Privacy Policy
Last updated: July 2, 2026
This Privacy Policy explains how SyncTube.live (the "Application") processes information when you use the website and related backend services.
- Data controller: Jakub Ignalewski, operator of SyncTube.live
- Contact: ignalewski@gmail.com
- Location: Poland, European Union
This policy is written for users in the European Economic Area (EEA), but the same factual explanation applies to all users.
SyncTube.live lets users create YouTube video playlists, watch videos in sync with other users, use playlist chat, and manage a user account. The Application processes information needed to provide those features, secure the service, communicate with users, and understand whether the service is working correctly.
1. Information We Process
A. Account Information
If you create an account, the Application processes account information, including:
- email address;
- username;
- hashed password;
- account role;
- email confirmation status and confirmation code;
- password reset token and expiration time, if you request a reset;
- account creation and update timestamps.
Passwords are stored as hashes. The Application does not store your plain text password.
B. Authentication Sessions and Cookies
When you log in or confirm your email address, the Application sets an authentication cookie named Authentication. This cookie contains a signed token used to keep you logged in and to authorize account-only actions.
The backend also stores session records connected to your account. When you log out, the server-side session is deleted and the authentication cookie is cleared.
C. Guest Identifier
If you use synchronized playlist viewing without being logged in, the frontend stores a guest identifier in browser local storage under bn_guest_id. It is a randomly generated value prefixed with guest-.
This identifier is used to give the same browser a stable temporary identity for live playlist presence across page refreshes. It is not an advertising identifier and is not intended to identify your real-world identity.
D. Profile Information and Uploads
If you update your profile, the Application may process:
- profile description;
- avatar image file and stored avatar path.
E. Playlist Information
When you create or manage playlists, the Application processes playlist data, including:
- playlist owner account ID;
- playlist title and description;
- playlist public or private status;
- chat and now-playing settings;
- playlist image file and stored image path, if uploaded;
- playlist video entries, YouTube video IDs, titles, thumbnails, durations, and positions;
- current playback state and playback start time;
- playlist creation and update timestamps.
F. Chat Messages and Live Presence
If playlist chat is enabled and you send a chat message, the Application stores and displays:
- message content;
- message source, such as user or system message;
- user ID, if sent by a logged-in user;
- playlist ID;
- related YouTube video ID, if applicable;
- message creation timestamp.
The Application also uses WebSocket connections to show live users and synchronize playlist playback. For logged-in users, live presence can include the user ID and username. For guests, it can include the guest identifier and generated guest username.
G. Feedback, Reports, and Support Requests
If you submit feedback, moderation mail, or a similar request, the Application may process:
- request type;
- title;
- message content;
- contact information you choose to provide;
- user ID, if submitted by a logged-in user;
- submission timestamp.
H. Email Communications
The Application sends transactional emails for account confirmation, account-exists notices, and password resets. These emails require processing your email address and the message content needed to deliver the email.
I. Analytics Events
SyncTube.live uses Umami analytics to understand basic product usage and website performance. Analytics may include standard browser and page metadata such as page URL, hostname, referrer, browser, operating system, device type, country or region inferred from network metadata, screen size, and performance metrics.
Analytics are used to understand service usage and reliability. They are not used for third-party advertising.
J. Frontend Error Logs and Technical Metadata
The frontend can send application logs to the backend. These logs may include:
- log level;
- error or diagnostic message;
- stack trace;
- frontend context;
- browser user agent;
- current URL.
When your browser communicates with the backend, WebSocket server, analytics endpoint, email service, or YouTube content, technical network metadata may also be processed automatically. This can include IP address, request time, requested URL, user agent, and similar connection information.
K. YouTube Data and Embedded Content
SyncTube.live works with YouTube videos. The Application processes YouTube video IDs, titles, thumbnails, durations, and availability data needed to build and play playlists.
When you play embedded YouTube content, YouTube or Google may process information according to their own terms and privacy policies. SyncTube.live does not control YouTube's independent processing.
2. Information We Do Not Intentionally Collect
SyncTube.live does not intentionally collect:
- payment information;
- precise GPS location from your device;
- contacts;
- health, biometric, or other special-category data;
- data for third-party advertising.
The Application does not sell user data.
