Legal
Privacy Policy
Effective and last updated: 1 October 2026
This policy explains what information StreamChum collects, why we use it, when we share it, and the choices available to you.
1. Who we are
StreamChum provides tools for combining and managing livestream chats, overlays, moderation, and related streaming features at streamchum.com.
Across StreamChum’s legal pages, the Operator (also “StreamChum,” “we,” “us,” and, for the Stream Deck plugin, the “Maker”) is:
Michael Way
trading as StreamChum
51 Wareham Road
Corfe Mullen
Dorset
United Kingdom
Contact for privacy and legal requests: [email protected].
2. Information we collect
- Account information: your email address, display name, encrypted password credentials, workspace membership, role, account preferences, whether you opted in to the StreamChum newsletter, and whether you receive stream recap emails.
- Billing information: when you purchase or manage a paid plan, we (and our payment provider) process billing contact details, plan and subscription status, invoices, tax/VAT information where required, and payment outcome records. Full card numbers are handled by Stripe, not stored by StreamChum.
- Connected-platform information: OAuth tokens and account/channel identifiers from services you connect, including Twitch, YouTube/Google, and Kick; for Discord, the installed server and connecting-user identifiers (Discord user OAuth tokens are not retained after connect).
- Livestream data: chat messages, usernames, profile images, badges, moderation events, and stream metadata made available through connected chat platforms (Twitch, YouTube, and Kick). StreamChum does not read Discord server chat.
- Phone camera and microphone: when you go live from the StreamChum phone app, the app uses this phone’s camera and microphone only after you allow it. Video and audio are encoded on the phone and sent directly to the Twitch, YouTube, or Kick ingest for the one channel you choose. StreamChum does not receive or store that recording. We do send the phone the ingest address and stream key for that channel so it can publish. You can also send that camera and microphone to StreamChum Studio on the same Wi-Fi. That video goes from the phone to Studio on your local network. StreamChum’s servers only pass the local address, port, and stream key so the phone can find Studio. They do not receive or store that recording. The camera and microphone are not used for chat, Deck, Produce, or Home.
- Configuration and content: overlays, widgets, commands, moderation settings, staff invitations, Discord announcement settings, and other content you configure.
- Device integrations & Play Host: when you connect software such as the StreamChum Stream Deck plugin or StreamChum Play Host, the integration stores the StreamChum API address, a revocable device token, and host configuration. For StreamChum Play sessions, WebRTC signaling data and remote controller input events (button presses and analog stick positions) are relayed directly between authorized viewer browsers and your host device to emulate virtual controllers. We do not inspect or record local gameplay screen capture streams.
- Studio diagnostics (opt-in): if you choose Send diagnostics in StreamChum Studio Settings, About, we receive that PC's local support.log (encoder, fps, skips, drops, GPU/VRAM, and related performance lines), a short hardware snapshot (OS, GPU, encoder, canvas), and any note you type. Studio must be signed in. We do not upload these logs automatically.
- Play tournament players: if you connect Twitch on a public Play tournament page without creating a StreamChum account, we store your Twitch user id, login, display name, and profile image so we can identify you on that event. See Play tournament players below.
- Technical information: session cookies (including a Play-player session cookie if you connect Twitch on a tournament page), IP address, browser and device details, request logs, errors, and security events.
- Usage analytics: aggregated and individual measurement data about how visitors and signed-in users use StreamChum’s marketing site and control panel (for example pages viewed, events, referrers, and approximate location), collected via Google Analytics as described below.
- Control panel session replay: after you sign in to the StreamChum control panel (including Live Center), we record the session with LogRocket so we can troubleshoot faults. That recording can include pages you open, clicks, on-screen text, console errors, and network requests. It does not run on the public marketing site, and it does not run before you are signed in.
