CueCast / Privacy policy
Privacy policy
Last updated: 6 October 2026
This policy covers the local CueCast application and its YouTube sign-in service. The sign-in service operator and project contact is Tomáš Svoboda, info@freeward.dev. The operator of each device or club is responsible for camera operation, rights to recorded content and informing people being recorded.
1. Data we access
When you optionally connect YouTube, CueCast uses YouTube API Services. It accesses the selected channel name, API authorization credentials, the identifier and status of a broadcast it creates, and the ingestion address and stream key. It also processes the broadcast title, description and visibility you enter.
Google grants access through https://www.googleapis.com/auth/youtube.force-ssl.
This permission technically enables broader management of YouTube data; CueCast uses it only
to identify your channel and create, bind and complete live broadcasts. It does not read
Gmail, contacts or Google Drive files. You enter your Google password only on Google's
pages; CueCast never receives it.
2. Why we use the data
We use the data to connect your selected channel, refresh access without repeated sign-in, create the broadcast you request, configure the video encoder destination and complete the broadcast on your instruction. You may instead use a stream key or RTSP camera mode without connecting an account.
Connection is optional. Before connecting you accept CueCast's terms and privacy policy; you then grant YouTube access on Google's consent screen. We process technical security information to prevent abuse. If you contact support, we use your contact information and message to respond to your request.
3. Storage and retention
- On your device: the channel name, encrypted authorization credential (grant), last broadcast metadata, and the version and time of terms acceptance are stored in local CueCast data until disconnection or deletion. Settings may separately contain a stream key and saved broadcast defaults. Access tokens are held in process memory and usually last at most one hour. Older Desktop app sign-in may store a refresh token directly. Running CueCast verifies access and refreshes metadata approximately daily, retrying failed checks after an hour. If access cannot be verified for 30 days, it deletes the connection and associated data. A powered-off device cannot delete files; overdue cleanup happens when the application next starts.
- In the sign-in service: authorization codes and tokens are processed during sign-in or access renewal. The refresh token is contained in the encrypted grant. The service decrypts it to communicate with Google, so the grant is not data inaccessible to the service operator.
- In temporary Upstash Redis storage: login sessions, verification data, terms acceptance version and time, the local CueCast return address and sign-in results expire within 10 minutes of each write; some are removed earlier after one-time use. Rate-limit records containing hashes of IP addresses or credentials expire within one hour of creation.
- In your browser: an essential Secure, HttpOnly sign-in verification cookie expires within 10 minutes and is removed after a successful callback. This website has no advertising trackers or analytics scripts.
The hosting provider may process technical request information such as IP address, time, URL and browser information for operation and security. Availability and retention also depend on the hosting provider's settings and policies; the Redis ten-minute lifetime does not cover hosting logs. Application logs do not intentionally include tokens or stream keys.
4. Video and other services
Video and any audio are processed on your CueCast device. YouTube broadcasts travel directly from that device to YouTube, not through the sign-in service or Redis. Preview video may be temporarily stored on the device and sent to the operator's browser. In IP camera mode it is accessible through the configured RTSP server.
If you enable a CueScore or other web overlay, the device loads its content from that provider, which may process connection information under its own policies. This public website does not embed external video or overlays.
5. Sharing and safeguards
Google and YouTube receive the authorization requests, broadcast data and video needed for the functions you request. Vercel hosts the sign-in service and Upstash provides temporary storage. Depending on service settings and provider terms, these providers may process data outside the European Economic Area. Connections between the sign-in service, Google and Redis use HTTPS. The local CueCast web interface may use HTTP on your network and must be appropriately protected.
We do not sell Google API data or use it for advertising, profiling or training AI models. We use it only for the features described here. Human access is limited to support with your consent, security needs or legal obligations.
CueCast's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Disconnecting, deleting data and your rights
- Choose “Disconnect account” in CueCast settings. This removes local authorization credentials, the acceptance record, channel name, tracked broadcast and remembered defaults. In API mode the stored stream key is also removed; an API-generated key is removed even after switching modes if you have not changed it. Repeat on every device where you connected the account.
- To revoke Google's authorization entirely, remove CueCast in your Google account app permissions. Local disconnection alone does not revoke Google's authorization.
- CueCast automatically performs the same local cleanup when it detects invalid or revoked access. Temporary network errors or exhausted API quotas do not immediately trigger deletion. A manually entered stream key in direct streaming mode is separate from Google sign-in and can be deleted separately. Broadcasts and recordings on YouTube remain there; manage or delete them in YouTube Studio.
For questions or requests to access, correct or delete data held by the service operator, contact info@freeward.dev. Do not send passwords, tokens or stream keys. Depending on applicable law you may also have rights to restriction, objection, portability and a complaint to a supervisory authority; in the Czech Republic this is the Office for Personal Data Protection.
7. Provider policies and updates
YouTube use is also subject to the YouTube Terms of Service and Google Privacy Policy. Hosting and storage information is available in the Vercel privacy notice and Upstash privacy policy.
When data processing changes, we update this page and its date. If new consent or additional permissions are required, we ask before enabling the new functionality.