1. Who we are and when this policy applies
StreamBruh is operated by José Ponce Muñoz, established in Chile. This policy explains how we handle personal information when you visit our website, sign in with Discord, configure your own bot, use notification services, link Patreon, or communicate with us. References to “we,” “us,” and “our” mean the operator of StreamBruh.
The policy also addresses information about public streamers and video creators referenced in notifications and limited information about Discord servers and channels used to deliver them. It does not replace the privacy notices of Discord, Twitch, Kick, Google/YouTube, Patreon, or your Discord server administrator. Those parties determine their own processing practices.
We determine the purposes of processing account, security, service administration, and subscription information. Where we process personal information solely on a customer’s documented instructions to deliver notifications, our role may instead be that of a processor or service provider under applicable law. Organizations requiring a data processing agreement must arrange one before submitting data that requires such an agreement. This policy alone is not a signed data processing agreement.
2. Information we receive
Account information includes your Discord user identifier, username, avatar, sign-in information, account creation dates, trial dates, service entitlement, and selected server. Discord authorization may provide the servers available to your account, server names and icons, ownership information, and permissions needed to determine which server you can configure.
Configuration information includes bot application identifiers and names; selected server and channel identifiers; streamer and channel identifiers, names, and URLs; game or category selections; languages and other notification filters; message templates; button settings; enabled status; and configuration revisions. Information entered into a template may become visible to everyone who can view the destination channel.
Credentials include the bot token and provider credentials you choose to supply, such as Twitch or Kick client credentials and YouTube API keys. We also process Discord OAuth credentials and, when linked, Patreon OAuth credentials needed to maintain an authorized connection. These are sensitive service credentials even where a particular credential does not itself identify an individual.
Public provider information may include a creator’s public identifier, display name, stream or video title, category, language, live status, viewer count, thumbnail, broadcast URL, and publication information. We obtain this information from the relevant provider to evaluate and produce your requested notifications.
Notification records include message, channel, server, and stream identifiers; notification content and preview references; color; delivery and update times; source configurations; and delivery, retry, deletion, and diagnostic states. These records allow us to avoid duplicate delivery, refresh previews, and remove tracked announcements.
When Patreon integration is available and you link it, we receive the Patreon account and membership identifiers and membership information needed to verify the authorized campaign, tier, current entitlement, payment status, and any dates supplied by Patreon. We keep synchronization and access-change records. StreamBruh does not ask for or store your payment card number, bank account details, or card security code. Patreon and its payment partners handle checkout and payment processing.
Technical information may include IP addresses, browser and request information, timestamps, error details, rate-limit states, and security or operational logs generated by our application and hosting infrastructure. If you contact us, we receive the information you provide, your contact details, and our correspondence. Do not send passwords, bot tokens, API secrets, or payment card information in support requests.
3. Discord messages and bot permissions
StreamBruh is a notification service, not a conversation-monitoring service. Its normal operation does not collect, profile, or monitor ordinary member conversations or private direct messages. The bot client does not request Discord’s Message Content gateway intent. The service does retrieve its tracked notification messages where necessary to check their existence or update their previews.
Our bot invitation does not request the Administrator permission. It requests permissions needed by the current integration, including View Channels, Send Messages, Manage Messages, Embed Links, Attach Files, and Read Message History. Read Message History and Manage Messages are broader capabilities than simply posting a new notification. We therefore do not claim that a bot token is technically incapable of accessing other messages or performing other actions permitted by Discord.
You control the bot’s actual Discord roles and channel permissions. A server administrator can grant additional permissions independently of our invitation. We recommend granting only the permissions required in the intended channels and not assigning Administrator. The application is designed to operate on configured servers, channels, and tracked announcements; those application restrictions do not reduce the underlying powers of a token if it is compromised.
Server administrators should inform their communities about the bot and avoid placing sensitive personal information in notification templates. Removing the bot, revoking its permissions, or rotating its token can prevent further operations, but does not automatically delete information already retained by StreamBruh or Discord.
4. Credential encryption and security
Sensitive credentials stored in application database credential fields are encrypted using AES-256-GCM. The service uses a server-side encryption key to decrypt them when it needs to authenticate with a provider. Credentials may therefore be available in decrypted form in server memory during authorized operations. Ordinary configuration responses do not return stored secrets as readable values.
This is encryption at rest, not end-to-end or zero-knowledge encryption. It would be inaccurate to say that we are technically unable to read the tokens: the running service, and a person who obtains both the encrypted data and the necessary server key, can decrypt them. Access must be limited to legitimate operational, maintenance, and security needs. Encryption does not make an overprivileged or compromised bot safe.
