Your Privacy Matters: We are committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your data.
1. Introduction
StreamHex ("we", "our", or "us") values your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Discord bot and dashboard, which provides Twitch stream alerts, YouTube video notifications, and reaction role management for Discord servers. The service is operated from Germany and is subject to the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Information We Collect
When you use StreamHex, we collect the following types of information:
Information from Discord OAuth:
- Discord User ID: Used for unique identification and authentication
- Discord Username: Displayed in your dashboard profile
- Discord Avatar: Used for profile display purposes
- Discord Email: If provided through Discord OAuth (optional)
- Discord Server List: Servers where you hold Administrator or Manage Server permissions, used to populate your server selection
Streamer Alert Configuration:
- Twitch channel names you wish to monitor
- Discord server IDs and channel IDs for notification delivery
- Discord Webhook URLs (Premium users only)
- Custom notification messages, colors, and embed settings
YouTube Alert Configuration:
- YouTube channel IDs and handles you wish to monitor
- Discord server IDs and channel IDs for notification delivery
- Discord Webhook URLs (Premium users only)
- Custom notification messages and embed settings
- A log of previously posted notifications (message content and timestamps) for display in the dashboard history
Reaction Role Configuration:
- Discord server IDs and channel IDs for embed placement
- Role assignments and emoji mappings configured by server administrators
- Custom embed content (title, description, color) created by you
Subscription and Premium Status:
- Your Premium subscription status as provided by Discord's entitlement system (e.g., active subscription, expiry date)
- We do not receive or store any payment details — all billing is handled exclusively by Discord
Automatically Collected Information:
- IP address (for security and abuse prevention)
- Browser type and version
- Access times and dates
- Session data stored server-side for authentication
3. How We Use Your Information
We use the collected information solely for the following purposes:
- Service Delivery: To monitor Twitch streams and YouTube channels, deliver notifications to Discord, and manage reaction role embeds on your servers
- Authentication: To verify your identity via Discord OAuth and maintain your login session
- Premium Verification: To check your subscription status via Discord's entitlement system and unlock Premium features accordingly
- Dashboard Functionality: To display your configured alerts, history, and server settings in the web dashboard
- Communication: To send important service updates or security alerts where necessary
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Legal Compliance: To comply with applicable laws, in particular the GDPR and BDSG
We do not use your data for advertising, profiling, or sale to third parties.
4. Third-Party Services
StreamHex integrates with the following third-party services to deliver its functionality:
- Discord: For user authentication (OAuth2), sending notifications and embeds, managing reaction roles, and processing Premium subscription payments. Please review Discord's Privacy Policy. Discord acts as an independent data controller for all payment and billing data.
- Twitch: For querying live stream status of configured channels. Please review Twitch's Privacy Policy. Only publicly available stream data is accessed.
- YouTube (Google LLC): For querying public video and channel data of configured YouTube channels via the YouTube Data API v3. Please review Google's Privacy Policy. Only publicly available channel and video data is accessed; no private account data is requested or stored.
We are not responsible for the privacy practices of these third-party services. We only query publicly available data from Twitch and YouTube — no user credentials or private data from those platforms are ever collected.
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: Data is encrypted in transit using SSL/TLS protocols
- Secure Storage: Personal data is stored in secure databases with restricted access
- Access Controls: Only authorized personnel have access to user data
- Regular Audits: We conduct regular security audits and updates
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
6. Data Retention and Account Deletion
We retain your personal information for as long as necessary to provide our services. Specifically:
- Active Accounts: All data is retained while your account is active
- Account Deletion: When you delete your account via the dashboard, the following data is deleted immediately and permanently: your user profile, all streamer alert configurations you created, all YouTube alert configurations you created, and all reaction role embeds you created. There is no recovery after deletion.
- Legal Requirements: Certain data (e.g., access logs) may be retained for up to 30 days after account deletion for security and abuse prevention purposes, after which it is permanently removed
7. Cookies and Local Storage
We use browser Local Storage to enhance your experience:
- Authentication: To maintain your login session
- Preferences: To remember your settings and preferences
- Performance: To improve loading times and user experience
You can clear Local Storage through your browser settings, but this may affect functionality.
8. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- With Your Consent: When you explicitly authorize us to share specific information
- Service Providers: With trusted third-party services that help us operate (e.g., hosting providers), under strict confidentiality agreements
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Protection of Rights: To protect our rights, property, or safety, or that of our users
9. Your Privacy Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and associated data
- Portability: Request a copy of your data in a machine-readable format
- Withdrawal of Consent: Withdraw consent for data processing at any time
- Objection: Object to certain types of data processing
To exercise these rights, please disconnect StreamHex from your Discord account or contact our support team.
10. Children's Privacy
StreamHex is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete such information promptly.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using StreamHex, you consent to the transfer of your information to these countries.
12. GDPR Compliance (EU/EEA Users)
StreamHex is operated from Germany and fully subject to the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The following applies to all users:
- Legal basis for processing: Art. 6(1)(b) GDPR (performance of a contract / provision of the service), Art. 6(1)(f) GDPR (legitimate interests, e.g. security)
- Right to access (Art. 15 GDPR): You can request a copy of your personal data at any time
- Right to rectification (Art. 16 GDPR): You can request correction of inaccurate data
- Right to erasure (Art. 17 GDPR): You can delete your account and all associated data directly via the dashboard at any time
- Right to restriction (Art. 18 GDPR): You may request that we restrict processing of your data in certain circumstances
- Right to data portability (Art. 20 GDPR): You may request your data in a machine-readable format by contacting us
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests
- Right to lodge a complaint: You have the right to lodge a complaint with the responsible supervisory authority. The competent authority for Germany is the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) or the data protection authority of your federal state (Landesbeauftragter für den Datenschutz).
To exercise any of these rights, please contact us at contact@streamhex.com. We will respond within the statutory period of one month (Art. 12(3) GDPR).
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:
- We will update the "Last updated" date at the top of this policy
- For material changes, we will notify you via email or Discord notification
- Continued use of the service after changes constitutes acceptance of the updated policy
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through:
- Our Discord support server
- Email support channels
- The support section in your dashboard
- Email: contact@streamhex.com
We will respond to your inquiry within 30 days.
Important: By using StreamHex, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.