Privacy policy
Your viewing habits are yours.
Effective and last updated:
BSCCBL (also called “Basic Cable,” “we,” “us,” or “our”) turns public videos into a personal, scheduled television dial. This policy explains what information the service handles, why it is needed, who helps us process it, and how you can control it.
1. Scope
This policy applies to the BSCCBL website, web application, device-pairing experience, and related television applications that use the same BSCCBL account and service. It does not replace the privacy policies of YouTube, Stripe, your browser, device maker, or other services you choose to use with BSCCBL.
2. Information we collect
Account and contact information
- Your email address, display name, and an optional profile image.
- One-time sign-in and account-action records. Secret tokens are stored as cryptographic hashes, not in readable form.
- Transactional email delivery status for sign-in links, account actions, and important service messages.
- If a signed-in viewer invites someone to try BSCCBL, the recipient email address, inviter account identity, invitation creation and delivery status, conversion status, abuse-prevention and cooldown state, and opt-out status needed to send and protect the invitation.
Your dial and viewing preferences
- Channels you create or adopt, including names, descriptions, search ideas, exclusions, freshness choices, and desired program lengths.
- Your channel lineup and schedule, last-tuned channel, likes, dislikes, captions choice, and similar playback preferences.
- Messages you choose to send to Programming Desk or its Help flow, and the channel definitions produced from channel conversations.
- Product feedback you explicitly submit, including its category, message, contact preference, app surface and screen, optional current channel or airing reference, submission time, and application version.
Device, session, and operations information
- A device identifier, optional shared device label, device owner if one is assigned, pairing status, last-seen time, and account-specific last channel for each linked device.
- The accounts linked to a device, whether each needs a fresh sign-in, which account is active, recent account-selection order, and a version used to prevent an old account context from changing another account.
- Secure account and device-session cookies, plus browser storage for device-local choices such as mute state and account-scoped choices such as resume and recall. The specific technologies and their lifetimes are described in Section 7.
- If a device owner invites another viewer, the recipient email, selected target devices, invitation status, and acceptance time.
- Internet Protocol address, browser or device type, request time, request identifier, error details, and security/rate-limit signals needed to run and protect the service.
- When approximate device geography is enabled, Cloudflare-derived latitude, longitude, country, region, city, and postal code for a signed-in logical device. We keep the first and most recent valid observations, not a continuous location history.
Approximate device geography
Approximate device geography comes from Cloudflare's estimate of the Internet Protocol address that reaches the service. It is not GPS and may identify a regional network point rather than the device's physical position, especially when you use a VPN, mobile connection, or Internet provider whose traffic exits somewhere else. BSCCBL does not ask your browser, phone, or television for location permission and does not track location in the background.
First-party activity information
We keep a limited record of whether core journeys start and finish. The only activity
event names are app_session_started, onboarding_finished,
channel_tune_requested, channel_tune_resolved,
playback_engaged, programming_desk_opened,
programming_desk_finished, channel_store_opened, and
channel_store_finished. The server associates these events with internal
account and device identifiers, optional internal BSCCBL channel or airing references,
and bounded surface, timing, and outcome information.
This activity dataset does not contain Internet Protocol addresses, email addresses, free-form text, YouTube video or channel IDs, video titles, search terms, Programming Desk or Help messages, feedback text, keystrokes, or arbitrary URLs. Network and security processing described above is separate from this activity dataset.
Billing information
Stripe collects and processes payment-card and wallet details inside Stripe-hosted payment fields. BSCCBL does not receive or store full card numbers. We do store Stripe customer and subscription identifiers, subscription status, invoice/payment events, and the number of paid channel slots needed to operate your subscription.
YouTube information
We store public video and channel metadata needed to build a guide, such as YouTube video IDs, titles, thumbnails, source channel names and IDs, publication dates, durations, and whether a video can be embedded. We also store which public videos have been scheduled on a BSCCBL channel. This is public catalog data, not private data from your YouTube account.
