Privacy notice

How BlokeBot handles your information.

This notice is the only authoritative notice for the BlokeBot deployment that BlokeBot operates. It applies to the public help site and the channel dashboard. It describes the data that BlokeBot receives from Twitch. It also describes these items for both origins:

  • Cookies.
  • Browser storage.
  • Retention periods.

Send questions and privacy requests to privacy@blokebot.com.

Information BlokeBot handles

BlokeBot is a Twitch channel toolkit that you can host. The controller for this deployment is BlokeBot. This notice describes the information that this deployment collects and stores. BlokeBot has none of these activities:

  • Advertising.
  • Behavioral tracking.
  • An analytics service.
  • Data sales.

Sign-in and account information

What
BlokeBot receives this Twitch account information:
  • Your user ID.
  • Your login name.
  • Your display name.
  • Your profile image address.
  • The channels that you moderate.
At dashboard sign-in, Twitch asks you to approve read access to your moderated-channel list. Website sign-in requests no other permission.
Source and purpose
Twitch supplies the information during OAuth sign-in. BlokeBot uses it to identify you and select the channel dashboards that you can open. You must sign in to use the dashboard. The help site and read-only public feature pages do not require an account.
Storage location
An encrypted browser cookie contains your session identity for at most eight hours. BlokeBot does not create a separate account record when you sign in. BlokeBot checks moderator authority against Twitch. It does not store that authority.

Channel records

What
For each hosted channel, BlokeBot stores these records:
  • The Twitch ID.
  • The login and display name.
  • The profile image address.
  • The enabled features.
  • The time zone.
BlokeBot also stores each feature's configuration. This configuration includes:
  • Commands and replies.
  • Announcement schedules.
  • Guessing profiles and points settings.
  • Boards and queues.
  • Bounties and seasons.
  • Quests and achievements.
  • Bingo templates.
  • Overlays and automations.
  • Access lists.
Source and purpose
BlokeBot creates the record when the server admin adds the channel and the channel owner configures it. BlokeBot needs the record to operate the tools that the channel enables.
Lifecycle
BlokeBot keeps the record while it hosts the channel. Channel removal deletes the database records and the directory for uploaded overlay media.

Twitch authorizations

What
BlokeBot stores OAuth tokens for the bot account and an optional custom bot account. It also stores the broadcaster's channel permission, granted scopes, and grant times. Server-held application keys encrypt the token payloads.
Purpose and lifecycle
BlokeBot requires these authorizations for these features:
  • Chat and announcements.
  • Shoutouts.
  • Polls and predictions.
  • Clips and markers.
  • Channel Points.
BlokeBot deletes them when you disconnect the connection in the dashboard or remove the channel. The Twitch section explains the difference between a local disconnect and revocation.

Viewer participation records

What
When viewers use enabled channel features, BlokeBot stores their Twitch login. Where Twitch supplies them, BlokeBot also stores the user ID and display name. BlokeBot stores these participation records:
  • Guesses.
  • Points balances and points history.
  • Giveaway entries and wins.
  • Request-board submissions and votes.
  • Submitted text and links.
  • Play-queue entries and answers supplied for queue entry.
  • Moment captures.
  • Suggestions and votes.
  • Bounty pledges and settlements.
  • Season progress and quest progress.
  • Achievement completions.
  • Persistent reward unlocks and equipped selections.
  • Bingo rosters and assigned cards.
  • Bingo marks and evidence.
  • Bingo wins.
  • Shoutout history.
  • Channel Points redemptions and typed input.
  • Viewer command permissions and command use.
  • Whisper recipients.
Source and purpose
The information comes from the viewer's chat messages and Twitch events in that channel. BlokeBot uses it only to operate the feature that the channel enables. Participation is voluntary. A feature does not record a viewer who does not use it.
Lifecycle
BlokeBot keeps the information while it hosts the channel and the information serves the enabled feature. Each feature's limits also apply. For example, play-queue history has a configurable retention period. Records for outgoing chat expire within seven days. BlokeBot deletes the information after channel removal or a verified erasure request.