We use application safeguards such as authentication, authorization checks, signed session cookies, encrypted credential storage, and request validation. No system or internet transmission can be guaranteed completely secure. If a personal information breach occurs, we will assess it and provide notifications to affected individuals or authorities where required by applicable law.
You are responsible for protecting your Discord and provider accounts and using appropriately restricted credentials. If you suspect exposure, revoke or rotate the affected credential at its provider and notify support without including the secret itself. Replacing credentials does not necessarily erase copies retained in restricted backups immediately.
5. Why we use information
We use information to authenticate you, determine server-management permissions, save your configurations, connect your bot and providers, detect eligible streams and videos, publish notifications, update previews, remove tracked messages, and show operational diagnostics. We also use it to administer trials, verify subscriptions and administrative grants, enforce the one-server entitlement, and restore service after recoverable failures.
Other purposes include responding to requests, investigating incidents and abuse, maintaining reliability, preventing unauthorized access or duplicate operations, enforcing our terms, resolving disputes, and complying with legal obligations. We do not use bot credentials to operate unrelated services, and we do not use ordinary Discord conversations for advertising or model training as part of this service.
Where the GDPR or a comparable law requires a legal basis, processing may be necessary to perform our contract with an individual customer, comply with a legal obligation, or pursue legitimate interests in secure and reliable service administration, subject to the individual’s rights. Processing information about authorized business representatives, public creators, or server administration may rely on legitimate interests rather than a contract with that person. Where consent is required, we will seek it and permit withdrawal; withdrawal does not invalidate earlier lawful processing.
Entitlement and permission checks are automated and can allow or restrict service access. You may request review of a disputed result. We do not use the service to make credit, employment, or insurance assessments or to build advertising profiles.
6. Cookies and local storage
The streambruh_session cookie maintains your authenticated session and has a maximum configured lifetime of 180 days. Discord and Patreon authorization state cookies are short-lived, normally ten minutes, and help protect their respective sign-in or linking flows. Session and authorization cookies use security attributes appropriate to their production use. Signing a cookie protects its integrity; it is not a claim that its contents are encrypted.
Your browser may retain streambruh-theme in local storage to remember a light or dark appearance until you change it or clear browser storage. The current application does not install advertising cookies or third-party analytics trackers. External sites you open, including payment and streaming providers, operate under their own cookie policies.
You can clear cookies and local storage through your browser. Blocking necessary cookies may prevent sign-in or account linking. We do not currently sell personal information or share it for cross-context behavioral advertising, so there is no such advertising activity to disable through an opt-out preference signal. If our practices change, we will update this notice and implement any required consent or opt-out controls before that processing begins.
7. When information is disclosed
We send the information necessary to carry out your chosen integrations to Discord, Twitch, Kick, Google/YouTube, and Patreon, as applicable. For example, Discord receives notification content and destination identifiers, streaming providers receive authenticated API requests, and Patreon provides membership verification. These platforms may act as independent controllers for their own processing.
Hosting, database, infrastructure, and communication providers may process information needed to run the service. Authorized personnel may access information for necessary support, security, and maintenance. We do not sell personal information, rent user lists, or provide personal information to advertisers for behavioral targeting.
Information may be disclosed when legally required, to respond to a valid legal process, to protect rights and safety, or to investigate misuse, subject to applicable law and appropriate limits. If the service is transferred or reorganized, relevant information may be transferred as part of that transaction with legally required safeguards and notice. This provision does not authorize an unrelated use inconsistent with applicable law.
Notifications are disclosed to people who can access the Discord channels you select. Public provider images may be loaded through Discord or the provider’s infrastructure. We cannot control recipients’ screenshots, onward sharing, or retention of a notification after it has been delivered.
8. International processing
The operator is established in Chile. Our infrastructure and the platforms you connect may process information in other countries, including countries with privacy laws different from those of your residence. A provider’s location and contractual arrangements determine where its processing occurs; we do not represent that all information remains in Chile or in your own country.
Where a restricted international transfer requires an additional legal mechanism, that transfer must be supported by an applicable adequacy decision, approved contractual safeguards, or another lawful mechanism. This statement does not mean that Chile automatically has an EU adequacy finding or that every provider agreement contains a particular clause. You may ask for information about relevant transfer arrangements and available safeguards, subject to necessary security and confidentiality limitations.
9. Retention, disconnection, and deletion
Account and configuration records are retained while needed to provide and administer your account. Subscription expiry alone does not delete your configurations: they may be retained to support recovery or reactivation. You can request account closure and deletion, subject to limited information we must retain for legal obligations, security, dispute resolution, or the establishment or defense of claims.
