TeslaStreams

Privacy Policy

DRAFT — outside counsel review required before this page is treated as final. Bracketed fields are placeholders to be filled before launch.

Draft prepared 2026-09-22

This policy describes what TeslaStreams collects, why, and for how long. It exists so you can read it, not so we can hide behind it.

What we collect

Account and pairing identifiers (your email, a device pairing token). If you connect Trakt or Simkl, the OAuth token for that connection — never your Trakt or Simkl password, which we never see. Search and lookup activity against TMDB's where-to-watch data. If you connect Plex or Jellyfin, your own server's connection details, supplied by you. If you grant Tesla Fleet API access (a separate, optional, later-stage feature), vehicle data such as charge state — only with your explicit consent, described in its own section below.

What we never collect

We never collect or store a password to Netflix, Prime Video, Disney+, YouTube, Instagram, Google, or any other third-party service. We do not run an advertising network and do not sell personal information to data brokers.

Legal basis (EU/EEA users)

For users in the EU/EEA, we process personal data on the basis of your consent (for optional connections like Trakt/Simkl/Plex) and our legitimate interest in operating the account and subscription you've signed up for.

California privacy rights (CCPA/CPRA)

California residents have the right to know what personal information we hold, to request deletion, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA/CPRA. To exercise these rights, contact us at the support address on our Trust page.

Retention

Account and pairing identifiers are kept for the life of your account plus 30 days after a deletion request. Trakt/Simkl OAuth tokens are kept only for the life of that connection and revoked immediately on disconnect. Tesla Fleet API tokens, if ever granted, are cached no longer than 30 days and re-verified on that cadence.

Tesla Fleet API vehicle data

If you grant Fleet API access, you are consenting to share vehicle data — such as charge state — under Tesla's own third-party-app terms, which place compliance responsibility for that data on us, not Tesla. We only request this data with your explicit, revocable consent, and only to power features you opted into (such as a real-time charge-session picker). This is a heavier category of data than ordinary account or watch-history information and we treat it that way.

Deleting your data

You can request account deletion at any time from your Account page or by contacting support. We complete deletion within 30 days of your request.

Cookies and consent

Our marketing site uses a small number of cookies necessary for the site to function (such as a session or CSRF cookie) and, for EU/EEA visitors, shows a consent banner before setting anything beyond what's strictly necessary.

Contact

Questions about this policy can be sent to the support address listed on our Trust page.