Privacy Policy
Last updated: Aug 7, 2026
Overview
StreamLine AI helps live-stream creators monitor performance in real time, generate speech transcriptions, and receive AI-powered coaching feedback and reports. This policy describes what data we collect, how we use it, the third-party services involved, and your choices.
Data we collect
- Account information: when you sign in with Google, we receive your email address and basic profile information from Google OAuth. We do not receive or store your Google password.
- Gmail (Brand Deals feature, opt-in): the optional Brand Deals feature lets StreamLine AI manage brand-partnership emails for you. It is off unless you connect your Gmail account. When you connect it, we request the Gmail "modify" permission, which grants read access to your entire mailbox plus the ability to compose, send, label, and archive messages. To find brand-partnership inquiries, we scan your incoming inbox mail (and, on connection, up to the previous 30 days) and send message content to our AI provider (AWS Bedrock) to determine whether each message is a brand deal. This means messages that are not brand deals are also read and processed by the AI in order to classify them. We store the message subject, a short preview snippet (up to 200 characters), and details extracted from brand-deal messages (the brand and contact name, the brand contact's email address, the counterparty domain, deal amounts, and message identifiers). We do not store the full body of your emails. Automated replies are sent only for brand-deal correspondence, and only if automatic sending is enabled for your account; otherwise drafts are prepared for review. See the Brand Deals section below for details, including how to disconnect.
- Live dashboard metrics: if you use the StreamLine AI browser extension, it reads publicly displayed metrics from your TikTok Live seller dashboard (e.g. views, viewers, items sold, GMV, click-through rates). The extension reads on-screen data only; it does not intercept network traffic or access your TikTok account credentials.
- Session data: session identifiers, timestamps, status, and metadata required to associate captured data with your StreamLine AI session.
- Optional microphone transcription: if you enable the microphone, your audio is streamed in real time to OpenAI's transcription service and converted to text. Audio is never stored by StreamLine AI; only the resulting text transcripts are saved with your session.
- Scripts & product information: if you upload a stream script or enter product details (name, price, discount), these are stored with your session to power AI analysis.
- User preferences: settings you choose such as transcription language, dark/light mode, and TikTok region.
- AI-generated content: coaching feedback, session reports, and script suggestions generated by our AI are stored with your session.
What we do not collect
- Passwords or full authentication credentials
- Payment card or billing details
- Precise location (GPS)
- Keystroke logging or general browsing history
- Raw audio recordings (audio is streamed for transcription but never stored)
- TikTok account credentials or private TikTok data
- The full body of your emails (Brand Deal messages are read and AI-processed to classify them and extract deal details, but only the subject, a short preview snippet, and those extracted details are stored, never the full body)
Browser extension
The StreamLine AI Chrome extension requires the following permissions to function:
- Host access to tiktok.com domains: to read live dashboard metrics displayed on your TikTok seller dashboard.
- Scripting: to inject a content script that reads on-screen metric values.
- Tabs & webNavigation: to detect when you navigate to a live dashboard page.
- Offscreen document: to capture microphone audio for transcription (only when you enable it).
- Storage: to save your extension preferences (e.g. microphone toggle state) in
chrome.storage.local, and to preserve active session state across service worker restarts inchrome.storage.session. - Alarms: to periodically wake the Manifest V3 service worker during an active session, ensuring metric scraping continues even if Chrome suspends the background process.
The extension only activates on TikTok Live dashboard pages and communicates exclusively with StreamLine AI servers. It does not read, modify, or transmit data from any other websites.
Brand Deals (Gmail access)
Brand Deals is an optional feature that helps creators handle brand-partnership emails. It is off unless you explicitly connect your Gmail account, and you can disconnect it at any time.
- Permission: connecting grants the Gmail "modify" scope, which allows reading your entire mailbox and composing, sending, labeling, and archiving messages. We use only the operations needed to run the feature (reading messages, sending replies, and reading message metadata); we do not delete your mail.
- What we read: to identify brand-partnership inquiries, we scan incoming inbox messages, and on first connection up to the previous 30 days of inbox mail. Because our AI is what decides whether a message is a brand deal, the content of messages that turn out not to be brand deals is also read and processed. We also check your Sent mail (message headers only, never bodies) to confirm which of our replies were delivered.
- AI processing: message content is sent to our AI provider (AWS Bedrock, running Anthropic Claude) to classify the message and extract deal details (such as the rate, video count, and contact name). Replies themselves are filled from a fixed set of templates; the AI does not write the text we send.
- What we store: the message subject, a short preview snippet (up to 200 characters), and details extracted from brand-deal messages, including the brand and contact name, the brand contact's email address, the counterparty domain, deal amounts, and message identifiers. We do not store the full email body.
- Sending: replies are sent on your behalf only for brand-deal correspondence, using a fixed set of templates, and only when automatic sending is enabled for your account. Otherwise, drafts are prepared for you to review.
- Contracts: if you choose to send a partnership contract, the deal details (your legal name, the brand contact's name and email address, and the agreed terms) are shared with our e-signature provider (eSignatures.com) to generate the agreement and signing link. eSignatures.com does not contact the brand directly; the signing link is delivered in the reply sent from your own Gmail account.
- Third-party data: because these are two-sided conversations, we necessarily store some information about the brand's representative (their name and email address) to manage the deal.