3. How we use information
- Create your account, authenticate sign-ins, pair devices, maintain the Linked Accounts roster, switch the active account, and keep each account's dial available across supported devices.
- Build, schedule, refresh, and play the channels you request.
- Use likes and dislikes to improve future rotation within the affected channel.
- Calculate paid channel slots, process subscriptions, reconcile invoices, and prevent duplicate billing actions.
- Send requested transactional email, including one-time product referrals, answer support requests, detect abuse, troubleshoot failures, and monitor reliability.
- Review product feedback, respond when you permit contact, and improve the service. The product-feedback form is deterministic and does not send its contents to Anthropic.
- Measure whether core app, onboarding, tuning, playback, Programming Desk, and Channel Store journeys start and finish so we can improve reliability and usability.
- When approximate device geography is enabled, produce internal aggregate maps of where BSCCBL devices are being used so we can understand product adoption. We do not use this information for advertising, pricing, billing, content access, or account enforcement.
- Comply with law and enforce our Terms of Service.
We do not sell or rent personal information, and we do not use your Programming Desk conversation to build advertising profiles for other companies.
4. Linked Accounts on shared devices
A browser profile or installed app is treated as one logical device. More than one independent BSCCBL account may be linked to it. The account dropdown changes which account is active, but linking does not combine accounts. Channels, schedules, viewing history, Programming Desk context, billing, checkout, and account preferences remain separate. The device's chosen name is shared across its Linked Accounts.
A device owner may send an email-bound invitation to add the recipient to one or more devices. Accepting an invitation adds the recipient to those rosters but does not switch what any target is currently watching. Accepted viewers remove only themselves. If an owner removes their own membership, ownership is left empty rather than silently given to another viewer.
Signing out and unlinking are different. Signing out requires fresh authentication before that account can be used again on the device, but leaves it listed. Unlinking removes that account from the device's roster without deleting the account elsewhere. Account deletion remains a separate, email-confirmed action.
Product referrals are separate
Invite Someone sends a one-time invitation to create an independent BSCCBL account. It does not link accounts, share channels or billing, or add the recipient to any of the inviter's devices. The recipient is not added to a newsletter or marketing list, and referral messages do not use open pixels or tracked links. Each message includes a link that lets the recipient stop future BSCCBL product referrals to that address.
Before sending, we tell the inviter that their BSCCBL display name and account email will be shared with the recipient. The message comes from a fixed, authenticated BSCCBL sender. Our server, rather than the browser or app, derives the Reply-To address from the signed-in inviter's verified account email, so a recipient who replies sends that reply directly to the inviter. We do not let an inviter supply an arbitrary From or Reply-To address.
5. YouTube API Services and playback
BSCCBL uses YouTube API Services to search and retrieve public metadata and the YouTube IFrame Player API to play video. Your use of video features is also subject to the YouTube Terms of Service. Google explains its data practices in the Google Privacy Policy. The official player may process information and show advertising according to Google and YouTube settings, even though you signed in to BSCCBL with email rather than Google.
When the official player loads, Google and YouTube may receive your Internet Protocol address, browser or device information, the page and playback context, player events, and cookies or similar identifiers that they control. They use those signals to deliver the player, display the video title and thumbnail, determine playability, prevent fraud and abuse, serve advertising when applicable, and measure playback. BSCCBL does not interfere with the context signals or player interface Google uses for policy enforcement and view verification.
BSCCBL refreshes or deletes stored YouTube API metadata within 30 calendar days. BSCCBL currently uses only an application API key for public catalog data and does not request Google OAuth permission. You can review or revoke services that do have Google-account access in Google’s security settings; because BSCCBL does not request that access, it ordinarily will not appear there.
