Privacy Policy

Version 2.15, last updated 7 September 2026

1. Who we are

bot-able is provided by Codetiles AB, a company registered in Sweden (org. no. 559586-2250). We are the data controller for the personal data of people who create a bot-able account ("Streamers", "you"). For data relating to your viewers (see Section 3), the roles work differently: you, the Streamer, are the data controller for your community's data, and Codetiles AB acts as your data processor. This is explained further in Section 9.

2. What we collect from you (the Streamer) and from website visitors

  • Authentication data: if you sign in with Twitch, we receive your Twitch OAuth access and refresh tokens (used to operate the bot on your channel), your verified email address, and your Twitch profile (user ID, login name, display name, avatar). If you sign in with email and password instead, we store your email and a securely hashed password. We never see your Twitch password.
  • Configuration data: the commands, timers, and stream bible (personality and settings) you set up for your bot.
  • Stream statistics: viewer counts, follower counts, subscriber counts, bits, and chat message counts collected during your streams.
  • Session summaries: end-of-stream summaries generated by the bot.
  • Usage and cost logs: records of AI calls made on your behalf, used for reliability and cost management.
  • Voice usage counters: if you use the Voice Companion, we store how many seconds of audio have been transcribed for your channel, used for the Voice add-on's fair-use allowance and billing. We do not store the audio itself, or the transcript text derived from it, beyond what the bot already uses to reply, described in Section 11.
  • Cached follower/subscriber counts: stored so your dashboard can show recent numbers between live updates.
  • Discord integration data: if you connect the optional Discord integration, we store which Discord server and channels you have connected, your channel and role choices for each announcement type (go live, clips, session summaries), and the webhook credential Discord gives us to post on your behalf. We treat this credential as a secret: once created it is never shown to you again, and your dashboard only ever shows whether a channel is connected, not the credential itself. If you choose to also announce when another Twitch streamer goes live ("watched streamers"), we store that streamer's Twitch user ID, username, display name and avatar for as long as you keep the watch active. See Section 12.
  • Billing and subscription data: if you subscribe, we store your Stripe customer and subscription identifiers, which plan and add-ons you have, the subscription status, the current billing period end and the date your subscription started (which is what your 14 day withdrawal right is measured from), any top-ups you buy, and the billing country from your purchase, which we use to check that we are allowed to sell to you. We also count your usage against the plan's fair-use allowances. Your card details are entered on Stripe's own pages and never reach our servers.
  • Email send records: which service or marketing emails have been sent to your address, and whether each one succeeded. This is what stops us sending you the same notice twice.
  • Alert sound files you upload: if you use alert sounds in the Chat Monitor (previously called the Stream Companion), we store the audio files you upload, their file names, and which Twitch event or channel point reward each one is mapped to, so we can play them back on your own devices. These are files you provide; please only upload audio you have the right to use.
  • Your location, if you switch it on: the optional location feature for IRL streams sends us your device's position while you are sharing, and we turn it into an area name such as a town. We do not store the position itself, and we do store your on/off setting and any area names you choose to hide. This is explained in full in Section 14.
  • Questions asked on our website: if you use the question box on our home page, we store the text of your question, whether it matched one of our prepared answers, and which language it was written in. You do not need an account to use it, and we do not store your IP address, browser details, cookies, or anything else that could identify you. If your browser offers it, you can speak your question instead of typing it. Your browser does the listening and the transcribing, using its maker's own speech service, which is Google in Chrome and Apple in Safari, under their terms rather than ours. Your microphone opens only after your browser asks your permission, no audio ever reaches us, and nothing is sent to us until you press send. What we receive and keep is only the finished text, exactly as if you had typed it. We use this to see what people want to know and to write better answers (legitimate interest, GDPR Art. 6(1)(f), see Section 4). If your question matches one of the answers we have written in advance, that is what you get and no third party is involved. If it does not match one, we send the text of your question to Anthropic, the AI provider already named in Section 6, which writes a short automated reply in the bot's voice; we show you that reply and store it alongside your question. Your reply is written by software, not by a person. There is a limit on how many of these automated replies one visitor can be given in a day, and on how many the site writes in a day. What we keep does not change: your question, the reply, which language you wrote in, whether one of our prepared answers matched, and nothing else. Please do not include personal details in your question. We have no way of identifying you, nobody at Codetiles AB is on the other end of this box, and we cannot come back to you afterwards. Kept for up to 12 months, then deleted; see Section 7.

