01 / SCOPE
Scope and operator
This policy explains how the person operating Codebam Stream under the online username Codebam ("we" or "us") handles personal information for stream.codebam.ca, the personal livestream at live.codebam.ca, public channel watch pages, account access, live media, relays, prepaid credits, refunds, and disputes.
It does not replace the privacy policies of Discord, GitHub, Stripe, Cloudflare, YouTube, Twitch, X, Kick, Telegram, OBS, or another service you choose to use.
02 / AUDIENCE
Site visits and public viewing
Cloudflare processes technical request information needed to deliver and protect the sites. This can include your IP address, browser and device information, requested address, timestamps, connection details, and security signals. Infrastructure and security logs follow the settings of the relevant Cloudflare service. Codebam Stream also keeps limited operational events, status codes, failure reasons, and timing data needed to secure, diagnose, reconcile, and maintain the Service; credentials and full live-media contents are not intentionally written to application logs.
When you open a live broadcast, your browser creates a receive-only WebRTC session through Cloudflare Realtime. The Service keeps temporary session identifiers, connection state, heartbeat time, and start and end times needed to connect, account for delivery, and clean up the viewer. For customer channels, viewing duration is added to the channel owner's aggregate viewer-hour usage. It is not used to identify individual viewers in the channel owner's dashboard.
Codebam Stream does not use advertising pixels or third-party analytics and does not intentionally set analytics or advertising cookies. Cloudflare may use strictly necessary security technologies as part of its service.
03 / IDENTITY
Accounts, OAuth, and browser state
If you sign in with Discord or GitHub, Codebam Stream receives the provider account identifier, display name, and a verified email address when the provider makes one available. If you connect both providers, both identifiers are associated with the same Codebam Stream account. OAuth access tokens are used to retrieve that identity during sign-in and are not stored by the Service.
The Service stores a one-way hash of the account session token, session creation and expiry times, and a random anti-forgery token in your browser. Strictly necessary browser state includes:
- account session and anti-forgery cookies lasting up to 30 days;
- temporary Discord or GitHub sign-in cookies lasting up to 10 minutes; and
- an optional Stripe Checkout Session identifier in browser session storage, used only to assist status recovery after a prepaid Checkout redirect.
The server-owned prepaid order list remains the primary Checkout recovery record; browser session storage is not the only source of order state. Logging out deletes the current server session and clears the account cookies in that browser.
04 / SIGNAL
Channels, credentials, and live media
For a customer channel, Codebam Stream stores the account owner, channel name and public address, enabled state, timestamps, the always-start-enabled-destinations preference, and a one-way keyed hash of the ingest token. The original ingest token is shown only when created or rotated and is not retained for later display.
If you configure a relay, Codebam Stream stores the provider name, enabled or paused state, revision information, and encrypted provider configuration. The encrypted configuration can contain a YouTube, Twitch, X, Kick, or Telegram stream key and, for X, Kick, or Telegram, the secure server address. Saved stream keys and server addresses are not returned to the browser. They are decrypted only when needed to validate or run the relay.
Live audio and video pass through Cloudflare Realtime and, when a relay is running, through the Codebam Stream relay process to selected destinations. Codebam Stream does not record the broadcast or provide a recording archive. A destination may record or retain it under that destination's settings and policies.
The Service stores temporary broadcast and viewer session identifiers, track references, source resource identifiers, relay generations, desired destination revisions, provider health, cleanup state, and usage timing needed to deliver and account for a live session. Viewers and configured destinations do not receive the publisher's source network address from Codebam Stream, but Cloudflare necessarily receives connection information from publishers and viewers.
05 / SETTLEMENT
Prepaid orders and usage accounting
When you start a prepaid purchase, Codebam Stream sends Stripe the customer identity and billing metadata needed to bind a one-time Checkout to your account and chosen credit kind and whole-hour quantity. Stripe collects payment and billing information. Codebam Stream does not receive or store your full payment-card number.
