StreamFan · Legal
Privacy Policy
Draft version: 2026-09-28
1. Who is responsible
The StreamFan operator is responsible for personal data processed to provide this service. Its legal name, address, country and privacy contact must be completed before launch. This draft describes the product's intended processing and must be checked against the final configuration.
2. Information we process
Account information includes your email, display name, account identifier, verification state, profile settings, age confirmation and acceptance of legal documents. Authentication is handled with protected credentials and sessions. When you sign in with a provider, we receive the profile details and authorization necessary for that login.
Community information includes creator profiles, follows, posts, comments, poll votes, chat messages, uploaded media, reports, blocking relationships, moderation records and notification preferences. Public content is visible to visitors; other content is available according to its visibility and access rules.
Technical information may include device or browser details, push notification tokens, security and request logs, and operational analytics. Streaming connections use provider identifiers and protected authorization tokens. We do not request a full date of birth as part of ordinary onboarding.
3. Why we process data
We use information to create and secure accounts, deliver community features, process uploads, send requested notifications, connect streaming channels, provide support, investigate abuse and maintain reliability. We use aggregate activity to help creators understand engagement and improve the service.
Where applicable law requires a legal basis, the intended bases are performance of the service agreement, compliance with legal obligations, legitimate interests in security and service operation, and consent for optional communications or permissions. The operator must confirm these bases and any required assessments before launch.
4. Who receives information
Other people receive content you choose to make public or share with a community. Creators and moderators can access information necessary to operate their community; administrators can access information needed for support, safety and service management. A report is not shown to its target as a disclosure of the reporter's identity.
Service providers process information for hosting, storage, authentication, email and notifications. The planned infrastructure includes Cloudflare and, for Android push delivery, Expo and Google Firebase. Google, Twitch, YouTube and Kick receive requests when you use their login or integration features, or open their sites. The final provider list, contractual safeguards and international transfer arrangements require operator review.
We may disclose information when legally required, to respond to valid legal process, or to protect people and the integrity of the service. We do not build advertising tracking into the initial release.
5. Storage and retention
We retain account and community data while it is needed to provide the service. Deletion workflows revoke access and remove or anonymize associated data. Limited records may remain for documented legal, security or dispute-resolution needs. Backups and provider systems may have separate deletion cycles.
Exports are stored privately with temporary download access and scheduled expiry. Operational logs and aggregate analytics follow configured retention controls. Exact periods and the reasons for any exceptions must be finalized and published by the operator before launch.
6. Your choices and rights
You can edit your profile, disconnect platforms, control notifications, block people, export your data and request deletion in Settings. Device permissions are controlled in Android settings. Optional communications can be declined without losing the core service.
Depending on the law that applies to you, you may have rights to access, correct, delete, restrict or object to processing, obtain portable data, withdraw consent and complain to a competent supervisory authority. Contact Support to exercise a request that cannot be completed in the product. We may need to verify your identity without asking for unnecessary information.
7. Security and children
We use access controls, protected sessions, encryption for provider tokens, rate limits and moderation tools. No online service can guarantee absolute security. Please use a unique password and report suspected account compromise.
StreamFan is not designed for children. Registration includes a configurable minimum-age confirmation. If you believe an ineligible child has provided personal data, contact Support so the operator can review and take appropriate action.
8. Updates
We will update this policy when our processing materially changes and provide notice where appropriate. The version and effective date will be shown in the published policy.
Contact
Questions about this document or your rights can be sent through StreamFan Support. The operator's formal contact details will be published here before launch.