Last updated: August 28, 2026
Kyatti Studio ("we," "us," or "our") establishes this Privacy Policy regarding the handling of personal information in ToruLive (the "App").
The App may collect the following information.
User ID automatically generated by Firebase Authentication
Display name obtained from Apple ID or set by the user
Email address, when provided through Sign in with Apple
Team membership information, including team ID and team name
Role within a team, such as administrator, broadcaster, or viewer
Invitation code
Highlight videos shared with a team
Video metadata, including file name, upload date and time, and uploader name
Date and time of the most recent login
We use the information we collect for the following purposes:
To provide App features, including account management, team features, and video sharing
To enable team members to share highlight videos
To identify users and manage permissions within teams
To improve the App and respond to technical issues
Firebase Authentication, provided by Google LLC: account authentication information
Cloud Firestore, provided by Google LLC: user information, team information, and video metadata
Cloudflare R2, provided by Cloudflare, Inc.: highlight video files
For more information about these services, please see their privacy policies:
Google Privacy Policy: https://policies.google.com/privacy
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
We do not disclose collected personal information to third parties except in the following cases:
When the user has given consent
When disclosure is required by law
To the extent necessary to store information using the external services described above, including Firebase and Cloudflare
When a user uses team features, the user's display name and videos shared by that user may be visible to other members of the same team.
The App may request access to the following device features:
Camera: used to record and live stream matches
Microphone: used to record match audio
Photo Library: used to save recorded videos
Users can disable these permissions at any time in iOS Settings.
ToruLive provides two methods for YouTube live streaming: manual stream key entry and Google Account integration through the YouTube API using OAuth authentication.
With manual stream key entry, users enter a stream key issued through their own YouTube account. The stream key is stored on the device and, when a team plan is used, may also be stored in our Cloud Firestore database. We do not obtain or store the user's YouTube login credentials.
With YouTube API integration, Google OAuth authentication allows users to create, start, and end YouTube live streams within the App. When this integration is enabled, we obtain the Google OAuth refresh token, access token, and the email address of the connected Google Account for the purpose of confirming the connection status. This information is encrypted and stored in Cloudflare Workers KV.
We use this information only to create, start, and end YouTube live streams. We do not use it for any other purpose. We do not view, edit, or delete video content, and we do not share this information with third parties.
The App uses the following OAuth scopes, which are limited to those required for YouTube live streaming features:
Users can disconnect YouTube API integration using the "Disconnect YouTube API" button in the App or through the Google Account permissions page at https://myaccount.google.com/permissions. When the connection is revoked, the authentication information stored by us is deleted promptly.
The App's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. For details, please see https://developers.google.com/terms/api-services-user-data-policy.
OAuth tokens and related data are protected through the following security measures:
Communications between the App and our servers, and between our servers and Google API servers, are encrypted using TLS 1.2 or later.
OAuth tokens are stored in encrypted form in Cloudflare Workers KV.
Access to tokens is limited to authenticated backend services and protected using bearer authentication.
OAuth scopes are limited to those necessary to create and end YouTube live streams.
OAuth tokens are retained only while the user keeps the integration connected and are deleted when the integration is disconnected.
Data obtained through the integration is not shared with third parties.
Users can delete their account from within the App. Deleting an account removes the following information:
Account information, including user ID, display name, and email address
Team membership information
Data associated with the user
Videos that have already been shared with a team must be deleted separately by a team administrator.
Users can use basic features, including recording and streaming, without registering an account. When the App is used anonymously, Firebase Authentication generates an anonymous ID, but we do not collect information that directly identifies the user.
The App does not knowingly collect personal information from children under the age of 13. If we learn that a child under 13 has provided personal information, we will delete it promptly.
The App does not use advertising tracking or third-party analytics tools.
We may update this Privacy Policy when necessary. An updated Privacy Policy becomes effective when it is published in the App or on our website.
For YouTube API Data obtained through YouTube API Services, including video IDs, viewing URLs, and thumbnails, the App automatically revalidates the data within 30 days of its retrieval or most recent validation. This process does not require the user to open or operate the relevant screen.
When a video remains available on YouTube, we update the validation date and retain the data. We do not delete the data in response to a network failure or temporary API error. We delete only the information obtained from the YouTube API when a successful response from the YouTube API confirms that the video has been deleted or is no longer available.
This periodic validation does not automatically delete match names and dates stored by ToruLive, recordings stored on the user's device, or recordings and highlight videos shared with a team.
When a user disconnects their Google Account or deletes their ToruLive account, we promptly delete the stored YouTube API-derived data and authentication information associated with that user.
Information obtained or processed in connection with YouTube API Services is also subject to the Google Privacy Policy at https://policies.google.com/privacy.
For privacy-related inquiries, please contact:
Developer: Kyatti Studio
Email: torulive.app@gmail.com