Privacy Policy
Last updated: April 1, 2026
Draft Notice: This privacy policy is a draft and is subject to review by legal counsel before becoming effective. It outlines how StreamForge handles your data.
1. Overview
StreamForge (“we,” “us,” or “our”) operates the StreamForge platform at streamtools.bifrostlive.com, a SaaS tool for live streamers to track community engagement, manage VIP rewards, run interactive events, and view real-time statistics. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information.
By using StreamForge, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the service.
2. Data We Collect
We collect information necessary to provide and improve our services:
- Account Information: Email address, display name, and authentication credentials provided during sign-up (via email/password, Twitch OAuth, or Google OAuth).
- Twitch Data: When you connect your Twitch account, we access your Twitch username, avatar, user ID, and stream events (subscriptions, bits, raids, chat messages) through the Twitch API and EventSub webhooks.
- Viewer Activity Data: Twitch viewer activity such as chat messages, subscriptions, gift subs, bits, raids, and channel point redemptions may be tracked and displayed on public leaderboards when enabled by the streamer.
- Discord Data: When you connect your Discord server, we access guild information, channel lists, and role lists to manage VIP role assignments and post leaderboard embeds.
- Usage Data: We collect information about how you interact with StreamForge, including pages visited, features used, and actions taken within the dashboard.
- Billing Data: Payment processing is handled by Paddle. We store your Paddle customer ID and subscription status but do not directly handle credit card numbers or payment method details.
3. How We Use Data
We use collected data to:
- Provide, operate, and maintain the StreamForge platform
- Calculate community engagement points based on configurable rules
- Evaluate and grant VIP status to qualifying community members
- Display leaderboards and analytics dashboards, including public-facing leaderboards that show viewer usernames, display names, avatars, and engagement scores when enabled by the streamer
- Manage your subscription and billing
- Send transactional emails (billing alerts, platform announcements)
- Improve our services through aggregated, anonymized analytics
- Respond to support requests and communicate about your account
4. Third-Party Services
StreamForge integrates with third-party services to provide its functionality:
- Supabase: Database hosting, authentication, and real-time subscriptions. Data is stored on Supabase-managed PostgreSQL infrastructure.
- Twitch (Amazon): OAuth authentication and stream event data. Subject to the Twitch Developer Agreement.
- Discord: Bot integration for role management and notifications. Subject to the Discord Developer Terms of Service.
- Paddle: Payment processing and subscription management. Subject to Paddle's Privacy Policy.
- Vercel: Application hosting and edge deployment.
- Sentry: Error tracking and performance monitoring (when performance cookies are enabled).
5. Data Retention
We retain your data for as long as your account is active or as needed to provide our services. When you delete your account:
- Your personal profile data is deleted within 30 days
- Aggregated, anonymized analytics data may be retained indefinitely
- Billing records are retained as required by applicable tax and financial regulations
- Twitch and Discord OAuth tokens are revoked and deleted immediately upon disconnection
6. Your Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure: Request deletion of your personal data.
- Right to Restriction: Request restriction of processing of your data.
- Right to Data Portability: Request transfer of your data in a machine-readable format.
- Right to Object: Object to processing of your personal data.
To exercise any of these rights, please contact us at the address listed in the Contact section below.
7. Your Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of personal information we have collected from you.
- Right to Opt-Out: You may opt out of the sale of personal information. StreamForge does not sell personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
9. Children's Privacy
StreamForge is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information promptly. If you believe a child under 13 has provided us with personal data, please contact us.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Row-Level Security (RLS) policies ensuring tenant data isolation
- OAuth token encryption at rest via Supabase Auth
- CSRF protection and webhook signature verification
- Rate limiting on public-facing endpoints
- Regular security reviews and dependency updates
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the “Last updated” date. We encourage you to review this policy periodically. Continued use of StreamForge after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
- Email: privacy@bifrostlive.com
- Platform: StreamForge — streamtools.bifrostlive.com
We will respond to data rights requests within 30 days of receipt.
Public Leaderboard Removal: Viewers may request removal from public leaderboards by contacting privacy@bifrostlive.com.