Privacy Policy
Version 1.2 ยท Effective 2026-08-09
This Privacy Policy explains how StreamEcon collects, uses, discloses, retains, and protects information when you use the Service. It is intended to describe current practices and does not authorize uses of information beyond what is reasonably necessary to operate, secure, support, and improve StreamEcon.
1. Scope
This Policy applies to StreamEcon websites, authenticated dashboards, public workspace pages, overlays, support systems, account onboarding, connected-platform features, APIs, and related services. Third-party websites and platforms have their own privacy practices.
2. Information We Collect
Account and profile information
We may collect your email address, display name, password hash, locale, timezone, account status, verification status, workspace membership, role assignments, and settings. StreamEcon does not store your plaintext password.
Workspace and creator configuration
We process workspace names, public slugs, creator-tool settings, public-dashboard preferences, chat-command configurations, moderation settings, banned-word lists, overlay preferences, and other information you configure in the Service.
Connected-platform information
When you connect Twitch or another supported service, we may receive identifiers such as account ID, login/display name, granted OAuth scopes, token expiration information, access/refresh tokens, channel status, chat events, moderation events, subscription/cheer/raid/follow events, and other information necessary for the features you enable. OAuth tokens are treated as credentials and should be encrypted at rest where supported by the platform architecture.
Chat and moderation history
If Chat or Viewer Management features are enabled, StreamEcon may store chat messages, timestamps, user identifiers, display names, username colors, badges, deletion status, moderation-hidden status, session association, bans, timeouts, and related event metadata. Retention may be configurable by the workspace owner. Messages removed from public dashboards or overlays may remain in private creator history for moderation, audit, troubleshooting, and safety purposes until the applicable retention period expires.
Support information
When you contact support, we collect the information you submit, including your name, email, message, subject category, priority, and up to three supported image attachments. For authenticated users, we may also attach workspace, account, current-page, browser/user-agent, and application-version context to help troubleshoot the request.
Technical and security information
We may collect IP addresses, request timestamps, browser/user-agent strings, session identifiers, authentication events, audit records, application logs, runtime health information, API request identifiers, security events, and related diagnostic data. For successful account sign-ins, StreamEcon records the IP address, login timestamp, and browser/user-agent information associated with the sign-in so authorized administrators can investigate account compromise, abuse, suspicious access, and security incidents.
Public information
Information intentionally published by a workspace owner through a public StreamEcon workspace page or overlay may be visible without authentication.
3. Information We Do Not Intentionally Request
Unless a future feature clearly says otherwise, StreamEcon does not ask you to submit Social Security numbers, government identification numbers, full payment-card numbers, card verification values, medical records, or similarly sensitive identity documents. Please do not place such information in support tickets, chat commands, workspace biographies, or other free-text fields.
4. How We Use Information
We use information to create and authenticate accounts; verify email addresses; provision and operate workspaces; provide creator tools, public pages, overlays, moderation, automation, and integrations; send transactional emails; process support requests; secure accounts and infrastructure; prevent fraud and abuse; diagnose errors; maintain audit trails; enforce policies; comply with lawful obligations; and improve the reliability and usability of the Service.
5. Legal Bases Where Required
Where laws such as the GDPR or UK GDPR apply, our processing may rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is legally required. The applicable basis depends on the data and purpose.
6. How We Disclose Information
We may disclose information to service providers that host infrastructure, deliver email, provide security or operational services, or otherwise process information on our behalf; to connected third-party platforms when necessary to perform actions you request; to law enforcement or authorities where disclosure is legally required; in connection with a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate protections; or with your direction or consent.
We do not currently sell personal information for money or use personal information for cross-context behavioral advertising. If that practice changes, this Policy and any required opt-out mechanisms will be updated before implementation.
7. Twitch and Other Connected Platforms
When you authorize a third-party integration, StreamEcon processes data made available under that provider's API and developer rules. Disconnecting an integration stops future authorized access through that connection but may not automatically delete historical data already stored for legitimate Service purposes. You may request deletion subject to legal, security, and operational retention requirements.
