Skip to content

Privacy Policy

Last updated: August 23, 2026

TRaX Streaming ("TRaX," "we," "us," or "our") operates the TRaX Streaming platform at traxstreaming.live ("Service"). This Privacy Policy describes what information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

1. Information We Collect

Waitlist and Contact

If you join the waitlist we collect your email address, optionally your name and use-case notes, and submission context: how you found us (UTM parameters, the referring page) and the page you submitted from. We send a confirmation email and only keep you on the list if you click the confirmation link within 7 days. If you use the contact form we collect your name, email address, message, browser user-agent, and the page you wrote from.

Account Information

Registration and sign-in are handled by our self-hosted identity provider. It stores your email address, a hashed password (never plaintext), an email-verified flag, and account status metadata. Our other services store an opaque account identifier that links your data to your account.

Platform Connection Data

When you connect a streaming platform (YouTube, Twitch, or Kick), we store your OAuth access and refresh tokens, the permission scopes you granted, and connection status. These tokens are encrypted at rest with AES-256-GCM. We also store RTMP/SRT stream URLs and stream keys you provide for custom destinations; stream keys are encrypted at rest with AES-256-GCM.

Streaming and Studio Data

We store your studio configurations, scenes and layouts, stream destinations, media files you upload (in S3-compatible object storage), streaming session history, and collaboration records (shared inputs, approval actions, roles). If you configure your own S3-compatible storage for recordings, we store your bucket credentials encrypted at rest with AES-256-GCM, and your recordings are written to your bucket under your control.

Chat Messages

When you connect platform chat, we relay and store the chat messages from your connected channels: message text, the platform author's display name and platform ID, roles and badges, and moderation flags. These messages include personal data of your viewers. See the Retention section below.

Phone Call-In Data

Phone call-in runs on the Twilio account you connect. Twilio carries the call and keeps its own records under your agreement with Twilio, not ours. What reaches us is the call audio, the number the caller dialed, and — unless the caller withholds their caller ID — the caller's telephone number, which we use as the on-screen label for that caller's audio strip in your studio. It lives in your studio's live session state while the call is up and goes away with the call. Our own per-call record holds the number that was dialed, the provider call identifier, and the call's start time, end time and duration; it does not hold the caller's number. Call audio is mixed into the live broadcast, and depending on how the studio is configured it may also be recorded and redistributed to the studio's destinations. The studio operator controls whether a broadcast is recorded and is responsible for giving callers the notice and obtaining the consent their jurisdiction requires. This is personal data of your callers. See the Retention section below.

Payment Information

When paid plans launch, payment processing will be handled by Stripe. Your payment card details are collected directly by Stripe and never touch our servers. We store your Stripe customer ID, subscription and plan details, and payment history (amounts, currency, status).

Automatically Collected Data

  • Server logs may record IP addresses and user agents for security and operations
  • Attribution data (UTM parameters, referrer, timestamps) is stored in your browser's local storage on marketing pages and submitted with your waitlist entry
  • Bot protection: the waitlist form uses Cloudflare Turnstile; the verification token is checked server-side and not stored
  • Analytics: we run our own analytics (Umami) on our own servers. It records page views — the page, the referring site, the approximate region, and the browser and device type. It sets no cookie, stores nothing in your browser, and creates no cross-site or long-term identifier: visits are counted using a value derived from your IP address and browser that is discarded and regenerated daily. Nothing about these page views is sent to a third party, because there is no third party involved
  • Other analytics and error reporting: where separately enabled, product analytics (PostHog) and error reporting (Sentry) may collect page views, interaction events, and error traces
  • Network routing: when your device connects to our streaming ingest servers, our own DNS servers use the connecting IP address to estimate an approximate (city/region level) location and answer with the nearest ingest server. The lookup runs entirely on our infrastructure against a locally stored copy of the GeoLite2 database; your IP address is never sent to the database provider, and the lookup result is used only to answer that request and is not stored

2. Cookies and Similar Technologies

  • Session cookie: an essential authentication cookie that keeps you signed in. It cannot be disabled.
  • Local storage: attribution data on marketing and signup pages, as described above.
  • Our own analytics set nothing at all: Umami, described above, uses no cookie and writes nothing to your browser’s storage. The single thing it reads is an opt-out flag you can set yourself: running localStorage.setItem('umami.disabled', 1) in your browser’s console stops it counting your visits on this site. There is nothing here to consent to because there is nothing stored on your device.
  • Other analytics cookies and storage: used only where the third-party analytics above are separately enabled, and only with your consent where the law requires it.

