This Privacy Policy explains how HALFORD SUCKS LTD, company number 14173794 (“Company”, “we”, “us”, or “our”) collects, uses, stores and protects information in connection with the Streamneeds platform, website, software, applications and related services (the “Services”). By accessing or using Streamneeds, you acknowledge and agree to the practices described here.
1. Who we are
Streamneeds is operated by:
- HALFORD SUCKS LTD
- Company Number: 14173794
- United Kingdom
- Contact: streamneeds@sucksmedia.com
2. Information we collect
2.1 Account information
When you register for or use Streamneeds, we may collect:
- email address;
- a password — only for accounts that sign in with a password (e.g. moderator accounts); passwords are stored as a one-way bcrypt hash and are never stored or visible in plain text;
- display name and avatar / profile image;
- your Kick username, where used to authenticate the chat bot;
- subscription details — your plan tier, status and trial dates, and a Stripe customer / subscription identifier (see Section 3);
- optional onboarding details you choose to provide, such as a Discord or Telegram contact handle, plan interest, and how you heard about us.
Account sign-in is provided through Google OAuth and/or email-and-password credentials. Where you sign in with Google, we receive your basic profile details (such as email, name and image) from Google in order to create and authenticate your account.
2.2 Platform integration information
Where you connect third-party services to Streamneeds, we may collect and store:
- Discord account identifiers, usernames and display names;
- Kick account identifiers, usernames and display names;
- Twitch account identifiers, usernames and display names;
- Twitch and YouTube channel identifiers, channel names / handles and channel profile images;
- OAuth access and refresh tokens for the platforms you authorise (e.g. Kick, Twitch, YouTube), stored encrypted and used solely to read and send messages and perform actions on your behalf — we never receive or store your platform password;
- channel / stream information and related integration metadata.
If you configure stream alerts, we may also process inbound event data sent to us from third-party platforms including Twitch and YouTube (for example follows, subscriptions, tips, super chats and chat events) so we can display alerts. We never receive or store your password for any connected platform. Where you connect a YouTube channel, Section 7 sets out in full what YouTube data we access, how it is used, and how you can revoke our access.
2.3 Viewer and engagement information
Streamneeds processes viewer and engagement information on behalf of creators using the Services, including:
- viewer usernames, display names, avatars and platform user IDs;
- chat messages. When a creator connects their channels, chat messages sent in those channels — on Discord, Kick, Twitch and Hype (casino-site chat) — are stored in our database. A stored message includes the message text, your username and display name, your platform user ID, the channel, a timestamp and, where your message is a reply, the name of the person you replied to and a preview of their message. Stored chat is retained for 30 days and then automatically deleted (see Section 10). You can opt out and erase your stored chat at any time — see Section 11;
- chat activity and message counts;
- participation and engagement data — points balances, gifted subs, giveaway and raffle entries, store purchases, slot requests and balance guesses;
- moderation activity (e.g. bans, flags and related notes).
Viewers may also voluntarily provide additional details through features a creator enables, such as casino account usernames, cryptocurrency wallet addresses, affiliate codes, and — where a creator ships physical prizes — a name and postal address. We do not collect casino passwords or account balances.
These details are only ever collected through a form hosted on streamneeds.com. When a viewer asks for it (for example with /myinfo), the bot sends them a private, single-use link to that form. The bot does not collect personal details through Discord messages or direct messages, and it does not read direct messages at all.
For viewer data, the creator is the data controller and Streamneeds acts as a data processor on the creator’s instructions. Creators are responsible for telling their viewers what data they collect and for having a lawful basis to do so in their jurisdiction.
