privacy policy
Last updated 2026-10-05. One policy for everything doink: doink.tv and all its products. We store something only while the service needs it. If it is not on this page, we do not store it. The data controller is the person who runs doink.tv, reachable at privacy@doink.tv.
your account
- Username + join date. Your one public name everywhere on doink, and your channel address if you stream. Kept while the account exists.
- Verified email. The address, for signing in and not losing the account, plus a normalised copy of it (lowercase, dots and +tags removed) so one mailbox is one account. Sign-in codes are stored hashed and expire after 15 minutes. Never public, never shared, no marketing.
- Passkeys (optional). The public half of the key, the label you typed and a use counter. The private half, and your fingerprint or face, never leave your device.
- Chat channels (optional, Twitch / Kick). The channel names you type, for the chat overlay visible to viewers.
- Profile picture (optional). The image you upload, resized to two small squares.
- Profile page (optional). The bio and links you enter, and if you build your page: the text you write, up to four images (re-encoded on upload, originals discarded), one YouTube video id and where you placed them. Public on your profile page, editable and removable there.
- Badges. Whether you were one of the first 100 people to chat or stream (the early adopter badge), and the chat roles and supporter status a streamer gives you on their channel. Shown next to your name in that chat.
- Sessions. A hashed session token with its created and expiry dates. Sessions last 30 days; expired ones are cleaned up automatically. The raw token lives only in a cookie in your browser.
if you stream
- Channel config. Title, category, stream key, live state, dashboard settings, offline screen.
- Restream targets. The destination and that platform's stream key, encrypted at rest, decrypted only in the moment the ingest server pushes to that platform, never shown back to anyone, deleted when you remove the target. A keyed hash of the key is kept alongside it, used only to refuse the same key on a second doink account.
- Sub sources. If you connect Twitch subs, an encrypted token that can only read your subscriber list, granted in a separate optional flow, never during normal sign-in. If you connect a Discord server, the server and role ids.
- Subs and entitlements. Who is subbed to whom, from which source and until when. Sub events for viewers who have no doink account yet are stored against their platform id and claimed, or deleted, at their first sign-in.
- Moderators, stars and supporters. Who you made a moderator, a star or a supporter on your channel (and since when), the supporter badge image you upload (resized on upload), and every moderation action (who acted, on whom, what) as a permanent record in the channel log.
live and chat
- Chat messages are stored with your username and are public and permanent: every channel's log can be read by anyone. Removed messages stay in the log but are hidden from viewers.
- Clips you keep are stored with your username as the clipper until they are deleted, under random ids. Views are a counter, not a list of viewers.
- Comments on clips and playbook pages are public, stored with your account and deletable by you.
- Follows: which channels you follow, so your home page can show them.
- Channel wide viewer counts are counted in memory and not stored long term. There is no watch history and no viewing profile.
emotes
- Emotes you upload are public once approved, with your username as uploader; their keyword and tags are stored with them. Rejected uploads are deleted outright.
- Your collections and which one is active per platform.
- Emote moderation is logged (what, when, which moderator) to keep the review accountable.
- Creator claims you make on an emote: what you asked for, the link and note you gave, and the outcome, kept as a record. An evidence file you attach is stored only until staff resolve the claim, then deleted.
what we deliberately do not do
- No IP address or device storage. Your IP is used in the moment for rate limiting and Cloudflare Turnstile bot checks, then discarded. No table anywhere stores an IP or a user agent against a person. Chat connection limits use a one-way hash of the IP that is never stored.
- No analytics or tracking scripts, no ads, no profiling, no selling or sharing data beyond the infrastructure that runs the service.
cookies
Only what the service needs, none for tracking: a session cookie when you sign in, a short-lived playback cookie so the video player can fetch the stream, a cookie that remembers you passed the bot check.
who else sees data
- Cloudflare hosts the service (servers, storage, email delivery for sign-in codes, bot checks). Our own ingest servers receive your stream. Restream platforms receive the stream you point at them.
- YouTube, if you embed a video on your profile page: viewers of that page load the embed from YouTube, which has its own policy.
retention
- Live stream media auto-deletes after about a day. Media files have no backup copies: deleted is deleted.
- Database backups exist for disaster recovery and roll off after 30 days, so a deleted row can persist in a backup for up to 30 days before it is gone from everywhere.
- Ops alerts about our own servers contain no user data.
your rights
Self-serve on your account page: request my data downloads one JSON file of everything above that belongs to you, and delete account removes it all. If a button will not do, or you want something corrected, email privacy@doink.tv. You can complain to the UK Information Commissioner's Office if you think we handled your data badly.
children
doink is for people aged 13 and over. If we learn an account belongs to someone younger, we delete it.
changes
When this page changes the date at the top changes. If we ever start storing something new about you, it is added here in the same release.
Questions: our socials or inbox@doink.tv