Privacy transparency

Browser technologies

This disclosure is generated from Goodstream's reviewed browser-technology registry. It covers the current cookies, browser storage, external browser resources, analytics vendor, payment SDKs, and first-party browser services in scope for this review.

Registry browser-technologies-2026-07-v2 Reviewed 2026-07-29 22 entries

This engineering disclosure describes implemented technology and is not a claim of universal legal compliance. See the Privacy Policy for the broader policy summary.

Strictly necessary

Required for requested platform, account, security, commerce, or playback functions.

Clip handoff job

cookie · first party

Goodstream
Purpose
Carry a user-requested clip creation job from the stream page to the clips host.
When it is used
When a signed-in viewer starts clip creation.
Duration
10 minutes.
Scope
Goodstream public and clips hosts.
Data elements
  • opaque clip job identifier
Withdrawal or removal
Expires automatically after the short handoff window.
Goodstream responsibility
Media Platform Engineering

Clip handoff status capability

cookie · first party

Goodstream
Purpose
Authorize status checks for a user-requested clip creation handoff.
When it is used
When a signed-in viewer starts clip creation.
Duration
10 minutes.
Scope
Goodstream public and clips hosts.
Data elements
  • short-lived opaque status capability
Withdrawal or removal
Expires automatically after the short handoff window.
Goodstream responsibility
Media Platform Engineering

Clips interface stylesheet

external stylesheet · third party

jsDelivr
Purpose
Style the requested clips creation interface.
When it is used
When the authenticated clips creation page is opened.
Duration
Provider and browser cache controlled.
Scope
Goodstream clips creation page.
Data elements
  • IP address
  • browser request metadata
  • stylesheet version
Withdrawal or removal
The request stops when the clips page is not used or the resource is blocked through browser controls.
Goodstream responsibility
Media Platform Engineering

Goodstream browser API requests

first party endpoint · first party

Goodstream
Purpose
Perform authenticated account, chat, moderation, playback, and preference actions requested in the browser.
When it is used
When a visitor uses an interactive Goodstream feature.
Duration
Request scoped; related server records follow their applicable retention rules.
Scope
Goodstream web and API hosts.
Data elements
  • requested action
  • session and CSRF context
  • feature-specific submitted data
Withdrawal or removal
Requests stop when the related feature is no longer used; core account and security requests remain necessary.
Goodstream responsibility
Web Platform Engineering

Goodstream media and playback delivery

first party endpoint · first party

Goodstream
Purpose
Deliver requested live streams, videos, clips, images, and required playback-break media.
When it is used
When a visitor opens or plays Goodstream media.
Duration
Request and short-lived playback grant scoped; browser caching follows response controls.
Scope
Goodstream media, HLS, assets, clips, and regional playback hosts.
Data elements
  • requested media path
  • playback entitlement
  • network request metadata
Withdrawal or removal
Delivery stops when playback or media use stops; entitlement data expires on its configured schedule.
Goodstream responsibility
Media Platform Engineering

Goodstream realtime connection

first party endpoint · first party

Goodstream
Purpose
Provide requested chat, notification, overlay, and live-status updates.
When it is used
When a Goodstream surface requiring realtime updates is open.
Duration
For the active page session, with reconnects while the page remains open.
Scope
Goodstream chat and realtime hosts.
Data elements
  • channel subscription names
  • session authorization
  • realtime event payloads
Withdrawal or removal
The connection closes when the page or feature is closed.
Goodstream responsibility
Realtime Platform Engineering

Playback ad-break session state

session storage · first party

Goodstream
Purpose
Maintain tab-session continuity for requested playback and authoritative house-ad behavior.
When it is used
When a stream watch page evaluates required playback-break state.
Duration
Browser tab session.
Scope
Goodstream stream watch page.
Data elements
  • channel-scoped playback-break state
Withdrawal or removal
Clears when the tab session ends; playback continues if storage is unavailable.
Goodstream responsibility
Advertising Delivery Engineering

