StreamBridge Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains how StreamBridge (“StreamBridge,” “we,” “us,” or “the Bot”), operated by Gozar Productions LLC, accesses, processes, stores, shares, and deletes information when it is added to a Discord server or connected to Twitch, YouTube, Kick, or Social Stream Ninja.
Contact us with privacy questions or deletion requests at [email protected].
1. Scope
This Privacy Policy applies to:
- The StreamBridge Discord bot
- The StreamBridge website and account dashboard
- StreamBridge’s OAuth authorization pages and callback endpoints
- Direct Twitch, YouTube, and Kick integrations
- Optional Social Stream Ninja integrations
- Messages processed or relayed by StreamBridge
It does not govern Discord, Twitch, Google, YouTube, Kick, Social Stream Ninja, Cloudflare, or any other third-party service. Those services process information according to their own privacy policies.
2. How StreamBridge works
StreamBridge relays chat messages between an optionally configured Discord channel and enabled streaming platforms. A bridge can also operate without Discord.
Depending on a dashboard user’s or server administrator’s configuration, StreamBridge may:
- Relay messages from one streaming platform to other connected platforms
- Read messages sent in the specifically configured shared Discord relay channel
- Forward those messages to Twitch, YouTube, Kick, or Social Stream Ninja
- Receive public livestream chat messages from connected platforms
- Repost those messages in a configured Discord channel
- Connect to a Social Stream Ninja session
- Automatically switch between Social Stream Ninja and direct platform connections
- Suppress duplicate messages and relay loops
StreamBridge does not use artificial intelligence or language models to analyze messages.
3. Information StreamBridge accesses and processes
3.1 Discord server information
StreamBridge may access or store:
- Discord server IDs
- The ID of the shared Discord relay channel, when configured
- Discord server names while constructing relay messages
- Server-specific relay settings
- Whether transport-switch notices are enabled
- The direct relay message template selected by a dashboard user or administrator
Discord IDs are numeric identifiers assigned by Discord.
3.2 Discord message information
StreamBridge processes Discord messages for relay only when they are sent in the shared channel selected with /channel set or through the dashboard and forwarding from Discord is enabled.
For those messages, StreamBridge may process:
- Message ID
- Message text
- Message timestamp
- Author’s Discord user ID
- Author’s display name
- Author’s display avatar URL
- Author’s displayed role color
- Custom Discord emote names and image URLs
- Resolved user, role, and channel mentions
- The URL of the first attached image, when applicable
- Discord server name
- Source channel ID
StreamBridge ignores messages sent by bots and webhooks for forwarding purposes.
Message content is processed so it can be relayed to destinations selected by the Discord server’s administrators. StreamBridge does not intentionally write the full Discord message body to its configuration database.
A copy of the message may be stored by Discord or by each destination platform after StreamBridge posts it there. Those copies are controlled by the relevant platform and server or channel owner.
3.3 Streaming-platform chat information
For Twitch, YouTube, Kick, and messages received through Social Stream Ninja, StreamBridge may process:
- Platform name
- Platform message ID
- Chatter’s platform user or channel ID
- Username or display name
- Message text
- Profile image URL
- Username color, when supplied by the platform
- Message timestamp
- Broadcaster or channel information
- Whether the message appears to be a bot message, reflection, or duplicate
This information is used to display and relay the message and to prevent duplicates.
StreamBridge does not intentionally create permanent archives of complete livestream chat messages. Copies posted into Discord or other streaming chats remain subject to those platforms’ retention and deletion systems.
3.4 Social Stream Ninja information
When a dashboard user or administrator connects Social Stream Ninja through the dashboard or /ssn connect, StreamBridge stores:
- The Social Stream Ninja session ID
- The selected relay-target platforms
- Connection and transport state while the Bot is operating
The session ID is masked when displayed through /status.
StreamBridge does not require or store the separate password used for password-protected Social Stream Ninja overlay or VDO rooms.
Messages routed through Social Stream Ninja may be processed by Social Stream Ninja’s infrastructure according to its own practices.
3.5 Dashboard accounts, linked identities, and sessions
Users may sign in to the StreamBridge dashboard with Discord, Google, Twitch, or Kick and may link additional supported identities to the same StreamBridge account. For each linked identity, StreamBridge stores:
- Platform name
- Platform account identifier
- Display name
- Profile image URL, when supplied
- Granted OAuth scopes
- Encrypted OAuth access and refresh tokens, when supplied by the platform
- Creation and update timestamps
StreamBridge also stores an internal dashboard-account identifier and the configuration for that account’s single bridge. A bridge may be configured with or without a Discord server.