2.4 Discord data
Where a creator invites the Streamneeds bot into their Discord server, the bot reads the following data about members of that server:
| What we read | Why | Retention | Who can see it |
|---|---|---|---|
| Messages you post in connected servers — text, username, display name, Discord ID, channel and timestamp, plus the quoted author and message preview when you reply | Bot commands, chat points, automated moderation, poll votes, live cross-platform chat in the creator’s dashboard and overlays, and support-ticket transcripts | 30 days; ticket transcript content is kept for 12 months after the ticket closes | The creator and their moderators; live chat can also appear on the creator’s public overlay and stream (see Section 7) |
| Server join events (username, display name, avatar) | On-stream “new member” alerts, on plans that include them | Relayed in real time; a log entry is kept for 90 days | The creator, their moderators and their stream viewers |
| Member details — account-creation date (derived from your Discord ID), the date you joined the server, and your roles | The creator’s verification / anti-alt gate (minimum account age, minimum membership duration, role checks) | While the server is connected; purged 30 days after the bot is removed (see Section 10) | The creator and their moderators |
| Reactions (the 🎉 emoji and configured reaction emoji) | Giveaway entries and reaction-based chat points | Kept as giveaway entries and point transactions so results and balances stay auditable | The creator and their moderators |
| A per-account record — your Discord ID, account-creation date, first-seen date and a count of servers where you have been banned from bot features. Your per-server profile also records the time of your last message | Abuse prevention and moderation: detecting throwaway accounts, ban evasion and inactivity | Until erased on request (see Section 11) | Creators’ moderators, via moderation commands (see the cross-server note below) |
The per-account record above is created the first time you interact in any connected server and is shared across servers that use Streamneeds.
Cross-server ban reputation. When a creator bans you from bot features, a ban record is created and a global count of such bans is incremented. Moderators in other connected servers can see that count and the servers involved through moderation commands. Automatic enforcement (denying verification once the count passes a threshold) is enabled by default for every connected server — each creator can disable it, or change the threshold, for their server.
Chat messages and join alerts are relayed in real time through Pusher, our real-time messaging sub-processor (see Section 6), to render the creator’s dashboard and overlays.
2.5 Technical and usage information
We may automatically collect technical information including:
- IP addresses;
- browser and user-agent information;
- request, activity and diagnostic logs;
- a probabilistic device fingerprint derived from hardware and browser characteristics (such as GPU, screen and timezone), collected when your overlay renders or you use the app.
This information is used primarily for security, rate limiting, abuse prevention and debugging. The device fingerprint is used solely to detect sharing of a single subscription across multiple people — a legitimate-interest basis (abuse prevention); we never use it for advertising and never sell it. Streamneeds does not currently load third-party web analytics products (such as Google Analytics) on the site.
2.6 Uploaded content
You may upload files, graphics, overlays, logos, media and related assets through the Services. Uploaded files are stored using our hosting provider’s blob storage. You remain solely responsible for all content you upload.
2.7 Booking a call with us
Our booking pages (/book/[handle]) let you schedule a call with a member of our team without creating an account. When you book, we collect and store:
- the name you enter;
- your email address;
- your timezone, detected from your browser, so times are shown and sent to you in your own local time;
- an optional free-text note — please don’t include sensitive information in it; and
- the slot you chose and whether the booking is still live or cancelled.
We use this solely to schedule and run the call and to email you about it. On booking (and on any reschedule) we send you a confirmation email containing a calendar invite (.ics) — your note, if you left one, appears in the invite’s description — and we email you a reminder about an hour before the call. If you cancel or reschedule, the team member you booked with is emailed your name, email address and the affected time. These emails are sent through Resend, our transactional email sub-processor (see Section 6). Our lawful basis is our legitimate interest in responding to a meeting you asked us for.
We check the email address you give against existing Streamneeds accounts. If it matches one, the booking is linked to that account and a note is added to that account’s internal customer record so our team knows a call is scheduled; that note forms part of the account record and is kept for as long as the account is. If it does not match an account, no such record is created.
Every confirmation and reminder email contains a private link that lets you reschedule or cancel the booking yourself — no login, and no further contact with us needed. Bookings are deleted automatically 12 months after the scheduled time (see Section 10), and you can ask us to delete yours sooner by email (see Section 11).
3. Payment processing
Streamneeds does not directly store or process payment card information. Payments are processed by Stripe, our third-party payment provider. We retain only billing metadata such as a Stripe customer ID, subscription ID and plan/status information. Your use of payment services is subject to Stripe’s own terms and privacy policy.
