This Privacy Policy explains what personal data Stream collects, why, how we use and protect it, and the rights you have. Stream is operated by FOP Hnatiuk Yaroslav ("we", "us"), an individual entrepreneur registered in Ukraine and the data controller. Stream is built to be private by design: no ads, no advertising trackers, and no behavioral profiling.
1. Data we collect
- Account data — your email address, optional display name, and a hashed password. If you sign in with Google, we receive your email, name, and Google account identifier (we never receive your Google password).
- Content you create — the feeds and sources you subscribe to, articles you save, read/favorite status, translations, and PDF exports you generate.
- Payment data — handled entirely by our payment provider, Paddle. We receive confirmation of your subscription status and limited billing details (such as country and the last digits of your card for support), but we never see or store your full card number.
- Technical data — IP address, browser/device type, and log data needed to operate, secure, and debug the Service.
2. How we use it
- to provide the Service — sync your feeds, store your library, translate and export articles;
- to create and secure your account and authenticate you;
- to process subscriptions and prevent fraud (via Paddle);
- to send essential service messages (e.g. verification, password reset, billing notices);
- to maintain, improve, and troubleshoot the Service; and
- to comply with legal obligations.
We do not sell your personal data, and we do not use it for advertising.
3. Legal bases (GDPR)
Where the GDPR applies, we process your data on these bases: performance of a contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), legal obligation (e.g. tax and accounting), and consent where required (which you can withdraw at any time).
4. Who we share data with
We share data only with the service providers listed below, and only for the purpose named in each case:
- Paddle — payment processing and Merchant of Record. See Paddle's Privacy Notice.
- Google — optional "Sign in with Google" authentication.
- Hosting & infrastructure providers — to run the servers and database that store your data.
- DeepSeek — AI text processing: the clean reader view, translation, and PDF layout. It receives the text of an article you open in reader view, translate, or export — including a page you saved by URL. It does not receive your account data: no email address, no name, no account identifier, and no IP address of yours, because the request is made by our server and carries only the article text and the target language. DeepSeek is based in China and may process and store that text outside the EEA, under its own terms — see DeepSeek's Privacy Policy.
We may also disclose data where required by law, or to protect our rights, users, or the Service.
5. Cookies
Stream uses only the cookies and local storage strictly necessary to keep you signed in and remember preferences such as your interface language. We do not use advertising or cross-site tracking cookies. Paddle may set cookies during checkout to process your payment securely.
6. Security
No system is perfectly secure, but these are the concrete measures we take:
- Encrypted in transit. Stream is served over HTTPS/TLS, and our servers reach third-party providers over TLS as well.
- Passwords are never stored. We keep only a bcrypt hash of your password, which cannot be reversed into the original. If you sign in with Google, we hold no password at all.
- Short-lived sessions. Access tokens expire after minutes and are renewed with a separate refresh token that we can revoke. Resetting your password or deleting your account revokes every session immediately.
- Your library is yours alone. Every request is scoped to your account — which articles you can see, your tags, read status and favorites are filtered by your user identity in the query itself, not merely hidden in the interface.
- Administrative and security events are logged. Sign-ins, failed sign-in attempts, password resets, account deletions and every administrative action are written to an audit trail.
We deliberately do not claim more than this: we do not hold security certifications, and we do not commit to independent penetration testing. If you find a security problem, please write to privacy@stream-reader.com.
7. Data retention
We keep your account and content data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain records (e.g. invoices) to meet legal obligations.
8. International transfers
Your data may be processed in countries other than your own — see the providers in section 4, which names where each one processes what it receives. Where a provider offers them, we rely on recognised transfer safeguards such as the European Commission's Standard Contractual Clauses. Where a provider does not, we limit what it receives instead, which is why article text sent for AI processing carries no account data.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, email privacy@stream-reader.com. You also have the right to lodge a complaint with your local data-protection authority.
10. Children
Stream is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this Policy from time to time. We'll revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
12. Contact
Data controller: FOP Hnatiuk Yaroslav, Kamianske, Ukraine. For any privacy question or request, email privacy@stream-reader.com.