3. How We Use Your Information

We use the information we collect for the following purposes, with the lawful basis (where GDPR or UK GDPR applies) noted for each:

  • Provide, operate, and maintain the Service (contract)
  • Authenticate you and manage your account (contract)
  • Distribute your streams and chat to the platforms you connect (contract)
  • Process payments and manage subscriptions (contract and legal obligation)
  • Send transactional email such as waitlist confirmations, approval links, and security notices (contract and legitimate interest)
  • Detect and prevent fraud, abuse, and security incidents (legitimate interest)
  • Route your connection to the nearest streaming server using approximate IP-based location (legitimate interest)
  • Understand how visitors find us, via attribution data and, with consent where required, analytics (consent or legitimate interest)
  • Comply with legal obligations (legal obligation)

We do not sell personal data, we do not use your information or your content for advertising, and we do not send marketing email you have not asked for.

4. Google User Data and Limited Use

TRaX uses YouTube API Services. When you connect a YouTube account, we request the youtube.force-ssl scope so we can, at your direction: create and manage your live broadcasts (title, description, privacy, category), retrieve the ingest endpoint your stream is sent to, identify your connected channel, and read, send, and moderate your live chat (deleting messages and timing out or banning viewers in your own chat, as you could in YouTube Studio).

Specifically, through the YouTube API Services we access and use:

  • Channel identity — your YouTube channel ID, display name, and avatar image.
  • Live broadcasts you create or manage — broadcast IDs, titles, descriptions, privacy status, category, and scheduled start/stop times.
  • Live stream / ingestion endpoint — the RTMP ingest URL and stream key used to deliver your broadcast.
  • Live chat — message text, the author's display name and channel ID, badges and roles, and moderation actions you take (such as deleting a message or timing out or banning a viewer).
  • Authorization — OAuth access and refresh tokens and the permission scopes you granted.

The YouTube data we store at rest is your encrypted OAuth tokens and channel identity, which we delete when you disconnect, and the live chat messages you display and moderate through TRaX (message text, author name, roles and badges, and any moderation you apply). We store chat only to power your live chat and moderation, and we delete it within 30 days. When you disconnect a YouTube account, we also delete the chat we collected under that connection. We do not persist other YouTube API responses, such as broadcast metadata, beyond your active session.

TRaX's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google user data only to provide the streaming and chat features you request. We do not use it for advertising, we do not sell it, and we do not allow humans to read it except with your consent, for security purposes, to comply with applicable law, or as needed to operate the Service. You can revoke our access at any time via your Google security settings page at https://myaccount.google.com/connections?filters=3,4&hl=en or by disconnecting YouTube in your TRaX account settings. When you disconnect, we immediately delete the stored tokens and revoke the authorization at Google. Google's handling of your data is described in the Google Privacy Policy.

5. Third-Party Services and Data Sharing

We share your information only with providers needed to run the Service:

ServicePurposeData Shared
CloudflareBot protection (Turnstile), DNS/CDNIP address, request metadata
ResendTransactional email deliveryEmail address, email content
Stripe (when paid plans launch)Payment processingName, email, billing details, subscription state
YouTube (Google), Twitch, KickStream and chat distribution you configureYour stream audio/video, chat messages, OAuth tokens
TwilioTelephony for phone call-in. With bring-your-own-Twilio the account is yours: you contract with Twilio directly, Twilio acts as your processor, and we act on your instructions through it. For any number still provisioned on a legacy TRaX-managed account, Twilio acts as our subprocessor.Caller phone numbers, call metadata, call audio
Self-hosted infrastructureAuthentication, databases, media storage, and streaming servers we operateAll Service data as processed on our own servers
Umami (self-hosted — not a third party)Page-view analytics, running on our own serversPage views, referrer, approximate region, browser and device type. No cookie, no data leaves our infrastructure
PostHog, Sentry (when enabled)Product analytics, error monitoringUsage events, error traces

Geolocation database. To route streams to the nearest ingest server we use a copy of MaxMind's GeoLite2 database hosted on our own infrastructure. No personal data is transmitted to MaxMind: lookups happen locally, and MaxMind appears in this policy only as the database licensor, not as a recipient of your data. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

We may also disclose your information if required by law, in response to a valid legal process, or to protect the rights, property, or safety of TRaX, our users, or the public. We do not have third-party advertising partners.

