Bloopbot
Privacy Policy
What personal data Bloopbot holds, why it holds it, how long it keeps it and what you can ask us to do with it.
Draft pending legal review. This document is written by the team that builds Bloopbot and has not been reviewed by a qualified lawyer yet. It is published now so that it describes what the software really does.
Who we are
Bloopbot is a chat bot and stream-automation product for Twitch, operated as a sole trader in the United Kingdom. For the personal data described in this policy, the controller is:
[TO CONFIRM: the sole trader’s full legal name]Trading as Bloopbot[TO CONFIRM: a postal address where legal notices can be served]Email: [TO CONFIRM: a support and privacy contact email address]Product: https://bloopbot.com[TO CONFIRM: whether the trader is registered with the UK Information Commissioner’s Office as a data controller, or is exempt, and if registered, the registration number.]
This policy explains what personal data Bloopbot holds, why it holds it, how long it keeps it and what you can ask us to do with it.
This policy is written for the service at https://bloopbot.com. If you reached Bloopbot on a different address, a different organisation may be the controller: [TO CONFIRM: how a visitor of another installation finds its controller].
The personal data we collect
Bloopbot only works after you link a Twitch account, so most of what it holds starts with that link. The categories below are the ones the running code stores.
| What it is | Why we have it |
|---|---|
| Your Twitch account: Twitch user id, login, display name, the OAuth scopes you granted, and the times your link was created, updated, revoked or re-authorised | To sign you in, to know which channel you are allowed to manage, and to tell you when a permission is missing |
| Twitch OAuth access and refresh tokens for your channel | To act on your channel through the Twitch API: chat, events, moderation, channel points, clips, markers, polls, predictions and schedule |
| Your bot account(s): Twitch user id, login, display name, granted scopes and that account’s tokens | To send chat messages and run the actions your flows ask for |
| Editor records and invites: an editor’s Twitch user id, login and display name, who invited them, and a hashed, single-use, seven-day invite token | To let the people you choose help run your channel, and to expire unused invitations |
| Channel configuration: built-in command settings, keywords, moderation filters and escalation settings, nuke reports with the moderator who ran them, the channel’s own Regulars and custom role lists with their members, song-request settings and blocked-user lists | So your channel behaves the way you configured it |
| Viewer data for your channel: loyalty points balances and lifetime totals, watch time, subscriber flags, giveaway entries and tickets, quotes and who added them, and the song queue with who requested each track. Whether a viewer is a VIP or a moderator is read from Twitch when a message arrives and is not stored by Bloopbot | To run the loyalty, giveaway, quote and song-request features you enable |
| Flow data: the flows and flow versions you build (including their author), run logs with each step’s outcome, per-viewer flow variables, and the small amount of channel data flows remember from events | To run your automations and to show you what happened |
| Audit log: who changed what in your dashboard (a Twitch user id, login, the action, the entity and a summary), the time, and nothing else | So you can see who changed your channel settings |
| AI usage records: per channel, per AI feature, per day, the number of requests and the input volume billed | To meter AI features and keep them inside their limits |
| Widget and overlay credentials: hosted widget keys, uploaded widget media with its original file name, per-channel overlay, alerts and live-source read tokens | To serve your OBS overlays and widgets and to let them read your channel’s data |
| Spotify data, only for channels that connect Spotify: your Spotify app client id and encrypted secret, the linked account’s id, display name, scopes and tokens | To search for and queue the songs your viewers request |
| Content you send to our AI features: the chat message or text being judged, and the question or criteria you wrote for it | To answer the AI step in your flow |
| Public-site measurement: page views and the page address, clicks, demo selections, guide search terms and a yes/no “was this guide helpful?” answer — and only if you accept measurement | To understand which pages and guides are useful. See “Cookies and measurement” below |
| Backup sign-in email, only if you add one: the address, your Twitch user id, login and display name, when it was saved and when you confirmed it, and a one-way hash of each confirmation or sign-in link with the address it was sent to | To let you sign in to your dashboard by email when Twitch sign-in is not working, and to tell you when the address changes or is removed |
| Operational logs: application logs that include your Twitch login when your dashboard performs an audited action, and a channel id in maintenance messages | To diagnose faults and to keep an audit trail of changes |
We do not ask for your real name, your postal address or your payment details. If you choose to add a backup sign-in email, we store that address from the moment you save it, and use it only to send you the link that confirms it, sign-in links, and notices about changes to it. Only a confirmed address can sign you in. It is deleted when you remove it under Account, or when you unlink your channel’s Twitch account, together with the records of the links sent to it.