Codebam Stream stores prepaid order terms and identifiers, including account and customer generations, credit kind, whole-hour quantity, unit and total amounts, currency, one-time Stripe Price, Checkout Session, Payment Intent or zero-total settlement identity, charge, refund, dispute, idempotency, reconciliation, grant, hold, forfeiture, and timestamp data. Stripe processes promotion-code entry and discount restrictions; the Service verifies that an applied discount is percentage-based but does not store the customer-facing code in its prepaid ledger. Recent server-owned orders are returned to the authenticated dashboard so pending Checkouts can be displayed and safely resumed.
Confirmed credit grants and delivered relay or viewer usage are recorded in the prepaid ledger. At settlement, delivered usage is allocated first to immutable base credit and then to the oldest currently spendable purchase grant. Delayed events use credit available when they settle, and recorded physical allocations do not move later. Full-refund and lost-dispute outcomes can remove unused related credit while keeping delivered usage and its settlement allocation recorded. Partial refunds, open holds, releases, and refund attempts are retained so balances can be reconstructed and verified.
Historical customer, recurring-plan, billing-period, fixed top-up, portal, invoice, and related Stripe records may remain where needed to account for the earlier billing system. New credit purchases use one-time Stripe Checkout and do not create a monthly renewal.
06 / PURPOSE
How information is used
Information is used to:
- sign you in, link chosen login providers, and secure the account;
- create channels, authenticate OBS, and operate watch pages and relays;
- apply the always-start preference when a future OBS connection begins;
- deliver live video and maintain temporary media sessions;
- measure viewer concurrency, per-destination relay time, and aggregate browser viewer time;
- create and reconcile prepaid orders, grants, usage settlements, refunds, and disputes;
- diagnose failures, prevent abuse, and protect the Service; and
- respond to support, privacy, and legal requests and meet legal obligations.
Where applicable law requires a legal basis, processing is based on performing the service contract, your consent or direction, compliance with legal obligations, and the operator's legitimate interests in operating, accounting for, and securing the Service.
08 / RETENTION
Retention and deletion
Live media is not recorded by Codebam Stream. Temporary broadcast, viewer, relay, heartbeat, and cleanup state is kept while needed to run or safely close a session and resolve delivery or accounting failures.
Account identity, channel preferences, encrypted destination settings, and session records are kept while needed to provide and secure the account. Deleting a channel deletes its saved destination settings. Prepaid orders, grants, immutable usage settlements and allocations, usage events, webhooks, historical billing records, refunds, disputes, fraud signals, and transaction records may be retained longer where reasonably needed for accounting, legal obligations, security, dispute handling, and proof of correct balance calculation.
Information is deleted or de-identified when no longer reasonably needed, unless law permits or requires longer retention. Backups and provider systems can take additional time to cycle out deleted data.
09 / SECURITY
Security controls
Codebam Stream uses encrypted destination configurations, hashed ingest and session credentials, limited OAuth scopes, signed Stripe webhooks, account and payment ownership checks, same-origin request protection, immutable settlement controls, and restricted browser security policies. No internet service can guarantee absolute security. Keep ingest tokens and destination stream keys private and contact us if you suspect compromise.
10 / CHOICES
Your choices and rights
You can watch public pages without creating an account. In the dashboard, you can log out, turn automatic relay start off, manually stop a relay, pause or remove a destination, replace provider credentials, rotate the ingest token, and delete the channel and its destination settings. You can avoid future payment data by not opening or completing another one-time Checkout. There is no new recurring renewal to cancel.
Depending on where you live, you may have rights to request access to or correction of your personal information, ask for deletion, withdraw consent where processing depends on consent, or complain about how information is handled. These rights can be limited by payment, immutable usage-integrity, security, dispute, legal, or technical requirements.
Send a request to codebam@riseup.net. We may ask for enough information to verify that the request concerns you. For payment information held by Stripe or identity data held by Discord or GitHub, use that provider's privacy controls.
11 / REVISION
Children and policy changes
The paid Service is intended for people able to enter a binding contract and is not directed to children. Codebam Stream does not knowingly collect account information from a child who cannot legally consent to the Service.
This policy may be updated when the Service or legal requirements change. Material changes apply prospectively and will be posted here. The effective date identifies the current version.
12 / CONTACT
Contact
CODEBAM STREAM / PRIVACYIndependently operated under the online username Codebamcodebam@riseup.net