Stargaze Studio

Legal

Privacy Policy

Privacy policy for visitors to the Stargaze Studio platform (the “Policy”).

§ 1

General provisions

1.

The controller of your personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”) is Tivio Studio a.s., identification number (IČO): 193 03 742, with its registered office at Pobřežní 667/78, Karlín, 186 00 Prague 8, Czech Republic (the “Controller”).

2.

The Controller’s contact details are: email support@tivio.studio; address Tivio Studio a.s., Pobřežní 667/78 Karlín, 186 00 Prague 8, Czech Republic.

3.

Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

§ 2

Sources and categories of personal data processed

1.

The Controller processes personal data provided by users of the Stargaze Studio platform (“Users”), including when registering for the waiting list and, once available, when creating an Account in accordance with the Terms of Use of the Stargaze Studio platform (the “Terms of Use”).

2.

Waiting-list registration. When you register for the waiting list via our sign-up form, the Controller processes your first name and email address and, optionally, your audience size, your primary publishing platform, and the part of your workflow you would most like to improve. The Controller also processes your IP address.

3.

Account and platform use. Once the platform is available, the Controller may, in connection with the provision of the services, also process: the User’s IP address, first name, last name, email address, Account login password, and billing information required by law (first name, last name, IČO, registered office/place of residence, DIČ (VAT), bank account number, and payment card details).

4.

The Controller processes the above personal data to the extent necessary for the provision of electronic services on the basis of the Terms of Use. The data is obtained directly from Users. Providing the data is voluntary, but necessary for the proper provision of the services.

§ 3

1.

The legal basis for processing personal data is:

  1. consent given by the User — sending commercial information, newsletters, and information about the launch of the platform to Users who register for the waiting list and tick the consent box; the legal basis is Article 6(1)(a) of the GDPR, and consent may be withdrawn at any time;
  2. performance of a contract — managing your waiting-list registration and, once available, performing the Terms of Use (including maintaining an Account, enabling a Subscription, enabling the submission of opinions and complaints, and handling any complaints); the legal basis is Article 6(1)(b) of the GDPR;
  3. compliance with the Controller’s statutory obligations, resulting in particular from tax and accounting regulations (including the need to issue and archive an invoice or other accounting document); the legal basis is Article 6(1)(c) of the GDPR;
  4. the Controller’s legitimate interest in optimizing the platform to ensure the greatest possible convenience of use, and in the investigation of and defense against potential claims related to the use of the platform; the legal basis is Article 6(1)(f) of the GDPR.
2.

The purpose of personal data processing is:

  1. managing the waiting list and notifying registrants about the launch of the platform;
  2. sending commercial information and conducting other marketing activities on the basis of consent;
  3. exercising the rights and obligations arising from the Terms of Use — the agreement concluded between the User and the Controller;
  4. fulfilling the statutory obligations incumbent on the Controller;
  5. the pursuit and defense of claims;
  6. optimizing the platform in order to ensure the greatest possible convenience for Users.
3.

As a rule, the Controller does not make automated decisions in individual cases, including profiling within the meaning of Article 22 of the GDPR. Such processing may only take place if the User has given their explicit consent.

§ 4

Data retention period

1.

The Controller shall retain personal data:

  1. for the period necessary to exercise the rights and fulfil the obligations arising from the Terms of Use, or until the claims become time-barred or the relevant proceedings are concluded;
  2. for data processed on the basis of consent (including marketing emails sent to waiting-list registrants) — until the consent is withdrawn;
  3. until the Controller has fulfilled its legal obligations;
  4. for data processed on the basis of a legitimate interest — as a rule, until an objection is raised.
2.

After the storage period has expired, the Controller deletes the personal data.

§ 5

Recipients of personal data (the Controller’s processors)

1.

The recipients of personal data, on the basis of relevant agreements, may be entities:

  1. involved in the provision of the services by the Controller on the basis of the Terms of Use;
  2. involved in ensuring the operation of the services on the terms specified in the Terms of Use;
  3. providing marketing services on behalf of the Controller.
2.

The User’s personal data may be made available to external third parties processing payments, to the extent necessary to process those payments. The recipients of personal data are, in particular, mailing and cloud service providers.

3.

The Controller does not transfer personal data to third countries located outside the European Economic Area or to international organizations.

§ 6

User rights

1.

In accordance with the GDPR, the User has the right to:

  1. access their personal data pursuant to Article 15 of the GDPR;
  2. rectify their personal data pursuant to Article 16 of the GDPR, or restrict its processing pursuant to Article 18 of the GDPR;
  3. erase their personal data pursuant to Article 17 of the GDPR;
  4. object to the processing of data pursuant to Article 21 of the GDPR;
  5. data portability pursuant to Article 20 of the GDPR;
  6. withdraw consent at any time pursuant to Article 7(3) of the GDPR, without affecting the lawfulness of processing carried out before its withdrawal.
2.

In addition, the User has the right to lodge a complaint with the supervisory authority — Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic — if they believe that their rights have been violated.

§ 7

Personal data security conditions

1.

