Privacy Policy
Effective date: 8 September 2026
OBS Fuse Bridge is a Windows desktop production tool that connects Zoom Meeting SDK participant video to OBS Studio. This policy explains what Zoom-related data the application accesses, how it is used, where it is stored, and how users can revoke or delete it.
1. Zoom data the application accesses
Depending on the connection mode selected by the operator, OBS Fuse Bridge may access the following Zoom data:
- OAuth access and refresh tokens used to maintain an authorized Zoom connection.
- Zoom Access Key (ZAK) when the operator chooses ZAK mode.
- On Behalf Of (OBF) token when the operator chooses OBF mode for a specific meeting.
- Authorized user's Zoom display name so previously authorized Zoom identities can be shown in the local Zoom Identity selector.
- Zoom user ID transiently during identity registration only, to derive a local HMAC identity digest. The raw Zoom user ID is not retained.
- Meeting ID and passcode supplied by the operator for joining a meeting. The passcode is not intentionally logged or persisted by OBS Fuse Bridge.
- Meeting participant metadata needed during an active session for routing, such as participant identifiers, display names, video state, and related meeting status.
- Raw participant video frames after the required Zoom/host meeting-content permission is granted.
2. How the data is used
user:read:zakis used only to obtain the authorized user's ZAK when ZAK mode is selected.user:read:tokenis used only to obtain the authorized user's meeting-scoped OBF token when OBF mode is selected.user:read:useris used to obtain the authorized user'sdisplay_namefor the local Zoom Identity selector.- Meeting participant data and raw video are used only for operator-controlled live production inside OBS Studio.
OBS Fuse Bridge does not sell Zoom data, use it for advertising, or use it to build marketing profiles.
3. Storage and encryption
OBS Fuse Bridge does not use a cloud application database for Zoom user data.
- OAuth access and refresh tokens are stored only on the operator's Windows computer and are encrypted at rest using Windows Data Protection API (DPAPI), bound to the applicable Windows user context.
- The locally retained Zoom Identity metadata—authorized user's display name and a local HMAC identity digest—is also encrypted at rest using Windows DPAPI.
- The raw Zoom user ID used to derive the HMAC identity digest is discarded after the digest is created and is not stored.
- ZAK and OBF values are obtained for the selected connection flow and are not intentionally written to plaintext configuration files.
- Raw participant video is processed transiently in memory and is not intentionally written to video/frame files by OBS Fuse Bridge.
- Meeting passcodes are treated as transient input and are not intentionally logged or persisted.
4. Network and service providers
Zoom provides the Meeting SDK and OAuth/API services. OBS Fuse Bridge uses a Cloudflare Worker at oauth.fusebridge.top as a confidential OAuth relay. The desktop generates PKCE S256 verifier/challenge material and state; the relay securely holds the Zoom confidential Client Secret and performs the authorization-code and refresh exchanges. The Client Secret is not distributed to operator workstations for OAuth token exchange.
Cloudflare Pages hosts the public Privacy Policy, Terms, Support, Documentation, and Add App pages. Raw Zoom meeting media does not traverse the Cloudflare OAuth Worker or the public website.
5. Meeting-content permissions
Access to meeting media remains subject to Zoom and meeting-host controls. OBS Fuse Bridge requests the supported Zoom meeting-content permission needed for raw media. If the permission is unavailable or revoked, the application does not have authority to bypass that decision.
6. Logs
Local diagnostic logs may contain technical state, timestamps, SDK status codes, performance information, and error messages. They are designed not to contain OAuth access/refresh token values, Client Secrets, meeting passcodes, or raw video frames.
7. Retention and deletion
Locally protected OAuth and identity metadata remain on the operator workstation until the authorization is replaced, the application data is removed, or the application is uninstalled/cleaned by the operator. Diagnostic logs remain locally until deleted by the operator.
Users may revoke OBS Fuse Bridge from their Zoom account through Zoom's app/account management controls. Revocation prevents future use of that authorization. For privacy or deletion assistance, use the OBS Fuse Bridge Support page.
8. Data sharing
OBS Fuse Bridge does not intentionally share Zoom meeting media or Zoom profile data with advertising networks, analytics platforms, data brokers, or unrelated third parties. Zoom and Cloudflare process data as platform/infrastructure providers for the functions described above.
9. Children
OBS Fuse Bridge is a professional live-production tool and is not directed to children.
10. Changes to this policy
This policy may be updated when the application's scopes, data handling, infrastructure, or media-processing behavior materially changes. The effective date above identifies the current version.
11. Contact and support
For support, privacy questions, or data-deletion assistance, visit https://fusebridge.top/support.