Privacy notice
How BlokeBot handles your information.
This notice is the only authoritative notice for the BlokeBot deployment that BlokeBot operates. It applies to the public help site and the channel dashboard. It describes the data that BlokeBot receives from Twitch. It also describes these items for both origins:
- Cookies.
- Browser storage.
- Retention periods.
Send questions and privacy requests to privacy@blokebot.com.
Information BlokeBot handles
BlokeBot is a Twitch channel toolkit that you can host. The controller for this deployment is BlokeBot. This notice describes the information that this deployment collects and stores. BlokeBot has none of these activities:
- Advertising.
- Behavioral tracking.
- An analytics service.
- Data sales.
Sign-in and account information
- What
-
BlokeBot receives this Twitch account information:
- Your user ID.
- Your login name.
- Your display name.
- Your profile image address.
- The channels that you moderate.
- Source and purpose
- Twitch supplies the information during OAuth sign-in. BlokeBot uses it to identify you and select the channel dashboards that you can open. You must sign in to use the dashboard. The help site and read-only public feature pages do not require an account.
- Storage location
- An encrypted browser cookie contains your session identity for at most eight hours. BlokeBot does not create a separate account record when you sign in. BlokeBot checks moderator authority against Twitch. It does not store that authority.
Channel records
- What
-
For each hosted channel, BlokeBot stores these records:
- The Twitch ID.
- The login and display name.
- The profile image address.
- The enabled features.
- The time zone.
- Commands and replies.
- Announcement schedules.
- Guessing profiles and points settings.
- Boards and queues.
- Bounties and seasons.
- Quests and achievements.
- Bingo templates.
- Overlays and automations.
- Access lists.
- Source and purpose
- BlokeBot creates the record when the server admin adds the channel and the channel owner configures it. BlokeBot needs the record to operate the tools that the channel enables.
- Lifecycle
- BlokeBot keeps the record while it hosts the channel. Channel removal deletes the database records and the directory for uploaded overlay media.
Twitch authorizations
- What
- BlokeBot stores OAuth tokens for the bot account and an optional custom bot account. It also stores the broadcaster's channel permission, granted scopes, and grant times. Server-held application keys encrypt the token payloads.
- Purpose and lifecycle
-
BlokeBot requires these authorizations for these features:
- Chat and announcements.
- Shoutouts.
- Polls and predictions.
- Clips and markers.
- Channel Points.
Viewer participation records
- What
-
When viewers use enabled channel features, BlokeBot stores their Twitch login. Where
Twitch supplies them, BlokeBot also stores the user ID and display name. BlokeBot stores these participation records:
- Guesses.
- Points balances and points history.
- Giveaway entries and wins.
- Request-board submissions and votes.
- Submitted text and links.
- Play-queue entries and answers supplied for queue entry.
- Moment captures.
- Suggestions and votes.
- Bounty pledges and settlements.
- Season progress and quest progress.
- Achievement completions.
- Persistent reward unlocks and equipped selections.
- Bingo rosters and assigned cards.
- Bingo marks and evidence.
- Bingo wins.
- Shoutout history.
- Channel Points redemptions and typed input.
- Viewer command permissions and command use.
- Whisper recipients.
- Source and purpose
- The information comes from the viewer's chat messages and Twitch events in that channel. BlokeBot uses it only to operate the feature that the channel enables. Participation is voluntary. A feature does not record a viewer who does not use it.
- Lifecycle
- BlokeBot keeps the information while it hosts the channel and the information serves the enabled feature. Each feature's limits also apply. For example, play-queue history has a configurable retention period. Records for outgoing chat expire within seven days. BlokeBot deletes the information after channel removal or a verified erasure request.
Content and configuration records
- What
-
BlokeBot stores text and media that the channel team writes or uploads. This content includes:
- Custom command responses and message libraries.
- Announcements.
- Overlay names and appearance.
- Uploaded overlay media files.
- Board and queue definitions.
- Bounty content.
- Season and reward definitions.
- Bingo templates.
- Private moderator notes.
- Automation configuration.
- Lifecycle
- BlokeBot keeps this content while it hosts the channel. Channel removal deletes the content. The dashboard delete controls can delete individual items.
Event and diagnostic records
- What
-
BlokeBot stores feature event history for:
- Boards and queues.
- Moments and bounties.
- Progression and Bingo.
- Overlays.
- Automation run records and the trigger event context.
- Delivery receipts and operator alerts.
- Purpose and lifecycle
- BlokeBot uses these records for dashboards, recent-event views, and fault diagnosis. BlokeBot deletes application log files after at most fourteen days. The logs exclude secrets and authorization values. See providers and security.
Network information
- What
- The servers and reverse proxy receive your IP address and request metadata when they process requests. BlokeBot does not store visitor IP addresses in its database.
- Lifecycle
- Connection handling and service journals are operational copies. The periods in retention and deletion limit these copies.
