Privacy Policy
What data Chatlybot processes, whose, why, with which third parties, for how long, and how to exercise your rights.
1. Data controller
Itsemmagt, a natural person domiciled in the United States, is the controller of the data of Chatlybot users. Contact: [email protected].
2. Data of service users (streamers)
When you create an account and connect your channels, the service processes:
- Your email address and a session identifier (Firebase Authentication), and the name and photo you choose to show.
- The identity of each connected channel: username, display name, profile image and the permissions you grant on Twitch, Kick or Spotify. From TikTok only the profile is read (identifier, username, display name and photo) to confirm the account is yours; the access TikTok grants to read it is used once and revoked immediately, never stored.
- The access tokens for those platforms and, if you use restreaming, the stream key of your destination channel, encrypted with AES-256-GCM in the application and stored in a collection that no browser can access. They are never shown or sent to the panel.
- The configuration of your bot and channel: AI personality, commands, points, giveaways, alerts, overlays, songs, voice, and the files you upload for your alerts and as your profile photo.
- Your links page (name, bio, photo, links and their aggregated click statistics).
- The knowledge base you write for the bot (Pro plan) and your channel's time zone, used to split the days of your analytics.
- What you use of the service: what each use of artificial intelligence on your account costs, per day and per hour, and what it is used for (chat, assistant, seeing and hearing, memory and voices); the AI chat replies of each day; the type of each question to the assistant (help, data, change, small talk…), which is counted without its text; the seconds restreamed per day and per month, and the plan you are on.
- Your conversations with the panel assistant —your questions, its answers and a summary of the changes it proposed to you—, which are stored in your account so you can see them from any browser. The answers may include names and messages of viewers of your channel that the assistant looked up.
- If you use restreaming, the log of each session: source, destination, start, end, duration and why it ended.
3. Data of viewers (third parties)
When you enable the bot in your channel, the service processes public data of the people taking part in your chat, on your behalf and for the features you choose to enable:
- Their username and display name on the platform.
- Their watch time and activity in each stream, in 15-minute blocks: minutes watched, messages, commands, redemptions and contributions. On Twitch, whoever is connected to the chat is counted; on Kick, by their activity (chatting, redeeming or contributing); on TikTok, from when they join the room (TikTok reports joins, not departures) and by their activity. It is used for your channel analytics and for the assistant in your panel.
- Chat messages that add something (questions, mentions and conversation). The rest —lone emotes, "lol", spam and commands— is only counted, without keeping the text. For messages repeated in a chain (copypastas), a short sample of the text is also kept, without mentions or links and without saying who wrote it, to recognize the repeated text. When the platform reports a moderation action, what it affects is also deleted from the archive and from what the bot remembers of the current stream: on Twitch, the messages a moderator deletes and whatever whoever gets a timeout or a ban wrote in the previous 48 hours; on Kick, whatever whoever gets a timeout or a ban wrote in the previous 48 hours, which also leaves the overlay chat. TikTok does not report moderation actions.
- Stream events with their username (new followers, subscriptions, gifts, redemptions, polls…), shown in alerts and overlays and used for the rankings and analytics. The chat tops (who gifted or contributed the most in the stream, the week or the month) are a public ranking of the channel: they are shown in the chat and in the overlays.
- Their points, only if you enable the points economy; their participation in giveaways and their song requests.
- The bot's memory. When each stream ends, an AI model summarizes it, notes its key moments and records, for whoever chatted, what they said about themselves (what they like to be called, their favorite game…): a few short facts, at most 5 on Free and 20 on Pro, that the bot uses when replying to them. On Pro, the channel's memories (summaries, moments and facts) and your knowledge base are also stored as vectors, with a snippet of their text and, if any, who they name, so the bot can search them when a message asks about the past or about the channel; that search turns the message that triggers it into a vector. Health, religion, sex life or orientation, political views or origin, age, contact or location details, and anything about other people are never kept.
- The live state of the stream (viewers, likes), which is overwritten on each stream and deleted with your account.
In this processing you, as the streamer, are the controller: you decide to enable the bot and which features it uses in your channel. The provider acts as a processor on your behalf and only to provide you the service.
Any viewer can ask to be forgotten at any time by typing !borrarme in the chat, and you can do the same for them from the panel, even if they have no notes, with their username. Both ways work on Twitch, Kick and TikTok: in the panel, on Twitch and Kick it is in Brain → Memory, and on TikTok, which has no Brain, in Analytics → Forget a viewer. See "Your rights".
4. Purposes and legal basis
Data is processed only to:
- Provide you the service you signed up for, including the bot in your channel, the panel and the overlays (performance of the agreement with you).
- Show you the analytics of your own channel, give your channel's bot a memory (summaries of your streams and notes on your viewers) and answer what you ask the assistant using your channel's history.
- Apply the limits of your plan, prevent abuse and keep the service secure (legitimate interest of the provider).
There is no advertising, data is not sold and it is not shared with third parties for their own purposes.