Why we use it, and the lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, linking your Twitch channel, and providing the features you switch on | Performance of a contract with you |
| Keeping your channel and your viewers safe: moderation filters, screening, anti-spam, cooldowns and rate limits | Legitimate interests — protecting your channel and our service from abuse, and keeping chat usable |
| Sending your channel’s chat content to an AI feature you enabled, under the settings you chose | Performance of a contract with you, or your consent where the feature is optional and opt-in |
| Sending sign-in links, confirmation links and notices about changes to your backup sign-in email | [TO CONFIRM: lawful basis for the backup sign-in email — contract, or legitimate interest for security notices] |
| Recording audited changes to channel settings, so owners and editors can see who changed what | Legitimate interests — accountability for changes to a channel, and our own security |
| Measuring visits to the public website and the guides | Consent — the measurement tag is not loaded at all until a visitor accepts it |
| Fault diagnosis, security and capacity: operational logs, error reports and metrics | Legitimate interests — keeping the service working, secure and free of abuse |
| Answering your support and data-protection requests | Legal obligation or legitimate interests, depending on the request |
| Complying with tax, accounting and lawful-request obligations | Legal obligation |
Where we rely on legitimate interests we have weighed our interest against your rights and expectations: the data involved is what Bloopbot needs to run one Twitch channel, it is not used to profile you, and it is never sold or rented.
We do not use your data for automated decisions that have a legal or similarly significant effect on you. AI steps in a flow do make judgments about chat messages, but the consequences are moderation actions inside one Twitch channel and are always under a human streamer’s control — see “AI features” in our Terms. [TO CONFIRM: whether any AI moderation outcome needs a UK GDPR Article 22 statement.]
[TO CONFIRM: the lawful basis for any purpose added after this draft, for example billing or marketing email.]
Viewers, streamers and who is responsible
Bloopbot is used by a streamer, but it also processes data about that streamer’s viewers: chat messages, loyalty points, watch time, giveaway entries, quotes, song requests and moderation history.
The streamer decides how their channel is configured — which features are on, which filters run, what the loyalty and giveaway rules are, and what the AI is asked to judge. For that viewer data Bloopbot processes information on the streamer’s behalf: the streamer is the controller and Bloopbot is their processor, except where we act as an independent controller for our own security, abuse prevention and service operation. [TO CONFIRM: the processor/controller split and the data-processing terms offered to streamers.]
If you are a viewer and you want to know why a message was moderated, what points you have, or to have your viewer data removed, the streamer of that channel is the fastest route — they can see and change their channel’s data. You can also contact us, and we will pass the request on and help the streamer answer it.
If you are a streamer, you are responsible for the notices you give your own viewers about your channel, and for making sure you have a lawful reason to run the features you switch on.
Who else processes it
We do not sell personal data, and we do not share it for advertising. We use the following services, each under its own terms, and each only for the purpose listed:
| Service | What it does | When it is used |
|---|---|---|
| Twitch | Sign-in, channel linking, chat, events, moderation and channel actions. Twitch is the source of most of the personal data in the product | Whenever a channel is linked |
| Spotify | Searching for and playing requested songs through the streamer’s own Spotify developer app | Only for channels that link Spotify |
| Google Analytics | Counting visits to the public website and the guides, and the guide feedback answer | Only on public pages, and only after a visitor accepts measurement |
| TypeSafe | The AI judge that answers AI steps in a flow: the text being judged and the streamer’s question are sent as the state of the request | Only for channels with an AI feature switched on |
| OpenRouter | An alternative transport for the same AI judge, used when it is configured instead of TypeSafe | Only for channels with an AI feature switched on, and only if configured |
| Cloudflare R2 | Storing uploaded widget media when object storage is enabled instead of local disk | Only when that storage is enabled and a channel uploads media |
| Cloudflare Email Service | Delivers sign-in and security emails: the backup sign-in email address and the message sent to it. [TO CONFIRM: data-processing agreement] | Only for accounts that add a backup sign-in email |
The hosting, database, cache and message-broker infrastructure that runs the service is operated for us on infrastructure we choose. [TO CONFIRM: the hosting provider(s), their role, their region and their data-processing agreement.]
We also disclose personal data where the law requires it, or where we must protect the rights, safety or security of a person or of the service.
[TO CONFIRM: whether any service above is a sub-processor, the data-processing agreement in place for each, and any others (for example error tracking or payments) that a live deployment uses.]
Where your data goes
[TO CONFIRM: whether any of the services in “Who else processes it” store personal data outside the UK or the European Economic Area, and in which countries. The services are global platforms, so a transfer outside the UK/EEA is likely, but this policy does not assert one until it is confirmed.]
[TO CONFIRM: the transfer safeguard relied on for each provider that does process data outside the UK/EEA — for example the UK International Data Transfer Agreement or Addendum, the EU standard contractual clauses, or a UK/EU adequacy decision — and where that safeguard is recorded.]
You can ask for more detail about the safeguard used for a particular service by contacting us.
