Privacy Policy
Last updated: 2026-05-05
Tipr.gg is an ad-supported tipping layer for live streamers. This page explains what data we collect, why, and what we do (and don't do) with it. Plain English first; legal language at the bottom.
Plain English summary
- If you're a streamer (you signed up): we store your email, OAuth tokens (encrypted at rest), Twitch / Kick / YouTube channel ID, click + earnings telemetry, payout method, and IP address (hashed) on each authenticated request. We use this to make the platform work and to pay you.
- If you're a viewer who clicked a streamer's tracked link: we collect the IP address (immediately hashed before storage), user-agent string, geo country / region (derived from IP), and referer URL of the click. We do not set cookies on you, do not track you across sites, and have no idea who you are.
- If you installed the Tipr.gg Chrome extension:the extension authenticates you with Twitch (one-time OAuth) and reports which Twitch channel you're currently watching to our backend, every 5–10 minutes. We use this to attribute your supports back to you so the streamer can see your handle in their dashboard. The extension does not read chat, viewer lists, or other data on Twitch. It does not run on non-Twitch sites.
Data we collect
From streamers (account holders)
- Email address (provided at signup or via OAuth provider)
- OAuth provider profile (Twitch / Kick / YouTube): user ID, display name, profile image
- OAuth tokens (access + refresh) — encrypted with AES-256-GCM at rest
- PayPal email (encrypted at rest) — only if you choose to add one for payouts
- Click telemetry under your tracked link, earnings, downline relationships
- IP address + user-agent on authenticated requests (for security audit log)
From viewers (anonymous click traffic)
- IP address — hashed with HMAC-SHA-256 before storage (we keep the hash, not the raw IP)
- User-agent string
- Geo country / region (derived from IP at click time)
- Referer URL (where you clicked from)
- Click timestamp + the streamer whose link was clicked (for attribution and fraud detection)
From extension users (opt-in)
- Twitch user ID + display name (via OAuth)
- Twitch channels you're viewing while the extension is active
- Click events made on tracked links while signed in
What we do not collect
- We do not read Twitch chat content
- We do not track your browsing history outside of Twitch
- We do not collect financial information beyond your PayPal email
- We do not collect or store viewer email or real name (unless you sign up as a streamer)
- We do not use cookies on viewers who haven't installed the extension
Why we collect what we do
- Make the product work — track which streamer earned which click, pay them out
- Detect fraud — invalid traffic costs us our ad-network relationships; we filter aggressively to keep the platform legitimate for real streamers
- Provide streamer analytics — let streamers see geo breakdowns, top supporters, click patterns
- Comply with tax + legal — generate 1099 forms for US streamers earning over thresholds, retain audit logs
Who we share data with
- Ad networks (PropellerAds, Adsterra, AdGate, etc.) — we send them an opaque per-click correlation token so they can credit us for valid views. We do not send IP, geo, or any PII.
- PayPal — when a streamer requests a payout, we send their PayPal email + amount to PayPal Payouts API.
- Twitch / Kick / YouTube — only OAuth-flow data necessary for sign-in.
- Hosting + infrastructure — Vercel (compute), Neon (database), Axiom (logs). Standard sub-processors.
- We do not sell, rent, or trade your data with anyone else.If we ever monetize aggregated insights to advertisers, we'll do so only at a cohort level (e.g., "15-25K streamers in the gaming vertical with avg-CCV-100"), never as individual records.
Data retention
- Click rows: kept indefinitely for audit + analytics; IP hash is non-reversible
- Audit log: 2 years minimum (legal requirement)
- OAuth tokens: until you disconnect the platform OR delete your account
- Streamer account data: kept while account is active; deleted on account deletion
- Edge logs (raw IPs): 90 days max retention via our log provider
Your rights
If you're a streamer, you can:
- Export all your data (account, clicks, earnings, payouts) on request
- Delete your account at any time — this cascades to wipe all associated data
- Disconnect a streaming platform (revokes our OAuth tokens)
- Update your PayPal email at any time
If you're an EU resident, you have additional GDPR rights (access, rectification, erasure, restriction, portability, objection). Submit a formal request via our data request form (works for any user, not just EU). For other questions, contact privacy@tipr.gg.
Cookies
We use cookies for:
- Session cookies on streamer accounts (authentication only — set by Better Auth, HTTP-only + Secure + SameSite=Lax)
- Invite cookie: when someone clicks a streamer's invite link, we plant a 30-day cookie so we know who recruited them on signup
We do NOT use cookies on click traffic from viewers. The click endpoint is stateless from the viewer's perspective.
Children
Tipr.gg is not intended for users under 13. If you are under 18, please do not sign up as a streamer without parental consent (some jurisdictions require it for ad revenue payouts).
Changes to this policy
If we change this policy materially, we'll email signed-up streamers and post a banner on the dashboard 14 days before the change takes effect.
Contact
Questions? Reach out to privacy@tipr.gg (working address; will be canonical once the brand name + domain are locked).