5. Third parties that process data
To work, the service relies on providers that process data on behalf of the provider or as independent platforms:
- Google: Firebase (authentication, database and data hosting); BigQuery (the archive for analytics and the bot's memory: watch time, events, chat with signal and memories); Gemini (it writes bot replies, the summary and conversation topics of each stream and panel assistant answers, and for that it receives the same data described below for OpenAI); Google Cloud Text-to-Speech (the Google voices of the synthetic voice, which receive the text to be read); and the YouTube Data API (to search and resolve requested songs).
- Twitch, Kick and TikTok: the platforms whose stream events are read. On Twitch and Kick the bot also writes in chat on your behalf with the permissions you grant; on TikTok there is no bot and the service posts nothing. The synthetic voice —on any platform— is generated with TikTok's or Google's speech synthesis API, depending on the chosen voice, which receive the text to be read aloud. During restreaming, the video of your live stream passes through the provider's servers and is delivered to the destination platform: it is neither recorded nor kept.
- Spotify: only if you connect your own Spotify application to play the queue.
- Cloudflare: hosting of the panel and the links page, storage of the files you upload (R2), the AI gateway (AI Gateway) that calls to the models of TypeSafe AI, Workers AI, OpenAI (GPT-6 Luna and GPT-6.1 Sol) and Google (Gemini) go through, whose technical log keeps each call's model, tokens, cost, status and duration and, for a limited time, the text of the calls to GPT-6 Luna, GPT-6.1 Sol, Gemini and TypeSafe AI's classification model, which we use to review the quality of the service, fix errors and keep track of the costs, Workers AI (its bge-m3 model turns into vectors the channel's memories, the knowledge base and, on Pro, the messages that ask about the past or about the channel) and Vectorize (it stores those vectors, separately for each channel, with a snippet of the memory's text, its date, its type and, if any, the identifier of the person it is about, so it can be deleted with them).
- OpenAI: its GPT-6 Luna and GPT-6.1 Sol models write bot and panel assistant replies. For AI replies on Twitch and Kick they receive the message and the recent chat context; for the summary of each stream when it ends, that stream's chat messages with signal and its events, with the usernames that appear in them, and the notes of those who chatted; for the conversation topics of each stream, TikTok included, a short sample of the chat messages with signal, without mentions or links; and for the panel assistant, your question and a report of what the assistant looked up (data of your channel, including your viewers') and, if you attach it, a screenshot of your panel. Both are called through their API via Cloudflare's gateway, asking them not to store the replies; under its API policy, OpenAI does not use this data to train its models and keeps it for a limited time to monitor abuse (up to 30 days, unless the law requires longer). Its use is paid for by Chatlybot: OpenAI does not receive your account data.
- TypeSafe AI, directly and through Cloudflare Workers AI: a classification model that decides when and how to use AI in chat and in the panel assistant, and reviews what is about to be posted, without writing text. It receives the message or the question and the necessary context (in the assistant, the context of the conversation and data of your channel) and, before they go out, AI replies and what the bot posts on its own (your commands' replies and their automatic messages, the titles of requested songs and the name of a giveaway winner), the custom instructions you write for the AI, what the voice is about to read aloud and the names and messages shown in alerts and redemptions, together with whatever settings of your channel are needed. In all of that, it only receives a username when that is exactly what will be shown or said aloud: a giveaway winner's, the one shown in an alert or a redemption, the one the voice says if you have it announce who wrote the message, and any that is part of a text the bot is about to post (for example, a command reply that names whoever used it); never account identifiers. Its output may be used to not post or not read something, or to show a placeholder instead of a name. The record of that output keeps only probabilities, categories (such as the detected language) and the channel, never the text or the name.
- Mistral AI, through Cloudflare's gateway: only on paid channels that turn on «Hears your voice», it receives short pieces of the audio of their Twitch stream where someone is speaking, to transcribe them. It may include the voice of other people heard on the stream. The audio is not stored, not even in the gateway's log; the transcription lives a few minutes in the server's memory so the bot knows what was said and for voice commands («chatlybot, …»); the latest sentences are shown to the channel owner in their dashboard while they speak, and everything is discarded when the stream ends.
- The bot's sight: only on paid channels that turn on «Sees your screen», when a chat message asks about what is happening on the stream, the service takes a frame of their Twitch stream and sends it to an image classification model on Cloudflare Workers AI, which does not write text, and, when needed to answer, to the OpenAI or Google models that write the reply. Frames are not stored, not even in the gateway's log.
Chatlybot uses YouTube API Services. By using the music features you accept the YouTube Terms of Service and the Google Privacy Policy (linked below). Only public video metadata is queried; your YouTube account is not accessed.
