Privacy Policy
1. What We Collect
- Email address — used for magic-link sign-in and transactional emails (report alerts, billing notices).
- VOD URLs you submit — used to run the analysis pipeline.
- Processed chat data and reports — compressed chat statistics and AI-generated reports are stored to power your history, dashboard, and auto-monitoring. Raw, unprocessed chat replay logs are discarded after analysis; we do not retain the original message-by-message feed.
- Monitored channels (Pro users) — the streaming channel handles you register for daily auto-monitoring.
- Audio transcripts (monitored channels only) — for each new broadcast on a monitored channel we fetch the audio track, transcribe it to text so we can score pacing and delivery, and keep that transcript for 30 days so a repeat analysis of the same broadcast does not transcribe it again. The audio itself is processed in transit and not stored. Transcripts are never published and never used to identify anyone by voice.
- Anonymous session ID — a browser cookie that ties a report you started before signing in to the account you then create.
- Visitor log — a first-party record of how the website is used: the page you arrived from, the pages you view and in what order, how far down each page you scrolled, and the links and buttons you click. It is keyed to a visitor cookie (see §4). When you sign in, the visits made from that browser are linked to your account.
- IP address — used for rate-limiting anonymous users. It is not stored in the visitor log. The address a sign-in link was requested from is kept with that link's record and deleted within a day of the link expiring.
We do not collect passwords, payment card numbers, or video content of any kind.
2. How We Use Your Data
- To deliver, cache, and display your coaching reports.
- To send magic-link sign-in emails and daily new-report notification emails.
- To enforce the free-tier quota via cookie and IP address.
- To understand how visitors use the website — which pages are read, where people stop, and which paths lead to a report or a subscription — so we can improve it. This is done with our own visitor log, read only by us.
- To run daily auto-monitoring and live alerts on your behalf (Pro), including transcribing the audio of monitored broadcasts.
- To detect and prevent abuse of the Service.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
3. Third-Party Processors
The following companies process data on our behalf to operate the Service:
- Anthropic — Compressed chat data is sent to Anthropic's Claude Haiku model to generate your coaching report. Anthropic processes this data under its API terms. (anthropic.com/privacy)
- Stripe — Handles payment processing and subscription management. We never see your card number. (stripe.com/privacy)
- Groq — Transcribes broadcast audio from monitored channels to text. Groq processes the audio under its API terms and does not train on it. (groq.com/privacy-policy) When our own transcription server is in use, the audio does not leave infrastructure we operate.
- Resend — Delivers transactional emails (magic links, report notifications) and, only with your consent, the weekly free-report reminder. (resend.com/privacy)
- Fly.io — Cloud hosting provider where all Service data is stored and processed. (fly.io/legal/privacy-policy)
- Pusher (Pro live features only) — Provides the WebSocket infrastructure used to receive real-time live chat data from Kick. (pusher.com/legal/privacy-policy)
Each processor is bound contractually to process data only as instructed and to maintain appropriate security standards.
4. Cookies
- Session cookie — Authenticates your logged-in session. A random token, stored on our side only as a keyed hash, HTTP-only. Valid for a rolling 30 days.
- Anonymous session cookie — Ties a report started before sign-in to the account created afterwards. Expires after 90 days.
- Visitor cookie — A random identifier so that a returning browser reads as the same visitor in our visitor log. First-party and HTTP-only; it is never shared with anyone and carries no personal information itself. Expires after 12 months.
We do not use advertising cookies, tracking pixels, or third-party analytics scripts. The visitor log is built and hosted by us, and no analytics data is sent to any third party.
5. Data Retention
- Account data, report history, and monitored channels are retained as long as your account is active.
- After cancellation, your data is retained indefinitely so your history is available if you return. You may request deletion at any time (see §6).
- Anonymous session data expires with the cookie (90 days).
- Audio transcripts from monitored channels are deleted 30 days after they are made.
- Visitor log entries are deleted after 12 months. Entries linked to an account are deleted with the account.
6. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by emailing admin@bunshin.io. We will respond within 30 days. Account deletion removes your email address, report history, and monitored channels from our database.
7. Security
All data in transit is encrypted via TLS. Session and sign-in tokens are stored only as keyed hashes, so a copy of our database cannot be used to sign in as anyone; the cookies that carry them are HTTP-only. Stripe handles all payment credentials — we never store card numbers or bank details.
8. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us at admin@bunshin.io and we will delete it promptly.
9. Changes to This Policy
We will notify users by email at least 14 days before material changes to this Policy take effect.