Privacy Policy
Last updated: 26.07.2026
1. Responsible Party
Responsible for data processing on this website:
Emrah Can Görgü
Eggstrasse 47
CH-4402 Frenkendorf BL
Email: [email protected]
Phone: +41 78 215 44 55
Emrah Can Görgü
Eggstrasse 47
CH-4402 Frenkendorf BL
Email: [email protected]
Phone: +41 78 215 44 55
2. Collection and Storage of Personal Data
When visiting our website and using our service, we store the following data:
- IDs and display names of linked streaming accounts (Twitch, YouTube, Kick – only if you voluntarily connect them)
- OAuth access and refresh tokens for secure communication with Twitch, YouTube (Google), and Kick (stored encrypted; no storage of platform passwords)
- Email address (for communication)
- IP address (for security and fraud prevention)
- Media you upload (profile images, video and image files for streams), stored in Cloudflare R2
- Optional account security data: 2FA (encrypted TOTP secret, hashed backup codes) and/or passkeys (WebAuthn key data, device name)
- Activity and login logs (activity type, details, IP address, timestamp; sometimes browser/user agent)
- Payment data (only for paid subscriptions, processed by our payment service provider Stripe, Inc.)
- IDs and display names of linked streaming accounts (Twitch, YouTube, Kick – only if you voluntarily connect them)
- OAuth access and refresh tokens for secure communication with Twitch, YouTube (Google), and Kick (stored encrypted; no storage of platform passwords)
- Email address (for communication)
- IP address (for security and fraud prevention)
- Media you upload (profile images, video and image files for streams), stored in Cloudflare R2
- Optional account security data: 2FA (encrypted TOTP secret, hashed backup codes) and/or passkeys (WebAuthn key data, device name)
- Activity and login logs (activity type, details, IP address, timestamp; sometimes browser/user agent)
- Payment data (only for paid subscriptions, processed by our payment service provider Stripe, Inc.)
3. Purpose of Processing
The data is processed to:
- Ensure the operation and management of the platform
- Correctly link and display user accounts
- Manage linked streaming accounts (Twitch, YouTube, Kick) and control streams
- Store, manage, and provide uploaded media for 24/7 streams
- Improve account security through optional 2FA and passkeys
- Log security-relevant activities and logins and make them viewable to you
- Process payments and subscriptions
- Ensure the security and stability of our systems
- Ensure the operation and management of the platform
- Correctly link and display user accounts
- Manage linked streaming accounts (Twitch, YouTube, Kick) and control streams
- Store, manage, and provide uploaded media for 24/7 streams
- Improve account security through optional 2FA and passkeys
- Log security-relevant activities and logins and make them viewable to you
- Process payments and subscriptions
- Ensure the security and stability of our systems
4. Data Sharing
Your data will only be shared with third parties if necessary for contract fulfillment.
For payment processing, we use the service of Stripe, Inc. (USA). Your payment data is transmitted directly to Stripe. Stripe is PCI-DSS certified. You can find Stripe's privacy policy at: stripe.com/privacy.
To store your uploaded media (profile images, stream videos and images), we use Cloudflare R2 (Cloudflare, Inc., USA). See Section 9 for details. Cloudflare privacy policy: cloudflare.com/privacypolicy.
To control your streams, we transmit data via secure connections to the platforms you have linked:
- Twitch (Twitch Interactive, Inc.) – Privacy Notice
- YouTube / Google (Google LLC) – Privacy Policy
- Kick (Kick Streaming Pty Ltd) – Privacy Policy
For payment processing, we use the service of Stripe, Inc. (USA). Your payment data is transmitted directly to Stripe. Stripe is PCI-DSS certified. You can find Stripe's privacy policy at: stripe.com/privacy.
To store your uploaded media (profile images, stream videos and images), we use Cloudflare R2 (Cloudflare, Inc., USA). See Section 9 for details. Cloudflare privacy policy: cloudflare.com/privacypolicy.
To control your streams, we transmit data via secure connections to the platforms you have linked:
- Twitch (Twitch Interactive, Inc.) – Privacy Notice
- YouTube / Google (Google LLC) – Privacy Policy
- Kick (Kick Streaming Pty Ltd) – Privacy Policy
5. Cookies
Our website uses different types of cookies:
Necessary cookies: These cookies are essential for the basic functions of the website (session cookies, login status).
Functional cookies: These cookies enable advanced functions like Cloudflare Turnstile to protect against bots without annoying CAPTCHA queries.
Analytics cookies: These cookies collect anonymized data for website usage analysis (e.g., for login statistics).
You can adjust your cookie settings at any time via our cookie banner or view detailed information on our Cookie Policy page.
Necessary cookies: These cookies are essential for the basic functions of the website (session cookies, login status).
