Privacy Policy

Effective Date: February 18, 2026

Midstream Studio, Inc. ("Midstream," "we," "us," or "our") operates the Midstream platform at midstream.studio. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

1. Information We Collect

Account Information

When you sign up for Midstream, we collect information from your GitHub account through GitHub OAuth, including:

  • Your GitHub username and display name
  • Your email address
  • Your GitHub profile avatar

Repository and Source Code Access

To provide our services, Midstream temporarily accesses your source code repositories. Specifically:

  • During instance deploy, our Sandbox service clones your repository to execute Playwright tests up to a designated scene. This clone is temporary and exists only for the lifetime of the instance machine.
  • We do not permanently store your source code. Once an instance machine is shut down, the cloned repository is deleted.
  • We store capture artifacts such as screenshots and accessibility snapshots generated during test execution. Each capture records the state of your application at one scene in your tests, and we store it so that scene can be served as a live instance.

Usage Data

We collect information about how you interact with our platform, including:

  • Pages visited and features used
  • Captures created and instances viewed
  • Browser type, operating system, and device information
  • IP address and approximate location

CI/CD Integration Data

When Midstream runs as part of your CI/CD pipeline, we collect:

  • Capture metadata (names, associated pull requests, test file paths)
  • A screenshot image for each capture
  • Pull request identifiers for linking instances to code changes

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Midstream platform
  • Generate and serve interactive instances from your test captures
  • Authenticate your identity and manage your account
  • Post comments on your pull requests with instance links
  • Improve and optimize our services
  • Communicate with you about your account and service updates
  • Detect, prevent, and address technical issues and security threats

3. Data Storage and Security

  • Database: Account and capture metadata are stored in a PostgreSQL database hosted on Neon.
  • File Storage: Screenshots and artifacts are stored in S3-compatible storage (Tigris).
  • Source Code: Repository clones exist only on ephemeral instance machines and are not retained after the machine is terminated.
  • Encryption: Data is encrypted in transit using TLS. Data at rest is encrypted by our infrastructure providers.

We implement industry-standard security measures to protect your data. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

4. Third-Party Services

We use the following third-party services to operate our platform:

| Service | Purpose | |---------|---------| | GitHub | Authentication, repository access, pull request integration | | Vercel | Hosting for the web dashboard | | Fly.io | Hosting for the router and instance sandbox infrastructure | | Neon | PostgreSQL database hosting | | Tigris | S3-compatible file and artifact storage | | PostHog | Product analytics | | Axiom | Application logging and monitoring | | Inngest | Background job processing |

Each third-party service is governed by its own privacy policy. We recommend reviewing their policies for details on how they handle your data.

5. Cookies and Tracking

Midstream uses cookies for:

  • Session Management: To keep you signed in and maintain your session state.
  • Analytics: We use PostHog to understand how our platform is used. PostHog may set cookies to distinguish unique users and sessions.

You can control cookie behavior through your browser settings. Disabling cookies may limit your ability to use certain features of the platform.

6. Data Retention

  • Account Data: Retained for the duration of your account. You may request deletion at any time.
  • Capture Artifacts: Screenshots and metadata are retained as long as the associated repository and workspace remain active on Midstream.
  • Source Code: Not retained. Repository clones are ephemeral and deleted when instance machines are terminated.
  • Analytics Data: Retained in accordance with our analytics provider's policies.

7. Data Sharing

We do not sell your personal information. We may share your data only in the following circumstances:

  • With your consent: When you explicitly authorize us to share information.
  • Service Providers: With third-party vendors who assist in operating our platform, subject to confidentiality obligations.
  • Legal Requirements: When required by law, regulation, or legal process.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing of your data
  • Data portability
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at privacy@midstream.studio.

9. Children's Privacy

Midstream is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Effective Date" above.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: privacy@midstream.studio