Sign in Start streaming
← Back to home

Privacy Policy

Last updated 25 July 2026

Loopcast ("Loopcast", "we", "us") runs an automated service that loops a video you upload to Steam, YouTube or Kick as a 24/7 live broadcast. This policy sets out exactly what we collect, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it.

Who we are and what this covers

Loopcast.io operates the service and is the controller of the personal data described in this policy. The fastest way to reach us about anything on this page is privacy@loopcast.io, and we answer within one business day.

This policy covers the loopcast.io website, the knowledgebase and the customer panel at loopcast.io/panel. It does not cover Steam, YouTube or Kick. Once your broadcast reaches the platform you chose, that platform handles it under its own privacy policy.

Information we collect

We collect what the service needs to run your broadcasts, bill them by the minute and stay secure. Nothing more:

Account: your email address and your password, stored only as a bcrypt hash. We never see the password itself. We do not ask for your name to open an account.
Stream setup: a name you give each stream, the destination (Steam, YouTube or Kick), your Steam App ID where that applies, the RTMP ingest URL, and the stream key you paste in.
Video: the file you upload, up to 4 GB, and the transcoded copy we actually broadcast.
Balance and usage: your balance of minutes and a ledger of every credit and deduction, each with a reason and a timestamp.
Purchases: the Stripe Checkout session ID, the amount paid and the minutes credited. Card details are entered inside Stripe's own payment form and never reach our servers.
Security and activity log: signups including rejected attempts, logins and failed logins, email verifications, password resets, email changes, stream creation, start, stop and deletion, purchases and admin actions. Each entry records the email address involved, the IP address the request came from and the time.
Broadcast logs: per-stream encoder output, covering start and stop times, bitrate, restarts and errors.
Email records: for each message we send you, the recipient address, subject, delivery result, and whether and when it was opened or a link in it was clicked.
Contact form: the name, email address, topic and message you submit, plus the IP address and time, sent to our support inbox.
Server logs: ordinary web-server records of requests, including IP address, time, URL, referrer and browser user agent.

How we use it, and our legal basis

Under the GDPR we have to tell you the legal basis for each use. Ours are:

Running your account, your streams and your broadcasts, and metering your balance by the minute — necessary to perform our contract with you (Art. 6(1)(b)).
Sending transactional email: address verification, password resets, purchase confirmations, low-balance warnings and service notices — performance of our contract.
Answering your support and contact-form messages — performance of our contract, or our legitimate interest in replying to people who write to us.
Keeping the service secure and free of abuse: the activity log, failed-login records, IP addresses and payment-fraud checks — our legitimate interest (Art. 6(1)(f)) in protecting the service, our customers and ourselves.
Checking that important emails are delivered and read, and diagnosing delivery failures — our legitimate interest in reliable communication. See "Email we send you" below for how to switch this off.
Keeping payment and accounting records — a legal obligation (Art. 6(1)(c)).

We do not sell your data and we do not profile you. The one advertising use is the Google Ads tag described under "Cookies and tracking", which measures whether an ad led to a signup or a purchase and which needs your consent before it stores anything. Your account, streams, keys and video are never part of that. There is no automated decision-making that produces legal or similarly significant effects for you.

Your stream key and your video

Your stream key — Steamworks labels it a broadcast token — is the credential that lets anything broadcast to your channel or store page. We store it in our database on an access-restricted server and use it for one purpose: pushing your stream to the destination you chose. It is never sent back to your browser and never displayed again once saved — the panel only shows whether a key is set. It is not separately encrypted at rest, so the controls that protect it are restricted server access and the fact that it is never exposed through the interface. You can overwrite or delete it whenever you like.

We never ask for, and never need, your Steam, Steamworks, Google, YouTube or Kick password. We cannot log into your accounts.

Your uploaded video and its transcoded copy stay on our server so we can loop them around the clock. Videos belong to your account rather than to one stream, so the same file can feed several streams and deleting a stream leaves the video in place. Delete the video itself, from the video list in your dashboard, and both the upload and everything prepared from it are removed from disk immediately. The stream key is deleted with the stream, as before.

If you think a key has leaked, revoke it at the source — Steamworks, YouTube Studio or your Kick dashboard — and paste the new one into Loopcast. Revoking it there stops every broadcast using it, including ours.

Payments

Purchases are processed by Stripe through Stripe's embedded checkout. The card form is served by Stripe inside our page, so your card number, expiry and security code go straight to Stripe and are never transmitted to, processed by or stored on our servers. We are not able to see them.

What we receive and keep is the confirmation: the Stripe session ID, the amount, the minutes credited and the time. Stripe processes your payment as an independent controller under its own privacy policy, and its fraud-prevention tools may set cookies and collect device information inside the payment form.

Email we send you

Transactional email is sent from our own mail server. We do not use a third-party marketing platform, and we do not send newsletters or promotional email unless you ask for them.

Those messages contain a small tracking image and links that redirect through loopcast.io/e/, which lets us record whether a message was opened and whether a link in it was clicked. We use this to confirm that verification, password-reset and billing emails are actually arriving, because a silently undelivered verification email locks someone out of their account.

To stop open tracking, turn off remote images in your email client and the tracking image never loads. If you would rather we did not record this at all, email privacy@loopcast.io and we will exclude your address.

Cookies and tracking

The panel sets one cookie: a signed session cookie that keeps you logged in. It is HttpOnly, SameSite=Lax and lasts 30 days. It is strictly necessary — without it you cannot stay signed in.

The website and the panel carry the Google Ads tag (gtag.js). It is the advertising tag Google provides for measuring which ads lead to a signup or a purchase. When it is switched on it sets cookies in your browser, reads them on later visits, and reports two events to Google: that an account was created, and that minutes were bought, with the amount paid. It does not read your email address, your streams, your stream keys or your video.