Goodstream session

cookie · first party

Goodstream
Purpose
Maintain authentication, session continuity, CSRF binding, and security state.
When it is used
When a Goodstream web session starts.
Duration
Configured session lifetime, or longer when the user requests persistent sign-in.
Scope
Configured Goodstream session domain and path.
Data elements
  • encrypted session identifier and server-side session state reference
Withdrawal or removal
Removed through logout, browser cookie controls, or session expiration.
Goodstream responsibility
Identity and Security Engineering

Mature-content acknowledgement

cookie · first party

Goodstream
Purpose
Remember the visitor's explicit acknowledgement before showing requested mature stream content.
When it is used
When a visitor confirms a mature-content gate.
Duration
1 year.
Scope
Goodstream public stream and chat pages.
Data elements
  • channel-scoped acknowledgement flag
Withdrawal or removal
Can be removed through browser cookie controls and is never reused for advertising age inference.
Goodstream responsibility
Trust and Safety Engineering

PayPal checkout SDK

external script · third party

PayPal
Purpose
Render PayPal payment controls after a signed-in user opens the requested Bits purchase workflow.
When it is used
When the authenticated Bits purchase page is opened.
Duration
Payment page session and provider-controlled transaction state.
Scope
Authenticated Goodstream Bits purchase page.
Data elements
  • IP address
  • browser request metadata
  • PayPal client configuration
  • payment interaction data
Withdrawal or removal
The SDK is absent when the payment page is not used; provider transaction records follow payment obligations.
Goodstream responsibility
Commerce Engineering

Playback grant

encrypted cookie · first party

Goodstream
Purpose
Carry short-lived signed HLS entitlement after required playback conditions are satisfied.
When it is used
When requested playback becomes eligible for HLS delivery.
Duration
Short-lived playback grant configured by Goodstream.
Scope
Goodstream HLS and playback hosts.
Data elements
  • opaque signed playback entitlement
Withdrawal or removal
Expires automatically and is replaced only when playback is requested again.
Goodstream responsibility
Media Security Engineering

Playback viewer context

encrypted cookie · first party

Goodstream
Purpose
Bind authoritative playback and required ad-break state to an opaque first-party viewer context.
When it is used
When a visitor requests stream playback.
Duration
Bounded playback configuration.
Scope
Goodstream public and playback hosts.
Data elements
  • opaque random viewer context identifier
Withdrawal or removal
Expires on its configured schedule and can be removed through browser cookie controls.
Goodstream responsibility
Advertising Delivery Engineering

Privacy choice record

encrypted cookie · first party

Goodstream
Purpose
Remember versioned privacy category choices and Global Privacy Control state without identity or IP address.
When it is used
When a visitor saves a privacy choice.
Duration
180 days by default, subject to the current consent schema.
Scope
Configured Goodstream session domain and path.
Data elements
  • consent schema version
  • category choices
  • choice source
  • GPC state
  • timestamp
Withdrawal or removal
Updated whenever choices change and removed through browser cookie controls.
Goodstream responsibility
Privacy Engineering

Remembered sign-in

encrypted cookie · first party

Goodstream
Purpose
Keep a user signed in when they explicitly select persistent authentication.
When it is used
When a user signs in with the remember option.
Duration
Framework authentication duration.
Scope
Configured Goodstream session domain and path.
Data elements
  • encrypted persistent authentication reference
Withdrawal or removal
Removed through logout, account-security actions, expiration, or browser cookie controls.
Goodstream responsibility
Identity and Security Engineering

Remembered two-factor device

encrypted cookie · first party

Goodstream
Purpose
Remember a device after successful two-factor verification when the user requests it.
When it is used
When a user selects remember device after a valid two-factor challenge.
Duration
30 days.
Scope
Configured Goodstream session domain and path.
Data elements
  • signed device remembrance value scoped to the user
Withdrawal or removal
Removed through account-security actions, expiration, logout controls where applicable, or browser cookie controls.
Goodstream responsibility
Identity and Security Engineering

Stripe checkout SDK

external script · third party

Stripe
Purpose
Render Stripe payment controls after a signed-in user opens the requested Bits purchase workflow.
When it is used
When the authenticated Bits purchase page is opened.
Duration
Payment page session and provider-controlled transaction state.
Scope
Authenticated Goodstream Bits purchase page.
Data elements
  • IP address
  • browser request metadata
  • payment interaction data
Withdrawal or removal
The SDK is absent when the payment page is not used; provider transaction records follow payment obligations.
Goodstream responsibility
Commerce Engineering

