Privacy Policy
Last updated: July 11, 2026
Draft notice: this page was generated as a starting point and has not been reviewed by a lawyer. Before relying on it for a real, paying userbase, have it reviewed for your jurisdiction (e.g. GDPR if you have EU users, CCPA if you have California users) and business structure.
1. What we collect
Creator accounts — depending on how you sign up:
- Email address and a hashed password (if you sign up with email/password — we never store your plaintext password).
- Kick and/or Twitch account ID and username (if you sign up with or link Kick/Twitch).
- Any API keys or third-party account credentials you choose to add (Pulsoid, RTIRL, your own Stripe donation keys, ElevenLabs) — used only to power the corresponding feature on your own overlay/chat.
- Billing information, handled directly by Stripe — we don't see or store your card details.
Viewers — when you log in to a creator's chat games/wallet page:
- Kick, Twitch, or Discord account ID and username (from whichever platform you log in with).
- Your Credits balance and activity with that specific creator (not shared across creators).
2. How we use it
- To operate your overlay, chat bot, admin dashboard, and (for viewers) chat games/wallet.
- To process premium subscription billing and, where you've connected your own Stripe account, donations.
- To communicate with you about your account (e.g. billing issues, support requests you send us).
- To detect and prevent abuse (e.g. rate-limiting signups, fraud checks on payments).
We do not sell your personal data to third parties.
3. Third-party services
Depending on which features you use, your data may pass through:
- Supabase — our database and backend infrastructure provider.
- Vercel — hosts the application.
- Stripe — payment processing for subscriptions and (via your own Stripe account) donations.
- Kick / Twitch / Discord — OAuth login and chat integration, if you connect them.
- Pulsoid, RTIRL, ElevenLabs — only if you provide your own API key for heart rate, live location, or text-to-speech.
Each of these has its own privacy policy governing how they handle data once it reaches them.
4. Data retention
We retain your account data for as long as your account is active. If you delete your account (available any time from your admin Account page), your creator record, overlay settings, and associated chat/wallet data are deleted. Some records (e.g. billing history) may be retained where required for legal or tax compliance.
5. Your rights
You can access, correct, or delete most of your own data directly from your admin dashboard. To request anything not self-serviceable (e.g. a full data export, or deletion of viewer data tied to a Kick/Twitch/Discord account you no longer control), contact us using the details below. Depending on where you live, you may have additional rights under laws like GDPR or CCPA.
6. Cookies and sessions
We use essential cookies to keep you signed in (an HTTP-only session cookie) — these aren't used for advertising or cross-site tracking. We don't currently use third-party analytics or ad-tracking cookies.
7. Security
Passwords are hashed, not stored in plaintext. Sessions are signed and HTTP-only. Access to the underlying database is restricted to the platform's own backend. No system is perfectly secure, and we can't guarantee absolute security of data transmitted to or stored by the platform.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about this policy, or a data request? Reach out via the support option in your admin dashboard, or contact us directly at support@tazo.wtf (update this address before publishing).