Space City Stream Manager

Privacy Policy

What the manager accesses, where information goes, and how the owner can remove it.

Effective September 9, 2026 · Contact: spacecitylivecam@gmail.com

Overview

Space City Stream Manager is private software operated by the owner of Space City Live Cam, a Downtown Houston livestream. It uses YouTube API Services to manage the owner's channel and local encoder controls to support YouTube and Twitch output. It is not a public account-management service. This policy covers the manager and this informational website.

Data accessed and its purpose

With the owner's Google authorization, the manager accesses channel identity, broadcast identifiers, titles, descriptions, schedules, visibility settings, live-stream resources, ingest health, stream bindings and lifecycle status. It uses this information to verify the channel, monitor health, prepare and start new segments, end previous segments and reconcile interrupted operations.

The Google permission requested is youtube.force-ssl. The permission is broader than the subset of actions used by this manager. The manager does not request access to Google passwords, Gmail messages, contacts, payment information or unrelated Google services.

Local diagnostics can include timestamps, process and output status, upload counters, error categories and camera-health results. Camera samples are analyzed temporarily in memory; the manager does not continuously record or retain local livestream video or screenshots. YouTube and Twitch may separately retain streams and replays under their own services.

Local storage and protection

OAuth credentials are encrypted for the Windows user account on the stream computer. Local state and logs contain operational information and are separate from encrypted credentials. Previous encrypted credentials and recovery copies may be retained in backups. Passwords, stream keys, authorization codes and access or refresh tokens are excluded from diagnostic output and monitoring summaries.

External services and owner-authorized monitoring

The manager communicates with Google/YouTube to perform authorized livestream operations. The owner also uses OpenAI's ChatGPT/Codex app for optional monitoring and maintenance. Health summaries and owner-selected diagnostic context may be processed by OpenAI outside the stream computer. Summaries can include broadcast identifiers, channel-verification results, ingest and output health, timestamps, and incident categories. Their purpose is to identify outages, assist recovery and notify the owner; the monitor does not need raw credentials.

App conversations, tool results and related records are subject to the owner's applicable OpenAI service terms, privacy policy and account controls. They are not governed by the manager's local log timer. This policy does not promise a particular provider retention period or account setting. See OpenAI's Privacy Policy. The owner can disable the app monitor without stopping the manager.

The manager does not sell Google user data or use it for advertising, credit decisions, or identification or tracking of individuals. Authorized access is for the owner and owner-approved operational support. The manager itself does not train AI models. External app processing is governed by the applicable service and account controls described above.

This website and external watch links

This static website is hosted on Google Firebase Hosting. It has no sign-in form, embedded player, advertising, analytics scripts or site-set tracking cookies. Hosting necessarily processes connection information such as IP addresses and requested resources to deliver the pages. See the Google Privacy Policy. Following a watch link opens YouTube or Twitch, where the destination service's terms and privacy practices apply. Sending email shares the information you choose to include with the contact mailbox and its email provider.

Retention by record type

Routine managed logs
Configured for 14-day retention, a 16 MiB daily cap and a 64 MiB total target, checked periodically. Size limits can remove eligible logs earlier. These limits apply to the managed log directory, not every record or backup.
Current operational state and health
Active broadcast state is checked and updated during operation to support safe recovery. Archive-check history expires after 28 days, including from the previous recovery copy. Pending handoff ownership is preserved; unusually old operations raise an alert for owner reconciliation. Log rotation does not delete active recovery state.
Historical records and backups
Specifically inventoried historical API logs, test results and migration-state backups expire after 28 days, using the oldest recognizable record date. Cleanup runs periodically while the manager is available and outside an active handoff. Changed or newly discovered files require owner review. Source code, audit documents, OBS profile backups and encrypted credentials are outside this automatic inventory and require separate review and removal of any retained API data. Replacing an active credential does not delete its backup.
App and email records
Monitoring conversations, tool results and contact messages follow the applicable service's retention and deletion controls. Removing local logs does not remove these external copies.

Removal and revoking access

The owner can revoke access through Google Account third-party access settings. Revocation prevents subsequent authorized access when existing authorization is no longer valid; it does not erase previously stored local records.

  1. Disable the app monitor if external monitoring should end. Request and wait for manager maintenance acknowledgement before retiring its access or removing recovery state.
  2. Revoke Space City Stream Manager in Google Account access settings.
  3. Stop the manager and disable its automatic startup and supervisor tasks before removing local operational records. Then remove the active encrypted credential, previous credential backups, and relevant state, logs, historical records and copies from the stream computer and any owner-controlled backups. The owner should check these categories individually; routine expiry does not constitute a complete account-data purge.
  4. Use the relevant app/account controls to remove conversations or other external records, and contact the provider if further deletion assistance is needed.

Deletion requests are handled as soon as possible and within seven calendar days. The owner must also remove applicable external copies through the relevant service controls; local expiry cannot erase those copies. For help or a privacy request, email spacecitylivecam@gmail.com. Do not send passwords or tokens. Deleting local data or revoking access does not delete broadcasts or other data held by YouTube. Manage that content separately through YouTube.

Google API data commitments

Space City Stream Manager's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The application uses YouTube API Services. See also the Google Privacy Policy and YouTube Terms of Service.

Changes and contact

The effective date changes when material updates are published. The owner must review updated practices before enabling new data uses or monitoring. Questions and complaints may be sent to spacecitylivecam@gmail.com.