LEGAL

Privacy policy

Last updated: September 21, 2026

This is the short version for Shiny's Streaming Services (services.shinyarmor.net), run by shiny_armor. I’m not a corporation and I’m not here to collect your data. I only keep what the site needs to function.

What I store

Depending on how you use the site, that can include:

  • Account basics when you sign in with Twitch and/or Google - things like your account id, display name, profile image, and (for Google) email.
  • OAuth tokens you choose to connect - for example Twitch clip permissions (clips:edit), YouTube chat read access, a channel bot’s chat:read / chat:edit / user:write:chat / moderator:manage:chat_messages / moderator:manage:banned_users tokens (and channel:manage:broadcast / channel:edit:commercial when the bot is this channel), and an optional second channel:manage:broadcast / channel:edit:commercial token when a different account sits in chat - so features keep working without you logging in every few minutes. The bot token is refreshed on the server.
  • Your configurations - counters, timers, controllers, chat overlays, ignored chat usernames, display layouts, game wishlists (including public/private notes and viewer suggestions), channel-bot commands (triggers and actions), channel-bot moderation filters, channel-bot setup details (stream schedule, hardware specs, and social links), channel-bot viewer groups (Twitch logins you add to named lists), channel-bot viewers the bot has seen in chat (login, time in chat, last seen), an optional channel-bot chat log (message text, off by default; delete it from the Log tab), and similar settings you create in the dashboard. Shared wishlists at /lists/… are visible to anyone with the link; only public notes appear there. Catalog search may query Steam and IGDB when you add a game. Hardware catalog search uses a local database without external tracker calls.
  • Custom chat-effect images you upload (PNG, JPEG, or GIF). Those files are stored on the application server under a random token, not the original filename, and are served to your overlays. Deleting the custom effect removes unused images.

I don’t sell your data, and I don’t run ad trackers for marketing. Normal server logs may briefly include technical details (like IP addresses) when requests reach the site. That’s just part of running a website, not a way to make money from analytics. Suggestion rate limits may use the request IP for a short time so the same list can’t be spammed.

Channel bot

If you enable the channel bot, it reads Twitch chat in that channel so it can match commands and smart intents. Smart intent matching uses an internal token similarity algorithm running entirely on the application server; chat messages are never sent to third-party AI or external language model APIs. I store the commands you create, moderation filters, stream setup configurations (schedule, hardware specs, and socials), named viewer groups, everyone the bot has seen in chat (login, time in chat, last seen), an optional internal game title and catalog summary (for streams under Twitch’s Games + Demos category), and daily totals (messages seen, exact commands, smart commands) for the analytics graph. Those totals do not include the text of chat lines. If you turn on the Log tab (off by default), I store chat message text until you delete history; turning the log off keeps existing rows. Connecting a Twitch account for the bot (your channel or a separate bot account) stores its access and refresh tokens so chat login can renew automatically.

Twitch wishlist panel and viewer suggestions

The Shiny Wishlist Twitch channel panel (and public /lists/… pages) can let viewers suggest a game when the list owner has suggestions turned on. You do not need a site account to look at a public list or to send a suggestion.

If you send a suggestion, I store:

  • The game you picked or typed (title and catalog details)
  • An optional short message
  • A name so the owner knows who sent it. That name can be what you type, your display name if you are signed in on this site, or your public Twitch username if you share identity in the panel (see below)

The list owner sees pending suggestions in their dashboard and can accept or decline them. Accepted games join that public list. Declined suggestions are dismissed. Private notes never appear in the panel or on the public list page.

The panel may ask Twitch to share your identity so it can fill your Twitch username. That uses Twitch’s own prompt (Identity Link). If you agree, the panel sends your numeric Twitch user id to this site so I can look up your public username. I use that id only for that lookup and to pre-fill / attach the name. I do not use it to build a viewer profile, to contact you, or for advertising. The suggestion itself keeps the name, game, and message - not a standing copy of the numeric id - unless you already have a site account linked to that Twitch user.