Functional cookies: These cookies enable advanced functions like Cloudflare Turnstile to protect against bots without annoying CAPTCHA queries.
Analytics cookies: These cookies collect anonymized data for website usage analysis (e.g., for login statistics).
You can adjust your cookie settings at any time via our cookie banner or view detailed information on our Cookie Policy page.
6. Storage and Deletion
Your data will be stored as long as necessary for the operation of the platform.
Media after subscription end: Uploaded stream media (videos, images, and related folders in the media library) are deleted if your subscription has expired or ended and three months pass without a new active subscription. This helps save storage space. Profile images are excluded and remain while your account exists.
Deletion may be recorded in system audit logs (e.g., number of deleted media items and user ID).
You can request the deletion of your data at any time by deleting your account or contacting us.
Media after subscription end: Uploaded stream media (videos, images, and related folders in the media library) are deleted if your subscription has expired or ended and three months pass without a new active subscription. This helps save storage space. Profile images are excluded and remain while your account exists.
Deletion may be recorded in system audit logs (e.g., number of deleted media items and user ID).
You can request the deletion of your data at any time by deleting your account or contacting us.
7. Your Rights
You have the right to:
- Access information about your stored data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
Please contact us for this at: [email protected]
- Access information about your stored data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
Please contact us for this at: [email protected]
8. Account Security (2FA, Passkeys) and Activity Logs
To protect your account and provide transparency for security-relevant events, we process the following optional or automatically collected data:
Two-factor authentication (2FA, optional): If you enable 2FA, we store a TOTP secret (encrypted with AES-256-CBC), hashed backup codes, and status/usage timestamps (e.g., activation, last use). Setup uses an authenticator app. 2FA is used solely to secure your account.
Passkeys (optional): If you use passkeys/WebAuthn, we store technical key data (credential ID, public key), a device name you assign, and usage metadata. Passkeys enable passwordless sign-in and/or serve as an additional security factor.
Activity and login logs: We log security- and account-related events, e.g., logins, password changes, data exports, or email confirmations. This may include: activity type, short description, IP address, timestamp, and sometimes browser/user agent. You can view login history (IP and time) in your account.
Purpose, retention, and deletion: This data is used for account security, fraud prevention, and transparency for you as a user. It is not sold or used for advertising. Data is retained while your account is active; when you delete your account, related 2FA, passkey, and log data is deleted unless legal retention obligations apply.
Two-factor authentication (2FA, optional): If you enable 2FA, we store a TOTP secret (encrypted with AES-256-CBC), hashed backup codes, and status/usage timestamps (e.g., activation, last use). Setup uses an authenticator app. 2FA is used solely to secure your account.
Passkeys (optional): If you use passkeys/WebAuthn, we store technical key data (credential ID, public key), a device name you assign, and usage metadata. Passkeys enable passwordless sign-in and/or serve as an additional security factor.
Activity and login logs: We log security- and account-related events, e.g., logins, password changes, data exports, or email confirmations. This may include: activity type, short description, IP address, timestamp, and sometimes browser/user agent. You can view login history (IP and time) in your account.
Purpose, retention, and deletion: This data is used for account security, fraud prevention, and transparency for you as a user. It is not sold or used for advertising. Data is retained while your account is active; when you delete your account, related 2FA, passkey, and log data is deleted unless legal retention obligations apply.
9. Cloudflare R2 Object Storage (Media Data)
Streamovo uses Cloudflare R2 object storage from Cloudflare, Inc. to store content you upload to our service.
Data stored: Profile images and media you upload (e.g., video and image files for 24/7 streams), including related thumbnails and metadata in our media library. This content may contain personal data if you include it in file names, images, or videos.
Purpose: Providing the media library, streaming, account management, and 24/7 stream features.
Processing and security: Files are stored in data centers operated by Cloudflare and transmitted over encrypted connections (TLS/HTTPS). Access is restricted to your authenticated user account. When you delete individual media or your account, related files are removed from storage unless legal retention obligations apply.
Retention after subscription end: Stream media in the media library is retained for up to three months after your subscription expires or ends, and is then deleted automatically unless you start a new active subscription. Profile images are excluded from this automatic deletion (see section 6).
Data processing agreement: Cloudflare processes this data on our behalf as a processor. Cloudflare may process data in data centers inside and outside Switzerland/the EEA. Further information: Cloudflare Privacy Policy and Cloudflare Data Processing Addendum.
Data stored: Profile images and media you upload (e.g., video and image files for 24/7 streams), including related thumbnails and metadata in our media library. This content may contain personal data if you include it in file names, images, or videos.
Purpose: Providing the media library, streaming, account management, and 24/7 stream features.
Processing and security: Files are stored in data centers operated by Cloudflare and transmitted over encrypted connections (TLS/HTTPS). Access is restricted to your authenticated user account. When you delete individual media or your account, related files are removed from storage unless legal retention obligations apply.