4. How we use information
We may use collected information to:
- provide and operate the Services;
- manage accounts and subscriptions;
- authenticate users;
- process billing and payments via Stripe;
- provide moderation and automation functionality;
- operate real-time overlays and live updates;
- send transactional email (e.g. verification and password reset);
- schedule, confirm and remind you about calls you book with us, and notify the team member you booked with of changes;
- maintain platform security and prevent abuse;
- investigate misuse;
- communicate account or service-related notices;
- improve platform features and performance; and
- comply with legal obligations.
4.1 Aggregated and anonymised data
We use gameplay and engagement data generated through the Services in aggregated and anonymised form for research, statistics, benchmarking, platform optimisation, product development and related business purposes. This includes, but is not limited to:
- bonus hunt data — hunts, entries, slot titles and providers, bet sizes, bonus opens, payouts, multipliers, run/break-even figures and hunt outcomes;
- slot and game data — which games are played, requested, banned or favoured, and how they perform;
- slot requests and other viewer-submitted requests;
- points, store, giveaway, raffle and guess-the-balance activity — volumes, distributions and outcomes;
- chat and engagement volumes — message counts and activity levels, not message content; and
- feature-usage data — which parts of the Services are used, and how often.
Before this data is used in that way it is stripped of identifiers, so that neither you, a viewer, nor an individual creator’s channel can be identified from it, and it is not combined with other information to re-identify anyone. Anonymised and aggregated statistics of this kind may be published, displayed in the Services (for example in game or slot statistics), shared with partners, or used in marketing and research material. Once data has been anonymised in this way it is no longer personal data, and this policy’s deletion and retention rules do not apply to it — erasing your personal data does not remove statistics that have already been aggregated.
Our lawful basis for this processing is our legitimate interest in understanding, improving and reporting on the Services. We do not sell your personal data, and we do not use it to train third-party AI models.
5. Cookies and similar technologies
Streamneeds uses cookies and similar technologies to:
- maintain authenticated user sessions;
- remember preferences (such as your light/dark theme);
- support core platform functionality.
These are limited to what is necessary to operate the Services. We do not currently use third-party advertising or analytics cookies. If we introduce analytics providers in the future, we will update this policy accordingly.
6. Third-party services and sub-processors
We rely on the following third-party services to operate the Services. Each is bound by its own terms and data-protection obligations.
- Vercel — application hosting and file/blob storage
- Neon — managed PostgreSQL database
- Railway — bot hosting
- Stripe — payment processing
- Pusher — real-time messaging; chat messages, alerts (including Discord join alerts) and live updates transit Pusher to reach dashboards and overlays
- Resend — transactional email
- Upstash — rate limiting
- Discord, Kick, Twitch — platform integrations you authorise
- Google / YouTube — Streamneeds uses YouTube API Services for its YouTube integration, and Google OAuth for account sign-in. Google’s handling of your information is governed by the Google Privacy Policy. See Section 7 for full details.
We are not responsible for the privacy practices of third-party services. You should review their privacy policies separately.
7. YouTube integration and YouTube API Services
Streamneeds uses YouTube API Services. This section applies where a creator connects a YouTube channel to Streamneeds, and to the viewers who take part in that channel’s live chat. It sits alongside — and does not replace — the rest of this policy.
By using the YouTube features of Streamneeds you are also agreeing to the YouTube Terms of Service. Google’s own collection and use of information is governed by the Google Privacy Policy, which we encourage you to read.
7.1 What we access when you connect a channel
Connecting a YouTube channel is separate from signing in to Streamneeds with Google, and uses a separate authorisation. We request a single YouTube permission scope, youtube.force-ssl, which allows us to read your channel identity, read your live chat, send messages to your live chat, delete live chat messages, and time out or ban viewers in your live chat. We do not request access to your videos, watch history, playlists, comments, YouTube Analytics or Google account data, and we never receive your Google password.
For a connected channel we store:
- your YouTube channel ID, channel title, channel handle (where you have one) and channel profile image;
- OAuth access and refresh tokens, encrypted at rest (AES-256-GCM) and used only to operate the features you have enabled;
- live-broadcast state needed to run the integration — whether the channel is currently live, and the identifiers of the current broadcast and its live chat;
- broadcast information already public on YouTube — stream title, category, thumbnail URL, concurrent viewer count, total like count, subscriber count and channel member count — used for goal widgets, overlays and your own stream analytics;
- the integration settings you configure yourself, such as points rates, chat commands and timed messages.