The Controller declares that it has taken all appropriate technical and organizational measures to secure personal data, including:

  1. entrusting the processing of personal data only to persons who have been instructed on the obligation of confidentiality with regard to personal data and other obligations to be observed in accordance with the GDPR, other applicable laws, or this Policy;
  2. using appropriate technical equipment and software to prevent unauthorized or accidental access to personal data;
  3. storing personal data in appropriately secured facilities and rooms, and in electronic form on secure servers or data carriers accessible only to authorized persons using access codes or passwords, with regular backups;
  4. securing the remote transmission of personal data via protected communication channels in public networks;
  5. processing personal data in pseudonymized and encrypted form, where possible, appropriate, or necessary to limit the risks associated with processing;
  6. ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and the ability to restore timely access to personal data in the event of a physical or technical incident;
  7. conducting regular tests, assessments, and evaluations of the effectiveness of the technical and organizational security measures implemented.
2.

The Controller declares that only authorized persons have access to personal data.

§ 8

Google and YouTube API Data

1.Overview

1.1.

Stargaze Studio allows Users to connect their own YouTube account in order to publish audiovisual content directly to their YouTube channel.

1.2.

This functionality uses Google’s OAuth authorization process and the YouTube Data API.

1.3.

The Operator processes Google and YouTube data solely for the purpose of providing the requested publishing functionality.

2.Data We Access

2.1.

When a User connects a YouTube account, the Operator may access and process the following information:

  1. YouTube Channel ID;
  2. YouTube channel name;
  3. OAuth access token;
  4. OAuth refresh token.
2.2.

The Operator does not request access to YouTube data beyond what is necessary to provide the publishing functionality.

3.Purpose of Processing

3.1.

The above data is processed exclusively for the following purposes:

  1. identifying the YouTube channel selected by the User;
  2. authenticating requests to the YouTube Data API;
  3. publishing videos and related metadata that the User explicitly instructs the Platform to publish;
  4. maintaining the connection between Stargaze Studio and the User’s YouTube account;
  5. ensuring the secure operation of the integration.
3.2.

Videos are uploaded to YouTube only after the User explicitly initiates the publishing process or schedules publication using functionality provided by the Platform.

3.3.

The Operator does not publish content to YouTube without the User’s instruction.

4.Security of OAuth Credentials

4.1.

OAuth access tokens and refresh tokens are encrypted before being stored.

4.2.

The Operator uses infrastructure provided by Cloudflare and industry-standard security measures to protect authentication credentials against unauthorized access, disclosure, alteration or destruction.

4.3.

Only authorized systems and personnel have access to the encrypted credentials where necessary for operation of the service.

5.Data Retention

5.1.

Connection information (including encrypted OAuth credentials and channel identification data) is retained only while the User’s YouTube account remains connected to Stargaze Studio.

5.2.

Operational logs relating to publishing requests, upload status, error diagnostics and similar technical records may be retained for up to 30 days, after which they are deleted or anonymized unless a longer retention period is required by law or necessary for resolving security incidents or legal claims.

5.3.

If the Platform stores public YouTube metadata (such as video titles, video IDs or thumbnails) for operational purposes, such data is retained only for as long as reasonably necessary to provide the requested functionality and is periodically removed when no longer required.

6.Artificial Intelligence and Data Sharing

6.1.

The Operator does not use non-public Google or YouTube User data obtained through Google APIs for:

  1. training artificial intelligence models;
  2. profiling YouTube channels;
  3. advertising purposes;
  4. sale to third parties.
6.2.

Google OAuth credentials are never shared with OpenAI or any artificial intelligence service.

6.3.

If OpenAI-powered functionality is used within Stargaze Studio (for example, to assist Users in generating video titles, descriptions or other content), such functionality processes only the information that the User explicitly chooses to submit to that feature and does not receive Google OAuth credentials.

7.Disconnecting YouTube

7.1.

Users may disconnect their YouTube account at any time through the Platform settings.

7.2.

Upon disconnection, the Operator:

  1. removes the stored connection information;
  2. deletes encrypted OAuth credentials unless retention is legally required;
  3. attempts to revoke the granted Google authorization where technically supported.
7.3.

Users may also revoke Stargaze Studio’s access directly from their Google Account permissions page at any time.

7.4.

Disconnecting the account prevents future uploads but does not remove videos that have already been published to YouTube.

8.Compliance with Google Requirements

8.1.

The Operator’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

8.2.

Google User data is processed solely for providing or improving User-facing functionality requested by the User and is not used for advertising or unrelated purposes.

9.Third-Party Policies

9.1.

Further information is available in:

  1. Google Privacy Policy
  2. YouTube Terms of Service

§ 9

Final provisions

1.

By registering for the waiting list and ticking the consent box — and, where applicable, by creating an Account — on the Stargaze Studio platform, the User confirms that they have read this Policy and accept it in full, and, where consent has been given, consents to receiving commercial communications and other emails from the Controller. The User may withdraw such consent at any time.

2.

The Controller reserves the right to change this Policy. The updated version of the Policy will be published on the Stargaze Studio platform.

3.

This Policy enters into force on 8 June 2026.

← Back to the homepage
studio.stargaze.com