개인정보처리방침
BOUND LIVE · 시행일 2026년 8월 21일 · 개정 2026년 9월 15일
BOUND(이하 "서비스")는 https://live.boundstream.com(이전 주소 https://live.boundyoutube.com 포함) 및 BOUND 방송관리 시스템(윈도우 프로그램), BOUND 모바일 앱에 본 방침을 적용합니다.
1. 수집하는 정보
| 구분 | 항목 | 이용 목적 |
|---|---|---|
| 스트리머 계정 | 아이디, 비밀번호(해시 저장), 채널명 | 로그인 및 서비스 이용 |
| 구글 계정 | 이메일, 이름, 구글 계정 식별자 | 구글 로그인, 계정 식별 |
| 유튜브 데이터 | 채널명, 라이브 방송 정보, 실시간 채팅 메시지, 접근·갱신 토큰 | 방송 생성·시작·종료, 채팅 표시·전송·관리 |
| 시청자 예약 | 닉네임, 전화번호 | 노래방 예약 순서 관리(스트리머만 열람) |
| 후원 내역 | 입금자명, 금액, 시각 | 후원 알림 및 정산 |
| 이용권 문의 | 이름, 전화번호, 문의한 이용권, 메모 | 이용권 안내 및 상담 연락 |
2. 구글 사용자 데이터의 이용 (Google User Data)
서비스는 유튜브 연동 시 https://www.googleapis.com/auth/youtube.force-ssl 권한 하나만 요청합니다. 사용 범위는 아래로 한정됩니다.
- 라이브 방송 생성·연결·시작·종료 — 스트리머가 프로그램에서 "방송 시작/종료"를 누를 때만 실행됩니다.
- 실시간 채팅 읽기 — 통합 채팅창에 표시하기 위해서만 사용하며, 서버에 저장하지 않고 화면에만 표시합니다.
- 실시간 채팅 메시지 전송 — 스트리머가 설정한 안내 문구를 스트리머 채널에 보냅니다.
- 채팅 관리(차단·타임아웃) — 스트리머가 등록한 금지어에 해당하는 메시지에 대해 실행됩니다.
3. 제3자 제공 · 전송 · 공개 대상
서비스는 구글 사용자 데이터를 판매하지 않으며, 광고·마케팅 목적으로 제공하지 않습니다. 데이터가 전달되는 곳은 아래가 전부입니다.
| 대상 | 전달되는 데이터 | 사유 | 위치 |
|---|---|---|---|
| Cloudflare, Inc. (Workers · D1 · KV) | 계정 정보, 암호화된 유튜브 토큰, 예약·후원 기록, 이용권 문의 기록 | 서비스 호스팅 및 데이터 저장(수탁 처리) | 미국 및 글로벌 엣지 |
| Google LLC (YouTube Data API) | 방송 정보, 채팅 메시지 | 이용자가 요청한 방송·채팅 기능 수행 | 구글 인프라 |
| 스트리머 본인 | 해당 채널의 시청자 예약·채팅·후원 정보 | 방송 운영 | 이용자 기기 |
| Discord Inc. (웹훅 알림) | 이용권 문의 내용(이름, 전화번호, 이용권, 메모) — 구글 사용자 데이터는 포함하지 않습니다 | 운영자에게 문의 접수 알림 전달 | 미국 |
위 외의 제3자에게는 제공하지 않습니다. 다만 법령에 따른 수사기관의 적법한 요청이 있는 경우에 한해 관련 법률이 정한 절차에 따라 제공할 수 있습니다.
4. 민감한 데이터 보호 조치
전송 구간
- 모든 통신은 HTTPS(TLS)로만 이루어지며, HSTS(
max-age=31536000)를 적용해 평문 접속을 차단합니다. - 모바일 앱은 평문 통신을 금지(
usesCleartextTraffic=false)하고 접속 도메인을 정확히 검증합니다.
