; we never receive your Google password. Your use of Google sign-in is additionally subject to Google's privacy policy. For either registration method, we record the authentication method, time, language, legal-document version, exact document hashes and wording of your Terms acknowledgement so that the conclusion of the account agreement can be demonstrated.

Optional marketing choice

If you choose marketing emails, we process the choice and confirmation or withdrawal times, source, language, wording and version of the consent, and the confirmed account email address. A sign-up choice remains inactive until address ownership is confirmed with the account verification code.

Content you provide

We store the videos you upload (including automatically generated thumbnails and technical metadata such as duration, resolution, and file size), the playlists and stream profiles you create, your stream schedules, and the streaming destinations you configure (destination type, RTMP/RTMPS URL, and stream key). Stream keys are sensitive credentials: before database storage we encrypt them at application level using authenticated AES-256-GCM encryption and a versioned key ring. They are decrypted only for the requested stream delivery and are removed from application responses and technical logs. All of your content is private to your account — streamrunnr has no public profiles, sharing, or discovery features.

Payment and subscription data

Subscription payments are processed by Paddle, our Merchant of Record (see section 5). We never receive or store your full payment card details. To confirm the location-specific total price including tax, our server requests a Paddle pricing preview when the authenticated checkout page is opened. The request uses your IP address for country/tax localisation or, for an existing buyer, your Paddle customer identifier. Paddle returns the applicable country, currency, tax mode and rate, and subtotal, tax and total. We temporarily display these values and, when you start checkout, retain the preview together with the selected plan and legal acceptance. After purchase we also retain the signed final price, tax, discount, credit, balance and transaction totals as contract evidence. From Paddle we additionally receive subscription status, billing interval, billing-period dates and Paddle customer, subscription and transaction identifiers.

Usage and technical data

When you use the service, we automatically process technical information such as your IP address, browser type, device information, access timestamps, and log data relating to streaming activity and errors (for example, service events shown in your dashboard such as automatic stream restarts). We also keep a record of which service emails we have sent you, to avoid sending duplicates.

Support communication

If you contact us via the support form or email, we process the information you provide (name, email address, category, and message) to handle your request. Support requests are delivered to us by email and are not stored in our application database.

Cancellation and withdrawal declarations

If you use our public cancellation page (https://streamrunnr.com/cancel) or electronic withdrawal function (https://streamrunnr.com/withdraw), both available without logging in, we process the name, email address, contract/order reference, type and content of the declaration, any reason or requested date, receipt time, processing status and delivery evidence. We use these data to identify the contract, execute or review the declaration, provide an immediate downloadable receipt and send the legally required confirmation through a retryable delivery outbox. The declaration is recorded even when automatic account matching or a provider request is temporarily unavailable.

Reports of illegal content

If you report content through our Article 16 DSA mechanism (see section 8 of our Terms), we process the category, substantiated explanation, exact electronic locations, good-faith statement, receipt time and handling status. We also process your name and email address, except where Art. 16(2)(c) DSA removes that requirement for reports concerning offences covered by Articles 3 to 7 of Directive 2011/93/EU. We use the data to review and decide on the notice, confirm receipt, notify you of the decision and available redress, comply with the Digital Services Act, and document proper handling. We disclose your identity to the affected user only where necessary to establish the alleged illegality (for example in some intellectual-property or personality-rights cases) or where otherwise legally required. Evidence is retained for as long as necessary to document handling and establish, exercise, or defend legal claims.

3. Purposes and Legal Bases

We process your personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR): to create and manage your account, provide the streaming service, process your videos, operate your live streams, handle billing and cancellations, and respond to your support requests.
  • Legal obligation (Art. 6(1)(c) GDPR): to comply with statutory duties — in particular applicable retention duties, the handling of reports of illegal content under the EU Digital Services Act, and the electronic receipt, evidence and confirmation of cancellation and withdrawal declarations.
  • Legitimate interests (Art. 6(1)(f) GDPR): to ensure the security and stability of our service, prevent fraud and abuse, enforce our terms, and defend legal claims. Our legitimate interest lies in operating a secure and reliable service.
  • Consent (Art. 6(1)(a) GDPR): for marketing emails, where you have given your consent. You can withdraw consent at any time with effect for the future.

