Privacy Policy
Last updated 12 September 2026
In short: EchoStream takes one video stream from you and forwards it to the platforms you choose. To do that we hold your account details, your stream key, and the destinations you configure. We do not sell your data, we do not run advertising trackers, and we do not record or store your video.
1. Who we are
EchoStream ("we", "us") operates the restreaming service at https://echostream.live. For anything in this policy, contact us at mian@echostream.live.
2. What we collect
You give us
- Account details: username, and an email address if you provide one. Passwords are stored only as a hash, we never see them. If you sign in with Google or Facebook we also store the id that provider assigns you, so we can recognise you next time; we get your name and email address from them and nothing else.
- Your stream key: generated by us, used by your broadcasting software to authenticate.
- Destinations: the RTMP or SRT URLs you add. These contain the stream keys of your accounts on other platforms.
- Connected accounts: if you link a platform, we store the access and refresh tokens that platform issues, plus your channel name and id.
- Profile: an optional picture and bio. These are shown publicly only if you switch your public profile on, it is off unless you choose otherwise.
- Uploads: any files you store with us, and support tickets you write.
Created by using the service
- Stream records: when a stream started and stopped, which node carried it, and per destination success or failure.
- Viewer counts: if you connect a platform, we periodically read your public viewer count while you are live.
- Chat: if you use the multichat, recent messages from your connected channels pass through us so they can be shown in one place.
- Payments: plan, amount, and status. Card details are never handled by us.
- Technical logs: IP address and request details, used to keep the service up and to rate limit abuse.
3. Your video is not recorded
Relay nodes copy your stream to your destinations and hold nothing. There is no transcoding, no recording, and no copy kept after the stream ends. Nodes store no user data and no passwords. They ask this site whether a stream key may publish, and forward the result.
4. How long we keep things
- Chat messages: 10 minutes, and only the most recent 100 per account. The multichat is a live view, not an archive.
- Chat statistics (message counts per platform, most active chatters): 120 days, and 30 days for YouTube.
- Viewer samples: 90 days, and 30 days for YouTube.
- Login sessions: 30 days, or until you sign out.
- Account data, stream history, payments: for as long as your account exists, and afterwards only where we must keep records.
5. Who else sees your data
- The platforms you stream to. Your video goes to them and their own policies apply. We send nothing to a platform you have not configured.
- Platforms you connect. We call their APIs to read your channel name, live status and viewer count, and to fetch chat.
- Our hosting and network providers, including a CDN that fronts this website and therefore sees your IP address.
- A payment provider, if and when card payments are enabled. Where payment is arranged directly, we hold only the order record.
We do not sell personal data and we do not share it for advertising. Inside the service it is handled by automated systems; a person reads it only to answer a support request you raised, to investigate abuse or a security incident, or where the law requires it.
6. YouTube API Services
Where you connect a YouTube account, this service uses YouTube API Services. That connection is optional, because you can restream to YouTube with a stream key alone, and we request only what the features you are using need: your channel name and id, the ingestion key of your own live stream so the relay can send your broadcast to it without you copying that key across by hand, whether the channel is live and its public viewer count, and the live chat of your own broadcast so it can be shown alongside your other channels.
We do not upload, edit, delete or schedule videos, we do not post comments or messages as you, we do not change your channel, and we never use YouTube data for advertising or share it with anyone for their own purposes. Viewer counts we sample and chat statistics are kept for 30 days and chat messages for 10 minutes. Your channel name and id are read again from YouTube at least every 30 days so that what we hold stays current, and a connection YouTube no longer honours is deleted. Disconnecting the account deletes the stored tokens immediately and revokes our access at Google.
What we access from YouTube, and what each thing is for
- Your channel name and id: read when you connect and again at least every 30 days, to label the connection in the panel and in multi-chat, and to recognise the same channel if it is renamed.
- Your live stream keys: read when you connect, when you pick a key from the list and when you press refresh, to build the destination the relay sends your broadcast to. The key is stored inside that destination as a credential and is never shown on any page.
- Whether you are live, and the public viewer count: read every few minutes while you are live, to draw the viewer graph in Analytics and the count in the overlay.
- Your live chat: read every few seconds while you are live and the multi-chat is in use, to show it beside your other channels. Messages are held for 10 minutes; per-author message counts for 30 days.
- Access and refresh tokens: stored encrypted for as long as the connection exists, so the above can happen without asking you to sign in again.
How it is processed, and who sees it
All of this is processed automatically on EchoStream's own servers and stored in EchoStream's database, in the same hosting as the rest of your account. No YouTube data is passed to any other company: not to the relay nodes, which carry video only, not to analytics or advertising services, and not to other users. Inside EchoStream, a person looks at it only to resolve a support request you raised, to investigate abuse or a security incident, or where the law requires it. It is never sold, never used for advertising, and never combined with information about you from anywhere else.
You can see everything we hold from YouTube on the Channels, Analytics and Multi-chat pages, and remove it by disconnecting the account or deleting your account; both take effect immediately. A deletion request sent to mian@echostream.live is completed within 7 days.
By connecting a YouTube account you also agree to the YouTube Terms of Service, and Google's own handling of your information is described in the Google Privacy Policy. You can revoke this application's access to your Google account at any time from your Google security settings.
Limited Use. EchoStream's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this data only to provide the features you asked for, we do not transfer it to others except as needed to run the service or where the law requires it, we do not use it for advertising, and we do not allow humans to read it except with your permission, to resolve a support issue you raised, for security purposes, or where the law requires it.
7. Cookies
Two cookies, and neither one identifies you to an advertiser. The first is your login session, set only when you sign in. The second is set only if you arrive from a tagged link or from another website, and it records where you came from, the campaign name if there was one, the website that linked you and the first page you landed on, so that if you go on to create an account we can tell which of our own posts or pages brought you here. It expires after 30 days, holds no identifier for you, and is never shared or sold. Visitor numbers come from Cloudflare Web Analytics, which sets no cookie at all and collects no personal data. Pages load fonts, an icon set, a stylesheet framework and country flags from third party CDNs, and chat emote images from the platform they came from, those requests reveal your IP address to those providers in the ordinary way.
8. Keeping it safe
Passwords are hashed. Destination URLs and platform tokens are treated as credentials and are never shown on any public page. Access to the panel is over HTTPS and can be protected with two-factor authentication, which we recommend switching on. No system is perfect, if we discover a breach affecting your data we will tell you.
9. Your choices
- Change or delete your details, destinations, connections and profile from the panel at any time.
- Your public profile is off by default. Turning it off again removes the page immediately.
- Regenerate your stream key whenever you like. The old one stops working, including for anything already streaming.
- Ask us for a copy of your data, or for your account to be deleted, at mian@echostream.live.
- Step by step instructions for deleting your account and data are on the data deletion page.
10. Children
This service is not intended for anyone under 13, or under the minimum age set by the platforms you stream to.
11. Changes
If we change this policy we will update the date above, and tell you in the panel when the change is significant.