Legal
Privacy Policy
Last updated 2026-08-26 · PlayParty.io
Overview
PlayParty.io ("PlayParty.io", "we", "us", "our") operates a real-time synchronized media watch-party platform, companion browser extension, and supporting server infrastructure. We are committed to transparency in how we collect, process, and safeguard your personal data.
While PlayParty provides synchronization, communication tools, and media compatibility utilities, video and audio playback is rendered directly in each participant's web browser. We do not permanently host, transcode, or store proprietary video libraries on our servers. This policy explains what information we process, the purposes of processing, and your statutory privacy rights.
Information We Collect & Process
1. Account & Profile Information
When you create an account or authenticate via third-party sign-in (such as Google OAuth or Google One Tap), we store your account profile securely in our database:
- Identity & Profile Details: Email address, chosen username, display name, and unique account identifier.
- Authentication Data: Securely hashed authentication tokens or federated authentication identifiers.
- Profile Avatars: Selected default preset identifiers or custom avatar images uploaded through our secure media storage provider (Cloudinary).
- Account Lifecycle State: Verification status, account preferences, and scheduled deletion grace period timestamps.
2. Room Synchronization & Watch History
To maintain real-time playback synchronization and provide room management features:
- Room Metadata & Presence: Room identifiers, titles, access settings, host permissions, and real-time participant presence.
- Playback Coordination State: Active media URLs, provider type (e.g. standard video, streaming playlists, third-party embeds), current playback timestamp, and playback status (playing/paused).
- Watch History: For authenticated users, recently visited room details and media titles are stored in your account history (capped at 20 entries and automatically purged after 90 days). Guest users have watch history stored solely on their local device.
- Room Moderation Records: Temporary cooldown records and ban status entries to protect rooms against unauthorized re-entry and spam.
3. Direct Client-to-Source Streaming & Zero Media Hosting
PlayParty.io is architected for privacy and zero server-side media processing:
- Direct Client Decoding: All video and audio streams decode natively within each participant's local web browser directly from the original source (e.g. YouTube, Twitch, Vimeo, or user-provided links).
- Zero Media Relaying & Zero Storage: Our servers do not proxy, download, transcode, relay, or store third-party video or audio files. Only lightweight playback synchronization timestamp signals (<1 KB JSON packets) pass through our synchronization infrastructure.
- Domain Protection: Our application validates media URLs to protect users against malicious endpoints and prevent server-side network abuse.
4. Search & Media Discovery
Our platform includes search and content exploration features:
- When you perform a search or browse media suggestions, queries and public media identifiers are processed to retrieve titles, thumbnails, and stream metadata.
- Search queries are processed transiently to fulfill the immediate request and are not linked to your user profile or used to construct behavioral advertising profiles.
5. Voice & Video Communication (WebRTC)
We offer real-time voice and video chat powered by our dedicated WebRTC routing infrastructure:
- Real-Time Media Routing: Audio and video streams are transmitted between room participants in real time.
- No Communications Recording: Voice and video streams are routed ephemerally during active sessions. We do not record, transcribe, or store your voice or video conversations.
6. Local Device & Browser Storage
We store certain essential and functional data locally in your browser (via local storage and session storage):
- Display names, guest identifiers, and cached profile details.
- Audio volume preferences, interface layout settings, and room host credentials.
- Cookie preferences and Google Consent Mode settings.
- Secure authentication session tokens (cleared upon sign-out).
7. Companion Browser Extension
If you install the optional PlayParty companion extension, it operates strictly on demand:
- Detects public video stream URLs on the active browser tab when you choose to start or join a party.
- Temporarily retains detected stream references in session storage (automatically cleared when your browser closes).
- Adjusts cross-origin request headers solely to allow the companion player to load user-selected media streams across domains, without modifying DRM or circumventing access controls.
8. Privacy-Preserving Security & Rate Limiting
To protect our infrastructure against distributed denial-of-service (DDoS) attacks, brute-force attempts, and automated abuse:
- We use privacy-preserving, cryptographically hashed representations of IP addresses in volatile memory to calculate request rates.
- Raw IP addresses are not stored in our application database records. Standard connection logs may be processed transiently by our content delivery and network security providers for infrastructure defense.
9. Transactional Notifications
We use reputable transactional email delivery providers (such as Resend and Brevo) to send critical account notifications, email verification links, and password reset instructions. We do not send unsolicited marketing emails or sell your contact information.