3. What we collect about your viewers (community data)

bot-able is a chat bot that interacts with people in your Twitch chat, who never sign up for bot-able themselves. To provide features like personalized greetings and memory of returning viewers, the bot may store:

  • Twitch usernames of viewers in your chat
  • Free-text memory notes about a viewer (for example, things they mentioned in chat or plans they shared), captured either automatically by AI reading chat messages or manually via the !remember command
  • Greeting history (whether a viewer has been greeted in the current session)
  • Watch streak counts
  • Recent stream event history (for example follows, subscriptions, resubscriptions, gifted subs, raids, cheers, channel point redemptions and watch streak milestones), used to show a short catch-up feed and to play your alert sounds in the optional Chat Monitor feature. For a channel point redemption we record which reward was redeemed. Where a viewer chooses to share a public message with a resubscription or a cheer, that message is included as part of this history.

Chat messages themselves are processed transiently (in real time) by our AI to decide whether and how the bot should reply. We do not build a permanent archive of full chat logs. The two exceptions are the short memory note and the short-lived stream event history described above, both tied to a username and both kept only for the limited periods set out in Section 7.

You control this data. As the Streamer, you decide whether these features are enabled, and you can remove a viewer's stored memory at any time (including via the bot's !forget command). We act only on your instructions with respect to this data, as your processor.

4. Why we process this data (purposes and legal basis)

  • To provide the service you signed up for (running your bot, storing your configuration, showing your dashboard). Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To power AI features (chat replies, viewer memory, session summaries, and Discord announcements). Legal basis: our legitimate interest in delivering the core functionality of the product you asked for (GDPR Art. 6(1)(f)), balanced against viewers' interests as described in Section 3, and, for Discord announcements about a streamer you choose to watch, against that streamer's interests as described in Section 12, and always subject to your ability to disable these features or delete the data.
  • To keep the service secure and working (logs, error monitoring, cost tracking, and non-stored checks of request rate to prevent abuse of the website question box, one over a few minutes and one over the last 24 hours that caps how many automated replies a single visitor can set off). These counts are held in memory only, are never written to a database, and are gone when they expire or when our server restarts. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).
  • To answer visitors and to understand what they are asking on our website, so you get a useful answer, and so we can write better prepared answers and improve the site. Where we have no prepared answer, an AI service writes a short automated reply for us, described in Section 2 and named in Section 6. This only applies to the anonymous question box on our home page: we do not track who asked, the box requires no account, and choosing not to use it costs you nothing. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).
  • To send you service and account emails, such as changes to these policies, trial and billing notices, and other information about your account and your use of the Service. Legal basis: performance of our contract with you. These emails are part of the Service and cannot be turned off while your account is active.
  • To send you marketing emails about bot-able features and updates. If you are an existing or paying customer, we may email you about similar bot-able features and services based on our legitimate interest and the existing-customer exemption under Swedish electronic communications law, unless you tell us otherwise. In all other cases, we only send marketing emails if you have given us your consent. Legal basis: consent (GDPR Art. 6(1)(a)), or legitimate interest under the existing-customer exemption where applicable. Every marketing email includes a free and easy way to unsubscribe, and we honor unsubscribe requests within a few days.
  • To take payment and keep billing records (subscriptions, add-ons, top-ups, refunds, and the usage counts behind the fair-use allowances). Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)) and compliance with legal obligations such as accounting and tax law (GDPR Art. 6(1)(c)). Card details are handled entirely by Stripe and never reach our servers.

5. Where your data is stored and how it is secured

All bot-able data is stored on Codetiles AB's own self-hosted PostgreSQL database server, located in the European Union (Sweden). We do not use third-party database-as-a-service platforms to store your data. Access to the database is restricted to authorized Codetiles AB personnel. OAuth tokens and passwords are stored using industry-standard protections; passwords are never stored in plain text.

