Legal

Privacy Policy

Effective and last updated: 11 August 2026

This policy explains what information StreamChum collects, why we use it, when we share it, and the choices available to you.

1. Who we are

StreamChum provides tools for combining and managing livestream chats, overlays, moderation, and related streaming features at streamchum.com.

Across StreamChum’s legal pages, the Operator (also “StreamChum,” “we,” “us,” and, for the Stream Deck plugin, the “Maker”) is:

Michael Way
trading as StreamChum
51 Wareham Road
Corfe Mullen
Dorset
United Kingdom

Contact for privacy and legal requests: [email protected].

2. Information we collect

3. How we use information

We use information to provide and secure StreamChum, authenticate users and device integrations, run Actions expressly selected by users, connect requested streaming platforms, display and moderate chat, operate overlays and widgets, run optional AI-assisted features you use (see below), post streamer-configured announcements and slash-command replies to Discord, process paid subscriptions and related billing when you purchase, understand how the product and marketing site are used so we can improve them, troubleshoot faults, communicate service messages (including billing notices), prevent abuse, and comply with law. We do not sell personal information.

4. Google and YouTube data

StreamChum uses YouTube API Services. When you connect YouTube or sign in with Google, StreamChum uses Google APIs and YouTube API Services to access only the information and permissions you approve. This may include your Google identity, YouTube channel information, broadcasts, live chat messages and author details, moderation actions, and paid or membership events. We use this data only to provide the StreamChum features you request, such as combining and displaying your live chat, running overlays and commands, moderating chat, and showing stream status.

How we handle YouTube data: we access YouTube data through the YouTube Data API, store connection tokens in encrypted form, keep only recent chat, event, and viewer data needed to provide configured features, and do not sell it or use it for advertising. We do not use YouTube data to build user profiles for purposes unrelated to the features you request, and we do not transfer it to third parties except as needed to run the service at your direction.

By using StreamChum’s YouTube features, you also agree to the YouTube Terms of Service. StreamChum’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Information handled through Google and YouTube API Services is also subject to the Google Privacy Policy.

You can revoke StreamChum’s access to your Google and YouTube data at any time through the Google security settings page (also available at Google Account permissions). You can also disconnect YouTube inside StreamChum, which sends Google a request to revoke the OAuth authorization and deletes the stored credentials for that connection. To request deletion of YouTube data StreamChum has stored, see “Retention and deletion” below or email us at the address in the Contact section.

5. Discord data

When you connect Discord, StreamChum installs its hosted bot into a Discord server you choose and uses Discord’s APIs so you can post streamer-configured timers and event announcements to channels you select, and so Discord users can run StreamChum slash commands (for example uptime, command list, and social links). Replies to slash commands are ephemeral (visible only to the person who ran the command).

What we access: with your approval we request Discord OAuth scopes to install the bot and register slash commands (bot, applications.commands) and to identify who connected the workspace (identify). The bot asks only for permission to view channels, send messages, and embed links. We do not request privileged Message Content access, read Discord channel history or live chat, scrape member lists, send direct messages, or moderate Discord servers.

What we store: the Discord server (guild) id and name where the bot was installed, the connecting Discord user’s id and username/display name, connection timestamp, and your StreamChum Discord settings (such as default channel id and social-links text). Outbound posts use StreamChum’s shared bot token. We do not retain Discord user OAuth access or refresh tokens after the one-time connect handshake.

How we use Discord data: only to provide the Discord features you configure, map slash-command requests to your workspace, and secure the connection. We do not sell Discord API data, use it for advertising, profile Discord users beyond operating these features, mine or scrape Discord, or use Discord message content to train AI models.

Your use of Discord remains subject to Discord’s terms and policies, including the Discord Terms of Service, Discord Privacy Policy, and Discord’s developer terms for applications that use Discord’s APIs. You can disconnect Discord inside StreamChum (which removes the stored linkage for that workspace) and remove the StreamChum bot from your Discord server. To request deletion of Discord-related data StreamChum has stored, see “Retention and deletion” below or email us at the address in the Contact section.

6. Artificial intelligence features

Some StreamChum features use third-party AI models (currently OpenAI and Google AI / Gemini) to generate outputs for you. Which provider handles a request depends on the feature and the model selected for that feature. Depending on what you use, this may include:

We send only what is needed for the feature you requested. AI outputs can be incomplete, outdated, or wrong, treat them as suggestions and review before acting on them in a live broadcast or public channel. We do not sell your content, and we do not use your StreamChum content to train StreamChum’s own models. Under the providers’ current paid/API terms, API inputs and outputs are generally not used to train or improve those providers’ models by default (unless an organisation explicitly opts in). Providers may still retain limited data for abuse monitoring or as otherwise described in their policies. OpenAI and Google process data under their own terms and privacy policies as our processors for these features. Google AI used for model inference is separate from the YouTube/Google account connection described in “Google and YouTube data” above.