10. Performance Telemetry & Error Monitoring
- Google Analytics 4 (GA4): Measures aggregated traffic patterns and device metrics. GA4 operates under Google Consent Mode v2 and is only loaded when consent is granted.
- Application Error Diagnostics: We use error-tracking tools (such as Sentry) to monitor unhandled application errors and system crashes to improve software stability.
- Bug Submissions: When you voluntarily submit feedback or bug reports, the details you provide (description, technical context) are reviewed to diagnose and resolve software bugs.
How We Use Information
- Facilitate real-time playback synchronization and room chat between participants.
- Provide low-latency voice and video communication channels.
- Authenticate user accounts, enforce account security, and manage user profiles.
- Prevent platform abuse, mitigate DDoS threats, and maintain server reliability.
- Troubleshoot application crashes and improve service performance.
We never sell, rent, or monetize your personal data. We do not use your personal information for targeted advertising.
Legal Bases for Processing (GDPR & UK GDPR)
For individuals in the European Economic Area (EEA) and the United Kingdom (UK), our legal bases for processing personal data include:
- Contract Performance (Art. 6(1)(b) GDPR): Providing core features, user accounts, room synchronization, and real-time communication.
- Legitimate Interests (Art. 6(1)(f) GDPR): Ensuring platform security, preventing abuse and fraud, debugging errors, and maintaining operational stability.
- Consent (Art. 6(1)(a) GDPR): Where you have provided express consent for non-essential analytics tracking. You may withdraw consent at any time.
Data Retention & Erasure
- Account Data: Retained for the lifetime of your account. Deletion requests undergo a 30-day grace period, after which all account records and associated avatar files are permanently deleted.
- Server Watch History: Retained for a maximum of 90 days or up to 20 recent entries per account, whichever occurs first.
- Room State: Cleared once participants depart; inactive room metadata is automatically pruned after 30 days.
- Voice & Video Streams: Routed in real time with zero persistent storage or archiving.
- Diagnostics & Analytics: Aggregated telemetry and error logs are retained for up to 30 days before automatic purge.
- Local Browser Data: Persists on your local device until cleared via browser settings or through Settings → Privacy.
Third-Party Service Providers
We work with trusted infrastructure and service providers to operate PlayParty.io under strict confidentiality and data protection standards:
| Service Provider | Role / Function | Privacy Policy |
|---|---|---|
| Supabase Inc. | Cloud database hosting, user authentication, and real-time presence channels | supabase.com/privacy |
| Cloudflare Inc. | Content delivery network (CDN), edge security, asset storage, and DDoS mitigation | cloudflare.com/privacypolicy |
| Cloudinary Ltd. | User profile avatar processing, image optimization, and CDN delivery | cloudinary.com/privacy |
| Resend Inc. | Transactional email delivery (primary) | resend.com/legal/privacy-policy |
| Brevo (Sendinblue) | Transactional email delivery (fallback) | brevo.com/legal/privacypolicy |
| Google LLC | OAuth authentication, Google One Tap sign-in, and Google Analytics 4 | policies.google.com/privacy |
| Functional Software, Inc. (Sentry) | Application error monitoring, crash reporting, and stability analytics | sentry.io/privacy |
| LiveKit Inc. | WebRTC media server software engine for low-latency voice and video routing | livekit.io/privacy |
Your Rights & Self-Service Controls
You have extensive control over your data directly within the application:
- Data Export: Generate and download a complete JSON export of your profile information, watch history, and local preferences in Settings → Privacy.
- Account Deletion: Request immediate deletion of your account and associated profile records in Settings → Privacy.
- Local Data Reset: Clear all device-stored identifiers, preferences, and cached session data via the settings menu.
- Consent Preferences: Modify or withdraw your analytics cookie preferences at any time.
To submit a formal data subject request or contact our privacy team, email [email protected].
California Privacy Disclosures (CCPA / CPRA)
For California residents:
- We do not sell personal information or share personal data for cross-context behavioral advertising.
- You have the right to know what personal data is processed, request deletion, and correct inaccurate personal records.
- We do not discriminate against users for exercising their privacy rights.
- Requests can be made via our self-service settings dashboard or by emailing [email protected].
Children's Privacy
PlayParty.io is not directed to children under 13 (or under 16 where required by local law). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take immediate steps to delete it.
Policy Updates
We may update this Privacy Policy periodically. Significant changes will be noted on this page along with an updated "Last updated" date.