The short version
What we hold, at a glance
The whole data story in one view. Every point below is spelled out in full in the sections that follow.
Never, for anyone: profiling your viewers, advertising, or selling or sharing your data. The only data kept beyond your control is the billing records the law requires, described under the Privacy Policy.
The commitment at the core
The Sovereign User Promise
This is the promise the whole company is built around: minimal data, never sold, and strict rules on how that can ever change, binding on us even under future ownership.
1. Our commitment. SparkStream collects the minimum data needed to run the service, and never sells your data. This Promise governs how that can ever change, and it binds us including under any future ownership or management.
2. What counts as a material change. A "material change" is any change to how we collect, use, retain, share, or disclose your data, or to your rights over it. The following are always material and cannot be classified as anything else:
- a)collecting any category of data we did not previously collect;
- b)using your data for any new purpose;
- c)sharing, disclosing, selling, or transferring your data to any third party in a way not already permitted under the terms then in force;
- d)increasing how long we retain your data;
- e)reducing, removing, or weakening any right, remedy, or protection you have over your data; or
- f)any change to this Promise itself.
The only changes that are not material are: correcting typographical or formatting errors; clarifications that do not change meaning or your rights; and updating our company contact or registration details. Anything not in this list is treated as material.
3. The 14-day grace period. No material change takes effect, and no new or expanded collection or use of your data may begin, until 14 days after we send notice of it both inside the app and by email.
- •The grace period runs from the date the notice is sent, not the date you open or read it.
- •The notice states the date it was sent, the date the grace period ends, and the time remaining, so you can always see how long you have.
- •We send this notice by email to the address associated with every account, and display it inside the app, so it cannot be missed.
4. Your Clean Slate rights. Throughout the 14-day period, and at any other time, you may, with one clear action in the app:
- a)download a complete copy of your data;
- b)delete your historic data, so that data collected under the previous terms is not carried into the new terms; and
- c)delete your account and all associated data.
5. Your historic data stays under the terms it was collected under. Data we already hold remains governed by the version of this Policy in force when it was collected. We will not apply any material change to it retroactively, nor repurpose it under new terms, without your fresh, explicit consent.
6. While you decide, nothing changes. During the grace period the app does not transmit any newly-collected data to us. You are shown a clear, neutral notice explaining the change, and you choose how to proceed, including a simple acknowledgement, "I have read this and I am OK with data collection," if you wish to continue.
7. This Promise is self-protecting. This Promise is part of our agreement with you. Any future change of ownership, directors, or management is bound by it as it stands, and any attempt to change or remove it is itself a material change subject to every protection above.
The agreement
Terms of Service
The important points in plain language, no legalese. Version 1.0. By using SparkStream you confirm you are at least 16, or the minimum age required where you live, and that you may accept these terms.
SparkStream is a local desktop tool that connects to your Twitch account and lets you automate actions in response to channel point redemptions and stream events. It runs on your machine. The core features require no internet connection beyond Twitch itself.
By using SparkStream you agree to use it only for lawful purposes and in ways that do not violate Twitch’s own Terms of Service. You are responsible for the actions you configure. If a reward triggers a hotkey, a script, or an HTTP request, that is your configuration running on your machine.
SparkStream stores the minimum data necessary to provide the service. Everything that can stay on your machine, does. For an account using only the local core, the server holds little more than your Twitch user ID, your licence status, and a record of your agreement to these terms. Anything beyond that exists only because you used a feature that needs it, such as a support ticket, a direct message, or an opt-in Pro feature. We do not sell, share, or monetise your data or your viewers’ data. The only data retained beyond your control is data we are legally required to keep, held for exactly as long as the law requires and no longer. The full detail is set out in the Privacy Policy below.
Pro features require an active licence. Licences are non-transferable between Twitch accounts. SparkStream reserves the right to revoke a licence if it is found to be fraudulently obtained or used in violation of these terms. Refund eligibility is handled case by case; contact support.
SparkStream is provided as-is. While we work hard to keep it reliable, we cannot guarantee uninterrupted service or that it will work with every system configuration. We are not liable for any loss or damage resulting from the use of SparkStream, including actions triggered by the app on your machine.