3. How we use information
We use information to provide and secure StreamChum, authenticate users and device integrations, operate interactive StreamChum Play sessions (including tournament registration, public brackets, and virtual gamepad relaying), run Actions expressly selected by users, connect requested streaming platforms, display and moderate chat, operate overlays and widgets, run optional AI-assisted features you use (see below), post streamer-configured announcements and slash-command replies to Discord, process paid subscriptions and related billing when you purchase, understand how the product and marketing site are used so we can improve them, troubleshoot faults (including opt-in Studio diagnostics you send), communicate service messages (including billing notices), send optional product news if you opt in, prevent abuse, and comply with law. We do not sell personal information.
4. Google and YouTube data
StreamChum uses YouTube API Services. When you connect YouTube or sign in with Google, StreamChum uses Google APIs and YouTube API Services to access only the information and permissions you approve. This may include your Google identity, YouTube channel information, broadcasts, live chat messages and author details, moderation actions, and paid or membership events. We use this data only to provide the StreamChum features you request, such as combining and displaying your live chat, running overlays and commands, moderating chat, and showing stream status.
How we handle YouTube data: we access YouTube data through the YouTube Data API, store connection tokens in encrypted form, keep only recent chat, event, and viewer data needed to provide configured features, and do not sell it or use it for advertising. We do not use YouTube data to build user profiles for purposes unrelated to the features you request, and we do not transfer it to third parties except as needed to run the service at your direction.
By using StreamChum’s YouTube features, you also agree to the YouTube Terms of Service. StreamChum’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Information handled through Google and YouTube API Services is also subject to the Google Privacy Policy.
You can revoke StreamChum’s access to your Google and YouTube data at any time through the Google security settings page (also available at Google Account permissions). You can also disconnect YouTube inside StreamChum, which sends Google a request to revoke the OAuth authorization and deletes the stored credentials for that connection. To request deletion of YouTube data StreamChum has stored, see “Retention and deletion” below or email us at the address in the Contact section.
5. Discord data
When you connect Discord, StreamChum installs its hosted bot into a Discord server you choose and uses Discord’s APIs so you can post streamer-configured timers and event announcements to channels you select, and so Discord users can run StreamChum slash commands (for example /live, /schedule, /recent, /recap, and /streamchum admin tools). Public command replies are visible in the channel. Admin /streamchum replies are ephemeral (visible only to the person who ran the command). Adding the bot to a server, including from Discord’s App Directory, does not by itself connect a StreamChum workspace. Slash commands in an unlinked server reply with a login link and do not read Discord chat.
What we access: with your approval we request Discord OAuth scopes to install the bot and register slash commands (bot, applications.commands) and to identify who connected the workspace (identify). The bot asks only for permission to view channels, send messages, and embed links. We do not request privileged Message Content access, read Discord channel history or live chat, scrape member lists, send direct messages, or moderate Discord servers.
What we store: the Discord server (guild) id and name where the bot was installed, the connecting Discord user’s id and username/display name, connection timestamp, and your StreamChum Discord settings (such as default channel id and social-links text). Outbound posts use StreamChum’s shared bot token. We do not retain Discord user OAuth access or refresh tokens after the one-time connect handshake.
How we use Discord data: only to provide the Discord features you configure, map slash-command requests to your workspace, and secure the connection. We do not sell Discord API data, use it for advertising, profile Discord users beyond operating these features, mine or scrape Discord, or use Discord message content to train AI models.
Your use of Discord remains subject to Discord’s terms and policies, including the Discord Terms of Service, Discord Privacy Policy, and Discord’s developer terms for applications that use Discord’s APIs. You can disconnect Discord inside StreamChum (which removes the stored linkage for that workspace) and remove the StreamChum bot from your Discord server. To request deletion of Discord-related data StreamChum has stored, see “Retention and deletion” below or email us at the address in the Contact section.
6. Play tournament players
Some StreamChum Play events are public tournaments. Players open a link such as a /play/t/… page and may connect Twitch so the host can show a real name and avatar on the roster and bracket. That connect is not a StreamChum account and is separate from a streamer connecting Twitch as a channel destination in Settings.
