← back to home

privacy policy.

how we handle your data — what we collect, why, where it lives, and how you can take it back.

last updated: 4 September 2026

1. why you sign in with twitch

klypra requests two twitch scopes:

  • ·chat:read — to read your channel's chat and detect highlights.
  • ·user:read:email — used as your account identifier, never for marketing.

nothing else — no posting to your channel, changing settings, or reading dms. revoke access anytime from twitch's connections page — this stops monitoring immediately.

2. what we collect

from twitch, at sign-in

  • ·twitch user id, username, and display name
  • ·email address — your account identifier

what you create in klypra

  • ·monitored channels and their settings
  • ·clip settings — threshold, format, subtitle style
  • ·generated clips — files, transcript, scores, expiry
  • ·worker stats — chat rates, heartbeats, error logs

if you set up telegram delivery

  • ·bot token — server-side only, never sent back to your browser
  • ·chat id — where clips get delivered
  • ·notification preferences

if you join the waitlist

  • ·email address — to get early access and news about klypra

3. what we don't collect

  • ·your twitch password or access token (oauth handles this)
  • ·private twitch messages or dms
  • ·card or banking information — no payment processing yet
  • ·browser fingerprints or ad-tracking pixels
  • ·data from twitch accounts other than the one you sign in with

we do use one small, optional cookie to see how you found klypra — see section 5 for what it is and how to opt out.

4. how we use your data

  • ·operate the service — chat reading, highlight detection, clip generation, delivery
  • ·notify you — if you joined the waitlist, to let you know at launch
  • ·keep the service healthy — operational logs, error diagnostics

we do not use your data for advertising, profiling, ml training, or resale, and we don't send marketing emails.

legal basis (gdpr art. 6): contract performance for account/clip data, consent for waitlist emails, legitimate interest for operational logs.

5. where it lives & how it's secured

  • ·account & clip metadata — postgres db, hosted in the uk, encrypted at rest
  • ·clip mp4 files — object storage in the eu. public by default via an unlisted link; no private-clip option yet
  • ·telegram bot tokens — row-level access only, never returned to your browser
  • ·passwords — none, sign-in is via twitch oauth

the uk is a "third country" under gdpr post-brexit, but covered by the eu's uk adequacy decision — no extra safeguards needed for that transfer.

cookies

  • ·session cookie — strictly necessary, http-only, keeps you signed in. set automatically, no consent needed.
  • ·attribution cookie — optional. on your first visit, we ask whether you're okay with one cookie that records how you found klypra (a utm campaign tag, or the site that linked here, or "direct" if neither applies). only set if you click "accept" on that banner; declining or ignoring it means the cookie is never set. it's copied once onto your account the first time you sign in, so we can see e.g. "most signups this month came from reddit" — never used for ads, retargeting, or building a profile of you individually.
  • ·microsoft clarity cookies — optional, covered by the same banner. clarity gives us heatmaps and session recordings so we can see where the site confuses people. it sets its own cookies (_clck, _clsk) and is only loaded at all if you click "accept" — declining or ignoring the banner means the script never runs and no recording starts.

what session recording means

a recording is a reconstruction of how a page was used — mouse movement, scrolling, clicks, which elements were interacted with. it is not video of your screen and it does not follow you to other sites.

clarity masks text you type into form fields by default, so passwords and anything entered into an input are not captured. we haven't switched that off. we use it on the public marketing pages to work out which parts of the site fail to explain themselves.

you can withdraw consent anytime by clearing your browser's local storage and cookies for this site, which resets the banner. note that clarity keeps running until you reload the page or navigate away, since it is already loaded at that point. microsoft also offers its own opt-out at clarity.microsoft.com/terms.

6. how long we keep it

  • ·account data — until you delete your account
  • ·clips — 14 days, video and metadata both. no pro tier yet, so no longer retention option exists
  • ·waitlist email — until launch, or until you ask us to remove it
  • ·operational logs — short-lived, diagnostics only

deleting your account wipes everything above immediately, including storage files — no soft-delete.

7. third parties we share data with

  • ·database — managed postgres, uk-hosted
  • ·object storage — eu-hosted, holds clip files
  • ·email service — us-based, covered by the eu-u.s. data privacy framework
  • ·web hosting — serves the frontend, sees standard request logs only

you also actively connect two services yourself:

  • ·twitch — chat:read scope + identity verification
  • ·telegram (optional) — your own bot, your own chat id

we also use one third-party analytics service, only after you accept the cookie banner:

  • ·microsoft clarity — heatmaps and session recordings for the public pages. microsoft acts as a processor here and is a us company; the transfer is covered by the eu-u.s. data privacy framework. see section 5 for what a recording actually contains and what clarity masks.

we don't use ad networks, retargeting pixels, or anything that builds a profile of you across other sites, and we don't sell data to anyone.

8. your rights

you have the right to:

  • ·access the data we hold about you
  • ·correct anything inaccurate
  • ·delete your account and all associated data
  • ·revoke twitch access, from twitch's connections page
  • ·export your clips as mp4
  • ·data portability, restriction of processing, and objection to processing (gdpr)
  • ·lodge a complaint with a data protection supervisory authority

to exercise any of these, write to timpe.hen@gmail.com — account deletion and clip export are also available directly in your settings.

9. age requirement

klypra is intended for users aged 16 and older. we rely on twitch's own account requirements and on your own representation of your age at sign-up — we have no way to independently verify it.

10. changes to this policy

we will update the "last updated" date at the top whenever we change anything material. it is your responsibility to check this page from time to time for changes.

11. contact

questions, requests, or concerns? write to timpe.hen@gmail.com. for our full legal identity and address, see the imprint.

← back to home