PRIVACY POLICY · VERSION 2026-09-09
Privacy, without
the small-print fog.
This notice explains what information Streamwidgets uses, why we use it and the choices available to creators and visitors.
Who is responsible
Utomnia Limited is the controller of personal information used by Streamwidgets. Company 09085136, registered in England and Wales. Registered office: 20 Lloyd Drive, Kemsley, Sittingbourne, Kent, ME10 2GA. Contact info@streamwidgets.app.
Information we collect
We collect account details such as name, email, verification and policy-acceptance records; Twitch identity, profile, permissions and encrypted access credentials; widget settings, uploaded alert sounds, custom-widget content, private overlay tokens, stream events and—when you enable chat-powered widgets—a limited rolling set of recent public Twitch chat messages, display names, colours and badges. The Task Bot also stores submitted task text, the viewer’s Twitch identity and completion status until the creator removes it or closes their account. We also collect support messages; interest-list and invitation records; subscription status, Stripe customer references and voucher activity; connected creator payout-account status; and security, request and diagnostic logs. For creator tips we store the amount, currency, payment, refund and dispute status and reason, Stripe transaction references and the supporter-selected name and message, which may be anonymous or hidden from stream. Stripe receives payment-card, identity and bank information directly—we do not store full card or bank details.
How and why we use it
We use account, widget, platform and billing information to provide the service and perform our contract with you. We use verification, security logs, fraud prevention, product diagnostics and service improvement where necessary for our legitimate interests in operating a safe and reliable service. We retain transaction information where required by legal and accounting obligations. Interest-list marketing is based on consent, which can be withdrawn at any time.
Twitch, YouTube, Discord and connected platforms
When you connect Twitch, Twitch supplies profile and authorisation information and sends the events you enable. If you approve chat access, recent public messages are received for chat widgets. When Task Bot is enabled, recognised commands can create or change tasks and Streamwidgets sends confirmation replies to public chat as your connected Twitch account; it does not otherwise moderate chat. Game campaigns may receive signed completed-sale events from the relevant publisher. Depending on the purchaser’s choices, these contain either purchased item names or only an item count, and a purchaser’s Twitch name only when they chose to share it; otherwise the alert identifies them as a viewer. When campaign sale alerts are enabled, StreamWidgets posts the streamer’s configured sale message in their Twitch chat from their connected Twitch account. Campaign membership uses the Twitch account ID to confirm that the publisher-approved streamer is connecting the same account. When you connect YouTube, Google supplies your YouTube channel identity and a read-only authorisation token. As YouTube live features are enabled, Streamwidgets may use that permission to identify current broadcasts and receive live-chat activity; it cannot upload, edit or delete videos. When you install the Discord bot, we store the server identity, selected channels and roles, ticket-opening member identity, ticket subject, status and channel identifier needed to operate private support tickets. If role panels are enabled, we also store the selected role configuration and a recent activity record containing the member identity and roles added or removed. For role promotions we store the schedule and message configured by the server owner and a delivery record containing the member identity, display name and delivery status so the same promotion is not sent twice. Pro promotion codes are encrypted at rest and only decrypted for one-time delivery to the selected member; code values are not displayed in the dashboard or included in account exports. Ticket conversations normally remain in Discord. If a Pro creator explicitly enables transcripts for a server, up to the latest 1,000 messages—including message text, display names, embedded text and attachment links—are copied into encrypted StreamWidgets storage when a ticket closes. The bot tells the ticket member that retention is enabled. We use this information only to operate the services you configure. You can disconnect a connected platform from your account.
Kick connection data
When you connect Kick, Kick supplies your user and channel identity and encrypted authorisation credentials. StreamWidgets subscribes to the live events you enable, including follows, subscriptions, KICKs, channel rewards, stream status, category changes and public chat. We retain the event details needed for widgets and private analytics, keep only a limited rolling chat history, and may send Task Bot replies to the connected channel when you enable that feature. You can disconnect Kick from Account settings at any time.
Who receives information
We share only what is needed with infrastructure and email providers, Stripe for subscriptions, connected creator accounts and support payments, Twitch and Kick for account and event integration, Google for YouTube channel integration, and professional advisers or authorities where legally required. A creator receiving a tip sees its amount, status and the name or message the supporter chooses to provide. These organisations and creators may act as processors or independent controllers under their own terms. We do not sell personal information.
International processing
Some providers, including Twitch, Google and Stripe, may process information outside the UK. Where required, transfers are protected by UK adequacy regulations or approved contractual safeguards. You may ask us for information about the relevant safeguard.
How long we keep it
Account and widget information is normally kept while an account is active. A completely unused and unverified free account may be closed after 90 days of inactivity. A verified free account may be treated as dormant after 12 months without activity. We send advance warnings 30 days and seven days before automatic closure, and signing in cancels the warning. We do not automatically close accounts with paid or complimentary access history, widgets, connected platforms, tips, Discord servers, support history or recorded stream activity. When an eligible dormant account closes, its personal profile is anonymised.
For chat-powered widgets, only the latest 100 messages per connected account are retained and older messages are automatically removed; a selected highlight remains until replaced or cleared, while Task Bot entries remain until the creator or an authorised chat command removes them. Discord ticket transcripts use the server owner’s selected 30, 90, 180 or 365-day retention period and are then automatically deleted; the owner may permanently delete them sooner. Promotion delivery records and unused encrypted codes remain until the server owner deletes that promotion or disconnects the server; delivery records are retained for that period to prevent repeat rewards after a member leaves and rejoins. Attachment files are not copied, and Discord-hosted attachment links may expire independently. Pending or failed tip attempts are removed after seven days. Completed payment, billing and legal-acceptance records may be kept longer where needed for tax, accounting, refunds, disputes or legal obligations; Stripe retains its own records under its policy. Support and diagnostic records are retained for a reasonable period needed to resolve and understand issues. Interest-list records are kept until 12 months after the relevant launch or announcement unless consent is withdrawn sooner. We delete or anonymise information when it is no longer needed.
Security and cookies
We use access controls, encrypted platform credentials, private overlay tokens and other proportionate safeguards. No online service can guarantee absolute security. Essential cookies maintain sign-in, security and session state. We will request consent before adding non-essential analytics or advertising cookies.
Your rights
Depending on the circumstances, you can ask to access, correct, erase, restrict or receive your information, object to certain processing, or withdraw consent. Account settings provides a portable JSON export and secure account closure; you can also contact info@streamwidgets.app. You may complain to the UK Information Commissioner’s Office at ico.org.uk. We will not treat you unfairly for exercising a right.
Changes
We will update the version and effective date when this notice changes. If a material change affects account use, we will provide an appropriate notice and request a fresh acknowledgement where necessary.