Legal

Privacy Policy

This policy explains how VISP processes personal data when you use the website, dashboard, mobile apps, and related streaming relay services.

Last updated 14 August 2026 · Pöhinä Group Oy

1. Controller

The data controller is Pöhinä Group Oy (Business ID 3419352-5), Järjestökuja 2 B 10, 05400 Jokela, Finland. Contact: joni@pohina.group.

2. What VISP is

VISP is a self-hosted SRT/RTMP relay and control plane for remote live streaming. You are never asked to paste a broadcast/stream key. If you turn on VISP Direct for a device, VISP retrieves that platform's stream destination from Twitch, Kick, or YouTube using permission you grant in their OAuth screen, uses it only to run the forwarding process while that device is live, and does not store a stream key as a separate value or return it to any client app. YouTube Direct creates a public broadcast with automatic start and stop. VISP relays live media and provides account, dashboard, and device features around that relay.

3. Data we process

  • Account data from Twitch, Kick, Google, or Apple (iOS) sign-in: name, email address (including Apple private relay addresses when chosen), profile image, and linked provider account identifiers.
  • Authentication data: OAuth access/refresh tokens (stored securely), sessions, IP address, and user agent.
  • Service configuration: relay publishing paths, labels, hashed/encrypted publish secrets, native installation IDs, and setup preferences.
  • Operational measurements: connection and latency (RTT) samples associated with your account, plus relay session start/end times, publishing device, source type, and calculated duration. VISP does not store the streamed audio or video.
  • Dashboard snapshots: one private low-resolution (~640px) still image per publishing path while live, refreshed about once a minute and expired within about one day after updates stop.
  • BRB highlights: short video clips you deliberately upload for playback while Direct holds your broadcast. VISP does not create these clips from your live stream.
  • Chat connection metadata needed to connect chat integrations (for example subscription IDs). Chat message content is not retained by VISP as a content archive. If you enable hosted text-to-speech, the text selected for speech is sent to the hosted speech provider to create the requested audio.
  • Optional speech-processing data: if your account has hosted captions or hosted audio isolation enabled and you turn the feature on, live microphone audio is sent to ElevenLabs to produce caption text or isolated audio. The normal on-device speech and audio options do not send microphone audio to ElevenLabs.
  • Assistant conversations: messages sent to Seppo and, when you use it on the dashboard, a sanitized service-status summary. These are sent through the configured AI gateway to the selected model provider to generate a reply. Secrets and snapshot contents are not included in that summary.
  • Founding creator application data: your name, email address, YouTube channel and relevant-content URLs, description of your audience and setup, and disclosure acknowledgement when you apply to the creator program. Applications are also forwarded to our internal team chat so we can review and reply to them.
  • Security and service logs for reliability, abuse prevention, and debugging.

VISP does not process payment card data. The service is currently free in beta and does not bill users.

4. Purposes and legal bases

  • Providing the service (contract / steps prior to contract): account creation, authentication, relay configuration, dashboard, optional speech processing and assistant features.
  • Founding creator applications (steps prior to contract / contract): reviewing applications, responding to applicants, and administering accepted creator relationships.
  • Security and integrity (legitimate interests): session security, fraud/abuse prevention, and service reliability.
  • Legal obligations when we must retain or disclose data under applicable law.
  • Product analytics (legitimate interests / privacy design): when configured, cookieless Rybbit analytics for understanding site usage — see the Cookie Policy.
  • Optional cookies (consent), if and when enabled — see the Cookie Policy.

5. Recipients and processors

We use infrastructure and subprocessors necessary to run VISP (for example hosting, database, object storage for snapshots, and OAuth identity providers Twitch, Kick, and Google). Optional hosted speech features use ElevenLabs. Seppo uses the configured AI gateway and model provider (currently Google Gemini). Those providers process only the content needed to provide the feature you invoke. When analytics is configured, it runs on our own self-hosted Rybbit instance, so analytics data is not shared with a third-party analytics provider. Stream destinations you choose (OBS, platforms) receive the media you publish; VISP does not take ownership of your stream keys, and retrieves them only for the duration of a VISP Direct session you have enabled.

6. International transfers

Service infrastructure may process data in the EU/EEA or in other countries. Where data is transferred outside the EEA, we use appropriate safeguards required by GDPR (such as standard contractual clauses) where applicable.

7. Retention

  • Account and configuration data: kept while your account is active; deleted from active systems when you delete the account.
  • Relay session metadata and usage totals: kept while your account is active and deleted with the account.
  • Snapshots: replaced while live; expire within about one day after updates stop.
  • Uploaded BRB highlights: kept until you remove them or delete your account.
  • Unsuccessful founding creator applications: deleted within 12 months of the decision. Accepted partner data is retained for the relationship and any longer accounting or legal period that applies.
  • Encrypted backups: up to 30 days before overwrite after deletion.
  • Security and service logs: up to 90 days, unless law requires longer.
  • Optional speech and assistant inputs: VISP does not retain them as a content archive; the external provider's processing and retention are also governed by its applicable service terms and data-processing arrangements.

Continuous stream recordings and chat content archives are not kept by VISP. This does not include BRB highlight files you choose to upload.

8. Your rights

Under GDPR you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability, as applicable. You may withdraw consent where processing is based on consent. To exercise rights, email joni@pohina.group or use account deletion.

You may lodge a complaint with the Office of the Data Protection Ombudsman or another competent supervisory authority.

9. Cookies

Essential cookies are used for authentication and session security. Optional cookies are used only with your consent. Details: Cookie Policy.

10. Changes

We may update this policy when the service or law changes. The “Last updated” date at the top will change when we do. Material changes may also be communicated in the product or by email when appropriate.

11. Contact

Privacy questions: joni@pohina.group. Full company details: Contact.