Retention after subscription end: Stream media in the media library is retained for up to three months after your subscription expires or ends, and is then deleted automatically unless you start a new active subscription. Profile images are excluded from this automatic deletion (see section 6).
Data processing agreement: Cloudflare processes this data on our behalf as a processor. Cloudflare may process data in data centers inside and outside Switzerland/the EEA. Further information: Cloudflare Privacy Policy and Cloudflare Data Processing Addendum.
10. Google/YouTube User Data and Data Security
Streamovo uses YouTube API Services provided by Google. This section describes which APIs and permissions we use, how we process Google user data, and the data protection mechanisms we apply to sensitive data.
APIs and OAuth scopes used:
- YouTube Data API v3 (endpoints including
- OAuth scopes:
Google/YouTube data we collect: When you voluntarily link your YouTube account, we collect and store only the data required to provide the service: YouTube channel ID, channel name, channel description, profile image URL, public channel statistics (subscriber, view, and video counts), OAuth access and refresh tokens, and technical livestream/broadcast metadata (e.g., title, status) where needed to control your streams through Streamovo. Stream keys are retrieved from the YouTube API when needed and are not stored permanently. We do not store Google account passwords.
Use (Limited Use): Google user data is used solely to provide and improve the features you request—specifically managing linked YouTube accounts and controlling livestreams. We do not use Google user data for advertising, profiling, selling to third parties, sharing with data brokers or information resellers, creditworthiness checks, AI/ML model training, or any purpose outside the app's functionality.
Sharing: Google user data is not sold or shared with third parties for advertising purposes. Data is transmitted to Google/YouTube APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption)
- Access controls: Google user data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection and secure session management)
- Masking of sensitive values in system logs
- No employee access to Google user data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Google user data is retained only while your account is active and the YouTube connection remains linked. You may disconnect on the respective account page in Streamovo, delete your account, or revoke API access in your Google Account at any time. Related tokens and linked YouTube data are then deleted unless legal retention obligations apply.
Legal references: YouTube API Services Terms of Service, Google API Services User Data Policy, and the Google Privacy Policy.
APIs and OAuth scopes used:
- YouTube Data API v3 (endpoints including
channels, liveBroadcasts, liveStreams) to manage and control YouTube livestreams- OAuth scopes:
youtube, youtube.readonly, youtube.force-sslGoogle/YouTube data we collect: When you voluntarily link your YouTube account, we collect and store only the data required to provide the service: YouTube channel ID, channel name, channel description, profile image URL, public channel statistics (subscriber, view, and video counts), OAuth access and refresh tokens, and technical livestream/broadcast metadata (e.g., title, status) where needed to control your streams through Streamovo. Stream keys are retrieved from the YouTube API when needed and are not stored permanently. We do not store Google account passwords.
Use (Limited Use): Google user data is used solely to provide and improve the features you request—specifically managing linked YouTube accounts and controlling livestreams. We do not use Google user data for advertising, profiling, selling to third parties, sharing with data brokers or information resellers, creditworthiness checks, AI/ML model training, or any purpose outside the app's functionality.
Sharing: Google user data is not sold or shared with third parties for advertising purposes. Data is transmitted to Google/YouTube APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption)
- Access controls: Google user data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection and secure session management)
- Masking of sensitive values in system logs
- No employee access to Google user data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Google user data is retained only while your account is active and the YouTube connection remains linked. You may disconnect on the respective account page in Streamovo, delete your account, or revoke API access in your Google Account at any time. Related tokens and linked YouTube data are then deleted unless legal retention obligations apply.
Legal references: YouTube API Services Terms of Service, Google API Services User Data Policy, and the Google Privacy Policy.
11. Twitch User Data and Data Security
Streamovo uses the Twitch API (Helix). This section describes which APIs and permissions we use and how we protect Twitch user data.
APIs and OAuth scopes used:
- Twitch Helix API (endpoints including
- OAuth scopes:
Twitch data we collect: When you voluntarily link your Twitch account, we store your Twitch user ID, username, display name, email address (if provided by Twitch), profile image URL, OAuth access and refresh tokens, and stream metadata (e.g., title, category, live status, viewer and follower counts when queried). Stream keys are retrieved from the Twitch API when needed and are not stored permanently. We do not store Twitch passwords.
Use: Twitch data is used solely to provide and improve the features you request—specifically managing linked Twitch accounts and controlling livestreams. We do not sell Twitch data or use it for advertising, profiling, or AI/ML model training.
