Fishrift — Privacy Policy

Last updated: 18 July 2026

Effective: 18 July 2026

Data controller: Fishrift, The Netherlands

Privacy contact: privacy@fishrift.com


1. Introduction

This Privacy Policy explains how Fishrift collects, uses, stores, and protects your personal data. We are committed to full transparency about our data practices and to compliance with the General Data Protection Regulation (GDPR — Verordening (EU) 2016/679) and Dutch implementation law (Uitvoeringswet AVG).


2. What Data We Collect

Account data (collected at sign-up)

  • Your platform username and display name (from Twitch/YouTube/Kick OAuth)
  • Your platform user ID
  • Your email address (if provided by the platform)
  • Your profile picture URL
  • OAuth access tokens (encrypted at rest, never exposed to other users)

Usage data (collected while using Fishrift)

  • Stream events during your streams (follows, subscriptions, cheers, raids, donations, chat messages processed by the bot)
  • Overlay, alert, and bot configurations you create
  • Files you upload to your media library
  • Fishcoins balances and transaction history for viewers in your channel
  • Dashboard usage patterns for product improvement (aggregated, anonymized)

Payment data (collected on subscription)

  • Subscription tier and dates
  • Payment processing is handled by Stripe. Fishrift does not store full card numbers or sensitive payment credentials.

Technical data (collected automatically)

  • IP addresses (for security and fraud prevention only)
  • Browser type and operating system (for compatibility)
  • Cloudflare security logs (our infrastructure provider)

Data about your viewers

When your stream is live, Fishrift receives event data that includes your viewers' platform usernames. This data powers your alerts, activity feed, loyalty system, and bot features. We do not sell or share viewer data with any third party.


3. How We Use Your Data

We use your data to:

  • Provide and operate the Fishrift service
  • Process your subscription and manage billing via Stripe
  • Power your alerts, overlays, bot, and loyalty features
  • Send you transactional emails (account events, billing receipts)
  • Send product updates via Sonar (you may opt out of non-essential Sonar messages at any time)
  • Improve the platform based on aggregated, anonymized usage data
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

Legal bases for processing (GDPR Article 6)

PurposeLegal basis
Providing the serviceContract performance (Art. 6(1)(b))
Security and fraud preventionLegitimate interests (Art. 6(1)(f))
Product improvementLegitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))
Optional communicationsConsent (Art. 6(1)(a))

4. Data Sharing

We share your data only as follows:

Service providers (all with Data Processing Agreements)

  • Cloudflare — hosting, CDN, infrastructure. cloudflare.com/privacypolicy
  • Stripe — payment processing. stripe.com/privacy
  • AWS (Amazon Polly) — text-to-speech for alert TTS features. aws.amazon.com/privacy
  • Twitch, YouTube, Kick, Ko-fi, Patreon — connected platform APIs

Legal requirements

We may disclose your data if required by law, court order, or governmental authority in the Netherlands or EU.

What we never do

  • Never sell your data to any third party, ever, under any circumstances
  • Never share your data with advertisers
  • Never use your viewer data to train AI models without explicit consent
  • Never share your data with other Fishrift creators

5. Data Retention

Data typeRetention period
Account dataDuration of account + 30 days after deletion
Stream events24 months from event date, then purged
Payment records7 years (Dutch fiscal law requirement)
Fishcoins/loyalty dataDuration of account + 30 days after deletion
Media uploadsUntil manually deleted or 30 days after account deletion
Security logs90 days

We will notify you before implementing any change to these retention periods.


6. Data Security

We protect your data using:

  • TLS 1.3 encryption for all data in transit
  • Encryption at rest for sensitive data (OAuth tokens, payment references)
  • Strict access controls — only authorised Fishrift personnel may access production data, only when operationally necessary
  • Cloudflare infrastructure security (DDoS protection, WAF)
  • Regular security reviews

In the event of a personal data breach that poses a risk to your rights, we will notify you and the Autoriteit Persoonsgegevens within 72 hours as required by GDPR Article 33.


7. Your Rights Under GDPR

RightWhat it means
Access (Art. 15)Request a copy of all personal data we hold about you
Rectification (Art. 16)Correct inaccurate personal data
Erasure (Art. 17)Request deletion of your personal data
Data portability (Art. 20)Receive your data in a machine-readable format
Restriction (Art. 18)Ask us to pause processing in certain circumstances
Object (Art. 21)Object to processing based on legitimate interests
Withdraw consentWhere processing is consent-based, withdraw at any time

To exercise any right: privacy@fishrift.com

We will respond within one month. Complex requests may be extended by two additional months with notice to you.

Right to complain

You have the right to lodge a complaint with the Dutch data protection authority:

Autoriteit Persoonsgegevens autoriteitpersoonsgegevens.nl +31 88 1805 250


8. International Data Transfers

Fishrift primarily processes data within the European Economic Area. Where data is transferred outside the EEA (e.g. Cloudflare or AWS infrastructure in the United States), this is done under Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms under GDPR Chapter V.


9. Children

Fishrift is not directed at persons under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data about someone under 18, contact us at privacy@fishrift.com and we will delete it promptly.


10. Changes to This Policy

We will notify you via email and Sonar at least 30 days before making material changes to this Privacy Policy. The "Last updated" date at the top reflects when the policy was last revised.


11. Contact

Fishrift The Netherlands privacy@fishrift.com