6. Who else processes your data (subprocessors)

We use the following subprocessors to deliver the service. Voice transcription is not one of them: it runs on our own servers (see Section 11) and involves no third party.

  • Anthropic (Claude API), United States: generates AI chat replies and processes chat and context text. It also writes the short automated replies to questions asked in the question box on our home page, and receives the text of those questions when we have no prepared answer of our own (Section 2).
  • Google Cloud (Text-to-Speech): the primary text-to-speech voices for the Chat Monitor feature, processed through Google's EU-region service endpoint.
  • Microsoft Azure: an automatic fallback text-to-speech provider for the Chat Monitor feature, used only if Google Cloud is unavailable or not enabled for your account. If neither is available, voices are generated on our own servers instead, with no third party involved.
  • Twitch (Amazon), United States: platform APIs (chat, events, channel data) required to operate the bot on your channel.
  • Discord Inc., United States: if you connect the optional Discord integration, we use Discord's API to post go-live, clip and stream-summary announcements to a Discord server you choose, through a webhook you control and can remove at any time. Connecting also shows a Discord consent screen naming your username and avatar, the smallest identity scope Discord requires for the connection step; we never read or store that information. Our Discord bot itself requests permission to view channels, create webhooks, and mention @everyone, used only if you choose that option for a go-live announcement (Section 12). It has no connection that would let it read messages, and includes no feature to list server members; it can only post through a channel-scoped webhook it creates.
  • GitHub, United States: hosts downloads of the optional desktop Voice Companion app.
  • Stripe: takes payment for subscriptions, add-ons and top-ups, and issues refunds. Stripe receives your email address and the billing details you enter at checkout. Card numbers are entered on Stripe's own pages and are never sent to or stored by us.
  • Strato, Germany: delivers our outgoing email (account, service and billing notices).

Where a subprocessor is located outside the EU/EEA (such as Anthropic or Twitch), we rely on appropriate safeguards for the transfer, such as the EU-US Data Privacy Framework and/or Standard Contractual Clauses, as applicable. Anthropic does not use data submitted through its commercial API to train its models, per Anthropic's commercial terms. We may add or change subprocessors from time to time; material changes will be reflected in updates to this policy.

OpenStreetMap Foundation (Nominatim): if you switch on location sharing, your coordinates are sent to their Nominatim service to be turned into an area name. Nothing identifying you is sent with them. This is a free service shared by the public rather than a subprocessor we have an individually negotiated agreement with, which is set out in full in Section 14.

Third-party content loaded in your browser: if you use the Chat Monitor, your browser connects directly to Twitch (live chat and badge data) and to the emote services BetterTTV, FrankerFaceZ, and 7TV to display chat emotes. These connections expose your IP address to those services, in the same way as visiting their websites would. No bot-able account data is shared with them. The same is true if you speak a question on our home page: the speech recognition is your browser's own, and the audio goes to your browser maker rather than to us.