If the terms change in a material way, you will be shown the terms again and asked to re-agree before continuing. Changes will not be applied silently. The version of the terms you agreed to is recorded locally alongside the date of acceptance. Material changes to how we handle your data are additionally governed by the Sovereign User Promise above.
Your data
Privacy Policy
What we hold, what we never do with it, and the rights you always keep. Material changes to any of this are governed by the Sovereign User Promise above.
If you use only the local core, the server holds very little: your Twitch user ID, your licence status, a record that you accepted these terms, and the devices signed in to your account, which is what lets you see them in Settings and sign one out from another. Everything that can stay on your machine, does, so your chat and stream events stay on it. Beyond that, the server only holds what a feature you switch on needs: support tickets, your end-to-end-encrypted messages (which we cannot read), posts you make in the community, forum reports you file, your referral and loyalty records, your notification preferences, and your Cloud Sync backup if you enable it, which is encrypted on your device so that we only ever hold ciphertext.
By default, your redemption history and viewer data never leave your machine, and neither does your chat. Five opt-in features are the exception, and none of them is on unless you turn it on. Cloud Analytics (Pro) records channel-point redemption events for your own dashboard, with viewer identifiers hashed so individuals are never identified. Your stream statistics (Pro) go with it: while you are live we keep a running summary of your own channel’s numbers, your average and highest viewer count, how long you were live, and your subscriber and follower totals, so the same dashboard can show you how your streams compare over time. Those are your own figures, the ones Twitch already shows you, and they are totals: no individual viewer is described in them. The Mobile Approval Queue (Pro) temporarily syncs pending redemptions so your phone can show them, removes each one the moment you approve or decline it, and clears anything still waiting after four hours. The hosted chat bot (Pro), if you add it to your channel, reads your channel chat on our servers so it can spot when someone types a command: it acts on those messages and does not store your chat. Bot features you switch on go one step further, because a command like the subathon one has to know what is happening in your app before the bot can answer it: switching such a feature on sends us what that feature needs, only while it is on, and it is used to run that feature and nothing else. Where one of them has to hold something about the viewers who use it, a giveaway being the obvious case, it holds the least it can work with and lets go of it when the feature is switched off.
A collab session lets you link with another SparkStream streamer so your overlays, goals and countdowns can work across both channels. Nothing is shared until you choose to start a session. When you do, we relay between the two apps only what each of you has switched on, your viewers’ display names are off by default, and none of it is kept on our server once the session ends. Channel points never cross channels: a redemption is always settled on the channel it happened on.
A public channel page shows what is happening on your channel right now, at a web address anyone can open. Depending on the panels you turn on it can show the rewards you offer and what they currently cost, a goal in progress, a running auction or subathon, your commands, your saved quotes, and a short description of your channel if you write one. Your page is off until you switch it on, and only the panels you chose to show are sent. Anything concerning your viewers appears as a total rather than a name: no viewer is identified on the page, and an auction shows how many people have bid rather than who they are. Links on the page are a platform and a handle you pick from a fixed list, never a web address typed in free text, and no images are ever uploaded. The description is the one part of the page you write yourself, so it is checked for slurs and hate before it goes up and anyone who visits a page can report it. Switching the page off stops it being served and removes what was held for it.
Direct messages between streamers are end-to-end encrypted. Your private key never leaves your device, so we cannot read your messages, not in transit, not at rest, not ever. The limited data we do hold (such as support ticket contents) is encrypted at rest.
We do not profile you or your viewers for advertising, and we never sell or share your data. There is no advertising and no third-party tracking. The only analytics we offer is the opt-in Pro dashboard of your own channel activity, with viewer identifiers hashed.
At any time, with one clear action in the app, you can download everything we hold about you, delete your historic data, or delete your account and all associated data. The Sovereign User Promise above governs how any of this can ever change.
The only data retained beyond your control is data we are legally required to keep, such as the billing records UK tax law requires us to hold for six years for HMRC. These are limited to Stripe transaction records, kept separate from your ordinary account data, and used only to meet that obligation.
How it is built
Security by design
Security here is mostly about what does not exist: data we never collect, round-trips we never make, and messages we cannot read. Less to protect means less to lose.
