Privacy Policy
This policy explains what personal data Kafka Streamyard collects, how we use it, and your rights under applicable privacy law, including the GDPR.
1. Data controller
The data controller for Kafka Streamyard is FinnStream Oy, Finland.
If you have privacy questions or would like to exercise your data rights, contact us at support@kafkastreamyard.com.
2. Personal data we collect
Depending on how you use Kafka Streamyard, we may collect and process the following categories of personal data:
- Identity and contact data, such as your email address, which acts as your product user ID and license identity, and the name and email address you submit in contact requests.
- Message content, such as support, contact, and feedback submissions you send to us.
- Account and entitlement data, such as user status, trial status, paid status, plan, and access dates linked to that email-based product identity.
- Authentication data, such as sign-in attempt records, one-time code hashes, expiry times, usage timestamps, and attempt counters. The actual one-time code value is not stored in plain text.
- Device and session data, such as device ID, device name, platform, architecture, operating system version, host name, app version, IP address, session creation and last-seen timestamps, and revoked-session timestamps.
- Session security data, such as hashed access tokens and hashed refresh tokens used by the license and authentication service. The raw token values are not stored in plain text.
- Security and abuse-prevention data, such as IP-based rate-limit hits, temporary IP blocks, and security alert timestamps created to protect the authentication service.
- Payment and transaction data, such as purchase email, transaction identifiers, and status information needed to match Paddle purchases to licenses. We do not store full card details on our website.
On your own device, the desktop app also stores certain settings, UI state, caches, and working data locally. In the current desktop codebase, the local API/log working directory is ~/.kafka-streamyard. In addition, the Electron / Chromium-based desktop runtime keeps local app-profile data on your machine in its standard OS-specific app-data location, typically such as ~/Library/Application Support/Kafka Streamyard on macOS, %APPDATA%\Kafka Streamyard on Windows, or ~/.config/Kafka Streamyard on Linux.
For normal desktop-app use, Kafka Streamyard does not send your Kafka topic data, message data, or local app working files to FinnStream-operated servers. The only normal FinnStream-operated backend API used by the desktop app is the licensing and authentication API needed for status checks, sign-in code requests, code verification, logout, and session refresh. The app may also communicate directly with the Kafka, Schema Registry, and Kafka Connect services that you configure.
3. How we use personal data
We use personal data to:
- operate the website and desktop application;
- authenticate users and deliver one-time passcodes;
- manage trial access, paid licenses, and device/session limits;
- process and reconcile purchases made via Paddle;
- respond to contact requests, support questions, and feedback;
- send service-related messages such as sign-in, licensing, payment, and direct support replies, but not marketing newsletters or promotional campaigns;
- detect, prevent, and investigate fraud, abuse, or unauthorized access; and
- comply with legal obligations and enforce our terms.
4. Legal bases for processing
Where the GDPR applies, we typically process personal data on one or more of these legal bases:
- Contract — to provide the service you request, such as sign-in, trial access, licensing, support, and purchase-related access.
- Legitimate interests — to secure the service, prevent abuse, improve reliability, and respond to customer communications.
- Legal obligation — where we must keep records or disclose information under applicable law.
- Consent — where we specifically ask for it and you are free to withdraw it later.
Where we need data such as your email address, purchase email, or device/session information to provide sign-in, licensing, checkout reconciliation, or support, that data is required to enter into or perform the relevant contract or service relationship. If you do not provide required data, we may not be able to provide those functions.
5. Payments
Self-serve payments are handled by Paddle. Paddle processes billing, payment collection, tax, and VAT handling. When you start checkout, your email address may be passed to Paddle so the purchase can be associated with your account or license.
Your payment relationship may also be subject to Paddle’s own privacy notice and checkout terms.
6. Sharing personal data
We do not sell your personal data. We may share personal data only where needed with:
- payment providers, such as Paddle;
- hosting, infrastructure, and database providers used to run the service;
- email delivery providers used to send sign-in or contact-related emails; and
- professional advisers or authorities where legally required.
7. International transfers
Some service providers may process personal data outside Finland or the European Economic Area. Where we use such providers, we aim to use appropriate safeguards required by applicable law, such as contractual protections or other recognized transfer mechanisms.
8. Data retention
We keep personal data only for as long as needed for the purposes described in this policy, including account administration, licensing, security, legal compliance, and dispute handling.
- Account and entitlement records may be retained while your account is active and for a reasonable period afterward.
- Used or expired one-time sign-in code records may be deleted during maintenance and cleanup routines.
- Revoked or expired session records may be deleted when they are no longer needed for account administration or security.
- Security and abuse-prevention records, such as IP hit and temporary block records, may be retained only as long as needed to protect the service.
- Contact and feedback messages may be retained for support history and product improvement.
- Purchase-related records may be retained for accounting, tax, and audit obligations.
9. Security
We take reasonable technical and organizational steps to protect personal data. For example, the license server stores one-time sign-in codes and session tokens as hashes rather than plain-text secrets. However, no system can be guaranteed to be completely secure, and you should also protect your devices and email account.
10. Your rights
Where applicable, you may have the right to request access, rectification, deletion, restriction, objection, or portability of your personal data, and the right to lodge a complaint with a competent supervisory authority.
We do not currently use solely automated decision-making or profiling that produces legal effects or similarly significant effects on you, except for limited automated security, session, or anti-abuse checks needed to protect the authentication and licensing flow.
If you want to exercise a privacy right, contact support@kafkastreamyard.com. We may ask you to verify your identity before acting on a request.
11. Children
Kafka Streamyard is intended for adult users and business or professional use cases. We do not intentionally market the service to children.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date on this page.