Providing your account data (name, email address, password or Google sign-in) is necessary to enter into and perform the account agreement — without it, we cannot provide the service. Plan and billing details and the required legal declarations are necessary to conclude a paid subscription. The fields marked as required in cancellation, withdrawal and illegal-content forms are necessary to identify and process that declaration or notice; without them we may be unable to process it. Optional fields are identified as such in the respective form.

4. Processors We Use

To operate streamrunnr we use carefully selected service providers that process personal data on our behalf and on our instructions as processors under Art. 28 GDPR, based on data processing agreements:

  • Supabase — authentication and database hosting for your account and metadata.
  • Cloudflare — application hosting (Workers) and object storage (R2) for your uploaded videos.
  • Resend — dispatch of transactional and (where consented) marketing emails.
  • Google (Gmail/Workspace) — the operator mailbox that receives support and abuse reports; Google sign-in is separately described below as an independent recipient.
  • Hetzner Online — the servers that process your videos (conversion, thumbnails) and run your live streams. Temporary copies of your videos exist on these servers during processing and streaming and are removed automatically afterwards.

5. Independent Recipients

Some recipients of your data are not our processors but independent controllers with their own responsibility and privacy policies:

  • Paddle — depending on the buyer's region, the applicable Paddle entity may be Paddle.com Market Limited, Paddle.com Inc. or Paddle.com (Canada) Ltd. Paddle acts as Merchant of Record/reseller and processes your IP address or customer identifier for country, currency and tax localisation as well as payment, billing, fraud-prevention, refund and invoice data under its own responsibility. The entity shown in the checkout and transaction confirmation is authoritative. See Paddle's privacy notice.
  • Google — if you use Google sign-in (see section 2).
  • The streaming platforms you choose (for example YouTube, Twitch, or a custom RTMP destination) — when you start a live stream, we transmit your video content and your stream key to the destination you configured, at your direction. The processing of your content by these platforms is governed by their own terms and privacy policies.

Beyond that, we disclose personal data only where we are legally obliged to do so (for example to authorities on a valid legal basis) or where necessary to establish, exercise, or defend legal claims.

6. International Data Transfers

Some of our service providers and recipients (in particular Supabase, Cloudflare, Resend, Google, and Paddle) are headquartered in or may process data in countries outside the European Economic Area (EEA), in particular the United States. Where personal data is transferred to such countries, we ensure an adequate level of protection through appropriate safeguards: an adequacy decision of the European Commission — including certification under the EU-U.S. Data Privacy Framework, where the provider is certified — or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can request more information about the safeguards in place using the contact details in section 1.

7. Data Retention

We retain your personal data only as long as necessary:

  • Account data is retained while the account exists. When you request account deletion, new service mutations are blocked and session revocation is initiated. An idempotent deletion workflow then stops active processing and streams, cancels any renewable external subscription where applicable, removes content from primary systems and finally removes the identity. Temporary provider failures are retried. Paid-contract evidence and statutory declaration records are handled separately as described below and are not ordinary account content.
  • Your uploaded video library is retained while your subscription is active. If your subscription ends, the video rows and all associated video objects — including source files, converted variants, derivatives, and thumbnails — are normally kept for 30 days and are then removed from active storage unless you resubscribe. References to those videos are removed from your playlists. Empty playlists, stream profiles, schedules, and encrypted destination credentials are account configuration rather than video-library objects; they remain while your account exists unless you delete the relevant playlist or profile, and are removed through the account-deletion workflow when you delete your account. Residual copies may remain temporarily in provider backups until the applicable backup cycle expires.
  • One-time verification codes expire after at most 15 minutes (email verification) or 1 hour (password reset) and are single-use.
  • A pending marketing choice and its exact wording are retained until it is activated following email verification or the account is deleted. Active marketing-consent evidence — including wording, version, source, confirmed address and grant or revocation time — is retained while the account exists and is deleted with the account unless a legal hold applies.
  • Support communication is retained in our support mailbox for as long as needed to handle your request and any follow-ups, and thereafter only as required by law.
  • Log and technical data is retained only for a limited period necessary for security and troubleshooting; streaming logs are size-capped and overwritten on rotation.
  • Cancellation and withdrawal evidence, delivery attempts and related correspondence are retained for the period necessary to prove receipt and proper handling and for the applicable limitation period; longer retention applies only where a legal dispute or statutory duty requires it.
  • Evidence of a paid contract or paid plan change (the displayed price and tax snapshot, legal-document version and hashes, acknowledgement wording and time) is retained in pseudonymised form after account deletion for the period necessary to prove the contract, comply with legal duties, and establish, exercise, or defend claims. Evidence of a free account registration is deleted with the account unless a legal hold applies.
  • Invoicing and tax records relating to your purchases are issued and retained by Paddle as Merchant of Record. Our own business records are retained for the period applicable to the respective document category under tax and commercial law; there is no single retention period for every record.

