Effective September 9, 2026 · Last updated
Stream Slop (“we,” “us,” or “our”) is based in Massachusetts, United States. This policy describes how we handle personal information when you use streamslop.io, its games, and related account features. For privacy questions or requests, email admin@streamslop.io.
1. Information we collect
- Account information. When you sign in, we receive a provider account identifier, display name, profile image URL, and, when available, a channel login and email address. We store an internal player identifier, the sign-in method, and first and last activity timestamps. Guest play uses a guest identifier and session credentials.
- Gameplay and store records. We process lobby membership, roles, unit actions, match results, ratings, statistics, and battle history. We retain virtual credit balances, pack transactions, receipts, and streamer support allocations. The current store uses mock credits and does not collect payment card information.
- Communications. We process in-game chat and, if you enable it, microphone audio for live voice chat. If you email us, we receive your email address, message, and any information or attachments you choose to provide.
- Technical information. Requests and connections provide information such as your IP address, browser or device details, request times, and connection or error diagnostics. We and our hosting providers process this information to deliver the Service, troubleshoot failures, and prevent abuse.
- Browser storage. We use cookies and browser storage for sign-in, guest and match recovery, and preferences, as described below.
2. Twitch, Kick, and Google sign-in
Sign-in happens with your chosen provider. We do not receive your provider password. We use the information it returns to identify you, maintain your account and game records, and display your profile. Your provider display name and avatar may be public in the game and on leaderboards; a Google profile name may be your real name. Email addresses are not displayed in public profiles or match views.
Twitch sign-in requests basic account information and email access. Kick sign-in requests user profile access. Twitch stream-title verification reads public channel and live-stream information to verify control of a channel.
The option labeled “YouTube” uses Google sign-in with basic profile and email permissions (openid email profile). We receive your Google account identifier, name, profile picture URL, and verified email when provided. We do not request access to your YouTube channel, videos, subscriptions, contacts, or Gmail. You do not need a YouTube channel.
Provider access tokens are used during server-side sign-in and are not saved as account records or sent to your browser. We do not retain provider refresh tokens or request Google offline access. Signing in creates a separate Stream Slop session.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable. We do not use Google account information for advertising or to train generalized AI models.
3. How we use information
We use information to authenticate players; maintain accounts and sessions; run lobbies, matches, chat, and voice; restore connections; display profiles and rankings; maintain virtual credit records; answer requests; diagnose problems; prevent cheating and abuse; and comply with legal obligations.
Where a legal basis is required, we process information to provide the Service you request, for our legitimate interests in keeping it reliable and safe, to meet legal obligations, or with your consent when required. Optional microphone use requires your browser permission. You can withdraw that permission in your browser settings.
4. Public gameplay, chat, and voice
This is a multiplayer game designed for live streaming. Other players, spectators, and stream audiences may see your display name, avatar, channel, lobby participation, gameplay, chat, and public match records. Leaderboards and commander profiles are publicly accessible. Your account email and private wallet details are not part of those public views.
When you enable your microphone and use voice chat, your audio is transmitted to the listeners allowed by the game’s voice rules. The Service does not make or store voice recordings or transcripts. Audio and connection information may pass through voice infrastructure providers; direct peer connections may also expose network information, including your IP address, to connected peers.
Streamers and other participants may broadcast or record what they see and hear. Those recordings are controlled by their creators and the platforms hosting them. Avoid sharing sensitive information in gameplay, chat, or voice. Disabling your microphone stops future microphone sharing; it cannot remove a recording someone already made.
5. Cookies and browser storage
We use the following first-party storage to make the Service work:
- Account session (
ss_session). Keeps you signed in for up to 30 days after provider sign-in, or 12 hours after Twitch title verification. - Sign-in verification (
ss_oauth_stateandss_claim). Protects provider sign-in and stream-title verification, with a lifetime of up to 10 minutes. - Guest and seat recovery (
ss_guestandss_seat). Helps recover access to a guest or streamer seat, with a lifetime of up to 12 hours. A recovery cookie may be renewed when you reconnect or use a seat. - Session storage. Keeps match and reconnection credentials in the current browser tab. Your browser normally clears it when that tab’s session ends.
