PRIVACY
Privacy Policy
SceneMeld is a local-first live-production app. When you connect a streaming platform account, we process only the limited account data needed to authorize that connection and create broadcasts. We do not receive your camera, microphone, screen, or live media content.
Last updated: September 8, 2026
1. Scope
This policy applies to the SceneMeld apps for macOS, iOS, and iPadOS, this website, and the authorization service used to connect YouTube, Twitch, and other supported streaming platforms. It explains what we process, where it is stored, and how data moves when you create a broadcast or start streaming.
2. Content we do not collect
SceneMeld does not require a SceneMeld account and contains no advertising SDK, cross-app tracking, usage analytics, or automatic crash-upload service. The developer does not receive or retain your scenes, camera video, microphone audio, screen content, local movie files, or live media stream. We cannot see the password you enter on a streaming platform's sign-in page.
3. Streaming-platform connections
SceneMeld opens a platform's secure sign-in and consent page only after you choose to connect it. After authorization, we process the platform account identifier, display name, avatar URL, granted scopes, access token, optional refresh token, and connection time. We use this information only to maintain the connection; identify the channel that granted access; list, create, select, configure, start, or end a broadcast; retrieve its ingest destination; and display incoming audience messages—not for ads, profiling, or analytics.
Platform tokens are encrypted at rest by the SceneMeld authorization service hosted in Hong Kong. A device-specific session credential is stored in Apple Keychain. Platform client secrets are never embedded in the app or public source repository.
4. YouTube API Services
SceneMeld uses YouTube API Services and requests the youtube.force-ssl scope through Google OAuth. After you connect YouTube, we may access or process your channel identifier, channel title and avatar, broadcast identifiers, titles, status, latency preference, live chat identifier, ingest destination and stream key, as well as live chat messages, author display names, avatars, and timestamps. We use this data only to display and manage the broadcast you select, prepare its ingest destination, apply your latency choice, and read live chat.
Audience Activity in the current SceneMeld app is a read-only message monitor, not a chat composer. Use Open on YouTube to reply, use platform emoji, or moderate on YouTube itself. Those actions take place on YouTube, not in the SceneMeld app. Messages you post on YouTube may then appear in Audience Activity as incoming messages.
SceneMeld does not use YouTube API Data for advertising, profiling, surveillance, or resale. Live chat is held only in bounded app memory and is not persisted by the SceneMeld service. When using YouTube features, you should also review the YouTube Terms of Service, the YouTube API Services Terms of Service, and the Google Privacy Policy.
5. How we use, process, and share platform data
- Inside SceneMeld: platform data is available only to the authorizing user on the device holding that connection session. The developer may access encrypted service records only when necessary for security, support, deletion, or legal compliance.
- With YouTube and Google: SceneMeld sends OAuth tokens and the broadcast actions you explicitly choose to Google's documented OAuth and YouTube API endpoints. Encoded media is sent directly from your device to the YouTube ingest destination.
- With infrastructure providers: our hosting and network providers process encrypted traffic and limited operational request data only to run and protect the authorization service. They do not receive the live media stream.
- No unrelated sharing: we do not sell YouTube API Data, share it for advertising, or disclose it to data brokers, advertisers, or other users.
6. Device, browser, cookies, and similar technologies
The app uses Apple Keychain for the device-specific platform session credential and stream keys, and its sandboxed preferences storage for your selected destination and recently retrieved broadcast metadata. SceneMeld does not access advertising identifiers and does not include cross-app tracking technologies.
This public website does not set advertising or analytics cookies. Our hosting and security infrastructure may necessarily process standard request information—such as IP address, browser or device type, request time, and security logs—to deliver the site, prevent abuse, and diagnose failures. That operational information is not combined with YouTube API Data for advertising or profiling.
7. System permissions
- Camera: used only after you add a camera source.
- Microphone: used only after you enable microphone input.
- Screen Recording: captures only a screen or window you choose.
- Local Network: connects to a local streaming server you configure.
- User-selected files: reads and writes only locations you choose.
Permissions are requested in response to your feature action, not together at launch.
8. Local storage
Scene layouts, preferences, and file-access bookmarks are stored on your device in the app sandbox. A separately entered stream key is stored in Apple Keychain and is excluded from diagnostic exports. Platform-account session credentials are also stored in Apple Keychain. Imported and recorded files remain where you put them.
9. User-directed transmission
When you create a platform broadcast, the title, description, visibility, and other details you enter are sent through the authorization service to that platform. The platform returns a broadcast identifier, status, and ingest destination. SceneMeld sends encoded audio and video directly from your device only after you start streaming, and only to that platform or a manually configured RTMP, RTMPS, or WHIP destination. The SceneMeld authorization service does not proxy, copy, or retain the media stream.
Each third party processes account data and media under its own terms and privacy policy.
10. Retention, refresh, disconnection, and deletion
One-time OAuth state and claim values expire after 10 minutes and 5 minutes respectively. Broadcast lists and prepared ingest destinations are cached in service memory for no more than 15 seconds. Incoming live chat is held only in bounded app memory while Audience Activity is active and is not persisted by the authorization service.
A platform connection session is valid for no more than 90 days. While it remains active, SceneMeld checks token validity on active use at least once per hour and the service performs background maintenance every 6 hours. Stored YouTube channel profile data is refreshed at least every 29 days. Broadcast data shown in the app is fetched when you open or refresh the feature; any persisted platform broadcast record that has not been refreshed is removed on the next app launch once it reaches 30 days.
You may disconnect in Settings → Streaming → YouTube → Disconnect Account. SceneMeld immediately asks Google to revoke the grant, deletes the encrypted server-side tokens and account record, removes the device Keychain session, and deletes locally saved YouTube broadcast records and stream keys. You can separately revoke SceneMeld from Google Account connections. When Google reports an externally revoked or invalid authorization, our maintenance process deletes the associated stored API Data as soon as detected and no later than 30 calendar days. If you cannot use the app, contact us below to request deletion; we complete a verified request as soon as possible and no later than 7 calendar days.
Deleting data held by SceneMeld does not delete broadcasts, videos, or chat retained by YouTube. Use YouTube or another authorized client that supports deletion to remove content stored by YouTube.
You can remove a saved stream destination in the app. Removing SceneMeld and its local data clears its scenes and preferences. Media you imported or exported remains under your control in Finder or Files and is not deleted automatically.
11. Service providers and international processing
The authorization service is currently hosted in Hong Kong. Depending on your location and chosen platform, account-authorization data may be processed outside your country or region. We use cloud hosting and platform APIs only to provide connections you enable; we do not sell data or share it for advertising.
12. Security
We use HTTPS, encrypted server-side storage, one-time authorization callbacks, short-lived connection claim codes, and Apple Keychain to protect platform connections. No transmission or storage method can guarantee absolute security. If you suspect misuse, revoke access at the platform immediately and contact us.
13. Children's privacy
SceneMeld is not directed to children and does not knowingly collect personal information from children. Platform connections remain subject to each platform's age, account-eligibility, and live-streaming rules.
14. Changes to this policy
If our data practices, supported platforms, or network services change materially, we will update this policy before the relevant feature is released and explain important changes in the app or on the product page where appropriate.
15. Contact and deletion requests
For privacy questions, complaints, or a stored-data deletion request, visit SceneMeld Support or email sandsn.li@icloud.com.