Cross-site request forgery protection

cookie · first party

Goodstream
Purpose
Protect same-origin browser actions from cross-site request forgery.
When it is used
When a Goodstream web session supports state-changing requests.
Duration
Session scoped.
Scope
Configured Goodstream session domain and path.
Data elements
  • CSRF protection token
Withdrawal or removal
Expires with the session and is replaced as needed for security.
Goodstream responsibility
Identity and Security Engineering

Functional

Supports optional interface features and preferences.

Bunny Fonts stylesheet

external font · third party

Bunny Fonts
Purpose
Provide the Instrument Sans web font if the legacy welcome template is served.
When it is used
Only when the legacy welcome template is rendered.
Duration
Provider and browser cache controlled.
Scope
Legacy welcome template.
Data elements
  • IP address
  • browser request metadata
  • requested font family
Withdrawal or removal
The request stops when the template is not used or the resource is blocked through browser controls.
Goodstream responsibility
Web Platform Engineering

Emoji picker dataset

external data · third party

jsDelivr and emoji-picker-element
Purpose
Download the emoji names and search data used by the optional chat emoji picker.
When it is used
When an emoji picker component initializes on a chat surface.
Duration
Provider cache headers and browser cache controlled.
Scope
Stream chat and chat popout surfaces.
Data elements
  • IP address
  • browser request metadata
  • emoji dataset version and locale
Withdrawal or removal
Future requests stop when the emoji picker is not initialized or the resource is blocked through browser controls.
Goodstream responsibility
Chat Experience Engineering

Emoji picker local database

indexed db · first party

Goodstream using emoji-picker-element
Purpose
Cache emoji search data, skin-tone preference, and frequently selected emoji for the optional picker.
When it is used
When an emoji picker component initializes on a chat surface.
Duration
Until browser site data is cleared or the picker database is deleted.
Scope
The Goodstream origin that renders the chat surface.
Data elements
  • emoji dataset
  • skin-tone preference
  • emoji favorite counts
Withdrawal or removal
Can be removed by clearing Goodstream site data; later consent milestones may automate category withdrawal.
Goodstream responsibility
Chat Experience Engineering

Appearance preference

cookie · first party

Goodstream
Purpose
Apply the light, dark, or system appearance preference explicitly selected by the user.
When it is used
When a visitor changes the appearance setting.
Duration
1 year.
Scope
Goodstream web hosts.
Data elements
  • light, dark, or system preference
Withdrawal or removal
Changed or removed through the appearance selector or browser cookie controls; never used for analytics or advertising.
Goodstream responsibility
Design Systems Engineering

Analytics

Used only under the current analytics-consent control.

Google Analytics

analytics vendor · third party

Google Analytics
Purpose
Measure aggregate site use and performance after explicit analytics consent.
When it is used
Only after a current explicit analytics choice and while the global optional-vendor switch is enabled.
Duration
Provider controlled; Goodstream clears controlled analytics cookies on withdrawal.
Scope
Public and dashboard layouts after consent.
Data elements
  • page and event metadata
  • browser and device information
  • analytics identifiers
Withdrawal or removal
Disables future collection immediately and clears Goodstream-controlled analytics cookies.
Goodstream responsibility
Privacy Engineering

Advertising

Reserved for advertising or targeting technology; no third-party advertising vendor is enabled in this registry.

No current entries are registered in this category.

Privacy choices can be changed through . Questions about this disclosure can be sent to privacy@goodstream.net.

Your privacy choices

GoodStream uses necessary technology for login, security, streaming, and your privacy choice. Optional analytics stays off unless you choose it. See browser technologies.

Privacy preferences

Optional categories are off unless you enable them. You can change these choices at any time.

Policy: Global strict opt-in.

Strict fallback is active because no trusted mapped location was available.

Do Not Track is not treated as a consent signal. Global Privacy Control is honored for advertising and covered sharing choices.

This engineering control records your browser choice. See the current browser-technology disclosure. It is not a claim of universal legal compliance.