The core of SparkStream runs on your machine. Reward mappings, actions, game detection, and overlays all work without a cloud round-trip, so there is simply less of your activity anywhere for anyone to intercept or leak.
Streamer-to-streamer direct messages are encrypted with keys generated on your device. The private key never leaves it, so no one, including us, can read your messages.
Sensitive values kept on your machine, such as access tokens and API keys, are encrypted with your operating system’s secure storage rather than left in plain text.
Most of what a breach would want simply is not there. Your chat, your stream events, and your day-to-day redemption history stay on your machine rather than in a central store. What the server holds is the minimum each feature you use needs, which keeps the target small.
SparkStream does not quietly phone home with analytics about how you use the app. Diagnostics stay on your machine unless you choose to attach them to a support ticket. Nothing about how you use the app is ever sent automatically.
If you find a hole
Reporting a vulnerability
Security is not only what we build, it is what we do when somebody finds a problem with it. There is a published policy for that, and it is worth reading before you touch anything.
You have our permission to test SparkStream, and our word that we will not come after anyone who does it in good faith and inside the rules, including under the Computer Misuse Act 1990. We acknowledge a report within five working days, keep you posted while it is open, tell you when it is fixed, and credit you if you want the credit. We cannot pay for reports yet, and the policy says so plainly rather than leaving you to guess.
Third parties
Who we rely on
A short, deliberate list of the outside services SparkStream touches, split into the few that process a slice of your data for us and the optional integrations that run entirely on your machine.
Sign-in and the live stream events SparkStream reacts to. You authorise SparkStream through Twitch’s own login; we never see your Twitch password.
Cloud hosting for the SparkStream server and the database behind it, which holds only the limited data described above (such as your Twitch ID, licence status, and support ticket contents). Encrypted in transit and at rest.
Payments and billing for Pro. Card details go straight to Stripe and never touch SparkStream. We store only the reference needed to manage your subscription.
Two ways to connect, both opt-in. The free webhook keeps everything on your machine: the webhook URL is stored encrypted locally and posts go from your PC straight to your channel, our servers never see it. The optional SparkStream bot (Pro) is hosted by us, so for the features you turn on it relays only what is needed to post (the link to your server, and things like a redemption or your current track) through our servers to Discord. That is passed straight through, never stored, and spelled out in the Data Charter.
Only if you connect Spotify. It runs on a Spotify app you create, and your Spotify tokens stay encrypted on your PC. Our servers never touch them.
In your hands
Your data rights
These are not requests you file and wait on. Each one is a control inside the app that takes effect immediately.
One action in the app exports everything we hold about you, in the same form we hold it.
Clear your historic data whenever you want, without deleting your account.
Remove your account and all associated data. The only thing left is the billing records the law requires us to keep.
How any of this can ever change is governed by the Sovereign User Promise, binding on us even under new ownership.
If we fall short
Service Level Agreement
The Promise is only as good as what happens when it is broken. This is the consequence we accept, in your favour, for breaching the grace period or notice.
Compensation for breach of grace or notice. If the company breaches the 14-day grace period set out in the Sovereign User Promise, or begins or expands the collection or use of data without first providing the transparent notice that Promise requires, then each affected user is entitled to £100 in compensation.
- •"Affected user" means any user whose data was, or could have been, collected or used under the change before the grace period had properly elapsed and proper notice had been given.
- •This sum is agreed by the parties as a genuine pre-estimate of the harm caused to a user by the improper collection or use of their data contrary to this Promise, and as protecting the legitimate interest of both users and the company in the company's foundational commitment to data sovereignty. It is not a penalty.
- •This entitlement is in addition to a user's Clean Slate rights to download and delete their data, and does not limit any other remedy available to a user at law.
- •For the avoidance of doubt, this compensation is payable per affected user and is not capped by reference to the company's revenue or resources.
Talk to us
Contact
Questions about any of this, or want to exercise one of your rights with a hand? We are reachable and we answer.
The fastest route is the support system inside the app, which opens a ticket the SparkStream team can reply to directly. For anything else, email hello@sparkstreamapp.com.