Legal
Privacy Policy
Effective July 26, 2026
StreamFirefly ("we", "us") operates a shop where viewers spend loyalty points or Bits to trigger effects on a streamer's broadcast. This policy explains what data we collect from Twitch, YouTube, Kick, and Spotify when you connect or sign in, how we use it, and how to have it removed.
Data we collect
When you sign in with Twitch, YouTube, or Kick — as a streamer or as a viewer — the platform shares your account ID, display name, and avatar with us. If you connect a platform as a streamer to power your shop, alerts, or chatbot, we additionally request the specific permissions shown on that platform's consent screen:
- Twitch — channel point redemptions, live chat (to post chatbot acknowledgements), and follow / subscription / cheer events used to fire alerts.
- YouTube (Google) — live chat read and post access, used to detect Super Chats, new memberships, and gifted memberships, and to post chatbot acknowledgements. See "YouTube data" below for the full detail Google requires us to disclose.
- Kick — follow / subscription events and channel point reward redemptions, used to fire alerts.
- Spotify — see "Spotify data" below.
YouTube data
StreamFirefly uses YouTube API Services. By using the YouTube features of StreamFirefly you agree to be bound by the YouTube Terms of Service. Google's handling of your data is governed by the Google Privacy Policy.
StreamFirefly requests the youtube.force-ssl scope, used only for the streamer's own channel, for exactly four purposes:
- Resolving your channel ID when you connect your account.
- Finding the live chat ID of your currently active broadcast.
- Polling your live chat to detect Super Chat, new member, and gifted membership events that drive your alerts.
- Posting chatbot acknowledgements into your live chat when an alert or shop redemption fires.
We do not store chat message content, Super Chat amounts, or viewer identities from YouTube. The only state we keep is a poll cursor — your live chat ID, a page token, and a timestamp marking the last event we already processed — so a restart never replays old chat history. That cursor is deleted immediately when you disconnect YouTube.
Retention. We retain no YouTube authorized data beyond the poll cursor described above, and in no case longer than 30 days. If you revoke our access, every piece of YouTube authorized data we hold is deleted within 7 days — in practice immediately, when we next attempt to use the revoked credential.
Revoking access. You can disconnect YouTube at any time from your StreamFirefly dashboard, which deletes our stored tokens and your poll cursor right away. You can also revoke StreamFirefly's access to your Google account directly at the Google security settings page, https://myaccount.google.com/permissions.
Spotify data
If you connect Spotify to use song requests, we store your Spotify user ID, display name, and product tier (premium or free), plus the track metadata — title, artist, artwork, and duration — for songs requested in your channel, so requests can be attributed and revoked. We never receive or store your Spotify password or payment information, and viewers never authenticate with Spotify: no viewer data is sent to Spotify at any point. Disconnecting Spotify from your dashboard deletes our stored tokens immediately.
Text-to-speech
If a streamer configures a text-to-speech effect, the text to be spoken — which may include a short message written by the redeeming viewer — is sent to Amazon Web Services for speech synthesis and returned as audio. We do not retain the synthesized audio or the submitted text after the effect plays.
Browser extension
Our optional browser extension runs only on Twitch, YouTube, and Kick stream pages. It reads the channel identity from the page URL so it can find that streamer's shop, and — while the tab is focused and you are signed in — reports watch-time ticks so you earn loyalty points. It does not read page content, browsing history, or activity on any other site, and it sends data only to StreamFirefly.
Viewer data
Viewers earn and spend loyalty points in a streamer's shop. We keep a points balance and a redemption history per viewer so streamers can review their own shop activity. Redemption history is retained indefinitely for the streamer's records, the same way a payment ledger would be.
Token security
OAuth access and refresh tokens for every connected platform are encrypted at rest with AES-256-GCM before they touch our database, using a server-only encryption key that never reaches your browser or any client application.
Where your data is handled
StreamFirefly is operated from British Columbia, Canada. The data described in this policy is stored and processed by our infrastructure providers, which may be located outside Canada — including in the United States — and may therefore be subject to the laws of those countries. By using StreamFirefly you consent to that transfer.
Your rights
You can request deletion of your data at any time by emailing us (see Contact below). When you do:
- Your display name on past redemptions is replaced with "[deleted]".
- Your points balance is deleted.
- Your viewer account record is deleted.
- Past redemption records are kept for the streamer's records, but with your identity anonymized.
Streamers can delete their entire account from the dashboard settings page, which removes their shop, items, uploaded media, connected platform tokens, and viewer balances.
Disconnecting a platform from your streamer dashboard removes that platform's stored tokens immediately and, where the platform supports it, revokes our authorization on the platform itself; disconnecting YouTube specifically also deletes its live chat poll cursor right away.
Third-party platforms
Twitch, YouTube (Google), Kick, and Spotify are independent data controllers for the data they collect through their own apps. Please review their respective privacy policies to understand how each platform handles your data outside of StreamFirefly.
Changes to this policy
If we make material changes to this policy, we'll update the effective date above and, where required, notify connected streamers directly.
Contact
Questions or deletion requests: privacy@streamfirefly.com