← Back to PostStream

PostStream legal

Privacy

Last updated August 8, 2026

What PostStream handles

PostStream requires a signed-in account. For a locally created account, the service stores your email, username, display name, a protected password derivation, subscription state, and security records needed to keep you signed in. If you use Google, Discord, YouTube, or Twitch to sign in, PostStream uses the account identifier, display name, and verified email address supplied by that provider to create or find your account. If you sign in with Kick, PostStream uses the Kick account identifier and display name. Because Kick does not assert email verification, new Kick users enter a separate contact email. That address is stored as unverified and contact-only: it is not used to sign in, recover an account, link accounts, or prefill billing. Returning users sign in with the same Kick account. The short-lived provider token used for identity sign-in is not retained.

Public chat content

PostStream reads messages that the selected streaming platform exposes publicly. Those messages are delivered to your browser to build the live feed. The core product does not create a permanent archive of chat messages or viewer profile pictures.

Connected streaming accounts

PostStream uses YouTube API Services when you connect a YouTube account. PostStream accesses and uses YouTube data only to show and manage the connected creator's live chat and to carry out moderation actions that creator requests. Google's handling of data is described in the Google Privacy Policy. You can review or remove PostStream's access from your Google security settings.

If you connect Twitch, YouTube, Kick, or TikTok, PostStream stores the provider account identifier, display name, granted permissions, connection status, and encrypted access and refresh tokens needed to operate the connection. Provider credentials stay on the PostStream server and are never included in the desktop app or stream URL.

Message and viewer identifiers are handled only as needed to perform requested moderation, prevent a removed message from reappearing, or apply a time-limited local mute. Disconnecting a provider makes the stored authorization locally unusable and PostStream also attempts to revoke it with the provider.

Speech and preferences

Voice choice, language, quality, speed, pitch, volume, and auto-correction and chat-filter preferences are stored in your browser or desktop app. For Streamer subscribers, selected public chat text is sent through PostStream's authenticated service to a trusted AI processor for optional correction, selected hate or joke classification, and real-time speech synthesis. PostStream checks for likely private data before forwarding chat text; detected messages are not sent to the AI processor and may be hidden while a chat filter is enabled. PostStream does not create a permanent archive of those requests or returned audio. The processor may retain limited safety records under its service policies. The desktop app may keep a short-lived, in-memory audio cache to avoid immediately repeating a request.

Swizzie scene and widget creation

When you ask Swizzie to create a scene or widget, PostStream sends your prompt and a limited description of the active scene to a trusted AI processor. Swizzie first separates requests for a functional PostStream widget, generated artwork, or a complete scene layout. That description includes supported element types, positions, appearance settings, preset identifiers, and the scene or widget copy you entered or previously generated. It does not include chat messages, camera video, microphone audio, camera or display device identifiers, stored streaming-provider tokens, browser source URLs, stored passwords, local file paths, or access to your computer. For eligible visual-design requests, PostStream may create a generic public-web research query from the supported widget type and bounded visual terms derived from your request. It does not put your raw scene copy, chat, names, email address, credentials, device identifiers, tokens, URLs, file paths, or quoted text in that query. Search results are treated as untrusted and reduced to validated design settings; source text, scripts, links, and instructions are not stored in or executed by your widget. Functional widgets can use only fixed PostStream connectors. Camera and display capture remain local, require an explicit user action and operating-system permission, and are not sent to the AI processor. PostStream sends a prompt and safe design fields to its image-generation processor only when you request generated visual artwork. PostStream validates and re-encodes the returned artwork as a PNG, then stores it privately for preview and OBS use until you explicitly delete that generated artwork or delete your account. Publishing, replacing, or deleting a hosted widget does not remove its underlying artwork because it may still be used by a desktop scene. After the 30-image account limit is reached, you must explicitly remove an unused image before creating another. Provider image URLs and API keys are never exposed to the desktop app or Browser Source. PostStream renders generated widgets with its own validated component templates and does not execute model-generated HTML, JavaScript, URLs, or arbitrary CSS. PostStream does not give Swizzie terminal, shell, or unrestricted network access. The processor may retain limited safety records under its service policies.

Swizzie keeps only the recent user and assistant text from your current conversation in an encrypted file on this device. This temporary memory expires three hours after the latest conversational turn and is cleared when you start a new conversation, sign out, or switch accounts. Pending actions, confirmations, diagnostics, scene snapshots, tool results, and hidden model reasoning are not stored in this conversation memory. PostStream sends the retained text again only when you continue that conversation; it does not ask the AI processor to keep a permanent Swizzie thread.

Payments and connected sign-in

Stripe processes checkout and payment details; PostStream keeps Stripe customer and subscription identifiers, not full card numbers. Stripe collects the billing email used for checkout. Identity providers process the sign-in consent and supply the account details described above. Streaming providers separately process creator-account connection consent and any moderation request you choose to send through their official APIs.

Security and retention

Session credentials are stored as one-way hashes and expire. Billing-event identifiers are retained to prevent duplicate processing. Account and subscription records remain while the account is active or as reasonably needed for security, billing, and legal obligations.