Notification and diagnostic records are retained as needed for delivery verification, duplicate prevention, retries, cleanup, and troubleshooting. An encrypted recovery credential may remain attached to a pending cleanup operation so that the service can remove a previously sent notification after settings change. A failed deletion can leave the original Discord message in place. Revoking the credential may prevent automated cleanup.
Authorization state expires quickly. Processed Patreon event records are scheduled for removal after approximately 30 days when the billing cleanup worker is operating; this is not a 30-day deletion promise for all subscription, audit, or account records. Subscription verification and access-change records may remain necessary for account administration and disputes.
For logs, correspondence, and backups, retention depends on operational need, incident investigation, legal requirements, and backup rotation. Backups are not necessarily edited immediately when live records are deleted. Information retained only in backups must not be restored to ordinary use without honoring applicable deletion restrictions. We do not promise a universal fixed deletion period that the service cannot enforce.
Disconnecting a provider or deleting a StreamBruh configuration does not cancel a Patreon subscription or erase records held independently by that provider. Use the provider’s account controls for its own permissions, billing, and deletion requests.
10. Your choices and privacy requests
Depending on your location and the law that applies, you may request confirmation of processing, access or a copy, correction, deletion, restriction, portability, information about recipients, or withdrawal of consent. You may also have the right to object to certain processing, challenge a refusal, and complain to a supervisory authority. Some information may be exempt or subject to a legal retention requirement.
Send privacy requests to privacy@streambruh.com. Identify the account or context concerned and the request you wish to make. Do not include credentials. We may ask for proportionate information to verify identity or an agent’s authority and to avoid disclosing another person’s information. We will explain a refusal or limitation where required and will not retaliate for exercising protected privacy rights.
Where information was submitted on a server administrator’s behalf, we may need to refer the request to that administrator or assist them in responding. This does not remove our responsibility for information for which we are the controller. Requests about records held independently by Discord or another provider should also be directed to that provider.
11. Regional privacy information
Chile: the operator is subject to applicable Chilean law, including Law No. 19,628 as currently effective. Chile’s new personal data framework under Law No. 21,719 is scheduled to take effect on December 1, 2026. This policy does not present those future provisions as already effective. We will review our practices and this notice for that transition.
European Economic Area and United Kingdom: where their data protection laws apply, you may exercise the rights described above, object to processing based on legitimate interests, and complain to the competent data protection authority. GDPR requests are generally answered within one month, with permitted extensions and notice where applicable. Consent can be withdrawn at any time for processing that relies on it. Any requirement for a local representative or additional transfer safeguards depends on the service’s actual activities and must be assessed separately.
Canada: where PIPEDA or provincial privacy law applies, you may request access, challenge accuracy, inquire about our practices, and complain to the relevant privacy commissioner. PIPEDA access requests generally require a response within 30 days, subject to lawful extensions. Consent and exceptions depend on the information and applicable law. Provincial requirements, including Quebec requirements where applicable, are not displaced by this English-language notice.
Brazil: where the LGPD applies, rights may include confirmation, access, correction, anonymization, blocking or deletion of unnecessary or unlawfully processed information, portability under applicable rules, information about sharing, consent-related information and withdrawal, and review of relevant automated decisions. Access may be provided in simplified form promptly or through a complete statement within the applicable statutory period, generally 15 days for that statement. You may petition the ANPD and other competent bodies. Applicable international transfer rules must also be respected.
United States: privacy rights vary by state and many comprehensive state laws apply only when statutory thresholds or other conditions are met. Where applicable, rights may include access, correction, deletion, portability, an authorized agent, appeal, and opting out of sale, targeted advertising, or certain profiling. California access and deletion requests generally have a 45-day response period, subject to lawful extensions. We do not claim that every state statute applies to this small service, and we do not condition mandatory rights on accepting these terms.
12. Children and sensitive information
The service is intended for customers who are at least 18 and have reached the age of majority where they live, or authorized representatives of organizations. We do not knowingly solicit accounts from children. A customer’s Discord community may include younger people, but that does not authorize the customer to use StreamBruh to collect their private conversations or sensitive information.
Do not submit health information, government identifiers, financial account information, or other sensitive personal information in templates or support materials unless specifically necessary and a suitable secure process has been agreed. If you believe a child has supplied personal information directly to us improperly, contact us so we can investigate and take appropriate action.
13. Changes and contact
We will update this policy when our practices or relevant requirements change. A published version will identify its effective date. Material changes will receive additional notice where required; posting a new policy does not retrospectively authorize processing that required prior consent.
Operator: José Ponce Muñoz. Postal contact: Lo salas 2000, Olmué, Valparaíso, Chile. Privacy requests: privacy@streambruh.com. General support: support@streambruh.com. Please identify the account concerned without including passwords, bot tokens, or API secrets.