When data is no longer required and no legal retention obligation applies, it is deleted or anonymised. Residual copies in short-lived infrastructure backups are purged on the backup cycle of the respective provider.

8. Cookies and Local Storage

In production we use the strictly necessary host-only cookies `__Host-sr_at` (short-lived access session) and `__Host-sr_rt` (refresh session, up to 30 days). Temporary `__Host-sr_oauth_tx` and `__Host-sr_stepup` cookies protect Google sign-in and high-risk re-authentication and expire after the relevant flow. These cookies are Secure, HttpOnly, SameSite=Lax and scoped to the host root. We use local storage for the token-free user display object, user-selected theme and notification preferences, a user-scoped interface cache of profile/status/event information and the last known subscription-active flag. Actual stream keys are excluded, and account-scoped records are purged on sign-out or account switch. After a billing request, local storage additionally holds a user-bound billing-operation UUID and its timestamp for at most 30 days solely to resume the owner-scoped server status display; it contains no provider payload or authentication token. Session storage holds short-lived interface flags, the current Paddle checkout reference, and random idempotency identifiers for cancellation, withdrawal and illegal-content forms until completion or the end of the tab session. Authentication tokens are not stored in browser storage. We currently use no analytics or advertising trackers. Paddle checkout may use storage or device signals under Paddle's own privacy notice for payment and fraud prevention; Paddle.js is loaded only when you actively start checkout, while the server-side tax-inclusive pricing preview described in section 2 may occur earlier. Access to terminal equipment that is not strictly necessary will only occur with consent; otherwise we rely only on a specific exception under § 25(2) TDDDG.

9. Marketing Emails

We send marketing and product-update emails only after an active, optional choice. At email sign-up, the unchecked checkbox creates only a pending choice; entering the verification code confirms ownership of the address and activates that choice. A logged-in user with a verified address can also opt in from Settings. We record the exact wording, version, source, confirmed address and grant or revocation time so that the consent can be demonstrated. No marketing email is sent before activation. Every marketing email contains an unsubscribe link, and you can opt out at any time without any cost other than transmission costs at base rates; withdrawing consent does not affect the lawfulness of processing before withdrawal. Transactional emails (for example security, billing, renewal, storage, and service notifications) are sent regardless, as they are necessary to provide the service.

10. Data Security

We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. Web and storage connections use TLS. Streaming to your chosen destination uses that platform's ingest protocol — RTMPS (encrypted) where the platform offers it, or plain RTMP otherwise — so transport encryption of the stream depends on the destination you select. Passwords are stored only as salted hashes, one-time codes as purpose-bound HMAC values, and session tokens in Secure HttpOnly cookies. Stream keys are additionally encrypted at application level with AES-256-GCM and are not returned to the browser after storage. Access is tenant-bound and privileged backend tables are restricted to the service role. No method of transmission or storage is completely secure, but we review and improve our measures continuously.

11. No Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Decisions about your account (for example in content-moderation cases) are made by humans.

12. Minors

Accounts and contracts are intended exclusively for persons aged 18 or over. Personal data relating to minors may nevertheless appear in uploaded material or in safeguarding, illegal-content or legal reports. We process such data only where necessary to protect affected persons, comply with law, investigate a report, preserve required evidence or notify competent authorities. If you believe a minor's data is being processed improperly, contact us; we will assess and erase or restrict it where legally permitted and appropriate.

13. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interests, and to object to direct marketing at any time (Art. 21 GDPR)
  • Right to withdraw consent at any time, with effect for the future (Art. 7(3) GDPR)

To exercise any of these rights, contact us using the details in section 1. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your residence, your place of work, or the place of the alleged infringement. The authority responsible for our main establishment depends on where the relevant processing decisions are actually made; we will identify the competent authority on request and keep this information under review.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our service or legal requirements. The current version is always available on this page, with the date of the last update shown at the top. If a change materially affects how we process your data, we will inform you (for example by email or an in-app notice).