7. How long we keep your data

  • Twitch OAuth tokens: kept while your Twitch connection is active. When you disconnect Twitch or close your account, tokens are removed from our systems within a reasonable period. You can also revoke bot-able's access directly in your Twitch settings at any time, which invalidates the tokens immediately.
  • Viewer memory data: kept until you delete it, disable the relevant feature, or close your account. If nobody adds to or updates a viewer's memory for 12 months, it is deleted automatically.
  • Stream event history (used for the Chat Monitor catch-up feed): kept for up to 3 days, after which it is deleted automatically. It is also deleted when you disconnect your Twitch account.
  • Discord integration data: kept while your Discord connection is active, and deleted or anonymized within a reasonable period after you disconnect Discord or close your account. If you use the "watched streamers" feature, a watched streamer's data is kept until you remove that watch, you disconnect Discord, or you close your account. A webhook credential is deleted from our systems once no announcement type is still using it, for example when you disconnect Discord, or when you move every announcement that used it to a different channel.
  • Alert sound files: kept until you delete them or close your account. You can remove any uploaded sound at any time from the Alert Sounds page in your dashboard.
  • Giveaway entries and ticket events: kept for up to 30 days after a draw, then deleted automatically. If you delete a giveaway, its entries and ticket events are removed immediately. Entries in a giveaway that is never drawn are removed after 12 months without activity.
  • Giveaway winner records: kept as part of your giveaway history for as long as your account is active, and deleted or anonymized within a reasonable period after account closure. You can delete a giveaway, and its history, at any time from your dashboard.
  • Account and configuration data: kept for as long as your account is active, and deleted or anonymized within a reasonable period after account closure, except where we must retain limited records for legal or accounting reasons.
  • Logs (usage, cost, error logs): kept for a limited period for operational and security purposes, then deleted or aggregated.
  • Website questions: questions submitted through the question box on our home page, together with any automated reply we showed you, are kept for up to 12 months from the day they were sent, then permanently deleted.
  • Voice audio sent to our servers: never stored. It is held in memory only for the few seconds needed to transcribe it, then discarded (see Section 11).
  • Your location: never stored. Your most recent position and the area name derived from it are held in memory on our server only, and are discarded when you stop sharing, when they are more than 10 minutes old, or when our server restarts (see Section 14). Your on/off setting and your list of hidden area names are kept until you change them or close your account.
  • Voice usage counters: kept while your account is active for the Voice add-on's fair-use allowance and billing, and deleted or anonymized within a reasonable period after account closure, except for limited billing records we must retain for legal or accounting reasons.
  • Marketing email records: your marketing consent and unsubscribe status is kept for as long as needed to honor your preferences, including after you unsubscribe or close your account, so we do not email you again by mistake. Marketing send logs are kept for up to 24 months.
  • Service email records: a record of which account, trial and billing notices have been sent to your address is kept for as long as your account exists, so that a one-off notice is never sent to you twice.
  • Billing records: invoices, payments and refunds are kept for as long as Swedish accounting law requires (currently seven years), even after you close your account. Most of this data lives with Stripe as our payment processor.

8. Your rights (as a Streamer / account holder)

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data (subject to legal retention requirements)
  • Request a portable copy of your data
  • Object to or restrict certain processing
  • Object to direct marketing at any time, free of charge, including via the unsubscribe link in any marketing email
  • Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se), or your local supervisory authority

To exercise any of these rights, contact support@codetiles.com.

9. Rights of your viewers (community data)

Because you are the data controller for your community's data (Section 3), requests from your viewers about their own data (for example, "what do you have stored about me" or "please delete my memory") should generally be directed to you as the Streamer. As your processor, Codetiles AB will assist you in responding to such requests, and viewers may also contact us directly at support@codetiles.com; we will forward the request to the relevant Streamer or, where appropriate, act on it directly (for example, deleting a specific viewer's memory record on request).

A viewer's memory data can be deleted at any time by the Streamer (via the dashboard or the !forget command) or by contacting us.

10. Cookies

bot-able uses only strictly necessary cookies, specifically a session cookie used to keep you signed in. We do not use analytics, advertising, or marketing cookies anywhere on the site. Because these cookies are strictly necessary for the service to function, no cookie consent banner is shown, in line with applicable e-privacy rules for strictly necessary cookies.

11. Voice Companion and audio processing

bot-able offers an optional desktop app, the Voice Companion, which can listen to your microphone to let the bot react to what you say.

  • How audio is transcribed: when you use the Voice Companion, your microphone audio is streamed securely (encrypted in transit) to our own servers in the European Union, where it is transcribed by a speech-to-text model that we run ourselves. We do not use any third-party transcription service.
  • Audio is never stored: the audio is held in memory only for the few seconds needed to turn it into text, and is then discarded immediately. It is never written to disk, never saved in a database, and never kept after transcription. When you stop listening or the connection drops, any sentence still being transcribed is finished from memory over the next few seconds and then discarded. There is no listening beyond that.
  • Only the text continues: after transcription, only the derived text transcript continues on to the bot, in the same way the bot already uses your chat. We keep usage counters (how many seconds were transcribed) for the Voice add-on's fair-use allowance and billing, but we do not keep the audio.
  • Roles for other people's voices: where your microphone may pick up the voices of co-streamers, guests or bystanders (for example on an IRL stream), you, the Streamer, are the data controller for their voice data, and Codetiles AB acts as your processor, transcribing that audio only to produce a transcript on your behalf and for no other purpose. You are responsible for having a lawful basis and for giving notice before their voice is captured, as described in our Terms.