Content and configuration records

What
BlokeBot stores text and media that the channel team writes or uploads. This content includes:
  • Custom command responses and message libraries.
  • Announcements.
  • Overlay names and appearance.
  • Uploaded overlay media files.
  • Board and queue definitions.
  • Bounty content.
  • Season and reward definitions.
  • Bingo templates.
  • Private moderator notes.
  • Automation configuration.
The content can contain personal information if its authors add that information.
Lifecycle
BlokeBot keeps this content while it hosts the channel. Channel removal deletes the content. The dashboard delete controls can delete individual items.

Event and diagnostic records

What
BlokeBot stores feature event history for:
  • Boards and queues.
  • Moments and bounties.
  • Progression and Bingo.
  • Overlays.
BlokeBot also stores:
  • Automation run records and the trigger event context.
  • Delivery receipts and operator alerts.
Application logs record operational events and errors.
Purpose and lifecycle
BlokeBot uses these records for dashboards, recent-event views, and fault diagnosis. BlokeBot deletes application log files after at most fourteen days. The logs exclude secrets and authorization values. See providers and security.

Network information

What
The servers and reverse proxy receive your IP address and request metadata when they process requests. BlokeBot does not store visitor IP addresses in its database.
Lifecycle
Connection handling and service journals are operational copies. The periods in retention and deletion limit these copies.

Who can see the information

  • Twitch chat. BlokeBot sends replies, announcements, shoutouts, polls, predictions, and other bot output to Twitch. Everyone in that channel can see the output. Twitch's terms and privacy notice apply to it.
  • Public leaderboards. Guessing and points leaderboards are public pages. They show the names and positions of viewers who participate in a channel. Sign-in is not required.
  • Overlays. A channel's stream overlays can show participant names, queue entries, events, and moments to all stream viewers.
  • The channel team. The channel owner, channel moderators, and server admin can see that channel's records in the dashboard. These records include private moderator notes.
  • Nobody else. BlokeBot has no advertising network, analytics provider, or data sales. The providers and security section lists infrastructure providers that process data for the controller.

Your browser can make requests to third parties. The dashboard shows Twitch profile images from Twitch image servers. A channel can configure an overlay page with media or pages from hosts that the channel selects. Your browser contacts those hosts directly when it loads that page.

Twitch

BlokeBot is an independent service. Twitch has none of these relationships with BlokeBot:

  • Affiliation.
  • Sponsorship.
  • Endorsement.

BlokeBot gives a Twitch channel these features through one dashboard:

  • Chat commands and games.
  • Points and giveaways.
  • Queues and overlays.
  • Moderation tools.

Permissions that BlokeBot requests

  • Website sign-in. This permission confirms your identity. It lets BlokeBot see the channels that you moderate and show the applicable dashboards.
  • Bot account. This permission lets the bot account perform these actions:
    • Read and send chat.
    • Make announcements.
    • Manage its chat messages.
    • Read followers.
    • Read moderated channels.
    • Send or manage shoutouts in channels that authorized it.
  • Custom bot account. A channel can connect its own bot account as an option. This account uses the same chat permissions. Its messages use a name that the channel owns.
  • Broadcaster permission. The channel owner grants permission for the bot to operate in the channel. If the channel uses them, the owner also grants permissions for these features:
    • Polls.
    • Predictions.
    • Clips.
    • Markers.
    • Channel Points.

How BlokeBot uses Twitch data

Twitch supplies all information that BlokeBot receives about Twitch users. This information includes:

  • The user ID and login.
  • The display name and profile image.
  • Command chat messages.
  • Channel events from Twitch. Examples include:
    • Raids.
    • Redemptions.
    • Follows.
    • Similar events.

