1Scope
This Privacy Policy applies to all products and services operated by Creator Studios Labs ("we", "our", or "us"), including:
- The Creator Studios Labs website (creatorstudioslabs.stream)
- Mobile applications, including DeckPilot (OBS Stream Controller)
- Desktop software, including the OBS Plugin Installer and related companion applications
- Cloud account system that enables syncing between mobile and desktop devices
- Future applications, tools, and software products published under Creator Studios Labs
This policy covers how we collect, use, store, share, and protect your information across all of these Services. By using any of our Services, you agree to the practices described in this policy. If you do not agree, please discontinue use of our Services.
2Information Collected
Depending on the specific product or service you use, we may collect the following types of information:
A. Technical & Device Information
- Device type and model
- Operating system and version
- App version number
- Screen resolution and display metrics
- IP address (used for analytics, security, and connection management)
- Device identifiers (phone device ID, desktop device ID)
B. Analytics & Crash Reporting
We may use tools such as Firebase Analytics or similar services to collect:
- App engagement and feature usage metrics
- Crash reports and error diagnostics
- Performance data (app launch time, response times)
- Session duration and frequency
C. Advertising Data
If an app includes advertising through Google AdMob or a similar advertising service, third-party ad providers may collect:
- Advertising ID (device-level identifier for ad personalisation)
- Device identifiers
- Interaction data with advertisements (impressions, taps)
D. Support & Contact Data
If you contact us for support, we may receive:
- Your email address
- The content of your message
- Any attachments or screenshots you provide
E. Locally Stored App Data
Some of our apps store settings and connection data locally on your device. This may include:
- App preferences and configuration
- OBS connection details (IP address, port, WebSocket password)
- Scene layouts and custom button configurations
3Account & Desktop Sync Data
When you create an account or use the desktop-sync feature, we collect additional information necessary to provide the service. This section describes that data specifically.
A. Account Information
- Email address — used for account creation, login, recovery, and communications
- Password hash — used for secure authentication (we never store plain-text passwords)
- Internal user ID — a unique identifier assigned to your account
B. Desktop Sync Information
- Desktop device ID — a unique identifier for each connected computer
- Phone device ID — a unique identifier for the mobile device
- Desktop name — the name you assign to your computer, used to identify it in your device list
- Operating system of the connected desktop
- Desktop-agent version — to ensure compatibility and deliver updates
- Pairing information — data that links your phone to your desktop during setup
- IP address — collected for security purposes and connection management
C. Workspace & Configuration Data
- Workspace configuration — synced buttons, pages, macros, and custom layouts
- OBS scene and source configurations that you choose to sync across devices
- User preferences and settings stored as part of your account
D. Activity & Security Logs
- Login history — timestamps and IP addresses of account logins
- Command history — records of remote commands sent from your phone to your desktop (e.g., scene switches, OBS controls, macro triggers)
- Desktop connection logs — records of when desktops are paired, connected, or disconnected
- Security events — failed login attempts, password changes, and device revocation events
E. Crash & Diagnostic Data
- Desktop-agent crash logs and error reports
- Mobile app crash diagnostics related to cloud features
- Performance metrics for remote-command delivery
Whether providing information is required: Account creation requires a valid email address and a password. Device pairing requires both the mobile app and desktop agent to be online and authorised. Some features (such as remote commands and workspace sync) will not function without the associated data described above.
4How Information Is Used
We use collected information to:
- Create and maintain your account
- Authenticate you when you log in
- Pair your phone with your desktop computer
- Deliver remote commands from your phone to your desktop
- Sync workspace configurations (buttons, pages, macros) across your devices
- Display connected devices and their status
- Improve app performance, stability, and functionality
- Identify and fix bugs, crashes, and errors
- Understand usage patterns to guide product development
- Serve relevant advertisements where applicable
- Respond to support enquiries
- Ensure security and prevent misuse of our Services
- Investigate and respond to security incidents
- Comply with legal obligations
We do not sell your personal information to third parties.
Command history is stored to allow you to review recent remote activity and for troubleshooting purposes. You can clear your command history through the app settings.