7.2 Viewer information we process from YouTube live chat
While a connected channel is live, Streamneeds reads that channel’s public live chat on the creator’s behalf and processes:
- the viewer’s YouTube channel ID, display name and channel profile image;
- the text of chat messages, their message identifiers and timestamps;
- chat status badges shown publicly in chat — channel owner, moderator, verified, and channel member (including the number of months of membership where YouTube provides it);
- Super Chat and Super Sticker events — the amount and currency, the message attached to it, the colour tier, and the event data YouTube supplied for it;
- gifted channel memberships — the number of recipients, the membership level name, and whether the gift was anonymous;
- counters derived from the above — total messages sent, lifetime and per-month Super Chat totals, gifted-membership totals, points balances and last-seen timestamps.
Chat messages read from YouTube live chat are stored in our database as part of the creator’s chat history, so the creator can view per-viewer chat history and moderation context in their dashboard. See Section 10 for how long this is kept. We do not receive viewers’ email addresses, Google account details, watch history or any information that is not publicly visible in the live chat itself.
As set out in Section 2.3, for viewer data the creator is the data controller and Streamneeds acts as a processor on the creator’s instructions.
7.3 Information on or from your device
The YouTube integration does not place cookies on viewers’ devices and does not read information from viewers’ devices. For signed-in creators, connecting a channel uses the same session cookies described in Section 5, and no additional YouTube cookies are set by us. Where a page inside Streamneeds embeds a YouTube video, that player is loaded directly from YouTube and Google may set cookies or store data on your device under the Google Privacy Policy — we do not control or receive that data.
7.4 How YouTube data is used, and who it is shared with
YouTube data is used only to operate the features the creator enables:
- displaying live chat in dashboard panels and OBS chat overlays, and keeping the creator’s chat history;
- awarding and tracking loyalty points, daily bonuses and active-viewer rewards;
- running chat features — commands, giveaways, raffles, slot requests, guess-the-balance and polls;
- firing on-stream alerts and updating overlay widgets (for example Super Chat, new member, gifted membership and goal widgets);
- automated and manual moderation of the creator’s own chat (see Section 7.5);
- stream analytics for the creator’s own channel — session summaries, chat activity and top chatters.
We do not sell YouTube data, do not use it for advertising, and do not use it to train third-party AI models. It is not shared with other creators. Beyond the creator whose channel it came from, YouTube data is disclosed only to the infrastructure providers listed in Section 6 that host, store and transmit it on our instructions (application hosting, database, bot hosting, real-time messaging), and otherwise only as described in Section 14 (Legal disclosures).
7.5 Actions we take on your behalf on YouTube
With your authorisation, and only for the channel you connect, Streamneeds can act in your live chat. Specifically, it can:
- post messages in your live chat — command replies, timed messages, announcements and alerts you configure — sent either from the shared Streamneeds bot account or, where required or configured, from your own channel;
- delete messages in your live chat; and
- time out or ban viewers in your live chat, where your automated moderation rules or your moderators call for it.
These actions are taken on your instructions, are subject to a daily send limit per channel, and stop as soon as you disconnect or revoke access.
7.6 Revoking access and deleting your YouTube data
You can end our access to your YouTube channel at any time:
- In Streamneeds — disconnect the channel from the YouTube integration page in your admin settings. This stops all chat reading, sending and moderation immediately and deletes the stored tokens.
- Through Google — revoke Streamneeds’ access from the Google security settings page at https://myaccount.google.com/permissions, which lists every third-party application with access to your Google account.