8. Media Metadata
If you use Now Playing or a future media-source integration, StreamEcon may process media metadata such as track or episode title, artist or creator name, album or collection name, artwork URL, playback position, duration, playing/paused state, source type, and timestamps. StreamEcon is designed to process metadata rather than audio. Metadata may be exposed through a browser-source overlay when you intentionally use that overlay. Where a third-party account connection is used, access tokens are protected as credentials and handled under the connected provider's authorization rules.
9. Cookies and Similar Technologies
StreamEcon currently uses cookies or equivalent browser storage primarily for strictly necessary functions such as sessions, authentication, remember-me functionality, CSRF/security controls, and preferences. See the Cookie Policy. If non-essential analytics or advertising technologies are introduced later, we will update disclosures and provide consent/choice mechanisms where required.
10. Retention
Retention varies by category. Account records are generally retained while the account is active and for a reasonable period afterward where needed for security, fraud prevention, legal obligations, or dispute resolution. Chat history follows workspace-configured retention where available. Support tickets and internal support notes may be retained for operational history and dispute resolution. Successful-login IP address and browser/user-agent history is retained for up to 12 months for account security, abuse prevention, and incident investigation, after which it is automatically eligible for deletion. Other security, audit, and email-delivery logs may be retained for periods reasonably necessary to investigate incidents and maintain platform integrity. Backups may persist for a limited rotation period after primary deletion.
11. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the Service, including HTTPS, password hashing, credential/token protection, access controls, workspace scoping, CSRF protection, private attachment storage, audit logging, and least-privilege design. Login IP history is restricted to authorized platform administration functions and is not displayed publicly. No system is perfectly secure, and StreamEcon cannot guarantee absolute security.
12. Private Support Attachments
Support images are intended to be stored outside the publicly served web directory or otherwise protected against direct public access. StreamEcon generates storage filenames and serves attachments to authorized platform administrators through access-controlled application routes. Uploaded images are limited by file count, file size, MIME type, and image validation.
13. International Data Transfers
The Service may be operated or hosted in the United States and may use providers located in other jurisdictions. If information is transferred across borders, we will use safeguards required by applicable law where such requirements apply.
14. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of certain personal information, and to withdraw consent where processing relies on consent. You may also have rights to appeal certain privacy decisions or lodge a complaint with a regulator. We may need to verify your identity before fulfilling a request, and lawful exceptions may apply.
To make a privacy request, contact support@streamecon.com.
15. U.S. State Privacy Rights
Residents of certain U.S. states may have additional statutory rights concerning access, deletion, correction, portability, and certain disclosures or uses of personal information. StreamEcon will evaluate verified requests under the law applicable to the requester and will not unlawfully discriminate against a user for exercising a privacy right.
16. Children
StreamEcon is not intended for persons under 18. We do not knowingly permit accounts for users below that age. If we learn that an ineligible minor created an account, we may disable the account and delete information as appropriate, subject to legal obligations.
17. Account and Workspace Deletion
Account deletion tools may be introduced as the platform matures. Until self-service deletion is available, verified deletion requests may be submitted to support. Deletion may not immediately remove information from backups or records that must be retained for security, fraud prevention, legal compliance, transaction records, or dispute resolution.
18. Automated Processing
StreamEcon may use rules-based automation to perform creator-configured moderation or stream actions. We do not currently use automated decision-making that produces legal or similarly significant effects about StreamEcon account eligibility without meaningful human or rule-based administrative control.
19. Changes to this Policy
We may update this Policy as features, providers, and legal requirements change. Material changes may be presented for renewed acknowledgment or acceptance where appropriate. The current version and effective date are displayed at the top of this page.
20. Contact
Privacy questions and requests may be sent to support@streamecon.com. The Service operator is John Sacco.