Privacy Policy
Service: Streameria (streameria.com) · Last updated: September 19, 2026
Streameria is a web application that helps human moderators moderate live chat for streamers who broadcast simultaneously on Twitch and YouTube. It reads live chat from both platforms into a single unified feed and lets an authorized moderator apply moderation actions (ban, timeout, delete a message, or post a broadcast message) on the platform the message originated from.
This policy explains what data we access, why, how we store it, and the choices you have. It applies to everyone who signs in to Streameria with a Twitch and/or Google (YouTube) account.
1. Who we are
Streameria is operated by an independent developer. For any privacy question, data access, or deletion request, contact us at [email protected].
2. Data we access and store
We deliberately collect the minimum needed to operate moderation:
2.1 Account identity (login)
You create a Streameria account by signing in with Google. From your Google profile we store your name, avatar image URL, your email address, and a stable Google account identifier. This identity says who you are in Streameria — it does not grant any moderation access.
2.2 Moderation connections
Separately, you connect the Twitch and/or YouTube accounts you moderate with. For each, we store the platform user/channel ID and display name. These connections are what carry moderation permissions; they are authorized independently from your login, even when the underlying Google account is the same. The OAuth scopes we request are limited to what the product actually uses.
2.3 Authorization tokens
The Google login itself stores no token — it only authenticates you. Tokens are stored only for the moderation connections you add.
When you connect a platform, we store the OAuth refresh token needed to keep your session working. Refresh tokens are encrypted at rest using AES-256-GCM; the encryption key is held as a server-side secret and is never exposed to the client. A short-lived access token may be cached, also encrypted. Tokens are never written to logs.
2.4 Session data
- A server-side session record with creation/expiry timestamps.
- The IP address of the request and a hashed (not raw) user-agent string, used for security and abuse prevention.
Sessions use HttpOnly, Secure, SameSite cookies.
2.5 Live chat data (Twitch and YouTube)
To present the moderation feed, we read live chat messages and the author's public identity (platform ID and display name) in real time. Chat message content is streamed to the connected moderator for display and is not persisted as a chat archive.
2.6 Moderation audit log
Each moderation action you perform is recorded in an append-only audit log so that there is an accountable record of who moderated what. Each entry contains: the platform, the action type, the target user's platform ID and display name, an optional reason, timeout duration (for timeouts), the target message ID (for deletions), the message text (for broadcast messages you send), the request IP, and the result.
3. How we use your data
| Data | Purpose |
|---|---|
| Login identity (Google) | Create and identify your Streameria account (name, avatar, email). |
| Moderation connections | Link the Twitch/YouTube accounts you moderate with. |
| Authorization tokens | Read live chat and perform the moderation actions you request, on your behalf. |
| Session data | Keep you signed in securely and prevent abuse. |
| Live chat data | Display the unified moderation feed in real time. |
| Moderation audit log | Provide an accountable, forensic record of moderation activity. |
4. What we do NOT do
- We do not sell, rent, or trade your data.
- We do not share your data with third parties for advertising or marketing.
- We do not use your data, or any YouTube user data, to train machine-learning or AI models.
- We do not repost, republish, or redistribute chat content.
- We do not build advertising profiles from your data.
5. YouTube API Services
Streameria uses YouTube API Services. By using Streameria, you also agree to the YouTube Terms of Service. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google's handling of your data is governed by the Google Privacy Policy.
You can review and revoke Streameria's access to your Google account at any time via the Google security settings page. You can revoke Twitch access from your Twitch connections settings.
6. Data retention and deletion
- Login identity (name, avatar URL, email, Google account identifier) is stored for as long as your Streameria account exists and is deleted when the account is deleted.
- Authorization tokens are stored until you disconnect the platform or delete your account, after which they are deleted and the underlying OAuth grant is revoked.
- Sessions expire automatically and are removed after expiry or when you sign out.
- Live chat content is not retained beyond real-time delivery.
- Moderation audit log entries are retained for accountability and are not deleted automatically.
To request deletion of your account and associated data, contact [email protected]. We honor verified deletion requests within a reasonable time.
7. Security
We apply defense in depth: encryption of tokens at rest (AES-256-GCM), minimal OAuth scopes, hardened HttpOnly/Secure cookies, an append-only audit log, rate limiting on sensitive routes, a strict Content Security Policy, and structured logging that strips secrets. No method of transmission or storage is perfectly secure, but we work to protect your data in line with industry practices.
8. Children
Streameria is intended for use by streamers and their authorized moderators and is not directed to children under 13 (or the minimum age required in your jurisdiction).
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with an updated "Last updated" date.
10. Contact
Questions or requests: [email protected].
See also our Terms of Service · Streameria home.