Privacy Policy
StreamBuddy Privacy Policy
Last updated: 2026-06-24
This Privacy Policy explains how Danidoes LLC ("Danidoes", "we", "us") collects, uses, stores, and shares information when you use StreamBuddy (the "Service"), including the desktop client application, web frontends, and backend API.
If you do not agree with this Privacy Policy, do not use the Service.
1) Who we are / contact
Controller (for most data): Danidoes LLC, Washington, USA. For users in the United Kingdom and European Economic Area, Danidoes LLC is the data controller for the purposes of the UK GDPR and EU GDPR.
Contact for privacy requests: Email: support@danidoes.dev
2) What the Service does (plain-English summary)
StreamBuddy records user input (including microphone input if you enable it), sends audio and/or transcriptions to our servers, and uses third-party services to generate responses (for example a language model response and text-to-speech). To support features like memory/recall, StreamBuddy can store conversation history and summaries.
3) Information we collect
Depending on what features you use, we may collect:
3.1 Account and identity information
- account username and identifiers (for example: Twitch username)
- internal account IDs
- whitelist/API access information (for example: API keys used to access the Service)
3.2 Audio, text, and conversation data
- audio recordings or audio segments if the client sends audio to us (for transcription or processing)
- audio transcriptions
- messages you type or send
- conversation logs with the bot (prompts and responses)
3.3 Twitch-related data (if you connect Twitch)
If you enable Twitch integrations, we may collect and store:
- Twitch chat messages (message content, username/user_id, badges like mod/sub/vip, emotes)
- Twitch events (subs, gifts, cheers, raids, follows, stream online/offline, channel points redeems, etc.)
- EventSub session state and logs (session IDs, subscription IDs, deduplication logs)
- OAuth tokens (access token, refresh token, expiry time) and Twitch user ID
To disconnect your twitch account, do so through the Twitch account settings: https://www.twitch.tv/settings/connections
3.4 Memory, summaries, and embeddings
To support memory/recall, we may store:
- “memories” and summaries derived from conversation and events
- tags/metadata associated with memories
- embeddings/vectors used for semantic search or retrieval (for example using pgvector)
3.5 Settings and configuration
We store settings you choose in the Service, such as:
- bot settings (system prompt, temperature, feature toggles, timing intervals)
- subtitle settings, behavior settings, filters
- (if you choose to store them) third-party API keys you provide for services like OpenAI, ElevenLabs, Azure, AWS, etc.
If you provide third-party API keys to the Service, we store them in encrypted form to support enabled features. No system is perfectly secure, and you are responsible for rotating or revoking your external API keys with the relevant provider if you suspect exposure, leakage, unauthorized use, or account compromise.
3.6 Usage, logs, and device/network data
We may collect:
- approximate usage statistics and diagnostics
- API usage records (service used, request type, status, timestamps, estimated cost metrics, token counts, audio duration, characters processed)
- user agent / client identifier
- IP address (if provided by the client or logged by our servers)
- request IDs and error logs
4) How we use information
We use information to: - provide and operate the Service - process inputs and generate outputs (including calling third-party AI and TTS providers) - store conversation history and summaries to support memory/recall features (if enabled) - support Twitch integrations (if enabled) - monitor usage, prevent abuse, debug issues, and maintain security - calculate costs and support billing (if applicable) - comply with legal obligations and enforce our agreements
5) How we share information
We share information in these situations:
5.1 Service providers / subprocessors
To provide the Service, we may send some data (which can include text, audio, and metadata) to third-party providers you or we use, such as: - language model providers (for example OpenAI) - text-to-speech providers (for example ElevenLabs, Microsoft Azure, Amazon Polly) - cloud hosting and infrastructure providers (for example AWS, Azure) - Twitch (for EventSub and API access)
These providers may process data under their own terms and privacy policies. We do not control their retention practices.
5.2 Legal reasons
We may disclose information if we believe disclosure is required by law, regulation, legal process, or to protect rights, safety, and security.
5.3 Business transfers
If Danidoes LLC is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction.
6) Data retention
We keep data for as long as needed to operate the Service and for legitimate business purposes (for example: providing memory/recall features, preventing abuse, maintaining security logs, or resolving disputes).
Because StreamBuddy is currently offered as a direct-license service (not a public sign-up product), retention may vary by customer contract and configuration.
7) Your choices and controls
7.1 Requesting deletion
You can request deletion of data stored on our servers at any time by emailing: support@danidoes.dev
After we verify the request, we will delete (or de-identify) data from our systems within a reasonable time unless we need to keep certain information for legal, security, fraud-prevention, billing, or dispute-resolution purposes.
7.2 Limits of deletion (third parties)
When the Service sends data to third-party providers (for example OpenAI, ElevenLabs, Microsoft Azure, AWS, Twitch, or similar vendors), we can delete data from our systems, but we cannot guarantee deletion from third-party systems. Third parties may retain data according to their own policies and legal obligations.