BlokeBot stores the information that the sections above describe. It shows the information in these locations:

  • The channel dashboard.
  • Public leaderboards.
  • Overlays.

BlokeBot sends feature output to Twitch chat. The rules in retention and deletion control retention. BlokeBot deletes the information after channel removal or a verified request through privacy@blokebot.com.

Local disconnection and Twitch revocation

Dashboard disconnection deletes the OAuth tokens for the disconnected connection. This action applies to these connections:

  • A bot connection.
  • A custom bot connection.
  • A broadcaster connection.

The disconnection does not withdraw the authorization that Twitch records. To revoke the grant, use Twitch's Connections settings. The Twitch Privacy Notice describes how Twitch uses your data.

Cookies and browser storage

This section lists all items that the two BlokeBot origins put in your browser. BlokeBot sets all these first-party items. An advertising or analytics provider does not set any item. Browser storage and the server records above are separate. If you clear your browser, this action does not delete server records. Server record deletion does not clear browser storage.

Cookies on the dashboard (bot.blokebot.com)

BlokeBot.Auth
This cookie contains your encrypted sign-in session. The session identifies these details:
  • You.
  • Your role.
  • Your selected channel.
The cookie is essential for authentication. It is HttpOnly and Secure over HTTPS. It expires after eight hours, and activity does not extend it. It is strictly necessary and exempt from consent.
BlokeBot.AuthState
This cookie contains a random value that protects sign-in against cross-site request forgery. It is an essential security cookie. It has these attributes:
  • HttpOnly.
  • SameSite=Lax.
  • Secure over HTTPS.
It exists for ten minutes during sign-in. It is strictly necessary.
BlokeBot.AuthReturnUrl
This cookie contains the page that you return to after sign-in. BlokeBot sets it only when you arrive on a specific dashboard page. It has these attributes:
  • HttpOnly.
  • SameSite=Lax.
  • Secure over HTTPS.
It exists for ten minutes during sign-in. It is strictly necessary.
BlokeBot.ChannelBotState
This cookie gives the same forgery protection when a channel connects its custom bot account. It has these attributes:
  • HttpOnly.
  • SameSite=Lax.
  • Secure over HTTPS.
Its scope is the connection flow. It exists for ten minutes. It is strictly necessary.

Sign-in also sets the framework antiforgery cookie (.AspNetCore.Antiforgery.*). This cookie protects submitted forms against cross-site request forgery. It is HttpOnly and strictly necessary. Its lifetime is the session. The help site sets no cookies.

Saved preferences (localStorage)

blokebot.theme (both origins)
This key contains "light" or "dark". It stores your appearance choice. Until you make a choice, both sites use your system setting. The key remains until you clear it or turn preference saving off.
Dashboard navigation groups
These keys store the navigation state:
  • blokebot.sidebar.guessing.open
  • blokebot.sidebar.points.open
  • blokebot.sidebar.customcommands.open
  • blokebot.sidebar.automations.open
  • blokebot.sidebar.nativetwitch.open
These keys contain "true" or "false". They record which navigation groups you left open.
blokebot.shell.rail.v1 (dashboard)
This key records your choice of the full navigation rail or the compact icon rail.
blokebot.preferences.disabled (both origins)
This key exists only after you turn preference saving off. It is the only flag that records this choice. It is the minimum storage that this choice requires.

The preference keys apply your appearance choice to each site. If you receive clear information and a simple, free objection method, UK privacy rules exempt this storage from consent. This inventory gives the information. The control below gives the objection method.

All items above are strictly necessary security storage or exempt appearance preferences with this objection control. No item requires consent. Neither site shows a consent banner. If BlokeBot adds storage or third-party technology outside these exemptions, it must ask first.

Retention and deletion

BlokeBot keeps product history for the channel lifecycle instead of deletion on a timer. This history includes:

  • Guessing and points.
  • Requests and queues.
  • Moments and bounties.
  • Progression and Bingo.
  • Commands and automations.

