Privacy Policy
mobrule connects a streamer's Twitch channel to a local application ("the bridge") that turns channel-point redemptions and chat into in-game effects. This policy covers the whole service: the mobrule.tv website, the desktop app, and the cloud backend.
01Who we are
The mobrule service is operated by Aiko van Wingerden, based in the Netherlands. Contact: hi@aiko.works.
This is a solo, open-source, non-commercial service. There is currently no legal entity; the operator named above is the responsible party.
02What this policy covers
It is written for streamers — the people who connect their Twitch account. Data about a streamer's viewers also flows through the service; how that is handled, and who is responsible to viewers, is described in section 06.
03What we process
Streamer / operator data. Twitch OAuth access & refresh tokens; Twitch broadcaster ID and login name; token expiry timestamp; channel-point reward configuration you create.
Tokens are stored encrypted at rest (AES-256-GCM). They are used only to read your channel's redemption/chat events and to provision and refund channel-point rewards on your behalf.
Viewer data (passes through).
- Twitch username / display name / user ID
- Channel-point redemptions (what was redeemed, when)
- Viewer free text attached to a redemption
- Chat messages / votes when a pack uses chat-plays
- Undeliverable-redemption records (for refunds)
Technical / error data. Our self-hosted Sentry instance (across the bridge, ingester, and website services) captures error diagnostics — user-agent, the failing URL, and stack traces — to keep the service stable and secure. PII is not attached (IP/user are not sent), and website session replays mask all text, inputs, and media. Sentry is disabled unless a DSN is configured. Streamers can turn crash and error diagnostics off at any time from the desktop app — on the “connect your channel” screen or later under Settings — which stops new error and crash reports right away and is remembered for good on the next restart.
04Why, and on what legal basis
- Streamer tokens & config — to provide the service you signed up for. Legal basis: contract (GDPR Art. 6(1)(b)).
- Viewer redemptions / input — to execute the streamer's configured effects. Legal basis: legitimate interest (Art. 6(1)(f)).
- Error / technical data — stability & security. Legal basis: legitimate interest (Art. 6(1)(f)).
05Retention
- Streamer tokens: until you disconnect / revoke
- Reward configuration: until you delete it
- Chat-plays votes: 60 seconds
- Web session cookie: 30 days
- Viewer redemption / invocation records: 30 days (auto-pruned)
- Undeliverable-redemption records: 30 days (resolved rows)
- Sentry error data: 30 days
06Roles — who is responsible to viewers
Viewer data originates from Twitch, the primary controller of viewer accounts. For viewer data flowing through mobrule, the streamer is the controller and mobrule acts as a processor on the streamer's behalf.
Because we have no direct relationship with viewers, we do not serve viewers a privacy notice directly. Streamers are responsible for informing their own viewers that a third-party tool processes their redemptions and chat — for example via a Twitch channel panel, chat command, or channel rules.
07Sharing & sub-processors
- Twitch — source of channel events; recipient of reward provisioning/refund calls.
- Hetzner (Germany) — runs our servers (intra-EU).
- We do not sell data, run ads, or use third-party analytics.
08Where data is stored
On servers located in Germany, within the EU/EEA. No transfers outside the EEA.
09Your rights
You may request access, rectification, erasure, restriction, objection, or portability of your personal data at hi@aiko.works. You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
10Security
Twitch tokens are encrypted at rest (AES-256-GCM). Access to production infrastructure is restricted to the operator.
11Changes
We may update this policy; changes are posted here with a new date.