Last updated 25 July 2026
Loopcast ("Loopcast", "we", "us") runs an automated service that loops a video you upload to Steam, YouTube or Kick as a 24/7 live broadcast. This policy sets out exactly what we collect, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it.
Loopcast.io operates the service and is the controller of the personal data described in this policy. The fastest way to reach us about anything on this page is privacy@loopcast.io, and we answer within one business day.
This policy covers the loopcast.io website, the knowledgebase and the customer panel at loopcast.io/panel. It does not cover Steam, YouTube or Kick. Once your broadcast reaches the platform you chose, that platform handles it under its own privacy policy.
We collect what the service needs to run your broadcasts, bill them by the minute and stay secure. Nothing more:
Under the GDPR we have to tell you the legal basis for each use. Ours are:
We do not sell your data and we do not profile you. The one advertising use is the Google Ads tag described under "Cookies and tracking", which measures whether an ad led to a signup or a purchase and which needs your consent before it stores anything. Your account, streams, keys and video are never part of that. There is no automated decision-making that produces legal or similarly significant effects for you.
Your stream key — Steamworks labels it a broadcast token — is the credential that lets anything broadcast to your channel or store page. We store it in our database on an access-restricted server and use it for one purpose: pushing your stream to the destination you chose. It is never sent back to your browser and never displayed again once saved — the panel only shows whether a key is set. It is not separately encrypted at rest, so the controls that protect it are restricted server access and the fact that it is never exposed through the interface. You can overwrite or delete it whenever you like.
We never ask for, and never need, your Steam, Steamworks, Google, YouTube or Kick password. We cannot log into your accounts.
Your uploaded video and its transcoded copy stay on our server so we can loop them around the clock. Videos belong to your account rather than to one stream, so the same file can feed several streams and deleting a stream leaves the video in place. Delete the video itself, from the video list in your dashboard, and both the upload and everything prepared from it are removed from disk immediately. The stream key is deleted with the stream, as before.
If you think a key has leaked, revoke it at the source — Steamworks, YouTube Studio or your Kick dashboard — and paste the new one into Loopcast. Revoking it there stops every broadcast using it, including ours.
Purchases are processed by Stripe through Stripe's embedded checkout. The card form is served by Stripe inside our page, so your card number, expiry and security code go straight to Stripe and are never transmitted to, processed by or stored on our servers. We are not able to see them.
What we receive and keep is the confirmation: the Stripe session ID, the amount, the minutes credited and the time. Stripe processes your payment as an independent controller under its own privacy policy, and its fraud-prevention tools may set cookies and collect device information inside the payment form.
Transactional email is sent from our own mail server. We do not use a third-party marketing platform, and we do not send newsletters or promotional email unless you ask for them.
Those messages contain a small tracking image and links that redirect through loopcast.io/e/, which lets us record whether a message was opened and whether a link in it was clicked. We use this to confirm that verification, password-reset and billing emails are actually arriving, because a silently undelivered verification email locks someone out of their account.
To stop open tracking, turn off remote images in your email client and the tracking image never loads. If you would rather we did not record this at all, email privacy@loopcast.io and we will exclude your address.
The panel sets one cookie: a signed session cookie that keeps you logged in. It is HttpOnly, SameSite=Lax and lasts 30 days. It is strictly necessary — without it you cannot stay signed in.
The website and the panel carry the Google Ads tag (gtag.js). It is the advertising tag Google provides for measuring which ads lead to a signup or a purchase. When it is switched on it sets cookies in your browser, reads them on later visits, and reports two events to Google: that an account was created, and that minutes were bought, with the amount paid. It does not read your email address, your streams, your stream keys or your video.
The website and the panel also carry Google Analytics (GA4), loaded through Google Tag Manager. It measures how the site is used: which pages are opened, in what order, from which country and referring link, and on what kind of device. It sets its own cookie in your browser so that repeat visits are recognised as the same visitor rather than as new ones. It does not read your email address, your streams, your stream keys or your video.
Both tags are loaded with Google Consent Mode. Advertising storage is denied, for everyone, on every page: the Google Ads tag stores no cookies and reads none, and is in fact switched off entirely at the moment. Analytics storage is granted, which means the Google Analytics cookie described above is set when you load a page. We do not show a cookie banner, so you are not asked to accept this in advance. You can refuse it with any tracker-blocking extension, or with your browser's do-not-track and third-party cookie settings, and nothing on the site breaks if you do.
For the advertising data it receives, Google is a separate controller and uses it under its own privacy policy, not ours. We cannot control what Google does with it. If we ever turn the tag on, the way to refuse it will be the banner; you can also block it today with any tracker-blocking extension, and nothing on the site breaks if you do.
Two other third parties are contacted by your browser while you use the site. Google Fonts serves the typefaces on the public pages, which means Google receives your IP address and user agent when a page loads. Stripe.js loads on the billing screen inside the panel and may set its own cookies for fraud prevention.
We do not sell personal data. We share it where the service cannot run otherwise, and with Google for measuring our own advertising:
There is no other processor. Support is handled by our own team and email is sent from our own server.
Our servers are in the United States, in Phoenix, Arizona. If you are in the EEA, the United Kingdom or Switzerland, using Loopcast means your personal data is transferred to and stored in the United States.
For that transfer we rely on the European Commission's Standard Contractual Clauses, incorporated into our hosting provider's data processing agreement and read with the UK Addendum where the UK GDPR applies, together with the technical measures described under "How we protect it". Stripe and Google handle what they receive under their own transfer safeguards. Ask us at privacy@loopcast.io and we will tell you what is in place.
The site and the panel are served over HTTPS only. Passwords are stored as bcrypt hashes. Session cookies are signed, HttpOnly and SameSite=Lax. Access to the server and the database is limited to the people who operate the service, and administrative actions are written to the activity log.
Uploads are capped at 4 GB and stored on our own server, per stream. We do not copy your video to third-party storage.
No service is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will notify the competent supervisory authority within 72 hours where required, and tell you directly where the law requires it.
If the GDPR or UK GDPR applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we process it (including processing based on our legitimate interests), and to receive it in a portable format.
If you are in California, you have the right to know what we collect, to have it deleted or corrected, and to opt out of the sale or sharing of personal information. We never sell it. "Sharing" in the California sense means handing data to an advertiser for cross-context behavioural advertising, which is what the Google Ads tag would do — but it is held in the denied state and shares nothing, so there is nothing to opt out of today. If we switch it on we will publish a way to opt out before we do. We will not treat you differently for exercising any of these rights.
You can also complain to a data protection authority: in the EEA, the authority for the country you live or work in; in the UK, the Information Commissioner's Office. We would rather you came to us first so we can fix it.
Loopcast is a tool for game developers and publishers. It is not directed at children, and you must be at least 18, or the age of majority where you live, to open an account. We do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@loopcast.io and we will delete it.
If we make a material change we will update the date at the top of this page and, where it matters to you, tell you by email or in your dashboard. Continuing to use Loopcast after a change means you accept the updated policy. Ask us and we will send you the previous version.
For any privacy question or request, email privacy@loopcast.io. We aim to reply within one business day.
Questions about your data or this policy? Email privacy@loopcast.io or use our contact page.