The website and the panel also carry Google Analytics (GA4), loaded through Google Tag Manager. It measures how the site is used: which pages are opened, in what order, from which country and referring link, and on what kind of device. It sets its own cookie in your browser so that repeat visits are recognised as the same visitor rather than as new ones. It does not read your email address, your streams, your stream keys or your video.

Both tags are loaded with Google Consent Mode. Advertising storage is denied, for everyone, on every page: the Google Ads tag stores no cookies and reads none, and is in fact switched off entirely at the moment. Analytics storage is granted, which means the Google Analytics cookie described above is set when you load a page. We do not show a cookie banner, so you are not asked to accept this in advance. You can refuse it with any tracker-blocking extension, or with your browser's do-not-track and third-party cookie settings, and nothing on the site breaks if you do.

For the advertising data it receives, Google is a separate controller and uses it under its own privacy policy, not ours. We cannot control what Google does with it. If we ever turn the tag on, the way to refuse it will be the banner; you can also block it today with any tracker-blocking extension, and nothing on the site breaks if you do.

Two other third parties are contacted by your browser while you use the site. Google Fonts serves the typefaces on the public pages, which means Google receives your IP address and user agent when a page loads. Stripe.js loads on the billing screen inside the panel and may set its own cookies for fraud prevention.

Who else sees your data

We do not sell personal data. We share it where the service cannot run otherwise, and with Google for measuring our own advertising:

Our hosting provider, Namecheap, whose datacentre in Phoenix, Arizona, United States runs our servers, storage and broadcasts.
Stripe, for processing payments.
Google, on two counts beyond YouTube below: loading Google Fonts reveals your IP address, and the Google Ads tag reports a signup or a purchase, with the amount paid, once it has your consent to store anything. For that advertising data Google is a separate controller, not our processor.
The platform you choose to broadcast to — Steam (Valve), YouTube (Google) or Kick — which receives the video you broadcast, through the key you supplied.
Authorities, or our legal and accounting advisers, where we are legally required to disclose something or need to establish, exercise or defend a legal claim.

There is no other processor. Support is handled by our own team and email is sent from our own server.

Where your data is processed

Our servers are in the United States, in Phoenix, Arizona. If you are in the EEA, the United Kingdom or Switzerland, using Loopcast means your personal data is transferred to and stored in the United States.

For that transfer we rely on the European Commission's Standard Contractual Clauses, incorporated into our hosting provider's data processing agreement and read with the UK Addendum where the UK GDPR applies, together with the technical measures described under "How we protect it". Stripe and Google handle what they receive under their own transfer safeguards. Ask us at privacy@loopcast.io and we will tell you what is in place.

How long we keep it

Account records: for as long as your account is open. Ask us to delete it and we remove the account, its streams, the stream keys and the uploaded video.
Uploaded video and transcodes: until you delete the video from your dashboard or close the account. Videos are held against the account, not a single stream, so they outlive the streams that use them. Deletion from disk is immediate. There is a limit of 10 videos per account.
Security and activity log: 365 days, after which a daily sweep deletes it automatically. These entries keep the email address they were recorded against, so a limited trail of events such as logins and purchases survives account deletion for the rest of that period.
Broadcast logs: kept with the stream and deleted with it.
Email records: kept while they are useful for delivery diagnostics and support history.
Payment and accounting records: kept for as long as tax and accounting law requires, which is typically several years and longer than your account may last.
Web-server logs: kept on our host's standard short rotation.

How we protect it

The site and the panel are served over HTTPS only. Passwords are stored as bcrypt hashes. Session cookies are signed, HttpOnly and SameSite=Lax. Access to the server and the database is limited to the people who operate the service, and administrative actions are written to the activity log.

Uploads are capped at 4 GB and stored on our own server, per stream. We do not copy your video to third-party storage.

No service is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will notify the competent supervisory authority within 72 hours where required, and tell you directly where the law requires it.

Your rights

If the GDPR or UK GDPR applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we process it (including processing based on our legitimate interests), and to receive it in a portable format.

Some of this you can do yourself in the panel: change your email address, replace or delete uploaded video, and delete a stream together with its key.
For anything else, including deleting your account entirely or getting a copy of your data, email privacy@loopcast.io. There is no one-click account deletion in the panel today; we do it by hand when you ask.
We reply within one month, as the GDPR requires, and we will check that the request comes from the account's own email address before acting on it.

If you are in California, you have the right to know what we collect, to have it deleted or corrected, and to opt out of the sale or sharing of personal information. We never sell it. "Sharing" in the California sense means handing data to an advertiser for cross-context behavioural advertising, which is what the Google Ads tag would do — but it is held in the denied state and shares nothing, so there is nothing to opt out of today. If we switch it on we will publish a way to opt out before we do. We will not treat you differently for exercising any of these rights.

You can also complain to a data protection authority: in the EEA, the authority for the country you live or work in; in the UK, the Information Commissioner's Office. We would rather you came to us first so we can fix it.

Children

Loopcast is a tool for game developers and publishers. It is not directed at children, and you must be at least 18, or the age of majority where you live, to open an account. We do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@loopcast.io and we will delete it.

Changes to this policy

If we make a material change we will update the date at the top of this page and, where it matters to you, tell you by email or in your dashboard. Continuing to use Loopcast after a change means you accept the updated policy. Ask us and we will send you the previous version.

Contact us

For any privacy question or request, email privacy@loopcast.io. We aim to reply within one business day.

Questions about your data or this policy? Email privacy@loopcast.io or use our contact page.