After a successful sign-in, StreamBridge places a random session cookie in the user’s browser. The cookie is HTTP-only, is sent only to the dashboard API, and normally expires after 30 days. StreamBridge stores a SHA-256 hash of the session token, the associated dashboard-account identifier, and session timestamps in its database rather than storing the raw session token.
3.6 YouTube authorization information
When a user authorizes Google/YouTube, StreamBridge stores:
- Dashboard account associated with the authorization
- Google account subject identifier
- Google display name and profile image URL, when supplied
- Granted OAuth scopes
- Encrypted OAuth access and refresh tokens
StreamBridge requests the following Google OAuth scope:
https://www.googleapis.com/auth/youtube.force-ssl
This scope can permit broad YouTube account actions. StreamBridge’s current implementation uses it only to:
- Identify the authorized YouTube channel
- Discover that channel’s active livestream
- Read messages from its active live chat
- Post relayed messages into its active live chat
- Refresh the authorization token as needed
StreamBridge does not use this permission to upload, edit, or delete videos; manage playlists; read viewing history; access private messages; or obtain the Google account password.
StreamBridge never receives or stores the user’s Google password. Authentication occurs directly on Google’s website.
StreamBridge uses YouTube API Services. Its use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Use of YouTube features is also subject to the Google Privacy Policy, YouTube Terms of Service, and YouTube API Services Developer Policies.
3.7 Kick authorization information
When a user authorizes Kick, StreamBridge stores:
- Dashboard account associated with the authorization
- Kick broadcaster user ID
- Kick broadcaster username
- Kick profile image URL, when supplied
- Granted OAuth scopes
- Encrypted OAuth access and refresh tokens
StreamBridge requests these Kick permissions:
user:read
chat:write
events:subscribe
They are used to:
- Identify the authorized broadcaster
- Subscribe to that broadcaster’s chat-message events
- Receive public chat messages
- Post relayed messages using the linked Kick account
Although Kick may make additional user information available under an authorized scope, StreamBridge’s current implementation stores only the broadcaster ID, username, profile image URL when supplied, granted scopes, and authorization tokens needed for these functions. It does not intentionally store the broadcaster’s email address.
StreamBridge never receives or stores the user’s Kick password. Authentication occurs directly on Kick’s website.
3.8 Twitch information
When a user links Twitch through the dashboard, StreamBridge stores the Twitch account ID, display name, profile image URL, granted OAuth scopes, and encrypted access and refresh tokens. A linked Twitch account may be assigned to the single bridge owned by that dashboard account.
For Twitch chat, StreamBridge may process:
- Channel name
- Message ID
- Chatter’s Twitch user ID
- Login name and display name
- Message text
- Profile image URL
- Username color
A short-lived in-memory cache may retain Twitch user IDs or login names and profile-image URLs to reduce repeated API lookups:
- Successful avatar lookups may be cached for approximately 24 hours.
- Failed avatar lookups may be cached for approximately 5 minutes.
- The cache is held in memory and is lost when StreamBridge restarts.
- The cache is periodically pruned and bounded in size.
StreamBridge uses the linked Twitch identity to read and post chat for an enabled bridge. Other dashboard accounts and Discord servers do not receive that account's OAuth credentials.
3.9 OAuth state and temporary authorization data
Discord, Google/YouTube, Twitch, and Kick dashboard authorization links use random state values to associate an OAuth response with the correct dashboard session.
Pending authorization data:
- Is stored temporarily in the StreamBridge database
- Is associated with a dashboard session when linking another identity
- Expires after approximately ten minutes
- Is removed after use or expiration
- Does not include a user’s platform password
Kick authorization also uses a PKCE verifier, which is stored temporarily in the StreamBridge OAuth-state database record until the authorization completes or expires.
3.10 Duplicate-prevention and delivery history
To prevent duplicate deliveries and relay loops, StreamBridge stores limited event and delivery records containing:
- Discord server ID
- A generated event key
- Source platform
- Original platform message ID, when available
- A SHA-256 fingerprint derived from the platform, user identifier, and normalized message text
- Destination identifier
- Delivery status
- Creation timestamp
The fingerprint is a one-way hash rather than a stored copy of the message. However, it is still associated with platform and server records.
Duplicate-prevention and delivery records are retained for approximately 30 days and are removed during scheduled maintenance.
