Storms Live Stream
Back to home page

Privacy Policy

Effective September 12, 2026

This policy explains how the Storms Live Stream mobile app for Android and iOS handles data when live-streaming softball games. The app is not used for advertising profiles, and its operator does not use a proprietary server to transmit video, audio, or game scores.

1. Controller and contact

The app is operated by Michael Dudek.

Privacy enquiries: dudekxmichael@gmail.com

2. Data processed by the app

Camera, video, and microphone

After you explicitly start a broadcast, the app uses your device's camera and microphone. It processes video and audio in real time and sends them directly to the streaming service you select, such as YouTube or your own RTMP/RTMPS server. The app operator does not receive or store this media on a proprietary server.

Scoreboard data and Bluetooth

The app can use Bluetooth Low Energy to read game information from a compatible ESP32 device, including the score, inning, balls, strikes, outs, occupied bases, and time. This information is displayed in the app and can be added to the broadcast video. The operator does not send it to a proprietary server.

Location on older Android versions

Older Android versions require location permission to discover Bluetooth devices. The app does not determine, store, or transmit your physical location. This permission is used only to find a nearby scoreboard.

Google Account and YouTube

Signing in to a Google Account is optional and is used only to manage YouTube broadcasts. The app processes the Google Account email address and the ID, name, and public handle of the selected YouTube channel. It uses this information to display the connected channel and, through the YouTube Data API, to retrieve, create, and modify live broadcasts selected by the user. It requests the youtube.force-ssl scope. The app never receives the Google Account password.

Sign-in takes place in a secure system browser session through Google OAuth and the app's authorization service hosted on Firebase Cloud Functions. This service exchanges the authorization code for access and refresh tokens, verifies the selected YouTube channel, and securely passes the result to the mobile app. Tokens are not included in the mobile app's return URL.

Photos and team logos

You may voluntarily select an image from your gallery as a team logo. The selected image is processed on the device and may become part of the broadcast video. The operator does not separately upload or store it on a proprietary server.

Technical data

The app does not include a proprietary advertising or analytics system. However, the operating system, app store, or third-party service you use may independently process diagnostic data under its own terms.

3. Third-party services and data recipients

Data may be shared only with services that you actively use:

  • Google OAuth and YouTube Data API for sign-in and live broadcast management.
  • YouTube to receive, process, retain, and make the broadcast video available.
  • Firebase Cloud Functions and Cloud Firestore to securely complete Google OAuth sign-in and briefly pass tokens to the mobile app.
  • Another RTMP/RTMPS provider whose address and stream key you enter.
  • Google Play or Apple App Store when installing the app and using system services.

Processing by these providers is governed by their own terms. Information about Google's processing is available in the Google Privacy Policy.

The app's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, profiling, or purposes unrelated to YouTube features that you explicitly initiate.

4. Storage, retention, and security

Current game configuration, team logos, scoreboard state, and information needed for streaming are used by the app during the current session. For each connected YouTube channel, the app stores its ID, name, public handle, Google Account email, and OAuth refresh token in secure device storage backed by Keychain on iOS or Keystore on Android. The refresh token remains stored until you disconnect that channel, revoke access through Google, or remove the relevant data from the device. A short-lived access token is kept only in the running app's memory.

The Firebase broker temporarily stores a random OAuth transaction state, PKCE data, and an expiration time. An unfinished transaction is valid for no more than 10 minutes. Once sign-in is complete, the broker creates a one-time handoff containing the access and refresh tokens, selected channel details, email address, and expiration time. The handoff is atomically deleted when first retrieved successfully and expires within 5 minutes if not retrieved. Expired records are then automatically deleted under Cloud Firestore retention rules. Direct client access to these records is denied.

When the app needs a new access token, it sends the refresh token over an encrypted HTTPS connection to the Firebase broker, which passes it to Google's token service. The broker does not store it permanently during this operation. Tokens, authorization headers, and streaming credentials are not written to application logs.

The retention of broadcasts and related data on YouTube or another streaming provider is determined by your settings and that service's policies. RTMPS encrypts data in transit. If you choose standard RTMP, the transmission may not be encrypted.

5. Permissions and your choices

You control how individual features are used:

  • You can disable the camera and microphone in your device settings.
  • You can choose not to use Bluetooth or revoke its permission.
  • YouTube sign-in is optional. Disconnecting a channel in the app removes its locally stored information and refresh token.
  • Disconnecting in the app does not itself revoke permission granted through Google. You can revoke the app's Google Account access on the Google Account permissions page.
  • You can remove a selected logo from the app.
  • You can remove other local data by clearing app data or uninstalling the app. Due to iOS Keychain behavior, we recommend disconnecting channels in the app before uninstalling it.
  • Broadcasts stored on YouTube or another service must be deleted directly through that provider.

6. Your rights

To the extent provided by applicable law, you may request information, access, correction, restriction, or deletion of personal data, and object to its processing. The operator does not use proprietary user accounts or server-side media storage. Server-side OAuth data is short-lived and deleted automatically, while other data can be managed directly on the device or through your selected streaming provider.

Send questions and requests to dudekxmichael@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection.

7. Children's privacy and recorded individuals

The app is not designed to collect children's data or create accounts for children. The user who starts a broadcast is responsible for obtaining any permission required to record and publish footage of people at a sporting event, including consent from legal guardians where required.

8. Changes to this policy

We may update this policy when the app's features, services, or legal requirements change. The current version and its effective date will always be published on this page.