Privacy policy
Last updated: 10 October 2026
Draft for the site owner to review. This page is a plain-language draft written for the friend-test release. The owner should check every statement against what the service really does, fill in the highlighted parts and, if needed, have it reviewed by a lawyer before relying on it.
This policy explains what data MiniLive Studio (“we”, “us”) collects when you use minilive.studio, app.minilive.studio and the OBS widget, and what we do with it. We keep it short on purpose.
Who we are
MiniLive Studio is run by [owner: name or company, and country]. You can reach us at [email protected].
What we collect
- Your account. Your email address, your sign-in method, an optional display name, your time zone and the date you joined. If you sign up with a password we store only a salted hash of it (argon2id), never the password itself.
-
Sign in with Google. If you choose it, we ask Google for the
openid,emailandprofilescopes. We receive your Google account identifier, your email address and whether Google has verified it, and your name. We do not get access to your mail, files, contacts or anything else in your Google account. - TikTok accounts you verify. You prove an account is yours by placing a short code in its bio. For verified accounts we read the public information TikTok shows about the account and its LIVE streams: the profile name and picture, when you go live, viewer counts, and the gifts you receive. For each gift that includes the public username and display name of the viewer who sent it. We store these so we can show gift alerts, build the gift jar and compute your stats. We do not read private messages, and we do not watch accounts that no one has verified.
- Widgets. The settings of each widget you create, when it was last opened and the IP address it was last opened from (so you can tell if a link is being used somewhere unexpected). The widget link contains a secret; we store only a hash of it, so we cannot show you the link again.
- Technical data. Our servers and our network provider process IP addresses and request details to deliver the service and to protect it from abuse. We remove query strings from our access logs. [owner: confirm how long logs are kept]
Cookies and tracking
We use one session cookie to keep you signed in. It is strictly necessary for the service. We use no advertising or analytics cookies or scripts, no third-party fonts and no trackers. The OBS widget address does not set cookies.
How we use your data
- To run MiniLive Studio: sign you in, show your widgets and stats, and keep the service working.
- To keep it secure and to prevent abuse.
- To answer you when you contact us.
We do not sell your data, we do not use it for advertising and we do not profile you.
Who else handles it
We use a small number of providers to run the service: a hosting company for our servers and backups ([owner: confirm provider and region]), Cloudflare for DNS, TLS and delivery, Google if you use Google sign-in, and object storage for gift images. They process data on our behalf. We may also disclose data if the law requires it.
How long we keep it
We keep your data while your account exists. If you release a TikTok account, we stop watching it but keep the stats already recorded unless you ask us to delete them. Backups can hold deleted data for a limited time before they are overwritten ([owner: confirm backup retention]).
Your rights
You can ask us to show you the data we hold about you, correct it, or delete it. To delete your account and its data, email [email protected] from the address you signed up with and we will do it. If you are a TikTok viewer who sent a gift and you want your public username removed from a streamer’s stats, write to the same address. Depending on where you live you may have further rights, such as complaining to your data-protection authority.
Security
Traffic is encrypted with HTTPS, passwords and widget secrets are stored hashed, and access to our systems is limited. No system is perfectly secure, so please use a strong, unique password.
Children
MiniLive Studio is not meant for children under 13, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will update the date above and tell signed-in users.
Contact
Questions about this policy: [email protected].