You can limit AI use by not enabling or not using those features. Disconnecting a platform stops new chat from that platform being used for viewer briefs. To request deletion of stored brief or configuration data, see “Retention and deletion” below.

7. Cookies

We use essential cookies to keep you signed in, protect sessions, remember your active workspace, and provide security features. We also use Google Analytics cookies and related identifiers on StreamChum’s marketing site and control panel to measure traffic and product usage (for example which pages are viewed and how often). Google may process this data in accordance with its privacy policy; see “Service providers” below. StreamChum does not use third-party advertising cookies to show you ads.

8. When we share information

We share information only as needed with connected platforms at your direction; service providers acting for us (see “Service providers” below); other members of your workspace according to their roles; professional advisers; or authorities when legally required. We may disclose information during a merger, financing, acquisition, or sale of the service, subject to appropriate safeguards.

9. Service providers (sub-processors)

We use trusted providers to run StreamChum. They process personal data only to provide services to us, under contractual obligations appropriate to the work they do:

When you connect third-party platforms such as Twitch, Google/YouTube, Kick, Discord, or Ko-fi, those services process data under their terms as independent providers you choose, they are not StreamChum sub-processors in the usual sense, but your use of StreamChum features with them necessarily involves sharing or receiving data with those platforms at your direction.

We may change providers as the service evolves. Material changes to this list will be reflected in an update to this policy.

10. Retention and deletion

We retain account and configuration information while your account is active and for a reasonable period afterward for security, backup, dispute, and legal purposes. Billing and invoice records are retained as needed for accounting, tax, chargeback, and legal purposes. OAuth tokens (including Google/YouTube tokens) are retained while a platform remains connected and are deleted when you disconnect that platform or delete your account, subject to backup cycles. Discord connection linkage (guild and connecting-user identifiers) is retained while Discord remains connected and is deleted when you disconnect Discord or delete your account, subject to backup cycles. Transient chat data may be processed in memory; saved moderation, viewer, or event data is retained only as needed to provide configured features.

Stream Deck and API-token data. StreamChum stores only a one-way hash, a short identifying suffix, name, permissions, creation/last-use timestamps, and revocation status for each API token. The complete token is shown once and is stored locally by the Stream Deck application in plugin-wide settings. You can revoke it immediately under StreamChum Settings → API, after which it can no longer access StreamChum. Action-run history and security logs are retained only as needed to operate, secure, and troubleshoot the service.

YouTube data deletion. When you disconnect YouTube in StreamChum, we request revocation of the Google OAuth authorization and delete the stored credentials for that connection. Recent YouTube-derived chat, event, and viewer data expires or is pruned on an ongoing basis, and is removed when you delete your workspace or account. You may also revoke StreamChum’s access directly from your Google security settings.

Discord data deletion. When you disconnect Discord in StreamChum, we delete the stored Discord linkage and settings for that workspace. Removing the StreamChum bot from your Discord server stops further Discord API actions in that server. You may also email us to request deletion as described below.

To request account or data deletion, email [email protected]. We may need to verify your identity before completing a request.

11. Security

We use reasonable technical and organisational safeguards, including encrypted connections, protected session cookies, access controls, encryption of stored platform tokens, one-way hashing of StreamChum API tokens, limited token permissions, rate limiting, and immediate token revocation. No online service can guarantee absolute security.

12. Your choices and rights

You may access or update account information, disconnect platforms, revoke OAuth permissions, revoke device/API tokens, uninstall device integrations, or request access, correction, export, restriction, objection, or deletion where applicable. UK and EEA users may also complain to the Information Commissioner’s Office (ICO) or another competent data-protection authority. Depending on where you live, additional local privacy rights may apply.

13. Children

StreamChum is not directed to children under 13, or under the minimum digital-consent age in their country. We do not knowingly collect personal information from children.

14. International processing

StreamChum is operated from the United Kingdom. Your information may be processed in the UK, the EEA, the United States, or other countries where we or our service providers operate (for example DigitalOcean, OpenAI, and Google). Where UK or EU law requires safeguards for international transfers, we rely on appropriate mechanisms such as the provider’s standard contractual clauses or other lawful transfer tools, together with the technical and organisational measures described in this policy.

15. Changes to this policy

We may update this policy as the service changes. We will publish the revised policy here and update the date above. We will provide additional notice when required by law.

16. Contact

Questions or privacy requests can be sent to [email protected]. Postal correspondence may be sent to the Operator at the address in Who we are above.