- Twitch chat. BlokeBot sends replies, announcements, shoutouts, polls, predictions, and other bot output to Twitch. Everyone in that channel can see the output. Twitch's terms and privacy notice apply to it.
- Public leaderboards. Guessing and points leaderboards are public pages. They show the names and positions of viewers who participate in a channel. Sign-in is not required.
- Overlays. A channel's stream overlays can show participant names, queue entries, events, and moments to all stream viewers.
- The channel team. The channel owner, channel moderators, and server admin can see that channel's records in the dashboard. These records include private moderator notes.
- Nobody else. BlokeBot has no advertising network, analytics provider, or data sales. The providers and security section lists infrastructure providers that process data for the controller.
Your browser can make requests to third parties. The dashboard shows Twitch profile images from Twitch image servers. A channel can configure an overlay page with media or pages from hosts that the channel selects. Your browser contacts those hosts directly when it loads that page.
Twitch
BlokeBot is an independent service. Twitch has none of these relationships with BlokeBot:
- Affiliation.
- Sponsorship.
- Endorsement.
BlokeBot gives a Twitch channel these features through one dashboard:
- Chat commands and games.
- Points and giveaways.
- Queues and overlays.
- Moderation tools.
Permissions that BlokeBot requests
- Website sign-in. This permission confirms your identity. It lets BlokeBot see the channels that you moderate and show the applicable dashboards.
- Bot account. This permission lets the bot account perform these actions:
- Read and send chat.
- Make announcements.
- Manage its chat messages.
- Read followers.
- Read moderated channels.
- Send or manage shoutouts in channels that authorized it.
- Custom bot account. A channel can connect its own bot account as an option. This account uses the same chat permissions. Its messages use a name that the channel owns.
- Broadcaster permission. The channel owner grants permission for the
bot to operate in the channel. If the channel uses them, the owner also grants permissions for these features:
- Polls.
- Predictions.
- Clips.
- Markers.
- Channel Points.
How BlokeBot uses Twitch data
Twitch supplies all information that BlokeBot receives about Twitch users. This information includes:
- The user ID and login.
- The display name and profile image.
- Command chat messages.
- Channel events from Twitch. Examples include:
- Raids.
- Redemptions.
- Follows.
- Similar events.
BlokeBot stores the information that the sections above describe. It shows the information in these locations:
- The channel dashboard.
- Public leaderboards.
- Overlays.
BlokeBot sends feature output to Twitch chat. The rules in retention and deletion control retention. BlokeBot deletes the information after channel removal or a verified request through privacy@blokebot.com.
Local disconnection and Twitch revocation
Dashboard disconnection deletes the OAuth tokens for the disconnected connection. This action applies to these connections:
- A bot connection.
- A custom bot connection.
- A broadcaster connection.
The disconnection does not withdraw the authorization that Twitch records. To revoke the grant, use Twitch's Connections settings. The Twitch Privacy Notice describes how Twitch uses your data.
Cookies and browser storage
This section lists all items that the two BlokeBot origins put in your browser. BlokeBot sets all these first-party items. An advertising or analytics provider does not set any item. Browser storage and the server records above are separate. If you clear your browser, this action does not delete server records. Server record deletion does not clear browser storage.
Cookies on the dashboard (bot.blokebot.com)
- BlokeBot.Auth
-
This cookie contains your encrypted sign-in session. The session identifies these details:
- You.
- Your role.
- Your selected channel.
- BlokeBot.AuthState
-
This cookie contains a random value that protects sign-in against cross-site request
forgery. It is an essential security cookie. It has these attributes:
- HttpOnly.
- SameSite=Lax.
- Secure over HTTPS.
- BlokeBot.AuthReturnUrl
-
This cookie contains the page that you return to after sign-in. BlokeBot sets it only
when you arrive on a specific dashboard page. It has these attributes:
- HttpOnly.
- SameSite=Lax.
- Secure over HTTPS.
- BlokeBot.ChannelBotState
-
This cookie gives the same forgery protection when a channel connects its custom bot
account. It has these attributes:
- HttpOnly.
- SameSite=Lax.
- Secure over HTTPS.
Sign-in also sets the framework antiforgery cookie
(.AspNetCore.Antiforgery.*). This cookie protects submitted forms against
cross-site request forgery. It is HttpOnly and strictly necessary. Its lifetime is the
session. The help site sets no cookies.
Saved preferences (localStorage)
- blokebot.theme (both origins)
- This key contains "light" or "dark". It stores your appearance choice. Until you make a choice, both sites use your system setting. The key remains until you clear it or turn preference saving off.
- Dashboard navigation groups
- These keys store the navigation state:
- blokebot.sidebar.guessing.open
- blokebot.sidebar.points.open
- blokebot.sidebar.customcommands.open
- blokebot.sidebar.automations.open
- blokebot.sidebar.nativetwitch.open
- blokebot.shell.rail.v1 (dashboard)
- This key records your choice of the full navigation rail or the compact icon rail.