7.3 Access and correction
If you want a copy of your stored data, or want to correct inaccurate account information, email: support@danidoes.dev
7.4 Turning off features
Some features can be turned off in settings (for example: memory features, Twitch features). Turning off a feature may reduce new data collection, but does not automatically delete previously stored data unless you request deletion.
7.5 External API key revocation responsibility
We may provide usage insights, estimates, and related diagnostics in the app for convenience. These insights do not replace your provider account security controls. You are solely responsible for revoking, rotating, or otherwise invalidating your external API keys directly with the third-party provider when needed.
8) Security
We take reasonable measures to protect information, but no method of transmission or storage is 100% secure. You use the Service at your own risk.
9) Children’s privacy
The Service is not intended for children under 13 (or the minimum age required by your jurisdiction). We do not knowingly collect personal information from children.
10) International data transfers
We operate from the United States. If you access the Service from outside the U.S., you understand that your data may be processed and stored in the U.S. or other locations where our service providers operate.
If you are located in the United Kingdom or the European Economic Area, transfers of your personal data to the United States are "restricted transfers" under applicable data protection law. Where we make such transfers, we rely on an appropriate transfer mechanism recognized under UK and EU law — such as the UK International Data Transfer Agreement, the European Commission's Standard Contractual Clauses (with the UK Addendum), or the UK-US Data Bridge / EU-US Data Privacy Framework where the recipient is certified. You may contact us at support@danidoes.dev for more information about the safeguards we use.
11) Legal bases for processing (UK / EEA)
If you are located in the United Kingdom or the European Economic Area, we process your personal data only where we have a lawful basis to do so under the UK GDPR and EU GDPR. Depending on the activity, our lawful bases are:
- Performance of a contract — to provide the Service you have requested and operate its features.
- Consent — for processing that depends on your choice, such as capturing microphone audio, enabling Twitch integrations, or storing third-party API keys. Where we rely on consent, you may withdraw it at any time, without affecting processing already carried out.
- Legitimate interests — to secure and improve the Service, prevent abuse and fraud, and maintain operational logs, provided those interests are not overridden by your rights.
- Legal obligation — to comply with applicable laws and respond to lawful requests.
Audio recordings, transcriptions, and voice data may constitute special category or sensitive personal data in some jurisdictions. Where required, we process such data only with your consent or another lawful basis permitted by law.
12) Your rights (UK / EEA)
If you are located in the United Kingdom or the European Economic Area, you have the following rights under the UK GDPR and EU GDPR, subject to legal conditions and exceptions:
- the right to access the personal data we hold about you;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure ("right to be forgotten");
- the right to restrict or object to processing, including processing based on legitimate interests;
- the right to data portability;
- the right to withdraw consent where processing is based on consent; and
- the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, email support@danidoes.dev. We will respond within the timeframes required by applicable law. You also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner's Office (ICO) at ico.org.uk.
13) U.S. privacy rights
Depending on where you live, you may have privacy rights under applicable laws. You can contact us at support@danidoes.dev to request access, deletion, or information about our processing.
13.1 State privacy statutes we seek to honor
For U.S. users, we aim to provide rights and disclosures aligned with applicable comprehensive state privacy laws, including where relevant.
13.2 California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it (as described in Sections 3–5 above), the right to access and delete your personal information, the right to correct inaccurate personal information, and the right to be free from discrimination for exercising these rights.
California law also gives you the right to limit the use and disclosure of "sensitive personal information." We use sensitive personal information (which may include audio recordings, transcriptions, and account credentials) only to provide and secure the Service, and not for purposes that would require an offer to limit such use under the CPRA. We do not sell or share personal information as those terms are defined under the CPRA.
13.3 Rights requests and response timeline
Subject to applicable law and verification, you may request: - access to personal data we hold about you; - correction of inaccurate personal data; - deletion of personal data; - a portable copy of certain personal data; and - to opt out of certain processing where required by law (for example targeted advertising, sale, or profiling decisions with legal/similar significant effects).
To submit a request, email support@danidoes.dev. We will verify your request, respond within timelines required by applicable law, and explain any lawful basis for denial.
13.4 Appeals (where required)
If we deny a request, you may reply to our decision email to appeal. We will review and respond within the legally required timeframe. If your state law grants additional recourse, we will provide that information in the appeal response.
13.5 No sale of personal data for money
We do not sell personal data for monetary consideration. If this changes, we will update this policy and provide legally required opt-out mechanisms.
14) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we’ll make reasonable efforts to notify you (for example in the app, or by email). Continued use of the Service after the effective date means you accept the updated policy.
15) Third-party links and services
The Service may link to or integrate with third-party websites or services. Their privacy practices are governed by their policies, not ours.
16) Open-source software
The Service incorporates open-source software provided by third parties. A summary of these components and the applicable license notices is set out in our Open-Source Notices. This Privacy Policy governs only our own processing of your information and does not modify the license terms applicable to any such third-party component.
17) How to contact us
Privacy questions or requests: Danidoes LLC Email: support@danidoes.dev