Privacy Policy
This Privacy Policy explains what personal data is processed when you use StreamGiveawayBox, for what purpose, and what rights you have.
1. Controller
Responsible for data processing in connection with StreamGiveawayBox:
- Operator / Twitch: Motti_TV
Contact for privacy questions: see Legal Notice & Contact.
2. What Is StreamGiveawayBox?
StreamGiveawayBox is a web tool that lets a Twitch broadcaster ("streamer") sign in with their Twitch account, configure and run chat-based giveaways on their channel, and show the draw on an animated overlay. Each streamer who signs in gets their own isolated area ("tenant") — their settings, uploads, and history are not visible to other streamers using the Service.
3. What Data Is Processed
3.1 When you sign in as a broadcaster ("Sign in with Twitch")
| Data | Source | Purpose |
|---|---|---|
| Twitch user ID | Twitch, after login | identifies your tenant (isolates your data from other streamers) |
| Twitch login name & display name | Twitch | shown in your dashboard, used to connect the chat bot to your channel |
| Twitch avatar URL | Twitch | display in the dashboard / winner overlay (optional, can be disabled) |
| OAuth access token & refresh token | Twitch, after login | keeps the chat bot connected to your channel and lets the Service check follower status for join rules like "followers only" |
The requested Twitch scopes are chat:read, chat:edit, and
moderator:read:followers. The Service never sees or stores your Twitch password.
3.2 Session cookie
After signing in, a random session ID is stored in a cookie in your browser and mapped, in the Service's memory only, to your tenant. This mapping is not written to disk — it is lost whenever the Service restarts, at which point you'd need to sign in again.
3.3 Your giveaway configuration
Stored per tenant, for as long as your tenant exists:
- overlay theme, prize list, chat command text, sound settings, and similar dashboard settings,
- images and sound files you upload,
- saved presets ("profiles") you create.
3.4 Giveaway participants (your viewers)
When a viewer joins a giveaway on your channel via the chat command, the Service stores:
- their Twitch username, for the duration of that giveaway round (the entry list),
- if they win: their username, the prize, and the time, in an optional winner history log and a cumulative leaderboard (win counts per username) — both can be cleared by the broadcaster at any time from their dashboard.
This participant data is collected and controlled by the broadcaster running the giveaway, as part of their use of the Service on their own channel.
3.5 Technical data
Standard hosting-level logs (timestamp, requested path, response status) may be generated while the Service is used, for operation and troubleshooting. These are not used for tracking or advertising.
3.6 What is not stored
- no Twitch password,
- no payment data,
- no Twitch chat message content beyond recognizing the configured join/control commands,
- no email address (not provided by the Twitch scopes this Service requests),
- no profiling for advertising purposes.
4. Purpose & Legal Basis
Where data protection law such as the GDPR applies, processing is based in particular on:
- performance of the service you requested by signing in and using the dashboard,
- legitimate interest in operating the Service securely and preventing abuse,
- your consent, insofar as you actively start and complete the Twitch sign-in flow.
5. Storage & Retention
- Tenant data is stored on the Service's hosting (a persistent volume on Railway) for as long as your tenant exists, or until deleted.
- The entry list for a giveaway round is cleared when the round resets or ends.
- Winner history and the leaderboard persist until you clear them from your dashboard, or your tenant is deleted.
- Session mappings live only in memory and are lost on server restart.
Data is never sold to third parties.
6. Recipients / Third-Party Services
| Recipient | Role |
|---|---|
| Twitch | sign-in (OAuth), chat connectivity (IRC), follower checks (Helix API) |
| Railway | hosting of the Service and its persistent data |
| GitHub | hosts the Service's source code (no personal user data) |
These providers process data under their own privacy policies. The operator controls data flow only within the Service's own functions.
7. Your Rights
Where applicable data protection law (e.g. GDPR) grants them, you have the right to:
- access the data stored about you,
- rectification of inaccurate data,
- erasure ("right to be forgotten"),
- restriction of processing,
- object to processing based on legitimate interest,
- data portability, where technically and legally applicable,
- lodge a complaint with a data protection supervisory authority.
Deleting your data
- As a broadcaster: clear your winner history / leaderboard from your dashboard at any time, or sign out to disconnect your chat bot.
- For full deletion of your tenant's stored data, contact the operator (see Legal Notice & Contact).
- As a viewer/participant: to have your username removed from a specific broadcaster's history or leaderboard, ask that broadcaster (they can clear it directly) or contact the operator.
8. Minors
The Service is intended for people who are permitted to use Twitch and Twitch chat. It is not directed at children below the minimum age required by Twitch or by applicable law, and no data is knowingly collected from children for profiling purposes.
9. Security
Reasonable technical and organizational measures are used, including:
- no storage of Twitch passwords,
- use of the official Twitch OAuth login flow,
- session cookies scoped to this site (
HttpOnly,SameSite=Lax, andSecurewhen served over HTTPS), - per-tenant data isolation, so one broadcaster cannot access another's data.
No method of transmission or storage over the internet can be guaranteed 100% secure.
10. Automated Decision-Making
There is no automated decision-making with legal effect in the sense of profiling. The winner draw is a randomized game mechanic for entertainment purposes, run at the broadcaster's own request — it is not an evaluation or scoring of any person.
11. Changes to This Policy
This policy may be updated as the Service's features, technology, or legal requirements change. The current version is identified by the "Effective" date above.
12. Terms of Use
See also the Terms of Use.
13. Contact
This document is not legal advice. It describes, transparently, the actual data StreamGiveawayBox processes as a private, non-commercial project.