When you disconnect in Streamneeds, we delete the YouTube-sourced data we hold for your channel within seven (7) calendar days — the deadline set by the YouTube API Services Developer Policies for revocation through our own interface. In practice the work runs immediately as part of the disconnect; the seven days exist only so a temporary failure can be retried. Specifically, on disconnect we:
- revoke the access and refresh tokens with Google straight away, and delete them from our database;
- delete the YouTube live chat messages and the YouTube stream-event records (message, display name and event snapshots) held for your channel;
- clear the YouTube-sourced profile information we hold for each viewer of your channel — their YouTube display name, handle and profile image are removed. The points balances, giveaway entries and wins, purchases and other records those viewers earned in your community are ours to keep on your behalf and are not deleted, because they are records of our service rather than data we obtained from YouTube;
- strip the YouTube-supplied content from Super Chat and gifted-membership records — the supporter’s message text, the raw event data YouTube sent us and YouTube’s event identifiers are removed, while the amount, currency and count are kept as revenue statistics for your reporting, as the Developer Policies permit; and
- clear the cached information about your own channel — channel title, handle, profile image, subscriber and member counts, and any live broadcast identifiers.
If you instead revoke access from your Google security settings, we learn of it the next time our authorisation fails, and the same deletion runs within thirty (30) calendar days, the deadline the Developer Policies set for that route.
Separately, and whether or not you ever disconnect, a nightly job deletes YouTube live chat history and YouTube stream events older than 30 days, and strips the raw YouTube event data and message text from Super Chat and gifted-membership records older than 30 days. We do not retain YouTube-sourced data beyond 30 days unless your authorisation is still in place and the data is refreshed. Aggregated and anonymised statistics that no longer identify a channel or a viewer may be retained as described in Section 4.
One mapping is deliberately kept. For each viewer we retain a minimal link between their opaque YouTube channel ID and the loyalty record they hold in your community — no name, no profile image, no messages, no chat content. It exists for a single purpose: if the channel is disconnected by mistake and reconnected, viewers get their points, giveaway history and purchases back instead of losing them. The same opaque identifier is in any case attached to the loyalty record itself, so keeping this mapping does not expose anything further about a viewer. A viewer who does not want it kept can ask the creator whose channel they chatted in to have it removed, or contact us at streamneeds@sucksmedia.com.
These YouTube rules are faster than, not in conflict with, the general retention periods in Section 10. Section 10 describes an outer limit of up to twenty-eight (28) days for deleting account data when an account is closed; YouTube-sourced data is deleted within seven days of a disconnect made in Streamneeds and, in the ordinary course, within 30 days regardless. Where the two differ, the shorter YouTube period applies to YouTube-sourced data.
7.7 Questions and complaints about the YouTube integration
For any question, request or complaint about how Streamneeds handles YouTube data — including access, correction or deletion requests — contact us at streamneeds@sucksmedia.com. Full contact details, and details of your right to complain to a supervisory authority, are in Section 18.
8. Data shared through creator integrations and public pages
Creators can generate API keys and connect their own integrations (for example their website or a third-party service they use). API-key-gated endpoints return viewer data belonging to that creator — including viewer display names and platform user IDs, such as Discord IDs — to whatever integration the creator connects. This sharing is directed by the creator, is limited to that creator’s own community data, and each key carries scopes limiting what it can access.
Creators’ overlay pages (/o/[slug]) are public and do not require login — they are designed to be loaded in streaming software. Where a creator adds a live-chat widget to an overlay, chat messages (including usernames and message text) are rendered on that public page in real time and are typically visible on the creator’s stream. Other creator pages, such as leaderboards, stores and public hunt pages, can likewise display viewer usernames and engagement data at the creator’s direction.
9. Data storage and security
We implement reasonable technical and organisational measures designed to protect information against unauthorised access, misuse, disclosure, alteration and destruction. These include encryption in transit (TLS); encryption at rest at the storage layer, provided by our database provider (Neon); additional application-level AES-256-GCM encryption of platform integration tokens; bcrypt hashing of passwords; scoped access controls and audit logging. Our primary database is hosted on Neon in the EU (eu-west-2) region. However, no method of transmission or storage can be guaranteed to be completely secure, and use of the Services is at your own risk.