On our servers we never perform voice identification, voiceprint creation, or any other form of biometric processing on audio. Separately from the hosted service, we are running a closed technical test of an offline wake phrase feature: a test build of the desktop app, given only to testers who give separate explicit consent first, creates voice templates from the tester's own voice and keeps them, with any test recordings, in a folder on that tester's own computer. Nothing in that folder is uploaded, and it reaches Codetiles AB only if the tester chooses to send it, in which case Codetiles AB is the controller for that material, uses it solely to test wake phrase detection, stores it encrypted in Sweden and deletes it within 90 days. A tester can withdraw at any time by deleting the app's data folder and asking us to delete anything already sent, and adding voice identification or any other biometric processing to the live service would be a material change that we would make only after establishing a fresh legal basis and updating this policy.

12. Discord announcements

bot-able offers an optional Discord integration that can post announcements (for example when you go live, when a clip is made, or a stream summary) to a Discord server you choose, using AI to write a short line of text for each post.

Announcements about your own stream. These use your own stream information (title, game, viewer count, and for a stream-summary announcement, a general description of the session, such as what was played and the overall mood) and are processed the same way as our other AI features, described in Section 4. A stream-summary announcement is written by a separate process from the ordinary, internal version of that summary (Section 2): it is instructed not to name a viewer or repeat a personal detail a viewer shared, and its output is automatically checked against the usernames of people who spoke in your chat before it is posted; if that check finds a name, we post a plain line naming only you instead. Something shared in your chat is not the same as consenting to have it posted to a Discord server, so we keep the two summaries separate on purpose. This check looks for names; it cannot detect every way a personal detail could be described without naming anyone, so we ask the model not to include those details at all rather than relying on the check alone.

Announcements about streamers you choose to watch. If you turn on the option to also announce when another Twitch streamer goes live (for example a friend or a co-streamer), we store that streamer's Twitch user ID, username, display name and avatar so you can pick them from your dashboard, and we check their public Twitch status roughly once a minute for as long as you keep the watch active, so we can tell when they go live. While they are live, that check also reads their stream title, game, viewer count, how long they have been live, and a preview image of their stream, to build and keep the announcement up to date, including generating a short line about it using our AI subprocessor described in Section 6. This information is already public on Twitch, published by that streamer as part of broadcasting their own stream, and we are not able to obtain their consent before this processing happens; they are not a bot-able customer and may not know bot-able exists.

As with your community data (Section 3), you, the Streamer, are the data controller for this decision: you choose who to watch and can remove a watch at any time from your dashboard, which stops any further processing of that person's data for this purpose. Codetiles AB acts as your processor. If a watched streamer objects to appearing in your announcements, they, or you on their behalf, can contact us at support@codetiles.com and we will remove the watch and confirm to whoever contacted us that we have done so.

Pinging a Discord server. If you choose to have a go-live announcement notify the whole connected Discord server rather than a specific role, that only changes who is notified about content already described above; it does not involve any additional personal data.

This feature is entirely optional and off by default. You can disconnect Discord at any time from your dashboard, which stops all announcements and removes the stored webhook credential.

13. Giveaways

bot-able offers an optional giveaway feature that lets you run prize giveaways in your Twitch chat. Viewers enter by typing a command you choose, and the bot may award extra entries for gifted subscriptions, bits, or a channel point reward you select.

