Back to home
Legal

Privacy Policy

Last updated: June 27, 2026

StreamBoost is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described here.

1. Information We Collect

Account Information

When you register, we collect your name, email address, and password (stored as a bcrypt hash). We do not store your plaintext password at any time.

Twitch Account Data

When you connect your Twitch account via OAuth, we receive and store your Twitch user ID, username, display name, and profile image URL. We do not receive or store your Twitch password. The OAuth token is used solely to detect when your stream goes live via the Twitch EventSub API.

Stream Session Data

For each stream session, we record the stream title, game category, viewer counts, chatter counts, bot activity logs, and session start/end times. This data powers your live dashboard and historical session analytics.

Payment Information

Payments are processed entirely by Whop. StreamBoost does not store your card number, CVV, or full payment details. We receive a Whop membership ID and transaction records (amount, date, status) for billing management.

Usage Data

We may collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used solely for security monitoring and service improvement.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the StreamBoost Service
  • Detect when your Twitch stream goes live and trigger bot deployment
  • Process payments and manage subscription billing
  • Display your stream performance data in your dashboard
  • Send transactional emails (billing receipts, service alerts)
  • Respond to support requests
  • Detect fraud and enforce our Terms of Service

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

3. Twitch API & OAuth Data

StreamBoost uses the Twitch API in accordance with Twitch's Developer Agreement. The OAuth scopes we request are limited to what is required to detect stream status. We do not access your channel moderator tools, subscriptions, or financial data on Twitch.

You may revoke StreamBoost's access to your Twitch account at any time from your Twitch Connections Settings. Revoking access will disable stream detection but will not cancel your StreamBoost subscription.

4. Cookies & Session Storage

StreamBoost uses cookies and session storage for the following purposes:

  • Authentication — Session cookies to keep you logged in
  • CSRF Protection — Laravel XSRF tokens to prevent cross-site request forgery
  • Preferences — UI preferences such as billing period toggle state

We do not use third-party advertising cookies or tracking pixels.

5. Third-Party Services

We use the following third-party services, each governed by their own privacy policies:

  • Whop — Payment processing. Whop may collect device fingerprints and transaction data for fraud prevention.
  • Twitch API — Stream status detection via EventSub webhooks.
  • Telegram Bot API — Admin notifications for service requests. Only your Twitch username and order details are shared with the Telegram notification system.

6. Data Retention

We retain your account data for as long as your account is active. Stream session logs and bot activity records are retained for up to 12 months for dashboard analytics. Payment transaction records are retained for 7 years as required by applicable financial regulations.

If you request account deletion, we will remove your personal data within 30 days, excluding transaction records required for legal compliance.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Request correction of inaccurate data
  • Deletion — Request deletion of your account and associated data
  • Portability — Request your data in a machine-readable format
  • Objection — Object to processing of your data for specific purposes

To exercise any of these rights, contact us using the email below. We will respond within 30 days.

8. Data Security

We implement industry-standard security measures including HTTPS encryption in transit, bcrypt password hashing, and database access controls. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

In the event of a data breach affecting your personal information, we will notify you via email within 72 hours of becoming aware of the breach.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. We will notify active users of material changes via email.

10. Contact

For any privacy-related questions or data requests, please contact us at:

operations@twitchsaas.io