6. Data Security

  • All traffic between your browser and our servers is encrypted with TLS
  • Platform OAuth tokens, stream keys, and storage credentials are encrypted at rest with AES-256-GCM
  • Passwords are hashed by our identity provider and never stored in plaintext
  • Application secrets are managed through HashiCorp Vault in production
  • WebRTC connections use per-user TURN server credentials

No method of electronic transmission or storage is 100% secure. While we work to protect your information, we cannot guarantee absolute security.

7. Data Retention

We are honest about where retention stands today: we are still defining automated retention schedules, and where no schedule is stated below, data is retained until you ask us to delete it (see Your Rights).

  • Waitlist entries: unconfirmed entries expire after 7 days; confirmed entries are kept while the waitlist program runs
  • Account and studio data (configurations, session history, collaboration records): kept while your account exists
  • Platform OAuth tokens: kept until you disconnect the platform, which deletes them from our systems
  • Uploaded media: kept until you delete the file
  • Chat messages: currently retained without a fixed expiry; deleted on request
  • Contact form messages: currently retained without a fixed expiry; deleted on request
  • Phone call-in records: our per-call records — the number dialed, the provider call identifier, and the call's start, end and duration — are currently retained without a fixed expiry and deleted on request. The caller's own number is used as a live display label and is not written into those records. We do not keep a separate archive of call audio; where a broadcast containing a call is recorded, that recording is kept in the storage you configured, under your control. Twilio keeps its own call logs under its retention policy, in the Twilio account that placed the call — yours, where you connected one.
  • Payment records: retained as required for tax and accounting obligations
  • Server logs: rotated as part of normal operations and not kept long-term

Deletion log

When we carry out a deletion or data-removal request we keep one record of it: a request id, timestamps, the categories of data that were deleted, the categories that were retained, and a one-way hash of your account id. It contains no name, no email address and no account id, and it cannot be used to identify you. We keep it indefinitely as proof that the request was carried out, which the accountability principle in GDPR Article 5(2) requires us to be able to show.

8. Your Rights

Depending on your jurisdiction (including under GDPR and UK GDPR), you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent.

To delete your account, use Delete your TRaX account: signed in, it is one button in account settings; if you cannot sign in, the request form on that page emails a verification link to the address on file. To remove some data without closing your account (platform connections, chat history, media and recordings, or studios), use Remove your data without closing your account. For anything else, including data export, email [email protected]. We will verify your identity and honor your request within 30 days. Deletion requests remove your identity-provider account, platform connections, studio configurations, uploaded media, chat records, and waitlist or contact records, except data we must keep for legal, tax, or security reasons.

  • Disconnection: you can disconnect any linked streaming platform yourself at any time in account settings. We also recommend revoking TRaX's access from the platform's side (for Google, via your Google security settings page at myaccount.google.com/connections).
  • Correction: you can update your email and profile information through the identity provider's account console, or by contacting us.

You may also lodge a complaint with your local data protection supervisory authority.

California

We do not sell or share personal information as defined by the CCPA/CPRA. The categories we collect are identifiers (email, account ID), commercial information (subscription history), internet activity (attribution, usage), approximate location derived from IP addresses (used transiently to route your connection to a nearby server and not stored), and audio/visual content you choose to stream or upload. California residents may submit requests using the contact above.

9. International Data Transfers

Our servers are located in the United States, with additional ingest locations planned. The providers listed above may process data in other jurisdictions. Where GDPR applies, transfers rely on appropriate safeguards such as Standard Contractual Clauses with our providers.

10. Children's Privacy

The Service is not intended for anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete that information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on this page and updating the "Last updated" date above, and for significant changes affecting registered users, by email or in-product notice.

12. Contact Us

TRaX Streaming. Privacy requests: [email protected]. Legal: [email protected].