Privacy Policy
Last updated: 16 August 2026
StreamWarm ("we", "us") provides chat-interactive overlay games for live streamers. This policy explains what data we collect, why, and what we do with it. We keep it deliberately short because we deliberately collect very little.
1. Who we are
StreamWarm, contact: hello@streamwarm.com. For privacy questions or requests, email us at that address.
2. What we collect
Account data
- Your email address — this is your account identifier. We use it to send one-time sign-in links and essential service messages.
- Session data — a random session identifier stored in a cookie so you stay signed in for 30 days per browser.
- Membership status and plan — whether your subscription is active, and which tier.
Payment data
- Payments are processed by Stripe. We never see or store your card details. We store a Stripe customer identifier and your subscription status so we know whether to grant access.
Streaming configuration
- Your YouTube channel ID — so the games know whose live chat to read.
- A launch token — a random identifier linking your OBS browser source to your account.
- Optionally, your own YouTube API key, if you choose to supply one instead of using our connection.
Usage data
- We use Google Analytics 4 to understand aggregate site usage (pages viewed, country, device type, referring source). We do not use it to identify individuals, and we have not enabled advertising features or demographic tracking.
3. YouTube API Services
StreamWarm uses YouTube API Services to make the games work. By using StreamWarm you also agree to the YouTube Terms of Service, and Google's handling of data is governed by the Google Privacy Policy.
What we access
- Your channel's current live broadcast — to know which stream is running.
- The live chat messages on that broadcast, and the public display names of the people who sent them.
What we do with it
Chat messages are used as gameplay input: a viewer types an answer or a vote, and the game scores it and shows the result on your stream overlay. A viewer's public display name may appear on the on-screen leaderboard next to their score. This is visible only to people watching that same live stream.
What we do not do
- We do not store YouTube data in a database. Chat messages and display names exist only in the browser's memory while the game is running, and are discarded when the browser source is closed.
- We do not post, moderate, edit or delete anything on your channel — our access is read-only.
- We do not sell, rent or transfer YouTube data to third parties.
- We do not use YouTube data for advertising or ad targeting.
- We do not build profiles of viewers or track them across streams.
Your control
StreamWarm reads only public live chat data using an API key — we never ask you to grant Google account permissions, so there is no Google authorisation to withdraw. To disconnect StreamWarm from your channel at any time, use the Disconnect from my channel button on your Stream setup page. This immediately deletes your launch links and stops all chat access. You can also email us to delete your account entirely.
If you supplied your own YouTube API key, deleting that key in your Google Cloud console also revokes access immediately. You can review permissions granted to any application at the Google security settings page.
4. Service providers we use
- Cloudflare — hosting, content delivery, and data storage.
- Stripe — payment processing and subscription billing.
- Resend — delivery of sign-in links and service email.
- Google — YouTube API Services and Google Analytics.
These providers process data on our behalf under their own privacy terms. We do not sell your personal data to anyone, ever.
5. How long we keep data
- Account data — for as long as your account exists, and up to 12 months after cancellation in case you return.
- Sign-in links — expire within minutes of being issued.
- Sessions — 30 days, then expire automatically.
- YouTube chat data — not retained; held in memory only during a live session.
- Analytics — 14 months, then deleted by Google automatically.
- Payment records — retained by Stripe as long as required by financial and tax law.
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict how we use it. Email hello@streamwarm.com and we will action reasonable requests promptly and free of charge.
Because we identify accounts by email address alone, account deletion is straightforward: we remove your email, membership record, launch tokens and channel configuration.
7. Cookies
We use a single essential cookie to keep you signed in. Google Analytics sets its own cookies for aggregate measurement. We do not use advertising or cross-site tracking cookies.
8. Children
StreamWarm is not intended for children under 13 (or the minimum age required in your country), and we do not knowingly collect their data.
9. Changes
If we change this policy materially, we will update the date at the top and, where the change affects you meaningfully, tell you by email.