Legal
Privacy Policy
Plain English, no dark patterns. Here's exactly what we hold and why.
Last updated 14 August 2026
The short version
We collect the least we can get away with: enough to give you an account, keep you signed in across our apps, take a payment if you ever choose to make one, and email you if you asked us to. There are no analytics, no advertising and no third-party trackers anywhere on this site. We have never sold your data and we're not going to.
Who we are
StrmrX is a two-person studio building apps for streamers. If you want anything on this page actioned — a copy of your data, a correction, or a deletion — email support@strmrx.com and a person will read it.
What we collect
Your account
Your email address, a display name if you set one, and — if you signed up with a password — a hashed version of it. We never store your password itself and we cannot read it.
When you sign in with Twitch
Twitch tells us your platform user id, your handle, your display name, your avatar, the email address associated with your Twitch account, and which permissions you granted. Where an app needs to keep talking to Twitch for you — reading your chat, for example — we also store the access and refresh tokens that let it do so. You can disconnect Twitch from your dashboard at any time.
When you connect Discord
Connecting Discord is optional. If you do, Discord tells us your Discord user id, username, and avatar, and — so our apps can recognize you as the same person on both platforms — whether your Discord account vouches for a Twitch account you've linked there. We store the access and refresh tokens that let us read that, and we share only the paired platform ids with our own apps so they can treat you as one person. You can disconnect Discord from your dashboard at any time.
Staying signed in
When you sign in we create a session and record the IP address and browser user-agent of that sign-in, so we can show you your active sessions and spot abuse. Sessions expire after 30 days.
If you arrived through someone's referral link
We record which member's link you used and when, so that if you take out a plan they get the free month the offer promises them. Alongside that we store a hashed form of the IP address the signup came from — not the address itself, which we never write down here. It exists for one purpose: to notice when the two ends of a referral look like the same person, in which case a human checks it before anything is paid. A hash compares just as well for that and tells us nothing about where you are. Your friend is never shown your address, your email, or anything else about you beyond the fact that somebody joined.
Payments
If and when you buy a paid tier, Stripe handles the card details. They never touch our servers and we could not see them if we wanted to. We keep the customer reference Stripe gives us and whether your subscription is active, so we know what to unlock.
Newsletter and the beta list
If you subscribe to the newsletter we keep your email address and which page you subscribed from. If you claim a beta pass we keep your email address and the alias you chose, if any. These are two separate lists, on purpose: claiming a beta pass gets you exactly one email — the one telling you your wave is open.
When we do send one of those, we record that we sent it: the address, which email it was, when it went, and whether it arrived. That record exists for your benefit rather than ours — it is the thing that stops us mailing you the same announcement twice. It holds no message content beyond the name of the email itself.
Support tickets
If you open a support ticket from our help page, we keep your message and — only if you leave the checkbox ticked — the diagnostic report shown to you on that page: your browser's name and version, your operating system, screen size, and the pass/fail results of the checks the page ran (cookies, connection, app reachability and so on). You can read the entire report before you send it, word for word. It exists so we can fix your problem without a week of "what browser are you on?" back-and-forth. Tickets are tied to your account so we can reply to you, and closed tickets are deleted when no longer needed.
Admin actions
Changes made in our own admin panel are written to an audit log, so we can see who changed what. This records us, not you.
Cookies and local storage
We set one cookie in normal use. It is called sx_sess, it holds a random session
token and nothing else, and it is marked HttpOnly and Secure so scripts cannot read it
and it only travels over HTTPS. It is scoped to .strmrx.com so that a single sign-in works across
every StrmrX app. It lasts 30 days. Sign out and we delete it.
There is a second one, and you only get it if you follow somebody's referral link. Opening a
strmrx.com/r/… link sets sx_ref, which holds that link's short code and the moment you
clicked it — nothing about you, and nothing that identifies the person whose link it was. It exists so that if you
make an account we know who to thank, and so the 24-hour window on that offer is measured from your click rather
than from whenever you get round to signing up. It expires by itself after 24 hours, and we delete it the moment
you sign in or sign up, whichever comes first. If you never use a referral link you never get it.
Your browser also keeps two small values locally, which are never sent to us:
sx_beta_pass— your beta pass, so we can show it back to you instead of asking twice.sx_beta_bar— whether you dismissed the beta announcement bar.
One footnote: the help page briefly sets a throwaway cookie called sx_diag to
prove your browser accepts cookies, and deletes it in the same instant. It holds the value "1" and nothing else.
There is no analytics cookie, no advertising pixel, and no third-party script that could set one.
Who else sees your data
- Twitch — only if you choose to sign in or connect with it.
- Discord — only if you choose to connect it.
- Stripe — only if you make a payment. They are the payment processor.
- Railway — our hosting provider, on whose infrastructure this site and its database run.
- SiteGround — our email provider, who necessarily handle any mail we send you.
- Ko-fi — only if you follow our donate link. That happens on their site, under their policy, and we learn nothing beyond what Ko-fi chooses to show us.
That's the complete list. We do not sell, rent or trade your personal data, and there is no advertising business here to sell it to.
How long we keep it
- Sessions — 30 days, then they expire on their own.
- Account data — until you ask us to delete the account.
- Newsletter — until you unsubscribe or ask to be removed.
- Beta list — until your wave opens, or until you ask to be removed.
- Record of emails we've sent you — kept while the list itself is, so we don't repeat one.
- Support tickets — while they're open; closed tickets are cleared out periodically, or on request.
Your choices
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email support@strmrx.com. We'll do it, and we won't make you jump through hoops. Deleting your account removes your account record and its sessions; where we're required to keep a payment record for accounting, we'll say so.
You don't have to ask us to delete your account — you can do it yourself, from your dashboard, under Delete my account. It takes effect immediately and signs you out everywhere. Emailing us still works if you'd rather, and it's the route to take if you also want a copy of your data or a correction.
You can disconnect Twitch or Discord yourself from your dashboard, and unsubscribe from any email we send.
Security
Passwords are hashed, not stored. Credentials we hold for our own integrations are encrypted at rest. The site and the API are HTTPS-only, and session cookies are HttpOnly. No system is perfect; if we ever discover a breach affecting your data, we'll tell you rather than hope you don't notice.
Children
StrmrX is not for children under 13, matching Twitch's own minimum age. If you believe a child has given us personal data, email us and we'll remove it.
Changes to this policy
If we change what we collect or who we share it with, we'll update this page and the date at the top. If the change is significant and you have an account, we'll email you.