3. Purposes and Legal Bases
For users in the EEA, we rely on the following legal bases under the GDPR:
| Purpose | Data involved | Legal basis |
|---|---|---|
| Creating and managing accounts | Email, username, password hash, account status, account metadata | Performance of a contract, Article 6(1)(b) GDPR |
| Authentication and session management | Authentication cookie, signed token, session records | Performance of a contract, Article 6(1)(b) GDPR |
| Operating playlists, synchronized playback, chat, and live presence | Playlist data, video data, chat messages, user IDs, guest IDs, WebSocket metadata | Performance of a contract, Article 6(1)(b) GDPR |
| Profile and playlist uploads | Avatar files, playlist image files, stored file paths | Performance of a contract, Article 6(1)(b) GDPR |
| Security, debugging, abuse prevention, and service reliability | Server logs, frontend logs, technical metadata, rate-limiting data | Legitimate interests, Article 6(1)(f) GDPR |
| Transactional email delivery | Email address, confirmation and reset links, email metadata | Performance of a contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f) GDPR |
| Product analytics and performance measurement | Analytics events and limited browser or network metadata | Legitimate interests, Article 6(1)(f) GDPR, where analytics are privacy-preserving and not used for advertising |
| Responding to support, feedback, moderation, or privacy requests | Request content, contact details, account ID if applicable | Legal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f) GDPR |
Where local law requires consent for a particular analytics, cookie, or storage activity, we will rely on consent instead.
4. Processors and Third Parties
We do not sell, rent, or trade user data.
We use service providers and third-party services only where needed to operate the Application:
- Backend and database hosting: used to run the API, database, uploads, sessions, and WebSocket services.
- Analytics: Umami analytics, loaded from
umami.qbee.dev. - Email delivery: Resend, used for transactional account emails.
- YouTube and Google services: used for YouTube video metadata and embedded video playback.
These providers may process technical metadata, such as IP addresses, as necessary to deliver their services.
5. International Transfers
We aim to host and process personal data in the EEA where reasonably possible.
If any provider processes personal data outside the EEA, we will rely on an appropriate legal mechanism, such as an adequacy decision, Standard Contractual Clauses, or another transfer safeguard required by GDPR.
6. Data Retention
We keep data only for as long as reasonably needed for the purposes described in this policy.
- Authentication cookie: Stored until it expires, you log out, or your browser removes it.
- Guest ID in local storage: Stored until you clear browser storage for the site.
- Account data: Stored while your account exists and as needed for legal, security, or operational purposes.
- Session records: Stored while the relevant session is active, and deleted when you log out.
- Playlist, video, chat, and upload data: Stored while needed to provide the playlist and account features.
- Password reset tokens: Stored until used, replaced, expired, or otherwise cleared.
- Frontend and server logs: Retained as needed for security, debugging, abuse prevention, and operational reliability.
- Analytics data: Retained for product trend analysis, performance measurement, and service improvement.
- Support, feedback, moderation, and privacy requests: Retained as long as needed to respond and keep legally required records.
7. Your Rights
If GDPR applies to you, you may have the right to:
- access your personal data;
- request correction of inaccurate data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local data protection authority.
To exercise your rights, contact us at: ignalewski@gmail.com.
8. Deleting Local Data
You can remove locally stored data by:
- logging out to clear the active authentication session;
- clearing this site's cookies in your browser settings;
- clearing this site's local storage in your browser settings.
Clearing cookies or local storage may log you out, remove the guest ID, or reset local browser state. It does not automatically delete backend records that were already stored.
9. Children's Privacy
SyncTube.live is intended for a general audience and is not directed to children under 13. In the EEA, where consent-based processing of children's data is relevant, the applicable age may be up to 16 depending on the country.
We do not knowingly collect real-world identity information from children beyond the account and service data described in this policy. If you believe a child has provided personal data to us, please contact us so we can review and delete it where appropriate.
10. Security
We use reasonable technical and organizational measures to protect the data we process. These measures may include HTTPS, password hashing, signed authentication tokens, access controls, rate limiting, and limiting data access to what is necessary.
No internet service can guarantee absolute security.
11. Automated Decision-Making
SyncTube.live does not use your data for automated decision-making that produces legal or similarly significant effects.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date above.
Material changes will be communicated in a reasonable way, such as by updating this policy page.
13. Contact
For privacy questions or requests, contact:
ignalewski@gmail.com