Sharing: Twitch data is not sold or shared with third parties for advertising purposes. Data is transmitted to Twitch APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption)
- Access controls: Twitch data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection and secure session management)
- Masking of sensitive values in system logs
- No employee access to Twitch data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Twitch data is retained only while your account is active and the connection remains linked. You may disconnect on the respective account page in Streamovo, delete your account, or revoke access under Twitch Connections at any time.
Legal references: Twitch Privacy Notice and Twitch Developer Agreement.
APIs and OAuth scopes used:
- Twitch Helix API (endpoints including
users, channels, streams, channels/followers, search/categories) to manage and control Twitch livestreams- OAuth scopes:
user:read:email, channel:read:stream_key, channel:manage:broadcastTwitch data we collect: When you voluntarily link your Twitch account, we store your Twitch user ID, username, display name, email address (if provided by Twitch), profile image URL, OAuth access and refresh tokens, and stream metadata (e.g., title, category, live status, viewer and follower counts when queried). Stream keys are retrieved from the Twitch API when needed and are not stored permanently. We do not store Twitch passwords.
Use: Twitch data is used solely to provide and improve the features you request—specifically managing linked Twitch accounts and controlling livestreams. We do not sell Twitch data or use it for advertising, profiling, or AI/ML model training.
Sharing: Twitch data is not sold or shared with third parties for advertising purposes. Data is transmitted to Twitch APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption)
- Access controls: Twitch data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection and secure session management)
- Masking of sensitive values in system logs
- No employee access to Twitch data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Twitch data is retained only while your account is active and the connection remains linked. You may disconnect on the respective account page in Streamovo, delete your account, or revoke access under Twitch Connections at any time.
Legal references: Twitch Privacy Notice and Twitch Developer Agreement.
12. Kick User Data and Data Security
Streamovo uses the Kick Developer Public API. This section describes which APIs and permissions we use and how we protect Kick user data.
APIs and OAuth scopes used:
- Kick Public API v1 (endpoint
- OAuth scopes:
Kick data we collect: When you voluntarily link your Kick account, we store your Kick user ID, username/slug, display name, profile image URL, banner URL, channel description, OAuth access and refresh tokens, and channel/stream metadata (e.g., title, live status). Stream keys are retrieved from the Kick API when needed and used temporarily for streaming functionality; they are not stored permanently. We do not store Kick passwords.
Use: Kick data is used solely to provide and improve the features you request—specifically managing linked Kick accounts and controlling livestreams. We do not sell Kick data or use it for advertising, profiling, or AI/ML model training.
Sharing: Kick data is not sold or shared with third parties for advertising purposes. Data is transmitted to Kick APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption; stream keys are retrieved from the Kick API when needed and used only for streaming functionality)
- Access controls: Kick data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection, OAuth 2.1 with PKCE, and secure session management)
- Masking of sensitive values in system logs
- No employee access to Kick data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Kick data is retained only while your account is active and the connection remains linked. You may disconnect on the respective account page in Streamovo or delete your account at any time.
Legal references: Kick Privacy Policy and Kick Developer Services Agreement.
APIs and OAuth scopes used:
- Kick Public API v1 (endpoint
/public/v1/channels) to retrieve channel and stream information- OAuth scopes:
user:read, channel:read, streamkey:readKick data we collect: When you voluntarily link your Kick account, we store your Kick user ID, username/slug, display name, profile image URL, banner URL, channel description, OAuth access and refresh tokens, and channel/stream metadata (e.g., title, live status). Stream keys are retrieved from the Kick API when needed and used temporarily for streaming functionality; they are not stored permanently. We do not store Kick passwords.
Use: Kick data is used solely to provide and improve the features you request—specifically managing linked Kick accounts and controlling livestreams. We do not sell Kick data or use it for advertising, profiling, or AI/ML model training.
Sharing: Kick data is not sold or shared with third parties for advertising purposes. Data is transmitted to Kick APIs only as necessary to provide the features you use, or when required by law.
Data protection mechanisms for sensitive data: Security procedures are in place to protect the confidentiality of your data. Specifically, we use:
- Encryption in transit (TLS/HTTPS) and at rest (OAuth tokens stored with AES-256-GCM encryption; stream keys are retrieved from the Kick API when needed and used only for streaming functionality)
- Access controls: Kick data is accessible only to the authenticated account owner
- Protection against unauthorized requests (including CSRF protection, OAuth 2.1 with PKCE, and secure session management)
- Masking of sensitive values in system logs
- No employee access to Kick data except for troubleshooting with your consent or when legally required
Retention, deletion, and revocation: Kick data is retained only while your account is active and the connection remains linked. You may disconnect on the respective account page in Streamovo or delete your account at any time.
Legal references: Kick Privacy Policy and Kick Developer Services Agreement.
13. Changes to this Privacy Policy
We reserve the right to modify this privacy policy at any time.
Changes will be published on this website.
Changes will be published on this website.