Privacy & security
Which data we process for streamwizard.de, OBSBot, and the giveaway system, why, and which rights you have.
The controller under GDPR is the operator named in the imprint. For creator-controlled features (giveaways, community prizes, streamstats, Bot Protection), the respective creator decides about channel, rules, blocklists, and imports. StreamWizard provides the technical platform; the creator informs viewers in the channel/community context about data processing.
a) Discord login & account
Via Discord OAuth: Discord ID, username, avatar URL, and – if transmitted – email. Internal: rank, activation status, license linkage. Sensitive identifiers are stored in the enc/hash model (HMAC-SHA-256 for lookup, AES-256-GCM for reversible values).
b) Session, API key, downloads
Technically required session cookie (PHPSESSID). One API key per account for protected downloads/API. Signed one-time download links for support and dashboard flows.
c) OBSBot (24/7 stream bot)
Configuration data (playlist paths, scenes, OBS WebSocket target, Twitch/Kick connection). Runtime session data for single-instance enforcement: instance ID, pseudonymized device_id (hash), heartbeat timestamps, status. Command queue (skip/recover/update plus forwarded chat commands) contains command_name, requested_via, requested_by, timestamps, attempt counter and – for chat commands – only the necessary arguments (triggering Twitch login, mod status, optional mark text); stored briefly, deleted automatically. The OBSBot Twitch chat runs via the central StreamWizard system bot, NO LONGER via a local creator Twitch token: the system bot is added once (dashboard, OAuth with channel:manage:moderators) as a moderator in the channel, sends bot status messages, and only reads command triggers (!skip/!vote/!mark) – chat content is not stored. The broadcaster identity (Twitch login/ID) is stored in the enc/hash model. Kick OAuth codes still use the token bridge on our server (RSA-OAEP-2048 + AES-256-GCM); system client secrets never leave the server.
d) Giveaway system: giveaways
Creator data: campaign title, ticket/point rules, sub-tier bonuses, channel slug, response templates (encrypted). Viewer data (also without StreamWizard account): Twitch user ID, login, display name in enc/hash model + technical counters (point balance, tickets, watchtime, winner rank). Twitch chat purchases only when the stream is reported online; chat content is not stored, only command triggers. On a draw, the winner display name may be announced in the creator's Twitch chat (creator setting).
e) Giveaway system: community prizes
Submissions via Discord forum or !einreichen: Discord owner ID (hash + encrypted), display name (encrypted), thread ID (hash + encrypted), prize description (encrypted). Separate weekly participant list (tickets, Twitch login in enc/hash model). Winner tracking with drawn_at/claimed_at. Weekly reset on Sundays.
f) Giveaway system: streamstats
Creator Twitch connection (encrypted tokens, scopes). Aggregated viewer counters: watchtime seconds, chat message count (no content), bits, gift subs. Ignore lists maintained by the creator. Streamstats is available only after admin entitlement; no team/delegate sharing.
g) Bot Protection
Optional protection feature against bot/spam accounts in the giveaway system. The creator maintains a block list of Twitch login names (stored encrypted or as a hash). For listed names, no new points/stars, watchtime, or bonuses are credited in the giveaway (points accrual is frozen); the existing balance is preserved unchanged – nothing is set to 0 and nothing is deleted. Viewers with a genuine monetary contribution (active sub, bits, or gifted subs) are exempt from the freeze and keep earning normally. We process only the names entered by the creator (enc/hash) and technical run metadata (timestamp, number of checked entries). There is no StreamElements integration, no JWT, and no access to third-party loyalty/points systems. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in defending against bot, multi-account, and abusive participation in the creator's giveaway). Giveaway points and tickets are free participation values with no monetary value and no claim to payout.
h) Central Discord runtime & token bridge
Discord features for OBSBot and giveaway workers run via the central runtime (StreamwizardNode) with HMAC-signed dispatch, replay protection, owner/delegate check, idempotency dedupe, and multi-level rate limits. OAuth code messages in Discord guild channels are deleted automatically. Twitch/Kick/YouTube OAuth code exchange runs via the token bridge on our server; platform responses are returned hybrid-encrypted to the bot instance.