5Local Storage & App Settings
Several of our apps store configuration and preferences locally on your device. This data is not transmitted to Creator Studios Labs servers unless explicitly stated within the app.
Examples of locally stored data include:
- App theme and display preferences
- OBS connection settings (IP address, port number, WebSocket password)
- Custom button layouts and scene configurations (when not using cloud sync)
- Recent connection history
This data remains on your device and is only removed when you uninstall the app or manually clear the app's data through your device settings. Deleting your cloud account does not automatically remove locally stored data from your devices.
6Third-Party Services
Our apps, website, and cloud infrastructure may use third-party services that collect and process information independently. These services include:
- Google Play Services — app distribution and update delivery
- Google AdMob — advertising (where applicable)
- Firebase Analytics — usage analytics
- Firebase Crashlytics — crash diagnostics
- Cloudflare — content delivery, DNS, DDoS protection, and network security
- Vercel — website hosting and API infrastructure
- Email service provider — sending account confirmation, password reset, and support emails
- Database hosting provider — storing account information, workspace configurations, and command logs
- GitHub — private repository for desktop-installer distribution
- OBS Studio — local network WebSocket integration (no data sent to external servers)
Each third-party service operates under its own privacy policy. We encourage you to review their privacy policies for more information. We may add or change service providers, and will update this section accordingly.
When payments are introduced, we may use RevenueCat or a similar service to manage subscription entitlements. Transaction processing will continue to be handled by the platform billing system (Google Play Billing or Apple In-App Purchase).
7Advertising
Some of our apps may display advertisements through Google AdMob or similar advertising networks. When ads are present:
- Third-party ad providers may collect device identifiers and advertising IDs to serve personalised ads
- You can opt out of personalised advertising through your device settings (Settings → Privacy → Advertising on most devices)
- Ad interaction data (impressions and taps) may be collected by the ad network
Not all of our apps include advertising. Whether ads are present is specified on each app's store listing or within the app itself.
8Billing & Purchases
If an app offers in-app purchases, subscriptions, or paid features, transactions are handled entirely by the platform's billing system (Google Play Billing or Apple's In-App Purchase).
- Creator Studios Labs does not directly collect, process, or store payment information such as credit card numbers or bank details
- Purchase receipts and entitlement verification are managed through the platform's billing API
- We may use a third-party entitlement service (e.g., RevenueCat) to verify subscription status across devices
- Refund requests should be directed to the relevant app store (Google Play or Apple App Store)
9Local Network & OBS Communication
Some of our products, such as DeckPilot, communicate directly with OBS Studio over your local network using the OBS WebSocket protocol. It is important to understand how this works:
- Direct local connection: The app connects directly to OBS Studio running on your computer. This communication happens entirely within your local network (e.g., your home Wi-Fi).
- No cloud relay for local OBS data: Connection data (such as the IP address, port, and WebSocket password of your OBS instance) is not sent to Creator Studios Labs servers or any external server.
- Remote commands go through our cloud: When you send a remote command from your phone to your desktop over the Internet (not local Wi-Fi), the command is relayed through our cloud infrastructure. The command content and timestamp are logged.
- Stored locally: Connection credentials are stored on your device only so the app can reconnect. They are not transmitted externally.
- Scene and source data: Information about your OBS scenes, sources, and audio levels is read from OBS in real time. This data is used only within the app on your device and is not collected or stored by Creator Studios Labs, except for configurations you explicitly choose to sync through your account.
11Data Security
We take reasonable administrative, technical, and physical measures to protect information collected through our Services. These measures include:
- Using HTTPS/TLS for all website and API communications
- Hashing passwords using industry-standard algorithms (passwords cannot be decrypted)
- Encrypting data in transit between our servers, mobile apps, and desktop agents
- Keeping local network connections (such as OBS WebSocket) within your private network
- Relying on platform-level security (Google Play, App Store) for app distribution
- Limiting access to production data to authorised personnel only
- Using Cloudflare for network-level DDoS protection and security filtering
- Implementing token-based authentication with short-lived access tokens and revocable refresh tokens
- Maintaining security logs to detect and investigate suspicious activity
However, no method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. We will notify users of any data breach affecting personal information as required by applicable law.
