PRIVACY POLICY FOR ONESTARLIVE

Effective Date: July 11, 2026

OneStarLive is a Twitch Extension and related web services operated by OneStarLive ("OneStarLive," "we," "us," "our"). This Privacy Policy explains what information we collect, how we use it, how we share it, how long we keep it, and the choices you have.

This policy applies to OneStarLive, including our Twitch Extension, panels, overlays, shareable event pages, APIs, chat and notification tools, scheduling tools, and related services (collectively, the "Service"). It should be read together with our Terms of Service (https://onestarlive.com/terms).

A note on Bits and payments: OneStarLive never processes, holds, or receives your money. All Bits transactions are handled entirely by Twitch. We only receive a record from Twitch that a contribution occurred so we can display goal progress. See Section 1(D).

1. INFORMATION WE COLLECT

A) Information Broadcasters Provide
When you use OneStarLive as a Broadcaster, you may provide:

• Event content and configuration — event titles, descriptions, goal type and amount, schedule times and timezones, categories, uploaded images, vote options/outcomes, reaction settings, and related metadata.
• Automation configuration — message templates and, if you enable Discord delivery, a Discord webhook URL you supply. (This webhook URL points to your own Discord channel and is stored so we can post to it on your behalf.)
• Feedback and support content — messages, bug reports, survey responses, screenshots, or links you submit.

B) Information We Receive From Twitch
When you authenticate or interact with OneStarLive through Twitch, we may receive and store:

• Broadcaster identity and channel data — Twitch User ID, display name, channel/broadcaster identifiers, profile image, and profile description, used to associate Events, overlays, chat, and features with the correct channel.
• Twitch OAuth tokens — where you grant permissions (for example, to sync your Twitch schedule, send chat messages, or run polls/predictions on your behalf), we store the resulting access and refresh tokens and their scopes so the Service can act with your authorization. These tokens are stored with restricted access and are not exposed in our public responses.
• Viewer interaction identity — for Viewers who interact with an Event, we receive a Twitch Viewer identifier, display name, and avatar (as Twitch makes them available to the Extension).

C) Viewer Interaction Data
When Viewers interact with an Event, we collect and store:

• Contribution records — the fact and amount of Bits contributed toward an Event's goal (received from Twitch; see 1(D)), and any attributed outcome.
• Votes and reactions — vote selections and reaction choices tied to an Event.
• "Going" status — whether a Viewer marked themselves "going" or "maybe" for an Event.
• Live attendance — when an authenticated Viewer is present during a live Event, we may automatically create a live-attendance record (Viewer ID, display name, avatar, first-seen time) as a keepsake of who attended. This can happen passively, without an explicit action by the Viewer. Viewers may request removal where the feature allows.

D) Bits / Contribution Records (from Twitch)
When a Viewer contributes Bits, Twitch processes the transaction and sends us a verified record that it occurred (via Twitch's webhook), which we use to update goal progress and contribution tallies. We do not receive, store, or process payment-card data, banking details, or funds. All financial data and processing belong to Twitch.

E) Usage, Device, and Log Data
We may automatically collect limited technical and usage data, such as:

• Interaction events — event page views, clicks, scheduling actions, momentum start/stop, vote and reaction interactions, and goal-state transitions.
• Device/browser info — device type, browser type, and language settings.
• Server and hosting logs — which may include IP address, timestamps, request metadata, and error logs, used for security, debugging, and abuse prevention. These logs are handled through our hosting and monitoring providers.

2. HOW WE USE YOUR INFORMATION

We use the information we collect to:

• Provide and operate the Service — create and display Events across panels, overlays, and shareable pages; enable Momentum, scheduling, votes, reactions, attendance, and goal tracking; and, where you opt in, send chat messages and deliver notifications to your Discord webhook.
• Show analytics — provide Broadcasters with statistics about their own Events and engagement.
• Maintain safety and security — prevent abuse and fraud, troubleshoot, and enforce our Terms.
• Improve the Service — performance, reliability, and features.
• Support you — respond to inquiries and handle data and deletion requests.

We do not use your information for third-party advertising, and we do not sell your personal information.

3. HOW WE SHARE INFORMATION

We do not sell your personal information. We share information only in these limited circumstances:

• Service providers — trusted vendors that help us operate the Service (for example, cloud hosting, image storage, and logging/monitoring), only to the extent necessary to run and secure the Service.
• At your direction — when you enable a feature that sends data on your behalf, such as posting to a Discord webhook you provide or sending messages to your Twitch chat. Public-facing content (like an Event's title, image, "going" count, and attendance keepsake) is displayed to the audience by design.
• Legal and safety — to comply with law, regulation, subpoena, or legal process; to protect the rights, property, or safety of OneStarLive, our users, or the public; or to prevent fraud, abuse, or security incidents.
• Business transfers — if OneStarLive is involved in forming a company, a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, information may transfer as part of that transaction.

4. DATA RETENTION

We retain information only as long as reasonably necessary to operate the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. Some data has specific retention limits:

• Activity and automation logs are automatically deleted after approximately 60 days.
• Server/HTTP logs are retained for a limited period (on the order of weeks) for security and reliability.
• Event, contribution, attendance, and account records are retained while your account/Events are active and for a reasonable period afterward, unless you request deletion.

5. WHERE DATA IS STORED

Information is stored on systems operated by or for OneStarLive, including our hosting and cloud-storage infrastructure. We generally process and store information in the United States.

6. SECURITY

OneStarLive is operated as a small, independently run service. We take reasonable measures designed to protect the information we process, including access controls and network restrictions, and we store sensitive credentials (such as Twitch OAuth tokens) with restricted access.

However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You use the Service at your own risk.

7. YOUR CHOICES AND RIGHTS

• Access and deletion. You may request access to or deletion of data associated with your Twitch identity by emailing contact@onestarlive.com. We may need to verify your request, and we may retain limited information where necessary for legal compliance, security, or fraud prevention.
• Broadcaster controls. Broadcasters may edit or delete Events they created, subject to platform and technical limits. Some logs or historical records may remain for security and auditing.
• Viewer controls. Viewers may request removal of their attendance record where the feature allows, and may stop interacting with an Event at any time.
• Revoking Twitch access. You can revoke OneStarLive's Twitch permissions at any time through your Twitch account settings; doing so may disable features that rely on those permissions.
• Depending on your location (for example, the EEA/UK or California), you may have additional rights, such as to access, correct, delete, or restrict processing of your personal information, and to lodge a complaint with a supervisory authority. Contact us to exercise these rights.

8. CHILDREN'S PRIVACY

OneStarLive is not intended for children under 13 (or the minimum age required by your local law, and in no case younger than Twitch's minimum age). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

9. INTERNATIONAL USERS

OneStarLive is operated from the United States. If you access the Service from outside the U.S., you understand that your information may be transferred to, stored in, and processed in the U.S., where data-protection laws may differ from those in your country.

10. THIRD-PARTY SERVICES

The Service integrates with third parties, including Twitch (identity, Bits, chat, schedule, webhooks), Discord (delivery to a webhook you provide), Google (login/identity — we receive your email address and name only), and cloud hosting and storage providers. Their privacy practices are governed by their own policies, and we are not responsible for them. We encourage you to review Twitch's and any other relevant provider's privacy policy.

11. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will post the updated version and revise the Effective Date. Your continued use of the Service after changes take effect means you accept the updated policy.