StreamBridge also keeps a short-lived, in-memory reflection tracker for messages it recently sent. Those entries normally expire after approximately two minutes and are not written to the database.
3.11 Logs
StreamBridge creates operational logs that may include:
- Timestamps
- Platform names
- Discord server or channel IDs
- Connected channel names
- Connection and retry events
- Command or API errors
- Delivery failures
StreamBridge is designed not to log OAuth access tokens, refresh tokens, client secrets, Discord bot tokens, or account passwords.
Unexpected errors returned by third-party platforms may include limited response details. Log retention depends on the operator’s server configuration and is not currently controlled by StreamBridge itself.
4. Information StreamBridge does not intentionally collect
StreamBridge does not intentionally collect or use:
- Discord account passwords
- Google account passwords
- Twitch account passwords
- Kick account passwords
- Payment-card information
- Precise location
- Contact lists
- Browsing history
- Private Discord messages outside configured server channels
- Messages from Discord channels not selected for forwarding
- Voice or video content
- Biometric information
- Data for advertising profiles
- Data for training artificial-intelligence models
5. How information is used
StreamBridge uses information only as reasonably necessary to:
- Provide cross-platform chat relay
- Display streaming messages in Discord
- Send Discord messages to configured platforms
- Authenticate authorized YouTube and Kick accounts
- Find active YouTube livestream chats
- Subscribe to Kick chat events
- Look up Twitch profile images
- Maintain server-specific settings
- Detect duplicates and prevent relay loops
- Diagnose failures, secure the service, and maintain reliability
- Comply with legal obligations and platform rules
StreamBridge does not sell personal information or use it for targeted advertising.
6. How information is shared
StreamBridge shares information only as needed to provide the configured relay service.
6.1 Administrator-selected destinations
A message sent in the configured shared Discord relay channel, or in a connected streaming chat, may be sent to:
- Twitch
- YouTube
- Kick
- The configured shared Discord relay channel
- Social Stream Ninja
- Other platforms selected through Social Stream Ninja
Relaying necessarily makes the sender’s display name, source platform, message, and potentially avatar visible to users of those destinations.
Server administrators are responsible for telling their communities when a channel is connected to StreamBridge.
6.2 Service providers and infrastructure
Information may pass through infrastructure used to operate StreamBridge, including:
- Discord
- Google and YouTube
- Twitch
- Kick
- Social Stream Ninja
- Cloudflare, for secure OAuth callbacks and Kick webhooks
- The server or hosting provider running StreamBridge
These providers process information according to their own terms and privacy policies.
6.3 Legal and safety disclosures
We may disclose information if reasonably necessary to:
- Comply with law, regulation, subpoena, court order, or valid legal process
- Protect the safety, rights, or property of users, the public, StreamBridge, or its operator
- Investigate abuse, fraud, security incidents, or violations of the Terms of Service
- Enforce agreements or platform requirements
6.4 Business transfers
If StreamBridge or its operation is transferred to another owner, information necessary to operate the service may be transferred as part of that transaction. Users will be notified through an appropriate public notice if this materially changes the handling of their information.
7. Data retention
StreamBridge generally retains information as follows:
- Server configuration: Until changed, cleared, or deleted at an administrator’s request
- Linked platform authorization records: Until the identity is unlinked, the authorization becomes unusable, or deletion is requested
- Dashboard sessions: Until logout, deletion, or expiration, normally no more than 30 days
- Duplicate and delivery history: Approximately 30 days
- Pending OAuth state: Approximately ten minutes
- Reflection tracking: Approximately two minutes in memory
- Twitch avatar cache: Approximately 24 hours for successful lookups or five minutes for failed lookups
- Operational logs: According to the operator’s server and logging configuration
- Message content: Processed in transit and not intentionally stored as full message text in StreamBridge’s database
Removing StreamBridge from a Discord server does not necessarily delete all stored server configuration automatically. A server owner or authorized administrator should contact [email protected] to request complete deletion.
Backups, if maintained, may retain deleted records temporarily until they are overwritten through the normal backup cycle.
8. Security
StreamBridge uses reasonable technical measures designed to protect information, including:
- Encryption of stored Discord, Google/YouTube, Twitch, and Kick access and refresh tokens using Fernet symmetric encryption
- HTTPS for OAuth callbacks
- TLS-protected connections to supported platform APIs
- Signed-webhook verification for Kick events
- PKCE for Kick OAuth authorization
- Random, expiring OAuth state values
- Server-side OAuth callbacks; platform secrets are never embedded in the static website
- Restricted server-side storage for credentials and tokens
- Avoidance of secrets in normal application logs
No system can guarantee absolute security. Users should immediately contact [email protected] if they believe an account or authorization has been compromised.