12Data Retention
We retain collected information only as long as necessary to fulfil the purposes outlined in this policy, or as required by applicable law. Our specific retention periods are:
Account Data
- Account information (email, password hash, user ID) — retained until account is deleted
- Workspace configurations — retained until deleted by the user or upon account deletion
- Paired device identifiers — retained until the device is unpaired or account is deleted
Activity Logs
- Command history — retained for 30 days, then automatically deleted
- Security logs (logins, failed attempts, device changes) — retained for 90 days
- Desktop connection logs — retained for 30 days
Analytics & Crash Data
- Analytics data — retained for up to 14 months, or as configured in the analytics service
- Crash reports — retained for up to 90 days
Deleted Accounts & Backups
- Account data marked for deletion — permanently removed from live systems within 30 days of verified request
- Backup copies — purged within 30 days of deletion from live systems
- Transaction records — retained for 7 years after the transaction (legal requirement)
- Support correspondence — retained for 90 days after account deletion
Temporary Data
- Pairing codes — single-use; expire after 10 minutes
- Remote command relay data — discarded within 60 seconds of delivery
- Password reset tokens — expire after 1 hour
When data is no longer needed for the purposes described in this policy, we take reasonable steps to delete, destroy, or anonymise it.
13International Data Transfers
Creator Studios Labs is based in Lagos, Nigeria. To provide our Services, your personal information may be transferred to, stored on, and processed in servers located outside Nigeria, including in countries that may have different data protection laws.
Service providers we use may process data in:
- United States — Vercel (hosting), Google Cloud / Firebase (analytics, crash reporting), Cloudflare (CDN, security), GitHub
- European Union — email service provider, database hosting
- Other regions where our service providers operate
Where we transfer your data to countries outside Nigeria, we ensure appropriate safeguards are in place, including:
- Data processing agreements with our service providers
- Reliance on adequacy decisions or standard contractual clauses where applicable
- Contractual obligations requiring equivalent levels of data protection
By using our Services, you consent to the transfer of your information to countries outside Nigeria as described in this section.
14Children's Privacy
Our Services are not directed to children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children under this age.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@creatorstudioslabs.stream and we will take appropriate steps to delete such information promptly.
15User Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data. Under the Nigeria Data Protection Act and similar laws, you have the right to:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and associated data (subject to legal retention requirements)
- Objection: Object to the processing of your personal data in certain circumstances
- Data portability: Request a copy of your data in a structured, commonly used format
- Withdraw consent: Withdraw consent where data processing is consent-based
- Opt-out: Opt out of personalised advertising through your device settings
How to exercise your rights
To exercise any of these rights, please contact us at support@creatorstudioslabs.stream. We will respond to your request within a reasonable timeframe and no later than 30 days.
Deleting your account
You can delete your account directly within the app:
- In-app deletion: Go to Settings → Account → Delete Account
- Web deletion request: Visit creatorstudioslabs.stream/delete-account
When you delete your account, we revoke all phone sessions, refresh tokens, desktop device tokens, and cloud workspace access. You will need to unlink or uninstall the desktop agent on each connected computer separately.
Revoking a connected desktop
You can revoke access for a specific desktop at any time:
- In the mobile app, go to Settings → Connected Devices → select the desktop → Revoke Access
- On the desktop agent, you can also sign out or revoke access directly
16Complaints
If you believe we have processed your personal data in a way that does not comply with applicable data protection law, you have the right to lodge a complaint.
We encourage you to contact us first so we can address your concern directly:
If you are in Nigeria and are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
17Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our products, practices, or legal requirements. When we make changes:
- The "Last updated" date at the top of this page will be revised
- Material changes may be communicated through in-app notices, email, or our website
- Your continued use of our Services after changes are published constitutes your acceptance of the revised policy
We encourage you to review this page periodically to stay informed about how we handle your information.
18Contact Information
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us: