Streamer Assist Privacy Policy

Effective date: 2026-10-08
Operator: yechankun · Streamer Assist developer

1. Data and purpose

Broadcast records include titles, markers, start/end and capture times, connected-source metadata, original chats with occurrence/receive times, donations with amounts/currencies/messages, and sampled viewer counts. Reactions, keywords, questions, repeats and participant statistics are calculated on this PC.

Raffles and duplicate-vote prevention use public platform account identifiers, nicknames, subscription/membership status, participation/winner records and donation event identifiers. Donation voting reads platform-provided messages; the app does not collect card or bank details. Chat analysis also stores public roles/badges and observed nickname changes. Accounts on different platforms are not merged by nickname.

YouTube/Twitch connections store channel information and access/refresh tokens. CHZZK connections store public channel URLs/names. Twitch device-login information and approval codes are handled in memory and discarded after login/cancellation. Settings and roulette titles/entries/weights are stored locally.

Recording settings select live archiving, live raw archiving with deferred local analysis, or live features with later VOD chat collection. The latter skips live chat/donation text in the raw archive; participation, voting results, markers and viewer samples can still be saved. VOD records retain source-video IDs, offsets and available public participant information.

2. External connections

The app contacts connected platform APIs for chat/broadcast queries and supported polls. Saved connections can reconnect when the app starts. YouTube authorization uses the default browser and a temporary 127.0.0.1 callback. Twitch uses browser approval with Device Code authorization and official EventSub WebSockets.

The app does not upload broadcast records, chats or account tokens to a developer-operated server. It includes no advertising, analytics or remote error-reporting SDK. Platform services, the browser, Microsoft Store and the support forum apply their own privacy policies.

Optional VOD collection downloads pinned, hash-verified yt-dlp or TwitchDownloaderCLI tools from their official GitHub releases into the app profile. YouTube and Twitch replay collection uses these tools; CHZZK uses paged web-player endpoints. Only available accessible VOD chat can be imported, and internal endpoints can change. No video file is requested. Local automatic statistics/highlights do not call an external AI service.

3. Storage and protection

Broadcast metadata, participation/vote results and YouTube/Twitch tokens use Windows DPAPI in the app profile. New raw-chat batches, overload receipts, replay jobs and participant profiles use AES-256-GCM with a per-profile key protected by DPAPI. Derived indexes retain salted participant keys, timestamps, platform labels and counts; profile names and public identities are encrypted. Legacy archives migrate on first access on the same Windows profile.

Shortcuts, tray/channel settings, theme and roulette inputs are stored in local configuration or browser local storage. User-selected Markdown, JSON and JSONL exports are ordinary unencrypted files. Users decide whether to share them.

External replay tools may create unencrypted chat working files in the app's private work directory during download. The app imports them into encrypted archives and removes working files on completion, cancellation or handled failure. An abrupt OS/process failure can leave working files until the job is retried; users can delete the app's replay-work directory while the app is stopped. User exports remain unencrypted.

4. Retention

Broadcast, chat, donation and viewer records remain on this PC until the user deletes them. Original events are stored in encrypted broadcast/day files. Use Broadcast timeline → Chat/donations → Date/disk management for selective deletion, or Settings → Info & Data to clear all records.

Participation, winner and donation-deduplication records remain until replaced by a new recruitment/vote or explicitly deleted. The former 10,000-entrant and 50,000-donation-event cutoffs are removed; large active populations still consume memory. Encrypted recovery copies and derived participant/statistical indexes are removed by the relevant record-deletion actions.

5. User controls and deletion

Date/disk management confirms deletion of the selected dates across all platforms. Dates belonging to an active broadcast are protected; other dates and markers remain. End active recording, voting, recruitment and draws before clearing all records in Settings → Info & Data. Roulette inputs have a separate reset.

Disconnect accounts/channels in Settings → Platform connections. Local disconnection removes saved connections on this PC. Platform permissions can also be revoked through Google/Twitch connected-app settings.

Delete exported files and separately copied backups yourself. Windows determines data handling when Store packages are removed/reset. Default AI JSONL exports remove public account IDs and substitute pseudonymous nicknames while retaining analytical speaker keys; public identity fields are optional. Chat text, markers and reaction examples remain original and may contain personal information. No local AI CLI or external AI API receives this data automatically.

6. Optional AI connections and analysis

Settings → AI connections supports Codex/OpenAI, Claude, Grok, Antigravity/Gemini, DeepSeek, Kimi, and user-added compatible APIs. CLI components download from official distribution sources into this PC’s app profile only when the user chooses installation. They are excluded from the app installer. Existing installed CLIs can also be used.

API keys are encrypted using the Windows security store and saved keys are never returned to the renderer. Each CLI manages its own login credentials. Selecting Run analysis sends the chosen broadcast, date, platform, and time scope plus the request to the selected AI service. The app does not automatically run AI analysis or route these requests through a developer server. A user-added localhost API receives requests on this PC.

Before sending, the app shows included record counts, size, an approximate token estimate, and whether sampling is required. By default, public account identifiers are removed and nicknames are replaced with pseudonyms; stable analytical speaker keys, timestamps, and original chat/donation text remain. Personal information written into message text is not automatically removed. Users may opt to include public identities.

AI results are encrypted locally and can be deleted from the result view. Provider processing, retention, and charges follow the selected service’s policies. A CLI may maintain its own logs or sessions. Deleting app results does not remove copies retained by a provider or CLI.

Per-provider components downloaded from GitHub are stored in the app profile separately from API keys, broadcast archives, and analysis results. Version checks and downloads access the configured public GitHub repository without sending AI API keys or chat content.

7. Contact and changes

Contact the developer through GitHub Issues or the Store developer contact. Do not post account tokens or other people’s personal information on a public forum.

The policy version is updated when data processing or features change. Current information is available in the app and in the public documentation.