- Local storage. Remembers preferences such as audio levels, nameplates, and the embedded stream mode until you change them or clear your browser’s site data.
You can block or delete cookies and site storage through your browser. Doing so may sign you out, reset preferences, or prevent reconnection to a match. Clearing browser data does not delete account or match records on our servers.
We do not use first-party advertising cookies or cross-site behavioral tracking. The Service does not change its essential storage behavior in response to a browser’s Do Not Track signal. External content, such as an enabled Twitch player or a provider-hosted avatar, makes requests to that provider. Providers may receive your IP address and browser details and use their own cookies or collect activity across services under their own policies. Turning the embedded stream off stops loading that player.
6. When information is shared
We do not sell personal information or share it with advertisers for cross-context behavioral advertising. We disclose information in the following circumstances:
- To deliver gameplay. Other users receive the profile, match, chat, and voice information needed for the features you use, as described above.
- Service providers. Hosting, storage, network security, voice, and email providers process information needed to run the Service or respond to you. Stream Slop uses Cloudflare for hosting, application data, asset delivery, and network services. Voice may use Cloudflare Realtime, LiveKit-based infrastructure, or direct browser connections.
- Your chosen integrations. Sign-in providers process authorization requests, and embedded streaming providers receive information when their content loads.
- Legal and safety needs. We may disclose information when required by law, to respond to valid legal process, or when reasonably necessary to protect people, enforce our terms, or investigate fraud or security incidents.
- A change of operator. If the Service is transferred or acquired, relevant information may be transferred as part of that transaction, subject to applicable law and notice of material changes.
External providers explain their own practices in the Twitch Privacy Notice, Kick Privacy Policy, Google Privacy Policy, and Cloudflare Privacy Policy.
7. Storage, retention, and security
Account profiles, match history, rankings, and virtual credit records persist between visits. Signing out or revoking provider access does not automatically erase those records. We retain them as needed to maintain your account and game history, resolve requests or disputes, prevent abuse, and meet legal obligations. Retention depends on the type of information and why it is needed; cookie expiry is not the retention period for server records.
You can request deletion using the contact details below. Information no longer needed for those purposes is deleted or de-identified. Limited records may need to be retained for legal, security, or dispute-resolution reasons, and copies may remain in backups until those backups are replaced. We will explain any applicable limits when responding to your request.
We use safeguards such as encrypted connections, protected server-side credentials, and access controls designed to protect information. No internet service can guarantee absolute security. The Service is operated from the United States, and infrastructure providers may process data in other countries. Where applicable law requires safeguards for international transfers, we will use those safeguards.
8. Your choices and privacy requests
You can review your account details and battle history on the account page. Update provider-controlled details with that provider and sign in again to refresh the information we receive. You can sign out, clear site storage, disable voice, and turn off the embedded stream.
To request access to, a copy of, correction of, or deletion of your information, email admin@streamslop.io. Tell us which provider and display name you used and what you would like us to do. We may ask for reasonable information to verify that the account is yours. Do not send your password, provider tokens, or private match credentials.
You can remove the Google connection in your Google Account connections settings, or revoke other providers’ access in their connected-app settings. Revoking provider access prevents future authorized access through that connection; it does not itself delete your Stream Slop data or end an existing Stream Slop session. Sign out here and contact us if you also want stored records deleted.
Depending on where you live and which laws apply, you may also have rights to portability, restriction, objection, withdrawal of consent, or an appeal of a privacy decision. We respond within the time required by applicable law and do not discriminate against you for exercising applicable privacy rights. You may contact your local privacy regulator about a concern. Withdrawal of consent does not affect processing that was lawful before withdrawal.
9. Children’s privacy
The Service is not intended for children under 13, or under a higher minimum age where required by local law. We do not knowingly collect personal information from children under that age. If you believe a child has provided personal information, contact admin@streamslop.io so we can investigate and delete it as appropriate. The age and parental-permission rules are also described in our Terms of Service.
10. Changes to this policy
We will post updates here and change the date above. For material changes to how we handle personal information, we will provide a prominent notice through the Service and seek consent where required before using information in a new way. This policy describes the current Service; new features may require additional disclosures.
11. Contact
For privacy questions, requests, or complaints, contact Stream Slop at admin@streamslop.io. We are based in Massachusetts, United States.