6. How we process and share information
Inside BSCCBL
Authorized BSCCBL personnel and contractors may access only the information reasonably needed to provide customer support, investigate security or abuse, reconcile billing, operate and troubleshoot the service, review product feedback, or meet legal duties. Access is limited by role and protected by technical and organizational safeguards.
Service providers and independent platforms
We disclose only the categories of information reasonably needed for the recipient to perform the purpose described below. These recipients do not receive permission from BSCCBL to use the information for their own unrelated advertising.
We may also disclose information if reasonably necessary to comply with law, protect a person from harm, investigate fraud or abuse, or complete a merger, financing, acquisition, or sale after requiring the recipient to honor applicable privacy obligations.
We do not sell or rent personal information. We do not share personal information with data brokers or permit the providers above to use BSCCBL account, channel, device, or conversation information for their own unrelated advertising.
7. Cookies and device storage
BSCCBL and the services embedded in or protecting BSCCBL may store, access, or recognize information on your browser or device through cookies, local storage, session storage, network identifiers, pixels, and similar technology. BSCCBL uses these technologies as follows:
- Essential BSCCBL cookies: signed, secure, HTTP-only cookies authenticate an ordinary account session for up to 120 days. On a device using Linked Accounts, a separate signed, secure, HTTP-only device-session cookie may remain for up to one year so the device can keep its account roster and select grants that are still valid. These cookies are not available to client-side scripts and are not used for cross-site advertising.
- Local storage: BSCCBL stores a random logical-device identifier; TV-mode and mute choices; account-scoped last and previous channel choices; and short-lived pairing-code, checkout-return, or device-invitation handoff state. These values support continuity on that browser or installed app and are not authentication authority by themselves.
- Session storage: BSCCBL keeps short-lived tuning-transition, pairing-transition, and account-scoped resume state for the current browser tab or app session. It is an interface and playback-continuity aid, not an authentication credential.
- Activity queue: pending first-party activity events exist only in application memory while the page or app process is running. BSCCBL does not place this queue in cookies, local storage, or session storage and does not use an external analytics SDK.
- YouTube / Google: the official embedded player may set, access, or recognize Google or YouTube cookies and similar device, network, page, and playback-context signals. Google and YouTube use them to provide and customize the player, determine playability, prevent fraud and abuse, serve advertising when applicable, enforce policy, and measure playback and views under their own terms and privacy policy.
- Stripe: Stripe-hosted checkout and payment fields may set, access, or recognize cookies and similar device, payment, wallet, and fraud-prevention signals when you open checkout. Stripe uses them to present eligible payment methods, protect payment entry, process payment, and prevent fraud under Stripe's privacy terms.
- Cloudflare: Cloudflare may recognize Internet Protocol, request, browser, device, and security signals at the network edge to deliver and protect BSCCBL and to produce aggregate traffic measurement. When approximate device geography is enabled, trusted Cloudflare headers supply an Internet Protocol-derived location estimate to BSCCBL. This does not use a browser location permission or a Cloudflare analytics cookie set by BSCCBL's page code.
You can block or clear these technologies in your browser or device settings. Blocking essential cookies can prevent sign-in, account switching, device linking, and checkout return. Clearing local or session storage resets device identity and local preferences and can interrupt a pending pairing, invitation, checkout return, or playback transition. Blocking technology required by YouTube, Stripe, or Cloudflare can make embedded playback, payment methods, or security checks unavailable. Clearing storage does not itself delete information retained in your BSCCBL account; use the account-deletion process in Section 10 for that purpose.
8. Programming Desk and voice input
When you send a Programming Desk channel message, BSCCBL sends that message, recent conversation context, and summaries of your existing channels to Anthropic so the assistant can answer and propose a channel. A free-form Help question sends only the bounded Help conversation, selected Help topic, and active device-surface category; Help has no tool that can change channels, accounts, devices, or billing. BSCCBL does not maintain a separate server-side table of raw chat transcripts, but it stores the channel definition you approve. Anthropic may process and retain requests under its service terms and our provider agreement.
