Privacy policy
What Stream AB collects, why it collects it, and what happens to it. Written to be read rather than skimmed past.
Last updated 11 August 2026
The short version
One advertising pixel
This site runs the Meta (Facebook/Instagram) Pixel, so I can tell whether an ad actually led to a sale. It is the only analytics or advertising tag on the site.
Cookies, from that pixel only
The Meta Pixel sets a couple of first-party cookies in your browser. Nothing else on this site sets a cookie.
Not sold, ever
Your details are never sold, rented, or shared for anyone else’s marketing. There is a mailing list for people who download the free version, with a box to opt out of it at the time and an unsubscribe link in every message.
What is collected is essentially: your email address, so I can send you your licence key, or so I know who has the free version; an identifier for each computer you activate on, so the two-machine limit means something; and, if you came from an ad, the browser/cookie identifiers Meta uses to tell me the ad worked. That is the whole of it.
Who is responsible
Stream AB is run by Conor Quinlan, a sole trader in the United Kingdom, trading as Stream AB. I am the data controller for the information described here.
Post: 61 Bridge Street, Kington, HR5 3DJ, United Kingdom
Email: support@stream-ab.com
What is collected, and why
When you buy. Your email address and the reference Stripe gives your payment. Payment itself is handled entirely by Stripe - your card details go to them, never to this site, and I never see or store them. I keep your email because it is how your licence key reaches you and how I find your order if you write in about it.
When you download the free version. Your email address, the date, which page you downloaded from, and whether you left the box about being emailed ticked. The address is kept either way, because it is the record of who has the free version and the only way to reach you if something turns out to be wrong with the build you installed. It is used to market to you - new versions, the occasional offer - unless you untick that box, and unticking it never affects the download.
When you activate the plugin. Your licence key and a machine identifier derived from the computer you are activating on, plus the time you did it. The identifier is what makes “two machines per licence” enforceable. It is not a name, a serial number you would recognise, or anything that identifies you personally, and it is only ever compared against other activations of your own licence.
When you search Spotify from the plugin. What you typed and your licence key are sent to this site, which asks Spotify on your behalf. Your licence key travels in a request header specifically so it does not end up written into server logs. Search terms are cached for about an hour so a repeated search does not cost a second request - that cache holds the search text and its results, and nothing tying either to you. Spotify receives the search text, and never your email, your licence key or your machine identifier.
The Meta Pixel. Every page load sends an event to Meta (a “PageView”, and on the product page a “ViewContent”), and starting a purchase or completing one sends further events, so I can see how many sales came from an ad rather than guessing. Meta sets its own _fbp and, if you clicked through from a Facebook/Instagram ad, _fbc cookie to do this - these are Meta’s cookies, governed by their policies, not something I read directly. When you buy, I also send Meta a hashed (not plain-text) copy of your email and, if present, those cookie values, as a server-to-server backup of the same purchase event - this exists because browsers and ad blockers routinely drop the in-browser version, undercounting sales.
Server logs. The host records ordinary web-server information for each request, including IP address, time and page. This is standard operational logging used to keep the site up and to spot abuse.
Failed admin logins. If someone tries to log into the admin area, the IP address and a failure count are stored briefly so repeated guessing can be locked out. This only ever applies to the private admin page, not to customers.
If you email me. I keep the correspondence, because a support thread is not much use without its history.
Why I am allowed to hold it
Under UK GDPR, each of these rests on a specific legal basis:
- Performing our contract - your email, licence key, machine identifiers and activation records. Without them I cannot deliver or support what you bought.
- Legitimate interests - server logs, the admin login throttle, and the search proxy. The interest is keeping the service working, stopping abuse of it, and protecting the Spotify quota that every user shares. These are narrow, and none of them profile you.
- The soft opt-in (PECR regulation 22) - emailing you about new versions and offers after you download the free version. That rule allows marketing about my own similar products to someone whose address I took while they were considering buying, as long as refusing is simple at the time and in every message since. It is: the box on the download form, and an unsubscribe link in everything I send. Untick it, or unsubscribe later, and it stops - and either way the download is unaffected.
- Legitimate interests (again) - keeping the download record itself, ticked or not. The interest is knowing how many people are running the free version, and being able to contact someone about a security or licensing problem with software they have installed. It is not used to send marketing.
- Legal obligation - records of sales, which UK tax rules require me to retain.
- Legitimate interests (again) - the Meta Pixel, so I can measure whether advertising spend is actually converting into sales, weighed against the relatively low-impact use of cookie identifiers already visible to Meta.
Who else touches it
Only the services needed to actually run this. Each gets the minimum it needs, and none of them get your data for their own marketing.
- Stripe - takes the payment. They receive your payment details and email directly. Their privacy policy governs what they do with them.
- Supabase - the database holding licence records, and the storage the installers are downloaded from.
- Resend - sends the email containing your licence key.
- Vercel - hosts the site and this API, and keeps the server logs.
- Spotify - receives search text when you search from the plugin. Nothing identifying you is sent. Stream AB is not affiliated with Spotify.
- Meta - receives pixel events from your browser and, on a purchase, a hashed copy of your email, so ad performance can be measured. Their privacy policy governs what they do with it.
Some of these are based outside the UK, so your information may be processed elsewhere, including the United States. Where that happens it is covered by the standard safeguards those providers put in place, such as the UK addendum to the EU Standard Contractual Clauses.
I will also disclose information if the law actually requires it. Nothing else.
What the plugin itself does
Worth stating plainly, because a plugin that reads what you are listening to invites the question: the plugin does not send me anything about your listening. Reading the current track, controlling playback and the loop points all happen on your own computer and stay there.
The plugin contacts this site in exactly three situations: activating a licence, deactivating one, and running a search you typed. It does not phone home otherwise, does not check in periodically, and works offline once activated.
All three belong to the full version, so the free version never contacts this site at all until you enter a licence key.
It also does not process, record or transmit your audio. Nothing you play is analysed or leaves your machine.
How long it is kept
- Licence records - for as long as the licence exists, and then as long as tax law requires records of the sale, which is six years.
- Machine identifiers - until you deactivate that machine, at which point the entry is deleted.
- Free-download records - until you ask me to delete them, or until they stop being useful. Opt out or unsubscribe and the marketing stops immediately; say the word and the row goes entirely.
- Search cache - about an hour.
- Failed admin login records - minutes.
- Meta Pixel cookies - set and expired by Meta on their own schedule (up to 90 days), not by this site.
- Server logs - according to the host’s own retention, a matter of weeks.
- Emails you send me - as long as they are useful for supporting you, and no longer than is reasonable.
Your rights
You can ask me for a copy of what I hold about you, to correct it, to delete it, to restrict or object to how it is used, or to have it sent to you in a portable form. Email support@stream-ab.com and I will deal with it within one month.
One honest caveat: deleting your licence record means the licence stops working, since the record is the licence. I will say so before doing it rather than silently ending your access. Records I am legally required to keep for tax purposes cannot be deleted early, but they are not used for anything else.
There is no automated decision-making or profiling here, so there is nothing to opt out of.
If you think I have handled your information badly, please tell me first - but you are entitled to complain to the Information Commissioner’s Office at ico.org.uk regardless.
Children
Stream AB is sold to adults and is not directed at children. I do not knowingly collect information from anyone under 16.
Changes
If this policy changes, the date at the top changes with it. If a change materially affects existing customers, I will email them rather than rely on anyone re-reading this page.
Questions about any of it are welcome at support@stream-ab.com. The terms of service cover the sale itself.