i) Team delegates
A license holder can invite other accounts as delegate for dashboard moderation (owner/delegate ID, token hash, creation/expiration/revocation time, optional note). Delegates receive no license and no download. For their own mod tools, delegates or licensed owners may create a personal Team API key; only the key hash, display hint, creation/use/revocation time are stored. The key allows only capped read access to shared viewer and Giveaway data and becomes ineffective when team access is revoked. Invitation valid for 7 days, one-time use; max. 5 active delegates per owner.
j) Payment & Trustpilot
Payment via Stripe (Premium, VIP, Diamond, licenses). Stripe processes payment data as its own controller. We store Stripe customer/subscription IDs, status, tier (authoritative), timestamps. Optional: transactional review invitation via Trustpilot after a successful purchase (Art. 6(1)(f) GDPR). You can object to this review invitation already at checkout (opt-out); in addition, every invitation contains an unsubscribe link.
k) Live translation (CaptionBridge)
CaptionBridge runs locally on the creator's streaming PC and converts the stream audio into captions via speech recognition. Transmitted to StreamWizard: caption text segments, detected source language, timestamps/duration, and a hashed ingest token; optionally the Twitch channel ID as a hash only for mapping. Captions are buffered only briefly (retention configurable by the creator, default 20 minutes, max. 240) and then deleted automatically. Translation uses the creator's OWN API key with the chosen provider (Anthropic Claude, OpenAI, DeepL, or Google Gemini); for this the caption text is transmitted to that provider, which processes it as its own controller under its own terms. API keys are stored encrypted (AES-256-GCM) and released to the translator worker only for concrete translation jobs. Translated captions are shown to viewers via the Twitch extension per language; only aggregated language counters are stored, no viewer identity. The feature is available only after admin entitlement; on revocation the service is refused immediately. All live translation data can be deleted in the dashboard.
l) Cancellation button
When using the cancellation button, we process name, email address, contract/service details, requested cancellation date, optional identifiers, a reason for extraordinary cancellation, receipt time, and an anonymized IP bucket to receive, assign, confirm, and document the cancellation. The declaration is sent to the internal support mailbox through the configured mail infrastructure; a receipt confirmation is sent to the provided email address. The data is retained until processing is complete and as required for statutory evidence.
Security-relevant API/runtime events are logged in a structured way (JSON Lines with secret redaction). IP addresses are NEVER logged in clear text, only as subnet bucket (IPv4 /24, IPv6 /64). Rate limits protect security-critical endpoints; HTTP 429 on exceedance.
The privacy notices of the respective providers additionally apply. Some providers process data in the USA or other third countries – in particular Anthropic (Claude), OpenAI, and Google (Gemini). For live translation the creator uses their OWN API access with the chosen provider; to that extent the creator decides on and is responsible for the legal basis of this third-country transfer, and StreamWizard transmits the caption text to the provider chosen by the creator solely on the creator's documented instruction. Where StreamWizard itself transfers data to third countries, we base this on EU standard contractual clauses (Art. 46 GDPR), certification under the EU-US Data Privacy Framework, or equivalent safeguards. We provide information about the safeguards used on request.
You can export and delete account-owned data in the dashboard. After Twitch login on the public giveaway page, viewers can export their stored data or request deletion for the respective creator.
Technically necessary cookies (session, CSRF) are always set; they are required for login, session, and security (Art. 6(1)(f) GDPR, § 25(2) TDDDG). We do not set advertising cookies or advertising tags.
Optionally, we use Google Analytics (Google Tag / GA4, provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for anonymized reach measurement. Google Analytics is loaded only after your explicit consent in the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG) and remains disabled without consent. We use IP anonymization (anonymize_ip), no Google signals, no ad personalization, and no ad remarketing. The cookies are set with SameSite=Lax and Secure. You can withdraw your consent at any time with effect for the future via the "Cookie settings" link in the footer. This may involve a transfer to Google in the USA; we base this transfer on the EU standard contractual clauses or Google's certification under the EU-US Data Privacy Framework.
We may update this privacy policy when features or legal requirements change. The version published here is authoritative. Questions: support@streamwizard.de.
Version date: 2026-07-12