What we collect from Twitch: with your approval we use Twitch login only to identify you (Twitch user id, login, display name, and profile image). We do not request extra Twitch scopes for this flow, we do not receive your Twitch email, and we do not keep a Twitch access token after the handshake that reads that identity.
What we store and show: that identity in a Play player record, plus a session so you stay signed in on tournament pages (currently up to 90 days, or until you choose Log out). Your display name and profile image are shown to the host and to anyone with the tournament link (public roster, teams, and bracket). We use this so you can register, withdraw, and join a match when it is your turn.
How we use it: only to operate that Play event and to secure the player session. We do not sell this data, use it for advertising, or use it to train AI models. Your use of Twitch remains subject to Twitch’s terms and privacy policy. You can log out on the tournament page. To request deletion of a Play player record StreamChum has stored, see “Retention and deletion” below or email us at the address in the Contact section.
7. Artificial intelligence features
Some StreamChum features use third-party AI models (currently OpenAI, Google AI / Gemini, ElevenLabs, and AssemblyAI) to generate outputs for you or to transcribe speech. Which provider handles a request depends on the feature and the model selected for that feature. Depending on what you use, this may include:
- Viewer briefs: recent chat messages, display names, and related chatter context from connected platforms, so we can produce short coaching cards for the streamer or staff.
- AI overlay / widget generation: the prompts, settings, and optional reference images you provide, so we can generate widget code or assets.
- OBS setup assistance: your prompts, OBS scene/layout information exposed through the StreamChum OBS integration, and any reference images you attach, so we can propose or apply layout changes.
- Spoken audio, sound effects, and music: text you type (or that an overlay asks to speak) so ElevenLabs can synthesize voice, sound effects, and longer music tracks, or Google Lyria can synthesize music for scenes and widgets.
- Live captions: when you turn transcription on for a microphone in StreamChum Studio, microphone audio from Studio is sent directly from your computer to AssemblyAI for speech-to-text. StreamChum does not receive or store that recording. Only the resulting transcript text is sent to StreamChum so we can show captions on an overlay you add and match keyword alerts you configured. Transcription uses microphone capture only, not game, desktop, or overlay audio. The feature is off until you enable it on a microphone.
We send only what is needed for the feature you requested. AI outputs can be incomplete, outdated, or wrong, treat them as suggestions and review before acting on them in a live broadcast or public channel. We do not sell your content, and we do not use your StreamChum content to train StreamChum’s own models. Under the providers’ current paid/API terms, API inputs and outputs are generally not used to train or improve those providers’ models by default (unless an organisation explicitly opts in). Providers may still retain limited data for abuse monitoring or as otherwise described in their policies. OpenAI, Google, ElevenLabs, and AssemblyAI process data under their own terms and privacy policies as our processors for these features. Google AI used for model inference is separate from the YouTube/Google account connection described in “Google and YouTube data” above.
You can limit AI use by not enabling or not using those features. Disconnecting a platform stops new chat from that platform being used for viewer briefs. Turn off transcription on the microphone in Studio to stop sending microphone audio to AssemblyAI. To request deletion of stored brief or configuration data, see “Retention and deletion” below.
8. Cookies
We use essential cookies to keep you signed in, protect sessions, remember your active workspace, and provide security features. Those are required for the service to work. When you connect Twitch on a Play tournament page, we also set an essential Play-player session cookie so you stay signed in as that player on tournament pages. That cookie is required for that feature. It is not used for advertising. Play tournament pages do not show the analytics cookie banner.
We also use Google Analytics cookies and related identifiers on StreamChum’s marketing site and control panel to measure traffic and product usage (for example which pages are viewed and how often). Analytics cookies are optional. We only set them after you choose Accept analytics on the cookie banner. If you choose Essential only, we do not load Google Analytics. Your choice is stored in your browser (local storage) so we can remember it. You can change it later with Cookies in the site footer, or under Settings → Account in the control panel. Google may process analytics data in accordance with its privacy policy; see “Service providers” below. StreamChum does not use third-party advertising cookies to show you ads.