9. User and administrator choices
Discord server administrators can limit StreamBridge’s access by:
- Selecting one shared relay channel and its forwarding directions with
/channel setor the dashboard - Disabling Discord integration with
/channel removewhile retaining the saved channel and direction settings - Disconnecting Social Stream Ninja with
/ssn disconnect - Enabling or disabling a linked direct connection with
/direct enable,/direct disable, or the dashboard - Removing StreamBridge from the Discord server
Dashboard users can disconnect a linked identity with the Disconnect button. StreamBridge first requests revocation of the associated OAuth authorization from Discord, Google/YouTube, Twitch, or Kick. After the provider confirms revocation or reports that the token is already invalid, StreamBridge deletes its stored identity record and encrypted OAuth credentials and removes direct-relay assignments that depend on that identity. If revocation cannot be confirmed, StreamBridge retains the connection and reports an error so the user can retry. When another identity remains, disconnecting Discord disables Discord relay for the bridge but preserves its selected server and channel configuration. It does not remove the separately installed Discord bot from a server.
Disconnecting the final linked identity permanently deletes the StreamBridge dashboard account and its related saved data, including linked identities and encrypted credentials, dashboard sessions, pending OAuth state, bridge settings, direct-platform assignments, Discord relay configuration, and stored delivery and duplicate-prevention history. The dashboard displays a specific confirmation warning before this deletion.
Disabling a platform connection without disconnecting its identity does not delete the identity or revoke the platform grant. Users may also review or revoke StreamBridge through the provider’s account settings.
Revoke Google or YouTube access
The dashboard’s Disconnect button requests revocation of StreamBridge’s Google OAuth grant and then deletes the locally stored Google/YouTube identity and credentials. Users can also review or revoke StreamBridge’s authorization from their Google Account connections page.
Revoke Kick access
The dashboard’s Disconnect button requests revocation of StreamBridge’s Kick OAuth tokens and then deletes the locally stored Kick identity and credentials. Users may also revoke access through Kick’s account or connected-application settings when available.
Revoke Discord or Twitch access
The dashboard’s Disconnect button requests revocation of the Discord or Twitch OAuth authorization and then deletes StreamBridge’s locally stored identity and credentials. If it is the final linked identity, the StreamBridge account and its related saved data are also deleted. Users may also revoke StreamBridge through Discord’s or Twitch’s authorized-application settings.
Request deletion
A Discord server owner, authorized server administrator, or authorized platform-account owner may request access to or deletion of applicable stored information by emailing:
Please include:
- The Discord server ID
- Your Discord user ID
- The connected platform
- Enough information to confirm that you are authorized to make the request
Do not include passwords, bot tokens, OAuth tokens, or client secrets.
We may need to verify the requester’s authority before disclosing or deleting server-level records.
10. Legal rights
Depending on where you live, you may have rights regarding personal information, including the right to:
- Request access
- Request correction
- Request deletion
- Object to or restrict certain processing
- Withdraw consent
- Receive a portable copy of certain information
- Lodge a complaint with a data-protection authority
To exercise an applicable right, contact [email protected].
11. Children’s privacy
StreamBridge is not directed to children under 13 or under the minimum age required by Discord or a connected platform in their jurisdiction.
We do not knowingly collect personal information from children in violation of applicable law. If you believe a child’s information has been processed improperly, contact [email protected].
12. International processing
StreamBridge and its service providers may process information in countries other than the user’s country of residence. Those countries may have different data-protection laws.
Where required, the operator will use appropriate safeguards for international transfers.
13. Third-party services
Use of StreamBridge may involve third-party services governed by separate terms and privacy policies, including:
- Discord Privacy Policy
- Google Privacy Policy
- YouTube Terms of Service
- Twitch Privacy Notice
- Kick Privacy Policy
- Social Stream Ninja
StreamBridge does not control these third parties.
14. Changes to this Privacy Policy
We may update this Privacy Policy when StreamBridge’s features, data practices, platform integrations, or legal obligations change.
The updated policy will show a new “Last updated” date. If a change materially expands how authorized Google or YouTube data is accessed, used, stored, or shared, affected users may be asked to review or accept the updated policy as required by applicable platform policies.
15. Contact
For privacy questions, requests, or complaints:
Operator: Gozar Productions LLC Email: [email protected]