Home

Privacy policy

Privacy, without static.

What the public site and protected studio process, why it is needed, and how long operational records are retained.

At a glance

Daydream Radio does not sell personal information. The public site does not require an account. The protected studio is restricted to approved administrators and uses only the identity and operational information required to run and audit the station.

Public website

Firebase Hosting delivers the public pages and may produce standard infrastructure logs such as request time, requested path, network address, user agent, and response status. Daydream Radio does not add advertising pixels or behavioral analytics to these pages.

YouTube content

The homepage uses YouTube’s privacy-enhanced embed domain. Loading or playing an embedded video, or following a YouTube link, sends data to YouTube under Google’s privacy terms. The embed is lazy-loaded so it does not load until it approaches the viewport.

Protected studio

Studio sign-in uses Firebase Authentication with Google. The Radio API verifies the Firebase token, verified email, and administrator allowlist. Operational records can include administrator email, actions, correlation IDs, program state, schedules, source metadata, and transcript evidence. Browser code never receives stream keys or server credentials.

Retention and security

Current policy retains transcript records for 90 days, runtime events for 30 days, and audit events for 365 days. Private HLS preview objects expire after seven days. Phone and public listener-request features are disabled. Firestore backups and point-in-time recovery protect control data from accidental loss.

Your choices

You can use the public pages without signing in. Theme preference is stored only in your browser. Approved administrators can sign out to clear their active Firebase session from the studio.

Contact

For privacy questions, use the Daydream Radio contact page.