- Disconnecting: you can disconnect Gmail at any time from Brand Deals settings, which revokes our access and stops further reading of your mail. You can also revoke access directly from your Google Account permissions. Deal records already extracted are retained until you request deletion (see Data retention).
StreamLine AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, and we do not sell it.
Leaderboard (visible to other StreamLine users)
The leaderboard is the one place where information about you is shown to other people who use StreamLine AI. It is off by default. You are not listed until you turn it on yourself, from the toggle on the Leaderboard page.
- Who can see it: signed-in StreamLine AI users only. The leaderboard is not published on the open web, is not indexed by search engines, and is not visible to people without an account.
- What is shown in the rankings: your display name, your profile photo, your session score, your sales total (GMV) for the period, and how many streams you completed in that period.
- What is shown if someone opens your entry: the above, plus your TikTok username, your level and XP, your sales totals for the current week and month, your stream counts for the week, month and all time, and the date you joined.
- What is never shown: your session reports, transcripts, coaching feedback, scripts, email address, billing details, or anything from Brand Deals.
- Turning it off: switch it off on the Leaderboard page at any time and you are removed from the rankings immediately. Your own stats and reports are unaffected either way. If your subscription lapses you are removed automatically.
- Challenges are separate: joining a challenge is its own decision, and challenge standings are shown to the other participants whether or not the public leaderboard is on.
How we use data
- Provide real-time analytics dashboards for your live sessions
- If you connect Gmail for Brand Deals, detect brand-partnership inquiries, prepare replies from fixed templates, and (when automatic sending is enabled) send them on your behalf
- Generate AI-powered coaching feedback, recommendations, and warnings during your stream
- Produce end-of-session reports with performance summaries and actionable insights
- Enable speech-to-text transcription when you opt in
- Offer AI-assisted script editing and analysis
- Improve the reliability and quality of our service
Third-party services
We use the following third-party services to operate StreamLine AI. We share only the minimum data necessary for each service to perform its function. We do not sell your personal information.
- Supabase (database & authentication): stores your account, sessions, metrics, transcripts, and settings. Handles Google OAuth sign-in.
- OpenAI (transcription): if you enable the microphone, audio is streamed to OpenAI's Realtime API for speech-to-text conversion. OpenAI processes the audio in real time; refer to OpenAI's privacy policy for their data handling practices.
- Amazon Web Services / Anthropic Claude (AI analysis): session metrics, transcripts, scripts, and product information are sent to Anthropic's Claude models (via AWS Bedrock) to generate reports, coaching feedback, and script suggestions.
- Stripe (payments): if you subscribe to a paid plan, payment processing is handled entirely by Stripe. We never receive or store your credit card number or payment card details. We store only your Stripe customer ID, subscription status, and plan type. Refer to Stripe's privacy policy.
- Google (authentication and, if you connect it, Gmail): we use Google OAuth for sign-in and receive your email and basic profile. If you connect the Brand Deals feature, we also access your Gmail to read brand-partnership mail and send replies on your behalf (see the Brand Deals section above). Refer to Google's privacy policy.
- eSignatures.com (contract signing, only if you send a contract): when you send a partnership contract through Brand Deals, the deal details (including the brand contact's name and email address) are shared with eSignatures.com to generate the agreement and record the signature. eSignatures.com does not email the brand directly; the signing link is delivered in the reply sent from your Gmail. Refer to eSignatures.com's privacy policy.
Cookies & local storage
- Authentication tokens: stored in your browser's local storage by Supabase to keep you signed in.
- Preferences: theme (dark/light mode), onboarding status, and privacy-policy acceptance are stored in local storage.
- Sidebar state: a cookie (
sidebar:state) remembers whether the sidebar is open or closed (expires after 7 days). - Extension storage: the Chrome extension stores your microphone toggle preference in
chrome.storage.localand active session state inchrome.storage.session(cleared when the browser closes).
We do not use third-party tracking cookies or advertising cookies.
Data security
All data is transmitted over encrypted connections (HTTPS/WSS). Database access is protected by row-level security policies ensuring you can only access your own sessions and data. API endpoints use signed tokens for authentication. If you connect Gmail for Brand Deals, your Google refresh token is stored encrypted at rest (AES-256-GCM), is never exposed to your browser, and is revoked and deleted when you disconnect.
Data retention
Session data (metrics, transcripts, feedback, reports) is retained as long as your account is active. We may periodically purge raw metric data from older sessions while retaining aggregated reports. You may request deletion of your data at any time by contacting us.
Brand Deal records (deal status, message subjects and preview snippets, and the brand contact details described above) are retained for as long as your account is active so you can manage ongoing deals. Disconnecting Gmail stops further reading of your mailbox but does not by itself delete records already extracted; contact us to have your Brand Deal data deleted.
Your choices
- You can choose whether to enable microphone transcription; it is off by default.
- You can stop data capture at any time by ending your session.
- You can adjust your preferences (language, dark mode, region) in settings.
- The leaderboard is opt-in: you are not listed unless you turn it on from the Leaderboard page, and you can turn it off there at any time.
- Brand Deals is opt-in: you can connect or disconnect Gmail at any time from Brand Deals settings, or revoke access from your Google Account.
- You can request deletion of your account and associated data by emailing us.
Children's privacy
StreamLine AI is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
Changes to this policy
We may update this privacy policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact
Questions or requests? Contact us at yussefaltaher@gmail.com.