- blokebot.preferences.disabled (both origins)
- This key exists only after you turn preference saving off. It is the only flag that records this choice. It is the minimum storage that this choice requires.
The preference keys apply your appearance choice to each site. If you receive clear information and a simple, free objection method, UK privacy rules exempt this storage from consent. This inventory gives the information. The control below gives the objection method.
Preference saving on this site
Status: checking…
If you turn this off, the site immediately deletes its saved appearance preferences from your browser. The site does not store new appearance preferences. Sign-in and all features continue to operate. The site uses your system appearance instead.
Preference saving is off. This site does not store appearance preferences in your browser. If you want the site to store your theme choice, turn preference saving on.
The dashboard has the same control. Open the account menu in the top-right corner. Select Stop saving view preferences. The control for each origin governs the storage for that origin.
All items above are strictly necessary security storage or exempt appearance preferences with this objection control. No item requires consent. Neither site shows a consent banner. If BlokeBot adds storage or third-party technology outside these exemptions, it must ask first.
Retention and deletion
BlokeBot keeps product history for the channel lifecycle instead of deletion on a timer. This history includes:
- Guessing and points.
- Requests and queues.
- Moments and bounties.
- Progression and Bingo.
- Commands and automations.
The history remains useful while BlokeBot hosts the channel and the feature is in use. The limits are below.
- Channel removal. Removal of a hosted channel stops the channel bot and deletes its database records. The records include viewer participation records. Channel removal also deletes its uploaded overlay media directory from disk.
- Verified privacy requests. Verified erasure requests through privacy@blokebot.com delete the viewer's records from every feature. See your rights.
- Feature-specific periods. Some records expire automatically. Records for outgoing chat delivery expire within seven days. Play-queue history expires after the number of days that the channel configures.
- Logs. BlokeBot keeps application log files and service journals for no more than fourteen days.
- Backups. A rolling schedule creates database snapshots on the
server. It keeps these snapshots:
- 48 hourly snapshots.
- 14 daily snapshots.
- 8 weekly snapshots.
Deletion is immediate in the live system. Deletion does not change existing snapshots. BlokeBot does not rewrite existing backups. Their copies expire with the snapshot schedule after at most eight weeks.
Your rights and how to use them
You can make these requests about data that BlokeBot attributes to your Twitch identity:
- Request access.
- Request an export.
- Request correction.
- Request a restriction on its use.
- Object to its use.
- Request erasure.
If a process relies on consent, you can withdraw that consent.
Send requests to privacy@blokebot.com. This monitored address is the route for all privacy requests. BlokeBot does not charge for requests.
- Verification. Requests must be verifiable to protect the requested data. The simplest method is a request from a channel or route that proves control of the applicable Twitch account. You can also reply to a verification whisper or message. BlokeBot keeps only the minimum correspondence that fulfills and records the request.
- Effects of erasure. BlokeBot deletes records that exist only about
you. These records include:
- Guesses and balances.
- Entries and submissions.
- Votes and queue entries.
- Redemptions and similar records.
- Your Twitch ID and login.
- Your display name.
- Your submitted text and links.
- Your notes.
- Temporary copies. Erased data can remain in existing backups for at most eight weeks until the snapshot schedule expires it. Twitch rules, not BlokeBot rules, apply to bot messages that BlokeBot already sent to Twitch chat.
- Complaints. If you are not satisfied with how BlokeBot handles a request, you can complain to your data protection authority. In the UK, this authority is the Information Commissioner's Office (ico.org.uk).
BlokeBot makes no automated decisions about you that have legal or similarly significant effects. Automations send chat messages and update overlays according to rules that the channel owner configures.
Providers and security
The official deployment includes www.blokebot.com and bot.blokebot.com. It operates on one server that the controller leases from Hetzner. Hetzner processes the hosted data as the infrastructure provider. The deployment stores its backups on the same server.
Namecheap provides DNS and forwards privacy-address mail to the controller's monitored mailbox. Twitch is the platform for the service. No other processor receives the data.
Connections to both origins use HTTPS. Server-held application keys encrypt stored Twitch tokens. Each overlay page requires an unguessable key for that overlay. The server stores the key as a digest.
These log types exclude the values below:
- Application logs.
- Proxy logs.
- Diagnostic logs.
Excluded values:
- OAuth codes and state values.
- Overlay access keys.
- Authorization values and cookie values.
- Tokens and webhook secrets.
- Raw event payloads.
No internet service can promise absolute security. This notice describes the actual controls for this deployment. The person who operates a self-hosted copy controls that copy. Each operator gives its name and contact in the notice for its deployment.
Changes to this notice
This page is the only maintained copy of the notice. It describes the current release. Material changes update this page and appear in the release notes. Last updated: August 2026.