Privacy Policy
Effective date: October 7, 2026
This Privacy Policy explains how Streambox Labs, LLC ("Streambox Labs", "we", "us" or "our") collects, uses, shares and deletes information when you use streamboxlabs.com and its subdomains, the Streambox web app and related services, together the "Service". Organizations use the Service to produce live sports broadcasts and stream them to YouTube. By using the Service you agree to this Privacy Policy and to our Terms of Use.
1. We use YouTube API Services
The Service uses YouTube API Services to create and manage live broadcasts on the YouTube channels you link to it. By using these features you agree to be bound by the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
2. Information we access, collect and store
Your Streambox account
Accounts are created for members of an organization and signed in through our sign-in provider. We store your email address, your username, the organizations you belong to and your role. We record who starts each broadcast session, and when it starts and stops. People you work with on a broadcast can see your username.
Information from YouTube (API Data)
When you link a YouTube channel, you grant the Service permission to manage your YouTube account. With it we access:
- your channel's ID, name and profile picture;
- authorization tokens for the channel;
- the channel's live broadcasts and streams, and the videos made from them, with their settings.
We do not access YouTube Analytics, statistics such as view counts, comments, live chat, or your Google account's email address or profile. Section 5 explains what we store and for how long.
Broadcast content
The video, audio and data that make up your broadcasts, and media your organization uploads.
Technical information
Our servers log requests and errors, including IP addresses, browser type, the pages and features used and, for YouTube actions, broadcast and video IDs.
3. How we use information
- To sign you in and apply your organization's permissions.
- On the YouTube channels you link, and only as you or your organization's settings direct: to create and manage live broadcasts, streams and videos and their settings, and to show you the channel's name and picture.
- To produce and deliver your broadcasts.
- To provide support, keep the Service secure and fix problems.
We do not use API Data or other Google user data for advertising, we do not sell it, and we do not use it to build profiles or to calculate new metrics from it.
4. How we share information
- Inside your organization. Linked YouTube channels belong to your organization's account. Its members can see and use them, and people working on a broadcast can see its details.
- Inside Streambox Labs, only with staff who need the information to run, support or secure the Service.
- Google and YouTube receive what we send on your instructions, such as broadcast settings, images and video. Broadcasts are published with the privacy setting you choose, under YouTube's terms.
- Service providers that run parts of the Service for us, such as hosting, sign-in, media and content delivery providers. Each receives only what its service needs, and only our hosting provider stores YouTube API Data.
- Partners your organization chooses. When your organization turns on an integration with a third party, we share what that integration needs. This can include the YouTube video IDs of your broadcasts.
- For legal reasons: when required by law or to protect the rights, property or safety of our users, the public or us.
- In a business transfer, such as a merger or acquisition, under this policy's protections.
We do not sell personal information.
5. How long we keep information, and deleting it
- Linked channels (tokens, channel ID, name and picture): until you remove the channel or revoke access. We check each linked channel with YouTube every day and update its name and picture. If Google reports that access was revoked or the channel no longer exists, or we cannot refresh it for 30 days, we delete what we stored for it, except its name: we keep that for up to 7 days, only to tell your organization's administrators that the channel was disconnected.
- Broadcast history (broadcast IDs and channel names): deleted after 30 days.
- Live broadcast details and stream keys used during a broadcast session: deleted within two days of the session ending.
- Account information and uploaded media: while your organization's account is active, or until deleted.
Removing a channel. An organization member can remove a linked channel at any time under Settings → YouTube accounts. We then revoke the Service's access with Google and delete the channel's tokens, name, picture and broadcast history. If another organization has also linked the channel, its access is not affected.
Revoking access through Google. In addition to our normal procedure for deleting stored data, you can revoke the Service's access to your data at any time on the Google security settings page at https://security.google.com/settings/security/permissions. We detect a revoked grant within a day and delete what we stored for that channel, apart from its name in the disconnection notice described above.
Asking us to delete your data. Email team@streamboxlabs.com. We delete the data within 7 days.
6. Cookies and information stored on your device
The Service stores and reads information on your device and in your browser:
- A session cookie from streamboxlabs.com keeps you signed in and secures the sign-in and YouTube linking steps. It is needed for the Service to work and is deleted when you close your browser.
- Our sign-in provider sets its own cookies on its sign-in pages.
- Local storage in your browser remembers your preferences and work in progress. It stays on your device.
- Third parties whose content our pages load can read or set their own cookies and receive your IP address and browser information: Google, which serves images and fonts on some pages and runs its own pages, such as its consent screen; and the service providers described in section 4.
We do not use advertising or analytics cookies, and we do not let third parties serve content or advertisements in the Service.
7. Security
Information travels over encrypted connections. YouTube tokens are kept in an access-controlled database that is encrypted at rest, and are never sent to your browser. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information.
9. Where information is processed
The Service is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the United States.
10. Your choices and rights
You can ask to see, correct or delete your personal information by emailing team@streamboxlabs.com. You can remove a linked YouTube channel or revoke access as described in section 5.
11. Changes to this policy
We will post any change to this policy on this page with a new effective date, and tell organization administrators about material changes.
12. Contact us
Questions or complaints about our privacy practices go to Streambox Labs, LLC at team@streamboxlabs.com.