When you are signed in to the control panel, we also use LogRocket to record those sessions for troubleshooting, as described above. That recording is part of operating the signed-in product. It is separate from optional Google Analytics, and choosing Essential only on the cookie banner does not turn it off. LogRocket may set its own cookies or similar storage in the browser while you are signed in.
9. When we share information
We share information only as needed with connected platforms at your direction; service providers acting for us (see “Service providers” below); other members of your workspace according to their roles; professional advisers; or authorities when legally required. We may disclose information during a merger, financing, acquisition, or sale of the service, subject to appropriate safeguards.
10. Service providers (sub-processors)
We use trusted providers to run StreamChum. They process personal data only to provide services to us, under contractual obligations appropriate to the work they do:
- DigitalOcean, LLC, application hosting, managed PostgreSQL database, and object storage (Spaces) for assets such as uploaded or generated media. Production Spaces for StreamChum are configured in the London (
lon1) region; other DigitalOcean processing may occur in the regions where our App Platform services run. - Stripe, Inc. and Stripe Payments Europe, Limited (as applicable), payment processing, subscription billing, invoices, tax calculation where enabled, and related fraud prevention when you purchase or manage a paid plan. Card details are submitted to Stripe; see Stripe’s privacy policy for how they process payment data.
- OpenAI, L.L.C., AI model inference for viewer briefs, widget generation, image generation used by those features, and OBS setup assistance, as described above (depending on the feature and model).
- Google LLC, (a) AI model inference via Google AI / Gemini for features such as widget generation, OBS setup assistance, and music synthesis through Lyria, as described above (depending on the feature and model); and (b) Google Analytics for measuring how visitors and users use StreamChum’s marketing site and control panel (page views, events, device/browser information, and related measurement data). These uses are separate from Google/YouTube OAuth and YouTube API Services used when you connect YouTube. See also Google’s Privacy Policy and Business Data Responsibility materials.
- ElevenLabs, Inc., text-to-speech, sound-effect, and longer music synthesis for overlays and scene sounds. See ElevenLabs’ privacy policy for how they process text and generated audio.
- AssemblyAI, Inc., speech-to-text for optional Studio live captions. When transcription is on, microphone audio is sent from StreamChum Studio to AssemblyAI; StreamChum does not proxy that audio. See AssemblyAI’s privacy policy for how they process audio and text.
- Transpond, transactional email delivery (for example account, security, billing, stream recap after you go offline, and other service messages), and optional newsletter delivery if you opt in at signup or in Settings, Account.
- LogRocket, Inc., session replay and error reporting for the signed-in control panel, so we can troubleshoot product issues. See LogRocket's privacy policy.
When you connect third-party platforms such as Twitch, Google/YouTube, Kick, Discord, or Ko-fi, those services process data under their terms as independent providers you choose, they are not StreamChum sub-processors in the usual sense, but your use of StreamChum features with them necessarily involves sharing or receiving data with those platforms at your direction.
We may change providers as the service evolves. Material changes to this list will be reflected in an update to this policy.
11. Retention and deletion
We retain account and configuration information while your account is active and for a reasonable period afterward for security, backup, dispute, and legal purposes. Billing and invoice records are retained as needed for accounting, tax, chargeback, and legal purposes. OAuth tokens (including Google/YouTube tokens) are retained while a platform remains connected and are deleted when you disconnect that platform or delete your account, subject to backup cycles. Discord connection linkage (guild and connecting-user identifiers) is retained while Discord remains connected and is deleted when you disconnect Discord or delete your account, subject to backup cycles. Transient chat data may be processed in memory; saved moderation, viewer, or event data is retained only as needed to provide configured features.