If you use dictation in your device's keyboard or operating system, that provider may process audio and return text to the focused field. BSCCBL has no separate microphone control and receives the text you choose to submit, not the microphone audio. Your browser or device provider's privacy terms apply to its dictation feature.
9. Product feedback
Send Feedback is separate from Programming Desk and Help. You first choose a category, write and review your message, decide whether we may contact you, and explicitly submit it. BSCCBL associates the submission with your signed-in account and current logical device and may attach the app surface, screen, version, and optional current channel or airing so we can reproduce the issue. The feedback form does not use an AI or change channels, devices, billing, or account state. An owner notification may be attempted after storage; a notification failure does not discard or duplicate your feedback.
10. Retention and deletion
- Account data: kept while your account is active and removed when you complete account deletion, subject to limited legal, security, backup, and transaction-record obligations.
- YouTube metadata: refreshed or deleted within 30 calendar days.
- Sign-in records: expired one-time links are cleaned after 30 days; expired or revoked session records are cleaned after a short safety window.
- Product referrals: invitation links expire after 14 days. Readable invitation records are normally removed within 30 days after link expiry or a failed delivery; bounded conversion and suppression records are removed no later than 90 days under the ordinary cleanup schedule. We may retain a one-way hash of an opted-out address as needed to honor its referral suppression without keeping the readable address.
- Pairing and security records: expired pairing records and short-lived rate-limit records are routinely removed.
- Product feedback: kept for product review for up to 24 months and removed sooner when you complete account deletion.
- First-party activity events: raw events are kept for no more than 90 days and removed sooner when you complete account deletion.
- Approximate device geography: one record per logical device preserves the first valid location and refreshes only the most recent location, no more often than once every seven days. We do not keep each intervening observation. The record is removed through the associated device and account-deletion lifecycle, subject to limited backup obligations.
- Stripe events: detailed webhook payloads are redacted after 90 days; limited event identifiers and accounting records may remain to prevent duplicate processing and meet financial obligations.
- Operational logs and backups: retained for bounded operational, security, and disaster-recovery periods and then expired under our cloud settings.
To delete your account, open Account, choose Delete Account, or ask the Programming Desk to delete it. We send a single-use email confirmation before executing deletion. Confirmed deletion removes your BSCCBL account, channels, schedules, preferences, sessions, and devices, and deletes your Stripe customer so active BSCCBL billing is canceled. Data already present in protected backups may persist until those backups naturally expire and is not restored for ordinary use.
To request account deletion without access to the app, email [email protected]. Identify the BSCCBL account you want deleted. We will verify account ownership by email before completing the request.
11. Your choices and rights
- Edit your display name, switch among Linked Accounts, sign out an account, unlink your own account from a device, remove linked devices, change channel definitions, and remove channels inside the app.
- Use playback controls to change mute, captions, likes, and dislikes. Some device-local settings are stored only in that browser.
- Block or clear cookies and browser storage through your browser, subject to the feature effects described in Section 7.
- Request access, correction, or deletion of personal information by emailing us. We may need to verify the request before acting.
- Use the link in a product referral email to stop future BSCCBL product referrals to that address.
Depending on where you live, local law may provide additional rights concerning access, correction, deletion, portability, restriction, objection, or appeal. We will honor applicable rights and will not discriminate against you for exercising them.
12. Security and children
We use encrypted connections, restricted cloud access, hashed sign-in secrets, secure cookies, provider-webhook verification, rate limits, log redaction, backups, and monitoring. No security measure is perfect, so please protect access to your email account and tell us if you believe your BSCCBL account has been compromised.
BSCCBL is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child provided information without appropriate consent, contact us so we can investigate and delete it.
13. Changes and contact
We may update this policy as the service changes. We will change the date above and provide additional notice when required by law or when a change materially affects how we use personal information.
Privacy questions or requests
Email [email protected].