This policy explains what personal data BabelStreamer collects when you create an account, subscribe, or use the browser extension and OBS plugin, and why. The Service is operated by Kamayu B.V., a company incorporated in the Netherlands ("BabelStreamer", "we", "us"), which is the data controller for the purposes of the GDPR.
The short version: we store what's needed to run your account, bill you, and enforce plan limits — your email, session and billing metadata, and usage counters. We do not store your raw stream audio. The public website loads one third-party advertising tag — the X (Twitter) conversion pixel — to measure sign-ups from the ads we run on X, and records basic page engagement (scroll depth, time on page, link clicks, and how much of the homepage demo video plays) on our own server without cookies or any third party; the browser extension and OBS plugin contain no analytics or advertising trackers of any kind.
1. If you're a Viewer
The browser extension is the part of the Service most Viewers use — you install it to see captions on someone else's stream, and you never need to create a BabelStreamer account to do that. This section is about you specifically; everything from Section 2 onward describes what we collect from a Streamer (the account holder running the stream).
As a Viewer, we don't collect anything about you server-side: watching a stream's captions is a live relay, not something we log or store against an identity, and we don't know who you are. The only data involved is local to your own browser — your extension settings and a small debug log (see Section 7) — which stays on your device unless you choose to share it with us for support.
2. Account & sign-in
We use passwordless (magic-link) sign-in. When you create an account we store your email address, an internal account ID, and (once you subscribe) your Stripe customer ID.
Each time you sign in, we create a session and store the IP address and browser user-agent that session was created from, along with when it was created and last used. This lets us show you your active sessions and let you sign out other devices if your account is ever compromised. We set one cookie, bs_session — an opaque, HttpOnly session identifier, not a tracking ID — which expires automatically after 30 days or when you sign out.
3. Billing
Subscriptions are processed by Stripe. We never see or store your card number — Stripe handles that directly. On our side, we mirror the minimum needed to know what you're entitled to: your Stripe customer ID and subscription details (plan, price, status, renewal dates).
4. Usage & stats
To enforce plan limits (like streaming hours) and bill correctly, we log each streaming session's start and end time and connected duration against your account. We also keep aggregate usage statistics — including a translated-word count per account — to monitor system load and catch problems. Detailed, raw statistics are kept for 25 hours, then rolled up into daily (7 days), weekly (4 weeks), and monthly (12 months) summaries; the account-level word-count figure carries forward into those summaries for up to a year.
5. Your stream audio & captions
Speech recognition runs locally inside the OBS plugin, on your own machine — your raw audio never leaves your computer. Only the resulting transcript text is sent to our servers and translation backend, and it's processed entirely in memory: we don't write transcripts or translations to a database or file.
That text can, however, appear briefly in server-side process logs used for debugging, and in the browser extension's local debug log (see Section 7) — we want to be precise here rather than imply nothing is ever written down anywhere.
6. Currency detection
To show prices in your local currency, we look up your IP address against a copy of the MaxMind GeoLite2 database that we host ourselves. The lookup happens in memory, per request — we don't store your IP address or the resulting location, and it's never sent to MaxMind or any other third party.
7. Cookies & local storage
These are two different mechanisms for two different people — which one applies to you depends on whether you're a Streamer or a Viewer.
If you're a Streamer: the only first-party cookie we set is bs_session (Section 2), when you sign in to the dashboard. Separately, every page of the site loads the X (Twitter) conversion pixel (static.ads-twitter.com/uwt.js): X uses it to tell us when a visit led to a sign-up and to measure the ads we run on X. It sets its own cookies and sends X your IP address, the page URL, and a pixel ID; we pass it no account data and don't use it to profile you. It loads for every visitor — there is no cookie banner yet — so if you'd rather not be measured this way, use your browser's tracking protection or an ad blocker, or opt out of ad personalisation in your X privacy settings. We use no other analytics or advertising vendor.