Play tournament player data. Twitch identity we store for Play tournaments (user id, login, display name, and profile image) is retained while it is needed to operate events you joined and for a reasonable period afterward for security, backup, dispute, and legal purposes. Play-player session cookies expire (currently after 90 days) or when you choose Log out on the tournament page. Logging out ends the session; it does not delete the underlying player record. Email us to request deletion of that record as described below.
Stream Deck and API-token data. StreamChum stores only a one-way hash, a short identifying suffix, name, permissions, creation/last-use timestamps, and revocation status for each API token. The complete token is shown once and is stored locally by the Stream Deck application in plugin-wide settings. You can revoke it immediately under StreamChum Settings → API, after which it can no longer access StreamChum. Action-run history and security logs are retained only as needed to operate, secure, and troubleshoot the service.
YouTube data deletion. When you disconnect YouTube in StreamChum, we request revocation of the Google OAuth authorization and delete the stored credentials for that connection. Recent YouTube-derived chat, event, and viewer data expires or is pruned on an ongoing basis, and is removed when you delete your workspace or account. You may also revoke StreamChum’s access directly from your Google security settings.
Discord data deletion. When you disconnect Discord in StreamChum, we delete the stored Discord linkage and settings for that workspace. Removing the StreamChum bot from your Discord server stops further Discord API actions in that server. You may also email us to request deletion as described below.
Studio diagnostics. If you send diagnostics from Studio, we keep that report for up to 90 days so we can investigate performance on that setup, then delete it. Email us to request earlier deletion.
Phone go-live and Studio camera. Video and audio from a phone go-live are not stored by StreamChum. They are encoded on the phone and sent to the destination you select. Video and audio you send to Studio stay on your local network and are not stored by StreamChum. The local address, port, and stream key used to reach Studio are kept in memory only while Studio is waiting for the phone. Stopping the stream or the Studio camera, or turning off camera and microphone access in the phone’s system settings, ends that capture.
You can delete your StreamChum account from the phone app or from Settings, Account. That removes your login and workspaces where you are the only member. If a workspace still has other people, remove them first. You can also email [email protected]. We may need to verify your identity before completing an email request.
12. Security
We use reasonable technical and organisational safeguards, including encrypted connections, protected session cookies, access controls, encryption of stored platform tokens, one-way hashing of StreamChum API tokens, limited token permissions, rate limiting, and immediate token revocation. No online service can guarantee absolute security.
13. Your choices and rights
You may access or update account information, disconnect platforms, revoke OAuth permissions, revoke device/API tokens, uninstall device integrations, stop a phone go-live, deny or revoke camera and microphone access in the phone’s system settings, change your analytics-cookie choice, subscribe or unsubscribe from the optional StreamChum newsletter under Settings, Account, turn stream recap emails off under Settings, Account, or request access, correction, export, restriction, objection, or deletion where applicable. If you connected Twitch only as a Play tournament player, you can log out on the tournament page, revoke StreamChum in your Twitch connection settings, and email us to delete the stored Play player record. UK and EEA users may also complain to the Information Commissioner’s Office (ICO) or another competent data-protection authority. Depending on where you live, additional local privacy rights may apply.
14. Children
StreamChum is not directed to children under 13, or under the minimum digital-consent age in their country. We do not knowingly collect personal information from children.
15. International processing
StreamChum is operated from the United Kingdom. Your information may be processed in the UK, the EEA, the United States, or other countries where we or our service providers operate (for example DigitalOcean, OpenAI, Google, ElevenLabs, and AssemblyAI). Where UK or EU law requires safeguards for international transfers, we rely on appropriate mechanisms such as the provider’s standard contractual clauses or other lawful transfer tools, together with the technical and organisational measures described in this policy.
16. Changes to this policy
We may update this policy as the service changes. We will publish the revised policy here and update the date above. We will provide additional notice when required by law.
17. Contact
Questions or privacy requests can be sent to [email protected]. Postal correspondence may be sent to the Operator at the address in Who we are above.