  • Entrant and ticket data: when a viewer enters a giveaway, we store their Twitch user ID, username and display name, together with a record of the events (such as a gifted sub, a cheer, or a channel point redemption) that earned them extra tickets. Typing the entry command is what activates any tickets a viewer has earned; cheering or gifting on its own does not enter someone into a giveaway.
  • Winner records: when you draw a giveaway, we store the winner's Twitch identity, which place they won, when the draw happened, and a record of any reroll, as your history of that giveaway.
  • Prizes: bot-able does not collect shipping addresses or any other prize-fulfillment details. You contact winners and arrange delivery of prizes directly, outside the Service.

As with your other community data (Section 3), you are the data controller for this information and Codetiles AB acts as your processor. How long each part is kept is set out in Section 7.

14. Location sharing

bot-able offers an optional location feature for IRL streams. When you switch it on, the bot can mention roughly where you are, and you can use a {location} variable in your own commands and timers. This section is about your own location: you are the only person whose position is involved, so unlike most of this policy you are the data subject here, not your viewers.

It is off until you turn it on, in two separate places. There is an account-level switch on the Chat Monitor page in your dashboard, and a per-device switch in the monitor itself on the phone that would be sharing. Both must be on. Turning either one off stops the sharing within seconds: your device stops reporting, and we discard what we were holding rather than waiting for it to expire.

  • What your device sends us: while the monitor is open and both switches are on, your browser sends us its position (a latitude and longitude, and how accurate your device believes that is), at most once every 15 seconds. We ask your browser for a low-accuracy position rather than a precise one.
  • What we turn it into: we ask a mapping service for the name of the surrounding area at town-and-above level, such as "Karlshamn". We only ever read town, city, village, municipality, county, state and country from the answer. We never read, store or pass on a street, a house number, a neighbourhood or a full address, and no part of bot-able beyond that step ever receives your coordinates.
  • We do not store your position: there is no database table of your positions and no history. Your most recent position and the area name derived from it are held in memory on our server only, are replaced by the next one, and are gone when you stop sharing, when they are more than 10 minutes old, or when our server restarts. The only location-related things written to our database are your on/off setting and the list of area names you have chosen to hide.
  • Where the area name is seen: the area name is sent to the bot, which can use it in the chat messages it writes and as context when it writes a reply. If you put the {location} variable in one of your own commands or timers, the area name is shown to everyone in your chat. That is your choice to make, and it is worth making deliberately: a town name published to a live audience is public from then on.
  • Hidden areas: you can list area names the bot must never mention, for example your home town. A hidden area is refused twice, in two independent places in our code: once when we work out where you are, and again when anything asks to publish it.
  • Nothing out of date is presented as current: if we have not had a position from you in the last 10 minutes, the answer becomes "unknown" rather than the last place we knew about. A phone that runs out of battery does not leave you appearing to be somewhere you left.

The mapping service: to turn a position into an area name we use Nominatim, run by the OpenStreetMap Foundation. Your coordinates are sent to them for that lookup. Nothing identifying you is sent with them: no name, no account, no Twitch channel, no email address, only the position and our application's name. This is the one point at which a position leaves our own infrastructure, which is why we are spelling it out. Nominatim is a free service shared by the public, provided under the OpenStreetMap Foundation's own terms and privacy policy, and we do not have an individually negotiated data processing agreement with them. We intend to run our own copy of this service as the feature grows, which would remove that step entirely.

Legal basis: your explicit consent, GDPR Art. 6(1)(a). The two switches are how you give it, and turning either one off is how you withdraw it, at any time and with immediate effect. Withdrawing does not affect anything that happened while it was on, and nothing about the rest of bot-able depends on it.

Please keep in mind that sharing where you are while other people are with you may say something about where they are too. Your responsibility for the people around you on an IRL stream is set out in Section 6 of our Terms of Service.

15. Children

bot-able is intended for use by Twitch streamers and, in line with Twitch's own terms, is not intended for individuals under 13 years of age. We do not knowingly collect account data from anyone under 13.

16. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in our infrastructure, subprocessors, or features. We will post the updated version here with a new "last updated" date, and where changes are material, we will make reasonable efforts to notify you directly (such as by email).

17. Contact

Codetiles AB (org. no. 559586-2250), Sweden
Email: support@codetiles.com