저장 구간
- 유튜브 접근·갱신 토큰은 암호화하여 저장하며, 복호화 키는 서버 시크릿으로 분리 보관합니다.
- 비밀번호는 원문을 저장하지 않고 PBKDF2-SHA256(반복 10만 회) + 사용자별 난수 솔트 + 서버 시크릿으로 해시하여 저장합니다.
- 윈도우 프로그램은 OBS 비밀번호 등 민감 설정을 운영체제 보안 저장소(Windows DPAPI)로 암호화합니다.
- 모바일 앱은 Android Keystore(AES-GCM)로 토큰을 암호화하고 기기 백업을 차단합니다.
접근 통제
- 스트리머는 본인 계정에 연결된 데이터에만 접근할 수 있으며, 모든 요청은 서버에서 세션·라이선스를 검증합니다.
- 관리자 화면은 별도 PIN 인증으로 분리되어 있고, 로그인 시도 횟수를 제한합니다.
- 운영자는 유튜브 토큰과 채팅 원문을 열람하지 않습니다. 로그와 오류 기록에 토큰·비밀번호를 남기지 않습니다.
5. 보관 기간 및 삭제
- 실시간 채팅 메시지는 서버에 저장하지 않습니다. 화면 표시 목적으로만 전달됩니다.
- 유튜브 토큰은 연동이 유지되는 동안만 보관하며, 이용자가 연동을 해제하거나 계정을 삭제하면 즉시 삭제됩니다.
- 계정·예약·후원 기록은 서비스 이용 기간 동안 보관하고, 계정 삭제 요청 시 지체 없이 파기합니다.
- 이용권 문의 기록(디스코드 알림 포함)은 상담이 끝난 뒤 1년간 보관한 뒤 파기합니다.
- 연동 해제는 프로그램에서, 또는 구글 계정 권한 관리에서 직접 하실 수 있습니다.
- 데이터 삭제 요청: dami8959584@gmail.com (요청일로부터 7일 이내 처리)
6. YouTube API 서비스 이용
BOUND LIVE 는 YouTube API Services 를 사용합니다. 본 서비스를 이용함으로써 이용자는 YouTube 이용약관에 동의하는 것으로 간주됩니다.
YouTube API 를 통해 취득한 데이터의 처리에는 Google 개인정보처리방침이 함께 적용됩니다.
- 실시간 채팅 원문은 서버에 저장하지 않습니다(5항 참조). 서버에 남는 YouTube 유래 데이터는 금지어 조치 기록의 메시지 ID와 슈퍼챗 후원자 표시 이름 두 가지뿐입니다.
- 이 두 가지는 30일이 지나면 자동으로 삭제하거나 익명 처리합니다. 채널 정보·라이브 방송 정보는 화면 표시를 위해 그때그때 YouTube 에서 다시 받아옵니다.
- 이용자가 Google 계정 권한 설정에서 접근 권한을 철회하면, 해당 이용자의 YouTube API 데이터를 30일 이내에 전부 삭제합니다.
- 저장된 데이터의 삭제 요청은 아래 문의처로 접수하며 7일 이내 처리합니다.
7. 문의
개인정보 보호 책임자: BOUND 운영자 · dami8959584@gmail.com
Privacy Policy
BOUND LIVE · Effective 21 August 2026 · Updated 15 September 2026 · English translation of the Korean policy above
This policy applies to https://live.boundstream.com (including its former address https://live.boundyoutube.com), the BOUND Master desktop application for Windows, and the BOUND mobile applications.
1. Information We Collect
| Category | Data | Purpose |
|---|---|---|
| Streamer account | Username, password (stored hashed), channel name | Authentication |
| Google account | Email, name, Google account identifier | Google Sign-In, account identification |
| YouTube data | Channel title, live broadcast details, live chat messages, access & refresh tokens | Creating/starting/ending broadcasts; displaying, sending and moderating live chat |
| Viewer reservations | Nickname, phone number | Karaoke queue management (visible only to the streamer) |
| Donation records | Depositor name, amount, timestamp | Donation alerts and settlement |
| Plan inquiries | Name, phone number, selected plan, message | Responding to plan inquiries |
2. How We Use Google User Data
We request exactly one YouTube scope: https://www.googleapis.com/auth/youtube.force-ssl. It is used only for:
- Creating, binding, starting and ending live broadcasts — triggered only when the streamer presses Start/Stop in the application.
