LEGAL / PRIVACY-001
Privacy notice
This notice explains in plain language how Botxtream handles information across the website, account, live-video products, support, and billing.
- Effective
- 20 August 2026
- Version
- Google API disclosure v2
1. What this notice covers
This notice covers the Botxtream website, customer and guest experiences, Stream, Studio, Room, Conference, support, billing, and the internal service tools used to help customers. When you connect a destination such as YouTube, our handling of the connection data is covered here. The destination's own handling is governed by its privacy terms.
2. Data we handle
We may handle account and organisation details, workspace access choices, encoder and device diagnostics, live-session information, recordings you select, support conversations, invoices and payment references, security records, and campaign labels after optional consent. Passwords and payment-card details are handled by the relevant identity or payment service and are not exposed in the customer interface.
3. Why we use it
We use information to provide and secure the service, deliver and recover live sessions, manage subscriptions and usage, produce invoices, respond to support requests, prevent abuse, meet legal obligations, and improve Botxtream where consent or another lawful basis applies.
4. Security
Botxtream verifies account access, workspace permissions, and plan limits before sensitive actions. We use encryption, secure connections, protected sessions, limited staff access, security records, and retention controls. No security programme can remove every risk, so incidents follow an established response and notification process.
5. Google and YouTube user data
Botxtream accesses Google user data only after a workspace owner explicitly connects a YouTube account. We request https://www.googleapis.com/auth/youtube.force-ssl so that the owner can use Botxtream to identify the connected YouTube channel and create, bind, update, transition, complete, or delete the YouTube live broadcasts and live streams that the owner asks Botxtream to manage. Read-only or video-upload permissions cannot perform that live-broadcast lifecycle.
We receive the connected channel identifier and display name, the granted permission and its expiry, OAuth access and refresh credentials, and identifiers and status for the live-broadcast and live-stream resources created for the owner. We do not use this permission to download YouTube videos, comments, subscriptions, viewing history, or advertising data.
OAuth credentials are encrypted and stored with our approved cloud-hosting and encrypted-storage provider. Botxtream shares or transfers Google user data only (a) with Google and YouTube to perform the live-stream actions the owner requests, and (b) with that provider to host and protect the service. Access by authorised Botxtream personnel is limited to support, security, and service operation when necessary. We do not sell Google user data, use it for advertising, share it with data brokers, use it to train general-purpose AI models, or disclose it to unrelated third parties. We may disclose the minimum information legally required by a valid process, or as part of a business transfer subject to notice and equivalent protections.
Botxtream retains an active encrypted credential only while the YouTube connection is active. Disconnecting the account asks Google to revoke access and removes the stored credential. A limited connection record containing the provider, channel display name, resource reference, timestamps, and revoked status remains until the workspace is deleted or a verified deletion request is completed. Provider security records expire within 400 days, and service logs expire within one day. These records do not contain the OAuth credential. A legal hold or binding legal obligation may require restricted retention for longer. You can also revoke Botxtream from your Google Account permissions and request deletion at privacy@botxtream.com.
Botxtream's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Service providers and international processing
Approved providers may support cloud hosting, encrypted storage, email, payments, connected destinations, and analytics. Where required, an order form or privacy agreement identifies material provider, region, and transfer terms.
7. Retention
We keep information only for as long as its purpose requires, including account records, customer-selected recordings, legally required invoices, security history, and support conversations. Optional campaign attribution remains in the current browser session and is cleared when consent is withdrawn.
8. Your choices and rights
You can choose essential-only website storage, manage account and notification preferences as those controls launch, and request access, correction, export, restriction, or deletion where applicable. Some security, invoice, legal-hold, or fraud-prevention records may need to be retained with access restricted.
9. Contact and change control
Contact privacy@botxtream.com for a privacy request. Material changes create a new effective version and, where required, an in-product notice or renewed consent rather than silently rewriting an accepted record.
