Privacy Policy
This document is a draft. It has not yet been approved, has not been reviewed by a lawyer, and may change before SWAGVERSE launches publicly.
This policy explains what personal data SWAGVERSE collects when you use it, why, who it is shared with, how long it is kept and how you can use your rights. It applies to the SWAGVERSE website and its installable web app.
Who we are
SWAGVERSE is an unofficial fan community run by a single individual based in Türkiye, who is the data controller for the personal data described here.
- Operator: [OPERATOR NAME — to be added before launch]
- Contact: [CONTACT EMAIL — to be added before launch]
SWAGVERSE is not operated by, affiliated with or endorsed by Twitch or any streamer unless this is stated explicitly on the site.
What we collect
| Category | What exactly | Where it comes from |
|---|---|---|
| Sign-in identity | Your Twitch user ID, Twitch username and profile picture address | Twitch, when you sign in |
| Age check | Nothing about your birth date is stored — only the date you confirmed you are 16 or older (or that the check failed) | You, once, during sign-up |
| Profile | Your display name (you can change it); your handle and avatar are copied from Twitch | You and Twitch |
| Activity | XP and level history, quests, achievements, collectible cards, likes and dislikes, bookmarks, poll votes, event registrations and check-ins | Your use of SWAGVERSE |
| Reports and moderation | Reports you send, reports about you or your content, moderation decisions, appeals and the evidence they refer to | You, other members and moderators |
| Consent records | Which version of these documents you accepted and when, with a one-way hash of your IP address (never the IP itself) | Your browser, when you accept |
| Security data | For each active sign-in session: the IP address and browser user-agent. The sign-in event log keeps only one-way hashes of these | Your browser |
| Push notifications (optional) | An encrypted push subscription token for your browser | Your browser, only if you turn notifications on |
| Product usage events | Records of actions such as "quest completed", linked to your account | Your use of SWAGVERSE |
We ask for your birth year and month only to check that you are 16 or older. The value is used for that single check and is never saved.
What we do not collect
We do not ask Twitch for your email address or password. We do not collect your real name, precise location, contacts or full date of birth. SWAGVERSE does not take payments at launch, so we hold no payment details.
Why we use your data
- To provide the service you signed up for (performance of a contract): signing you in, showing your profile, calculating XP and levels, running quests, events, polls and seasons.
- To keep SWAGVERSE safe and fair (legitimate interests): preventing abuse such as bots, multiple accounts and vote manipulation, investigating reports, moderating, securing sessions and fixing errors.
- To understand how the product is used (legitimate interests): product usage events help decide what to improve. They are not used for advertising and are never sold.
- With your consent: push notifications and any optional feature that asks for permission. You can withdraw consent at any time in Settings.
- To meet legal obligations: answering valid requests from authorities and keeping records the law requires.
Who we share it with
We never sell your personal data. We use a small number of service providers to run SWAGVERSE; they may only use the data to provide their service to us.
- Twitch — sign-in. On the live page you can choose to load Twitch's player and chat; they then load directly from Twitch and Twitch's own privacy policy applies to them.
- Hosting — Oracle Cloud Infrastructure (servers and database, EU region).
- Cloudflare — network protection and content delivery, and storage for uploaded files and encrypted backups.
- Error monitoring — Sentry, which receives technical error reports that may include an internal account ID.
- Your browser's push service (for example Google, Mozilla or Apple) — only if you turn push notifications on.
- YouTube (privacy-enhanced mode) and TikTok — only if you click to load a video a creator linked.
Security alerts sent to the operator (via Telegram) contain internal IDs only, never your name or messages.
We may disclose data when the law requires it or to protect the safety of members.
International transfers
SWAGVERSE's servers are planned to run in the European Union and the operator is based in Türkiye. Some providers above (for example Twitch and Cloudflare) process data in the United States and other countries under their own transfer safeguards.
How long we keep it
These retention periods are based on the SWAGVERSE specification. Sign-in sessions, the sign-in event log and product usage events are deleted automatically once their period ends:
| Data | Retention |
|---|---|
| Sign-in sessions (including IP address and browser) | Deleted 7 days after you sign out or the session expires |
| Sign-in event log (IP address kept only as a one-way hash) | 30 days |
| Operational logs | 30 days |
| Product usage events | 90 days; daily totals without personal data up to 13 months |
| Moderation evidence | 90 days after a case is closed, unless an appeal or legal requirement needs it longer |
| Your profile and activity | While your account exists |
| Data export files | Deleted 7 days after they are ready |
| Encrypted backups | 35-day cycle; deletions are re-applied if a backup is ever restored |
If a person's records are subject to a legal hold (for example, a valid request from an authority), their deletion is paused until the hold ends. You can ask for your data to be deleted at any time.
Your rights
Depending on where you live (including under the UK GDPR, the EU GDPR and Türkiye's KVKK), you can:
- Access and download your data — Settings, "Download your data". An export is prepared within 24 hours and the download link is short-lived.
- Delete your account — Settings, "Delete account". You will be asked to sign in again first. Your public profile is hidden, sessions are ended and your personal data is removed. Records we must keep for security or legal reasons are explained when you request deletion.
- Correct your data — change your display name in SWAGVERSE; your Twitch username and picture are updated from Twitch when you next sign in.
- Withdraw consent — Settings.
- Object to or restrict some processing, and complain to a data protection authority (for example the ICO in the UK, your local authority in the EU, or the KVKK Board in Türkiye).
For anything else, contact [CONTACT EMAIL — to be added before launch].
Age requirement
SWAGVERSE is only for people aged 16 or older. If the age check shows you are younger, the account is blocked and signed out. If you believe a younger person is using SWAGVERSE, please contact us.
Security
Sign-in uses HttpOnly cookies that page scripts cannot read. IP addresses in sign-in and consent logs are stored only as one-way hashes, all traffic is encrypted, and administrator actions require a passkey.
Changes to this policy
Each version of this policy has a version number, shown at the top of this page. When it changes in a way that matters, you will be asked to read and accept the new version.