- Reading live chat — displayed in the application's chat window. Chat messages are not stored on our servers.
- Sending live chat messages — posts the streamer's own configured announcement to the streamer's own channel.
- Moderating live chat (ban / timeout) — applied only to messages matching the streamer's own banned-word list.
3. With Whom We Share, Transfer or Disclose Google User Data
We do not sell Google user data and do not transfer it for advertising or marketing. The following is the complete list of recipients:
| Recipient | Data transferred | Reason | Location |
|---|---|---|---|
| Cloudflare, Inc. (Workers, D1, KV) | Account records, encrypted YouTube tokens, reservation and donation records, plan inquiry records | Hosting and data storage (processor acting on our instructions) | United States and global edge |
| Google LLC (YouTube Data API) | Broadcast details, chat messages | Performing the broadcast and chat actions the user requested | Google infrastructure |
| The streamer (account owner) | Reservation, chat and donation data for their own channel | Operating their own broadcast | User's device |
| Discord Inc. (webhook notification) | Plan inquiry details (name, phone number, plan, message) — no Google user data | Notifying the operator of a new inquiry | United States |
We disclose data to no other third party, except where required by law in response to a lawful request from a competent authority.
4. Data Protection Mechanisms for Sensitive Data
In transit
- All traffic uses HTTPS (TLS) only. HSTS (
max-age=31536000; includeSubDomains) is enforced on every response. - Mobile applications disable cleartext traffic (
usesCleartextTraffic=false) and verify the exact host name before loading.
At rest
- YouTube access and refresh tokens are encrypted before storage; the decryption key is held separately as a server secret and is never stored alongside the data.
- Passwords are never stored in plaintext. We store PBKDF2-SHA256 (100,000 iterations) with a per-user random salt and a server-side secret.
- The Windows application encrypts sensitive local settings (such as the OBS WebSocket password) using the operating system keystore (Windows DPAPI).
- The Android application encrypts stored tokens with Android Keystore (AES-GCM) and disables device backup of application data.
Access control
- Every request is authorised server-side against the user's session and licence; a streamer can reach only their own data.
- The administrative console is separated behind an independent PIN with rate-limited login attempts.
- Our staff do not read YouTube tokens or chat content. Tokens, passwords and PINs are never written to logs or error reports.
5. Retention and Deletion
- Live chat messages are not persisted on our servers; they are relayed for on-screen display only.
- YouTube tokens are retained only while the integration is connected and are deleted immediately when the user disconnects the integration or deletes the account.
- Account, reservation and donation records are retained for the duration of service use and destroyed without delay upon a deletion request.
- Plan inquiry records (including the Discord notification) are kept for one year after the inquiry is closed and then destroyed.
- Users may revoke access at any time in the application or at Google Account permissions.
- Deletion requests: dami8959584@gmail.com — processed within 7 days.
6. Use of YouTube API Services
BOUND LIVE uses YouTube API Services. By using this service you agree to be bound by the YouTube Terms of Service.
Data obtained through the YouTube API is also governed by the Google Privacy Policy.
- Live chat content is never persisted on our servers (see section 5). The only YouTube-derived data retained server-side is the message ID of a moderation action and the display name of a Super Chat sender.
- Both are automatically deleted or anonymised after 30 days. Channel and live broadcast details are re-fetched from YouTube on demand rather than stored.
- If a user revokes access via Google Account permissions, all YouTube API data for that user is deleted within 30 days.
- Deletion requests are accepted at the contact below and processed within 7 days.
7. Contact
Data protection contact: BOUND operator · dami8959584@gmail.com