Page-engagement measurement: the public site also records how far down a page you scroll, how long you stay, which links you click, — on the homepage, where a short demo video loops — whether that video played and roughly how much of it ran, and, while we're occasionally testing an alternate homepage headline, which version you saw, by requesting a 1×1 image (/px.gif) from our own server. This one is first-party and self-hosted — no third party is involved and no vendor receives it. It sets no cookie and uses no persistent identifier: each page view gets a random value that exists only in your browser's memory and is discarded when you close the tab, so we can't link one visit to another, or to your account. What we keep is what our web server already logs anyway — your IP address, the page, your browser's window width, and the event itself — and we use it only to work out which parts of the site people actually read. Some content blockers will stop it and we don’t work around that — if you have asked not to be measured, not being measured is the right outcome, and we would simply rather lose the data. It collects nothing beyond what’s described here.
If you're a Viewer: we don't set any cookies at all. The browser extension instead stores your settings and a small rolling debug log (roughly 2KB) locally on your device via the browser's own extension storage — not a cookie, and not something we can read server-side. It never leaves your device unless you choose to copy it into a support request. That debug log can include recent caption text and your active viewer session identifier, so treat it as you would any other support diagnostic and only share it with us when asked.
8. OBS plugin connection
Connecting the OBS plugin to your account uses a device token — a long secret you generate from your dashboard. We store only a one-way hash of it, never the plaintext. Treat your device token like a password: anyone who has it can stream under your account.
Game vocabulary: every time OBS starts, the plugin separately fetches a small public file of per-game terms we use to prime speech recognition, so live captions get names like "Rift Herald" or "clutch" right. This does not need an account — it works identically whether or not you've connected one, so a streamer just trying the plugin out gets the same captioning quality as one who has signed up. Like any request to our server it lands in our ordinary web server logs (your IP address, the request, and the plugin's own version), which we use only to see roughly how many installations are active; there's no cookie or account link involved.
9. Who we share data with
| Who | What they get | Why |
|---|---|---|
| Stripe | Your email and billing details | Payment processing & subscription management |
| Our translation backend | Transcript text only — never raw audio or viewer IPs | Generating live translations |
| Our mail relay | Your email address | Delivering magic-link sign-in emails |
| X (Twitter) | Your IP address, the page URL, and the pixel's cookie ID — on every page of the site | Measuring ad conversions on X (Section 7) |
We run our own mail relay rather than a third-party marketing platform, and we don't use a CDN to serve the website. Apart from the X (Twitter) conversion pixel in Section 7, we use no analytics or tag-management vendor. We don't sell personal data, and the only advertising-related sharing is the conversion signal that pixel sends back to X.
10. Internal access
A small number of staff can view aggregate operational statistics — server load, active streamers and viewers, and per-account usage volume — through an internal tool, for monitoring and support. This access does not expose your email address, IP address, or caption/transcript content.
11. Data retention & deletion
| Data | Kept until |
|---|---|
| Sign-in sessions | Automatically deleted once they expire (30 days, or immediately on sign-out) |
| Magic-link tokens | Automatically deleted once they expire (15 minutes) |
| Operational stats (Section 4) | Rolled up and pruned on the schedule described there — raw detail for 25 hours, summaries for up to 12 months |
| Account, billing, usage & language data | For as long as your account exists |
You can permanently delete your account at any time from your account page's "Danger zone." Deleting your account cancels any active subscription and erases your email, sessions, device tokens, language selections, and usage history from our systems immediately — it isn't a soft delete, and we can't undo it on request. You can also email us to request the same thing if you'd rather not do it yourself.
12. Your rights
If you're in the EEA, UK, or another jurisdiction with similar protections, you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. Contact us to exercise any of these rights. You also have the right to lodge a complaint with your local data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.
Changes to this policy
If we make a material change to what we collect or how we use it, we'll update this page and adjust the effective date above.
Questions
If you have any questions about this policy, or want to exercise a data right, contact us at info@babelstreamer.com.