Privacy Policy
Effective: 5 July 2026
The short version: VIP Relay is built to know almost nothing about you. There are no fan accounts — no name, email, password, or phone number. To send a “they’re live” alert we only need an anonymous device token from your phone’s wallet and the public creator handle you asked about. Delete the pass and your data unregisters itself.
This policy explains what VIP Relay (“we”, “us”, “our”) collects, why, and your rights. It applies to viprelay.com and the wallet passes we generate. By using the service you agree to this policy. VIP Relay is a free, non-commercial project operated by an individual — there are no paid plans, no ads, and no sale of data.
1. The data we collect (and what we don’t)
We do not collect: fan names, emails, passwords, phone numbers, contacts, precise location, or any advertising identifiers. We do not build fan profiles.
Fans (people who add a pass):
- The public creator handle you search and the creator’s public profile (display name, avatar, channel id) returned by Twitch or YouTube — to build the pass and show “fans waiting”.
- An OS-level device push token / wallet object id your device sends when you add the pass. This is a pseudonymous routing identifier used for one purpose: delivering the go-live alert to that pass. It is not linked to your identity.
- Minimal technical logs (e.g. request id, coarse timestamps, delivery status) for security, abuse-prevention, and reliability. We don’t use them to track you.
Creators (people who claim a channel):
-
OAuth authorization from Twitch or Google/YouTube. We request
read-only scopes (e.g.
youtube.readonly; identity for Twitch) only to confirm which channels your account owns — for YouTube we callchannels.list?mine=trueto list the channels you control — so we can bind each pass to the person who proves ownership and keep your dashboard’s channel list current. We do not use this scope to detect when you go live: go-live is detected entirely from public data (the public WebSub feed and public channel metadata), never from your OAuth token. For Google we also requestopenidonly to read a stable identifier for your Google account, so the channels a single login manages stay grouped under the correct account — we do not request your email or profile. We never request write/broadcast permissions and never post, edit, or delete on your account. - The access/refresh token, stored encrypted at rest, used only to re-confirm the channels your account owns (so you can add or manage another of your channels without signing in again) and to keep the go-live subscription alive. We delete it when you disconnect that platform or revoke access.
- Multiple channels / logins under one account. You may claim and manage more than one channel from a single VIP Relay account, and you may connect more than one platform login (e.g. Twitch and YouTube) to the same account. We associate the channels and logins you authorise so you can switch between them without signing in again. We only ever link a channel or login that you have just proven you control via OAuth — we never merge accounts. You can unlink a channel or disconnect a platform at any time from your dashboard; disconnecting deletes that login’s stored token.
- A sign-in session so we recognise you when you return (instead of asking you to claim again). It’s a signed cookie holding only an opaque account id — no name, email, or token — and it clears when you sign out (see Cookies).
2. Why we process it (legal bases)
Where the EU/UK GDPR applies, we rely on: your consent (you add a pass to receive alerts; withdraw any time by deleting it), contract (to provide the service you requested), and our legitimate interests (keeping the service secure, reliable, and free of abuse). For creators, processing the read-only token is necessary to perform the claim and notification service.
3. Cookies
We use only strictly-necessary cookies — never advertising, analytics, or cross-site tracking — so no consent banner is required:
- a CSRF cookie that protects form submissions from cross-site request forgery; and
-
for creators who sign in, a session cookie that keeps you signed in so we
recognise you on return. It is signed,
HttpOnly, and holds only an opaque account id (no name, email, or access token); it expires on its own and clears when you sign out.
4. Platform data & Google Limited Use
VIP Relay’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google (your YouTube identity and public live-broadcast status) and from Apple/Twitch is used only to provide the go-live notification feature you requested; it is never used for advertising, sold, or transferred to others except to operate the service or as required by law.
5. Who we share with — and who we never share with
We never sell or rent your data. Device tokens are never shared with creators or any other user. We share data only with the providers that make the service work, acting on our instructions:
- Apple (APNs / Apple Wallet) — to deliver pass updates and pushes.
- Google (Google Wallet) — to deliver pass messages.
- Twitch / YouTube — to read public profile + live status and verify creator ownership.
- Our hosting & database provider — to run the application.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.
6. International data transfers
The service is hosted in, and data is processed in, the United States and by the providers above. If you access VIP Relay from the EEA, the UK, or elsewhere, your information may be transferred to and processed in countries with different data-protection laws. Where required, such transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) offered by those providers.
7. How long we keep it
Pass and device records are kept while the pass is installed. When you delete the pass, your device unregisters and the registration is deactivated, then purged in routine cleanup. Notification logs are retained for a limited window for delivery integrity and abuse prevention, then deleted. Creator tokens are kept until you revoke access, disconnect the platform, or unclaim — then they are deleted.
8. Your rights
Depending on where you live (including under the GDPR/UK GDPR), you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to or withdraw consent. The simplest control is built in:
- Fans: delete the pass from Apple/Google Wallet — this unregisters your token automatically.
- Creators: revoke VIP Relay’s access in your Twitch or Google account security settings.
- For any other request, email [email protected]. You may also lodge a complaint with your local data-protection authority.
9. California privacy (CCPA/CPRA)
We do not sell or “share” (for cross-context behavioral advertising) personal information, and we have not in the preceding 12 months. California residents have rights to know, delete, and correct their personal information and not to be discriminated against for exercising them. Exercise these via the controls above or [email protected].
10. Children
VIP Relay is not directed to children under 13 (or the minimum digital-consent age in your country, where higher), consistent with the Twitch/YouTube minimum age. We do not knowingly collect data from children. If you believe a child has used the service, contact [email protected] and we will delete the associated data.
11. Security
We apply industry-standard measures: encryption in transit, encryption of creator tokens at rest, signed/verified webhooks, and least-privilege access. No system is perfectly secure. To report a vulnerability or suspected abuse, email [email protected] — we welcome responsible disclosure.
12. Changes to this policy
We may update this policy at any time as the service evolves. Material changes are reflected by the “Effective” date above; continued use after a change means you accept the updated policy.
13. Contact
Privacy questions or requests: [email protected]. General support: [email protected]. Security/abuse: [email protected].