How long we keep it
Bloopbot deletes data through the paths below, each of which is enforced by the code that stores it:
| What it is | How long it is kept |
|---|---|
| Sign-in and account-linking handshake state | Ten minutes; it lives in memory and is never written to the database |
| Editor invites | Seven days, single use, and revocable at any time |
| Dashboard sessions | Thirty days of inactivity by default, and expired sessions are removed |
| Backup sign-in email links | Each works once; a sign-in link expires after 15 minutes and a confirmation link after 24 hours. Only a one-way hash is stored, and the record is deleted seven days after the link expires or is used |
| Audit log entries | The 200 most recent entries for a channel; older entries are deleted as new ones are written |
| Flow run history | The 50 most recent runs for each flow, and never longer than seven days |
| Flow versions | The 50 most recent versions of each flow |
| Per-viewer flow variables | Ninety days after the last time the viewer’s value changed |
| Flow webhook credentials | Until the flow is moved to the Trash; deleting the flow stops its trigger URL working |
| Public-site measurement | Held by Google, not by us; the Google Analytics property is configured to keep event data for [TO CONFIRM: the GA4 data-retention period set on the property] |
Everything else in the table under “The personal data we collect” is kept while the channel is linked, because that is the data the features read and edit. Unlinking a channel deletes the channel’s rows, and the rest of the data follows it. Retention windows for the categories below are not enforced by the service today, so instead of stating a period we are asking for legal review:
- Loyalty balances and watch time, giveaway history, quotes and the song queue: [TO CONFIRM: the retention period or age-out rule, or a decision that these are kept for as long as the channel is linked].
- AI usage records: [TO CONFIRM: the retention period for the per-day AI request counters].
- Revoked overlay and widget tokens, and old invite rows: [TO CONFIRM: whether these need a stated retention window].
- Operational logs and any backups: [TO CONFIRM: the hosting provider’s log and backup retention, and what is copied to them].
Your rights
If you are in the UK or the EEA you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Rectify data that is wrong or incomplete.
- Erase your data (the “right to be forgotten”).
- Restrict how we use it while a concern is looked into.
- Port data you gave us to another provider, in a machine-readable form.
- Object to processing based on our legitimate interests, and to any direct marketing.
- Withdraw consent at any time where we relied on consent — accepting or rejecting measurement is the everyday example, and withdrawing it never affects the rest of your account.
To exercise any of these rights, email [TO CONFIRM: a support and privacy contact email address] with enough detail for us to find your data (your Twitch login, and the channel if you are asking about a channel you do not own). If you are a viewer, we may need to involve the streamer of that channel, because the data sits inside their channel.
We answer within one month. If a request is complex we will tell you why and take a further two months. Asking us to use your rights is free, and we will not treat you differently for doing it.
[TO CONFIRM: the internal procedure and identity checks for answering access, objection and erasure requests, and the lawful reasons we may rely on to refuse a request.]
Complaints
If you are unhappy with how we have handled your data, please contact us first so we can put it right.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection, at ico.org.uk or on 0303 123 1113. If you live in the EEA you can complain to your own national regulator instead.
Children
Bloopbot is for people aged 13 or over. We do not knowingly collect data from anyone under 13, and we will delete any account we find that belongs to a child below that age.
Linking a channel needs a Twitch account, and Twitch applies its own minimum age, which is 13. Because viewer data belongs to a streamer’s channel, a streamer must not knowingly use Bloopbot on a channel whose viewers include children below 13.
[TO CONFIRM: whether any feature needs an age assurance step, and the deletion procedure for a discovered under-13 account.]
Security
Tokens, Spotify client secrets and integration credentials are encrypted in the application before they are stored, and the keys that decrypt them are held in the service’s configuration rather than in the database.
The audit log deliberately never records tokens, secrets, overlay token values, CSRF tokens or session identifiers. Tokens can be revoked by unlinking an account, rotating a widget or overlay token, or moving a flow to the Trash, and revoked overlay tokens stop working.
No service can promise perfect security. If we ever become aware of a breach that puts your rights at risk, we will tell the ICO and the people affected without undue delay, as the law requires. If you think you have found a security problem, email [TO CONFIRM: a support and privacy contact email address].
We do not sell your data
We never sell, rent or trade personal data, and we do not share it for advertising. We do not build advertising profiles, and we do not sell data to data brokers.
[TO CONFIRM: whether any future monetisation (for example a paid plan with a payment provider) needs to be disclosed here.]
Changes to this policy
This policy takes effect on 26 September 2026. When we change it, we update that date and list what changed. If a change is material — for example a new category of data or a new service that processes your data — we will tell you in the dashboard before it takes effect.
Older versions are available on request.
How to contact us
For anything in this policy — a question, a request or a complaint — contact:
[TO CONFIRM: the sole trader’s full legal name]Trading as Bloopbot[TO CONFIRM: a postal address where legal notices can be served]Email: [TO CONFIRM: a support and privacy contact email address]Product: https://bloopbot.comOur Terms & Conditions at https://bloopbot.com/terms explain the rules for using Bloopbot.