The history remains useful while BlokeBot hosts the channel and the feature is in use. The limits are below.

  • Channel removal. Removal of a hosted channel stops the channel bot and deletes its database records. The records include viewer participation records. Channel removal also deletes its uploaded overlay media directory from disk.
  • Verified privacy requests. Verified erasure requests through privacy@blokebot.com delete the viewer's records from every feature. See your rights.
  • Feature-specific periods. Some records expire automatically. Records for outgoing chat delivery expire within seven days. Play-queue history expires after the number of days that the channel configures.
  • Logs. BlokeBot keeps application log files and service journals for no more than fourteen days.
  • Backups. A rolling schedule creates database snapshots on the server. It keeps these snapshots:
    • 48 hourly snapshots.
    • 14 daily snapshots.
    • 8 weekly snapshots.
    Data deleted from the live database expires from all backups within eight weeks. One-off pre-release database backups expire automatically within the same eight-week period.

Deletion is immediate in the live system. Deletion does not change existing snapshots. BlokeBot does not rewrite existing backups. Their copies expire with the snapshot schedule after at most eight weeks.

Your rights and how to use them

You can make these requests about data that BlokeBot attributes to your Twitch identity:

  • Request access.
  • Request an export.
  • Request correction.
  • Request a restriction on its use.
  • Object to its use.
  • Request erasure.

If a process relies on consent, you can withdraw that consent.

Send requests to privacy@blokebot.com. This monitored address is the route for all privacy requests. BlokeBot does not charge for requests.

  • Verification. Requests must be verifiable to protect the requested data. The simplest method is a request from a channel or route that proves control of the applicable Twitch account. You can also reply to a verification whisper or message. BlokeBot keeps only the minimum correspondence that fulfills and records the request.
  • Effects of erasure. BlokeBot deletes records that exist only about you. These records include:
    • Guesses and balances.
    • Entries and submissions.
    • Votes and queue entries.
    • Redemptions and similar records.
    Some records must remain for non-personal integrity, such as point ledger arithmetic or moderation audit trails. These records keep their numbers but lose these personal fields:
    • Your Twitch ID and login.
    • Your display name.
    • Your submitted text and links.
    • Your notes.
    BlokeBot keeps no lookup that can identify you again from these records.
  • Temporary copies. Erased data can remain in existing backups for at most eight weeks until the snapshot schedule expires it. Twitch rules, not BlokeBot rules, apply to bot messages that BlokeBot already sent to Twitch chat.
  • Complaints. If you are not satisfied with how BlokeBot handles a request, you can complain to your data protection authority. In the UK, this authority is the Information Commissioner's Office (ico.org.uk).

BlokeBot makes no automated decisions about you that have legal or similarly significant effects. Automations send chat messages and update overlays according to rules that the channel owner configures.

Providers and security

The official deployment includes www.blokebot.com and bot.blokebot.com. It operates on one server that the controller leases from Hetzner. Hetzner processes the hosted data as the infrastructure provider. The deployment stores its backups on the same server.

Namecheap provides DNS and forwards privacy-address mail to the controller's monitored mailbox. Twitch is the platform for the service. No other processor receives the data.

Connections to both origins use HTTPS. Server-held application keys encrypt stored Twitch tokens. Each overlay page requires an unguessable key for that overlay. The server stores the key as a digest.

These log types exclude the values below:

  • Application logs.
  • Proxy logs.
  • Diagnostic logs.

Excluded values:

  • OAuth codes and state values.
  • Overlay access keys.
  • Authorization values and cookie values.
  • Tokens and webhook secrets.
  • Raw event payloads.

No internet service can promise absolute security. This notice describes the actual controls for this deployment. The person who operates a self-hosted copy controls that copy. Each operator gives its name and contact in the notice for its deployment.

Changes to this notice

This page is the only maintained copy of the notice. It describes the current release. Material changes update this page and appear in the release notes. Last updated: August 2026.