10. International users
Streamneeds is available globally and is operated from the United Kingdom. By using the Services, you understand and agree that information may be transferred, processed and stored in jurisdictions outside your country of residence, including the United Kingdom, the European Economic Area and the United States. Where required, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
11. Data retention
We retain information only for as long as reasonably necessary for the operation of the Services, legal obligations, security, dispute resolution, fraud prevention, enforcement of agreements and legitimate business interests. Specific retention periods, enforced by automated daily jobs:
- Chat messages (Discord, Kick, Twitch and Hype), including reply previews — deleted 30 days after they were sent;
- Support-ticket transcripts — message content deleted 12 months after the ticket closes (the ticket record itself is kept for audit);
- Raw platform webhook payloads for Twitch cheers and gifted subs — scrubbed after 30 days (aggregate statistics are kept);
- Activity and diagnostic logs — deleted after 90 days;
- Discord server data — purged 30 days after the bot is removed from a server; re-inviting the bot within that window cancels the purge;
- Twitch channel data — purged when the channel is disconnected or the authorisation is revoked;
- YouTube data — chat and channel data follow the shorter retention and deletion rules in the YouTube section above, and are purged when the channel is disconnected or access is revoked;
- Call bookings (your name, email, timezone and note) — deleted 12 months after the booked time, whether the call went ahead or was cancelled. Cancelling a booking stops the emails immediately, but the row is removed on that same schedule; ask us if you want it gone sooner (see Section 11).
Where a creator deletes their account through the account page, deletion is processed immediately on confirmation: their data — including their community’s stored chat — is deleted, and activity-log rows are anonymised rather than deleted so security audit trails remain intact. Certain information may be retained where reasonably necessary for legal, security or compliance purposes.
12. Erasure, amendment and your rights
Depending on applicable law and your jurisdiction, you may have rights to request access to, correction of, deletion of, or a portable copy of your personal information, and to restrict or object to certain processing. There are five ways to exercise erasure and amendment:
- In chat: run
/forgetmein Discord, or type!forgetmein Kick or Twitch chat. After confirmation, this deletes your stored chat messages for that creator’s community, removes previews of your messages quoted in other people’s replies, blanks the content of ticket messages you wrote, and stops your future chat from being stored there; - Through the creator: creators and their moderators can erase a viewer’s stored chat data from the viewer’s admin page;
- Amendment: details you submitted through a viewer info form (such as casino usernames or wallet addresses) can be viewed and updated through your personal form link — request it with
/myinfoin Discord; - Call bookings: use the private link in your confirmation or reminder email to cancel the call. Cancelling stops all further emails about it; email us if you also want the booking record deleted before its 12-month retention period ends;
- By email: send requests to streamneeds@sucksmedia.com. We action erasure requests within 30 days.
Chat erasure does not remove points balances, point-transaction history, purchases or linked-account records — these are retained so that balances, prize records and audit trails remain intact. Erasure also does not affect anonymised, aggregated statistics that no longer identify you (see Section 4.1), because those cannot be traced back to you. We may verify your identity before processing a request. For viewer data, the creator whose channel you interacted with is the data controller (see Section 2.3), so you may also contact them directly.
13. Eligibility and user responsibility
You are solely responsible for ensuring that your use of Streamneeds complies with the laws, regulations and eligibility requirements in your jurisdiction. The Company accepts no responsibility for unlawful or non-compliant use of the Services.
14. User responsibility for content
You are solely responsible for all content, uploads, files, messages and activity processed through the Services. The Company does not actively monitor all activity, does not endorse user content, and accepts no responsibility or liability for user-generated content or creator activity.
15. Legal disclosures
We may disclose information where reasonably necessary to comply with applicable laws, respond to lawful requests, enforce agreements, investigate misuse, prevent fraud or abuse, protect platform integrity, or protect the rights, safety or security of the Company, our users or third parties.
16. Children
The Services are not directed at children under 18 and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
17. Changes to this Privacy Policy
We may modify or update this Privacy Policy at any time. Continued use of the Services following an update constitutes acceptance of the revised policy.
18. Contact
For privacy-related enquiries or requests, contact:
- streamneeds@sucksmedia.com
- HALFORD SUCKS LTD
- Company Number: 14173794
- United Kingdom
If you are in the UK and believe we have not handled your data correctly, you also have the right to complain to the Information Commissioner’s Office (ico.org.uk).