Transparency
Privacy policy
This policy explains which data is processed when you visit, sign in to and use the streaming dashboard. A feature or provider that is not enabled does not receive data. The German version remains the primary legal working draft.
1. Controller
Streaming Dashboard (product name; operator name still to be entered)
Serviceable operator address still to be entered
Germany
Germany
Email: tcn.matchpulse@gmail.com
2. Hosting and server logs
The application is hosted on Railway with a PostgreSQL database. Technically necessary connection data such as IP address, time, requested address, browser information and transferred data is processed to deliver the service, defend against attacks and resolve errors. The legal basis is Article 6(1)(f) GDPR. Application logs redact email addresses, IP addresses, account and workspace identifiers and secrets. Railway may keep additional infrastructure logs under the agreed provider retention terms.
3. Account, sign-in and security
We process your email address, optional display name, role and product mode, password hash or Google account identifier, sessions and security settings. We never receive your Google password. Security-related login attempts include method, outcome, IP address and user agent and are retained for no more than 30 days. Transactional messages such as magic links, password resets and invitations may be sent through Resend. The legal bases are Article 6(1)(b) GDPR and, for abuse prevention, Article 6(1)(f) GDPR.
4. Saved work data
We store the workspace, overlay, match, design, role, chatbot and community settings you create so the requested streaming functions work. Part of the current work state is also mirrored in your browser's local storage. It is not used for advertising. Deliberately saved content remains until you delete it or delete the account.
5. YouTube and Twitch
If you expressly connect a platform, we process the required channel, chat, moderation and OAuth data. This may include channel names, platform user identifiers, chat messages, avatars, emotes and encrypted access and refresh tokens. Disconnecting the platform or deleting your account triggers provider revocation; temporary failures are retried and the local secret is deleted no later than seven days afterwards. YouTube use is additionally subject to the YouTube API Services Terms and the Google Privacy Policy. Google access can also be revoked in your Google security settings. If you use community features such as prediction rounds or leaderboards, we store the publicly visible display name of participating viewers and their score for the duration of the relevant season so that the leaderboard works. The legal basis is Article 6(1)(f) GDPR. Those affected can object to this storage using the contact address above; we will then remove the entry.
6. Google Gemini AI features
When you use an AI feature, only the input needed for that request is sent to the Gemini API, for example an ambiguous chat message with team names or a lineup image you upload. Google processes it to produce the response and for security and abuse prevention. Our AI cost log contains no prompts or responses, only daily model, purpose, call, token and estimated cost totals, which are deleted after 180 days. The legal basis is Article 6(1)(b) GDPR. For EEA users, public activation requires a contractually suitable paid Gemini service under the Google Cloud data processing terms.
7. Sports data and external media
Sports data is requested server-side from OpenLigaDB and attributed under ODbL 1.0. Depending on the view, fonts, flags, team logos, profile images or emotes may load directly from Google Fonts, FlagCDN, Sofascore, Wikimedia, YouTube, Twitch or an image address you provide. That provider technically receives your IP address, time and browser information. The legal basis is Article 6(1)(f) GDPR. Fixed design resources should be hosted locally before public launch where practicable. The scores, match times and names shown in the overlays are entered by you; we do not collect them from third-party sources and do not pass them on.
8. Subscriptions and payments
If billing is enabled and you choose a subscription, checkout is handled by Stripe. Stripe processes contact, payment, customer, transaction and subscription information. We do not receive full card or bank details, only provider identifiers and subscription, term and payment status. The legal bases are Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for mandatory accounting records.
9. Separate newsletter campaign
The newsletter is not a feature or navigation item of the streaming dashboard. Only if you voluntarily subscribe on a separate campaign page does Brevo process your email address, language and consent record. Subscription becomes active only after you click the confirmation link. We do not keep a separate local newsletter recipient database. The legal basis is consent under Article 6(1)(a) GDPR, which can be withdrawn for the future through the unsubscribe link or the contact address above.
10. Cookies, local storage and tracking
We use technically necessary session and security cookies and local browser storage (localStorage and sessionStorage) for sign-in, staging access, language, notices and your work state. These storage operations are necessary for the digital service expressly requested by the user under Section 25(2) no. 2 TDDDG. There is currently no advertising, audience measurement or user analytics and no corresponding tracking cookies. If this changes, any legally required consent will be obtained before activation.
11. Retention, export and erasure
Magic links are valid for 15 minutes, password reset links for 60 minutes and pending MFA setup for 10 minutes. Imported live-chat and prediction data is cleaned after 24 hours. Used recovery verifiers, login events and resolved invitations are deleted after 30 days; an unused session expires after no more than 30 days. You can request a JSON export and delete your account from account security. Account data, sessions, workspaces, AI aggregates, community data and personal login and invitation data are then removed. Mandatory legal retention may prevent immediate deletion of individual payment or contract records. Encrypted backups rotate after 30 days and intervening erasures must be reapplied after a restore.
12. Recipients and international transfers
Recipients are limited to processors and platform providers required for the selected feature: Railway, Google, YouTube, Twitch, Resend, Brevo and Stripe, plus the media and sports-data providers above where applicable. Providers or subprocessors outside the EEA are activated only after checking the applicable transfer mechanism, such as an adequacy decision or EU Standard Contractual Clauses and supplementary safeguards.
13. Your rights and contact
Subject to the legal conditions, you have rights to access, rectification, erasure, restriction, data portability and objection. Consent can be withdrawn for the future at any time. Use the contact address above for privacy requests. Requests are generally answered within one month; the statutory extension may apply to complex cases. You may also lodge a complaint with a data protection supervisory authority.
14. Internal privacy review, status and changes
The operator has reviewed and documented the processing activities, access safeguards, deletion paths, retention periods and providers described above through an internal self-assessment. Based on the current review, the application is designed and operated in accordance with the GDPR for the scope described here. This is an operator self-assessment, not a review by a supervisory authority, an official certification or a privacy seal. Last updated: 19 July 2026. We review and update this notice whenever functions, providers or legal requirements change.