Privacy Policy
Last updated: 21 June 2026
1. Who this covers
This policy explains what GridLive (“we”, “the service”) collects when you use the website and app, how we use it, and the choices you have. By using GridLive you agree to this policy.
2. What we collect
- Account — your email address, via Supabase authentication (including Google sign-in).
- Your channel list — the platforms and channels you choose to follow inside GridLive (platform, channel id, channel name).
- Notification tokens — only if you enable go-live push notifications, so we can deliver them.
- Minimal technical data — your IP address is used transiently for rate-limiting and abuse prevention, plus standard server logs.
We do not sell your data, run advertising trackers, or build advertising profiles.
3. Google user data (YouTube)
GridLive can import the channels you follow on YouTube. This is never automatic— it runs only when you explicitly tap “Sync”. We request the read-only scope youtube.readonly solely to read your subscription (followed-channel) list at that moment and turn it into your GridLive follow list. We do not access your watch history, search history, private videos, comments, or account settings, and we do not continuously poll your account.
Who we share, transfer, or disclose Google user data with. We do not sell Google user data, use it for advertising, or use it to train AI or machine-learning models. The only party we share, transfer, or disclose it to is our infrastructure provider Supabase(database & authentication hosting), which stores your imported follow list on our behalf under its own security and confidentiality obligations. We do not transfer or disclose Google user data to any other third party, except where required by law.
How we protect Google user data (sensitive data). It is encrypted in transit (HTTPS/TLS) and at rest (Supabase / PostgreSQL); access is restricted to your own account by row-level security; privileged service keys are kept server-side only and are never exposed to the browser; and the OAuth access token is used only transiently during the sync and is never stored.
GridLive’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The same applies to Twitch follow import, which also runs only when you explicitly start a sync.
4. How we use your data
- To show your followed channels and whether they are live.
- To deliver go-live notifications you have opted into.
- To operate, secure, and improve the service.
5. Data sharing and disclosure
We do not transfer or disclose your information — including Google user data — to third parties except for the limited purposes described in this policy. We do not sell, rent, or trade your personal data or any Google user data, and we never use it for advertising or to train AI/ML models. The only recipients are:
- Service providers (sub-processors) that run the service on our behalf, only so we can operate it: Supabase (authentication and database hosting) and Vercel (application hosting). They process the data under their own security and confidentiality obligations.
- At your direction — for example, the channels in a share link you choose to send.
- Legal compliance — if required by law, regulation, or valid legal process.
For Google user data specifically (your YouTube subscription list), see section 3 above: it is shared only with Supabase to store your follow list, and is never sold, used for advertising, used to train AI/ML models, or disclosed to any other third party.
6. How we protect your data
We use encryption and security procedures to protect the confidentiality of your data, including sensitive data such as Google user data:
- Encryption in transit — all connections use HTTPS/TLS.
- Encryption at rest — your data is stored in Supabase (PostgreSQL), which encrypts data at rest.
- Access controls — row-level security limits each user’s records to that user; privileged service keys are held only on our server and are never exposed to the browser.
- Token minimisation — for the YouTube sync, the OAuth access token is used transiently during the sync request and is not stored; we keep only the resulting channel list, never your tokens, watch history, or other account data.
- Rate limiting and abuse-prevention controls protect the service and your data.
7. Streams and third parties
Streams play through each platform’s official embedded player (Twitch, YouTube, Kick, Chzzk). When you watch, those platforms may set their own cookies and collect data under their own privacy policies — GridLive does not control that.
8. Retention and deletion
You can remove channels at any time, and you can delete your account to remove your stored data (email, channel list, notification tokens). To request deletion or ask a question, contact us at surfshortcut@gmail.com.
9. Cookies
We use a session cookie to keep you signed in. Embedded platform players may set their own cookies as described above.
10. Changes
We may update this policy; material changes will be reflected by the “last updated” date above. Continued use after changes means you accept the updated policy.
11. Contact
Questions? surfshortcut@gmail.com