Privacy Policy
What data WES Alert collects, why, where it lives, and what your rights are. No ads, no tracking, no selling: the data listed here exists to run your alerts, nothing else.
This policy explains what data WES Alert collects, why, and what your rights are. WES Alert is operated on a non-professional basis by an individual publisher ("we"), as permitted under French law; the publisher's identity is held by the hosting providers listed in the Legal Notice. You can reach us at [email protected].
1. What we collect
Account data (from Twitch). When you sign in with Twitch, we receive and store your Twitch user ID, your Twitch username, and the email address attached to your Twitch account. We never see your Twitch password.
Twitch authorization tokens. To subscribe to your channel events (follows, subscriptions, gifts, bits, raids), we store the OAuth tokens Twitch issues for your account. They are encrypted at rest (AES-256-GCM).
Channel events. While the service is active on your channel, we receive events from Twitch (new follower, subscription, gift, bits, raid) and store them to display your alerts, group them, and compute on-stream achievements. These events can include the username of the viewer who triggered them and the amount involved (bits, gifted subs, raid size).
Your settings. Selected alert pack, volumes, colors, positions, and other configuration you set in the dashboard.
Session data. A session cookie
(loom_token) keeps you signed in to the
dashboard. We keep a record of active sessions so you can
revoke them.
Technical logs. Like every web service, our infrastructure logs requests (IP address, timestamps, requested URLs) for security and debugging. Error monitoring may capture technical context when something breaks.
Bug reports. If you report a bug through our Discord bot, we store the content of your report and your Discord username, in order to fix the issue and follow up with you.
What we do NOT collect: payment data (the service is currently free; this policy will be updated before any paid plan launches), your stream content, your chat messages, or anything from your Twitch account beyond the scopes shown on the Twitch consent screen.
2. Why we collect it
- Account data, tokens · sign you in, subscribe to your channel events · legal basis: performance of the service you signed up for (GDPR art. 6.1.b).
- Channel events · display and orchestrate your alerts · performance of the service (art. 6.1.b).
- Settings · make the service work the way you configured it · performance of the service (art. 6.1.b).
- Session data, technical logs · security, abuse prevention, debugging · legitimate interest (art. 6.1.f).
- Bug reports · fix issues, follow up · legitimate interest (art. 6.1.f).
We do not sell your data. We do not use it for advertising. We do not profile you.
3. About your viewers
Channel events contain your viewers' Twitch usernames and amounts (a gift, a raid size). We process this data solely to render your alerts and on-stream achievements, and we store it as part of your channel's event history. Viewers who want their data removed from our systems can contact us at [email protected]; streamers relay requests the same way.
4. Where your data lives
Your data is processed by the following providers (our "sub-processors"):
- Supabase · database (accounts, events, settings)
- Railway · application hosting
- Cloudflare · CDN, asset storage, site hosting
- Twitch (Amazon) · identity provider and event source · per Twitch's own policy
- Discord · bug reports and community support · per Discord's own policy
- Sentry · error monitoring
Some of these providers are US companies or process data in the United States; where that is the case, transfers outside the European Union are covered by the safeguards they provide under the GDPR (standard contractual clauses or EU-US Data Privacy Framework certification).
5. How long we keep it
- Account data and tokens: as long as your account exists, then deleted within 30 days after account deletion.
- Channel events: kept for 12 months, then deleted.
- Technical logs: kept for 90 days.
- Bug reports: as long as needed to resolve the issue.
To delete your account and all associated data, email [email protected] from the email address attached to your Twitch account. We will confirm deletion within 30 days.
6. Cookies
We use a single cookie, loom_token, which keeps
you signed in. It is strictly necessary for the service,
HttpOnly and Secure. We use no advertising or analytics
cookies, which is why you do not see a cookie banner.
7. Security
Twitch tokens are encrypted at rest (AES-256-GCM). All traffic is HTTPS. Sessions can be revoked from the dashboard. Webhook payloads from Twitch are cryptographically verified before processing. More on the practical side in the Security guide.
8. Your rights
Under the GDPR you can ask us for access, rectification, erasure, portability of your data, or object to processing based on legitimate interest. Write to [email protected]. If you believe we mishandled your data, you can lodge a complaint with the CNIL (cnil.fr), the French supervisory authority.
9. Changes
If this policy changes in a way that matters, we will notify you in the dashboard or by email before the change takes effect.