- Google — Privacy Policy
- Firebase — Privacy and Security
- YouTube — Terms of Service
- Twitch — Privacy Notice
- TikTok — Privacy Policy
- Spotify — Privacy Policy
- Cloudflare — Privacy Policy
- OpenAI — Privacy Policy
- OpenAI — Enterprise privacy (API)
- TypeSafe AI — Privacy Policy
- Kick — Privacy Policy
- Mistral AI — Privacy Policy
6. How long data is kept
- Your account data, your configuration and your channel aggregates: for as long as the account exists. The figures in the analytics archive (no personal data), with the sample of repeated messages: 13 months.
- The live state of the stream: overwritten on each stream and deleted with your account.
- Chat messages with signal: 7 days on the Free plan and 30 on Pro. Watch time and events with a username: 90 days on Free and 13 months on Pro.
- Viewer notes: they expire 90 days (Free) or 180 days (Pro) after the person last chatted in your channel. Channel memories (summaries, moments and facts from each stream), with their vectors: 3 months on Free and 12 on Pro. The texts of each stream in your analytics (its summary, its topics and its questions) last the same; after that only its figures remain. The names of each month's most loyal viewers, as long as the watch time: 90 days on Free and 13 months on Pro.
- The log of AI calls (provider, model, tokens, time and result, without the text): 13 months.
- Conversations with the panel assistant: they are deleted automatically after 15 days without use on the Free plan and 60 on Pro, counted from the last message of each conversation (their messages at most 3 days later on Free and 12 on Pro), or earlier if you delete them yourself (one or all) or when you delete your account. For the ones you delete, only their identifier is kept, without any of their content, for 60 days, so they are not uploaded again from another browser.
- The record of who has asked to be forgotten (their platform identifier and when they asked, with nothing of what they said), which stops the bot from learning again what was said before and lets us check that the deletion was carried out: 30 days.
- The files you upload (including your profile photo, also when you replace it with another) live in separate storage (Cloudflare R2) that is not emptied automatically, not even when you delete your account: they are kept until you delete them yourself from "Your files", where they are deleted at once, or until you write to us and we delete them.
- Backups: up to 60 days.
- The restream session log: for as long as the account exists, like the channel aggregates.
7. Your rights and how to exercise them
You can access your data, correct it, ask for it to be deleted, object to a processing or request a copy of what you have provided: the copy, and anything the panel does not let you do directly, is requested by writing to [email protected].
The fastest way to delete everything of yours is from the panel: Account → Danger zone → Delete account. Deletion immediately removes your user, your channels, their data and your links page, and is irreversible; what your channels keep in the analytics and memory archive (BigQuery and Vectorize) is deleted on the next pass, within a couple of days at most. Uploaded files (sounds, images, videos and profile photos) are not deleted with the account: delete them beforehand from "Your files" or write to [email protected] and we will delete them.
If you are a viewer of a channel, type !borrarme in its chat. On Twitch and Kick the bot immediately forgets what it knows about you in that channel (its memory and your notes) and tells you so; on TikTok there is no reply (the service does not write in the chat there) and it is only recorded if the service is reading that stream's chat, which depends on what the streamer has turned on. Your messages, watch time, events and memories, with their vectors, are deleted from the archive on the next pass, within a couple of days at most; only a record that you asked remains, for 30 days. It does not touch the chat tops (a public ranking of the channel), the stream records, the latest events shown by alerts and overlays, your points, the channel's log of redemptions and commands, the streamer's conversations with their assistant (they expire on their own after 15 or 60 days), the history of requested songs, giveaways or the sample of repeated messages, which does not say who wrote them: for that, ask the streamer or write to us. On Twitch, Kick and TikTok, the streamer can also do it for you from their panel (Brain → Memory on Twitch and Kick; Analytics on TikTok), even if you have no notes, with your username. You can also ask them (they are the controller) or write to [email protected] indicating the channel and your username. We reply within an indicative period of 30 days.
8. Cookies and local storage
The service uses no tracking cookies and no third-party analytics tools.
The browser keeps, in its local storage, your preferences (theme, language, active platform), a copy of your conversations with the assistant (the cache of its history), the pending email when you sign in with a magic link and the Firebase Authentication session (in IndexedDB). They are necessary for the panel to work.
The overlay links you paste into OBS carry their own token in the URL. Treat it like a password: do not share it in screenshots or exported scenes; you can rotate it from Widgets.
9. Children
The service is not directed at children under 13. If you find that a child has created an account without consent, write to [email protected] and we will delete it.
10. Security
Access tokens and stream keys are encrypted in the application with a key that does not live in the database. Access to each channel's data is restricted by rules to its owner. All communication goes over HTTPS and sessions are managed by Firebase Authentication.
If a security incident affecting you occurred, we would notify you at your account email and in the panel.
11. International transfers
The service providers (Google, Cloudflare, OpenAI, TypeSafe AI and Mistral AI) host and process data on servers in the United States and the European Union, which may be outside your country, with the safeguards those providers offer in their own policies. The analytics and memory archive (BigQuery) is in the United States.
12. Changes to this policy
This policy may be updated. Relevant changes will be announced in the panel and the "last updated" date will change.
13. Contact
For any question about your data: [email protected].