Sharing identity is optional. You can still view the panel and, today, still send a suggestion with a name you type. Twitch never sends me your password. If you later stop sharing identity with the extension, I won’t keep collecting a user id from you that way. Suggestions already saved still show the name that was stored at the time.

To remove a suggestion you sent, ask the list owner to decline it or contact me (below) and I’ll do my best to delete it.

How Google user data is used

If you sign in with Google or connect YouTube, this app requests and uses Google user data only to operate the features you choose:

  • Google sign-in (OpenID Connect scopes openid, profile, and email): used to create or recognize your account, show your display name, store your Google account subject id and email for login / account linking with Twitch, and keep you signed in to the dashboard. This data is not used for advertising, profiling for ads, or unrelated analytics.
  • Optional YouTube chat connection (Google OAuth scope https://www.googleapis.com/auth/youtube.readonly): used only when you explicitly connect YouTube chat. Access and refresh tokens, plus your YouTube channel id and title, are stored so the app can read your channel’s live / test broadcast chat and show those messages in your OBS chat overlay. Chat content is processed in real time for display; it is not sold, mined for ads, or used to build marketing profiles.

Shiny's Streaming Services' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing, transfer, and disclosure of Google user data

I do not sell Google user data. I do not share, transfer, or disclose Google user data to third parties for advertising, data brokerage, or independent AI / ML training.

Google user data may be disclosed only in these limited cases:

  • To you - for example showing your linked Google email or YouTube channel title in the dashboard, or rendering YouTube chat on overlays you configure and publish.
  • To Google - when the app calls Google / YouTube APIs with tokens you authorized, so those features can work (login, token refresh, live chat read).
  • Infrastructure needed to run the site - data is stored and processed on the servers that host this application (database and application hosting). Those systems exist to operate the service, not to reuse your Google data for other products.
  • Legal requirements - if required by law, regulation, or a valid legal process, or to protect the security / integrity of the service.

If you unlink Google or disconnect YouTube chat, the related Google identifiers / tokens are removed from your account as part of that action. You can also contact me to request deletion of remaining account data.

Data protection

Sensitive account and OAuth data (including Google sign-in identifiers, email, and YouTube access / refresh tokens) is protected with practical safeguards appropriate for a small single-operator service:

  • Encryption in transit - the public site is served over HTTPS / TLS so data between your browser and the server is encrypted.
  • Access control - dashboard and API actions that touch your account require an authenticated session. OAuth tokens are stored server-side and used only by backend processes that refresh tokens and call the APIs you authorized.
  • Least privilege - Google scopes are limited to what each feature needs (sign-in profile/email, or read-only YouTube access for chat). Extra Google permissions are not requested by default.
  • Operational limits - there is no advertising stack and no sale of personal data. Access to production systems is limited to the operator needed to keep the service running.
  • Retention and removal - tokens and Google account fields are kept only while the related feature / account link exists. Disconnecting an integration or requesting deletion removes that stored data from the application database.

No method of transmission or storage is perfectly secure. If you believe your account or tokens were compromised, disconnect the relevant OAuth integration, revoke access in your Google Account settings, and contact me.

Cookies

The only cookies this site sets are essential ones needed to keep you signed in (session / login). There is no advertising cookie wall, no analytics cookie pack, and no “accept all” pop-up. There’s nothing non-essential to accept. Signing in with Twitch or Google means those providers may set their own cookies on their domains under their policies.

Third parties

Login and optional integrations go through Twitch and/or Google / YouTube. Their own privacy policies apply to those services. I only ask for the scopes needed for the features you use (account login, clips, or YouTube chat, etc.). See the Google-specific sections above for how Google user data is used, shared, and protected.

How long it stays

Data sticks around while your account and configs exist so the tools keep working. If you want something deleted, get in touch and I’ll do my best to remove it.

Contact

Questions about privacy? Ping me on Twitch or Twitter / X.