Legal

Privacy Policy

Last updated September 17, 2026

This Privacy Policy explains how Chatmons (“Chatmons,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal information when you use chatmons.com, api.chatmons.com, the streamer panel, Play, the stream overlay, and related services (together, the “Service”). It is written to meet the disclosure duties that apply to a live overlay product that uses Twitch and Kick OAuth, stores gameplay accounts, and processes payments through Stripe — including Twitch’s Developer Services Agreement, Kick’s developer terms, Stripe’s Privacy Policy, and privacy laws such as the GDPR, UK GDPR, CCPA/CPRA, and similar Latin American rules (including ARCO-style access rights).

Who we are

Chatmons is the overlay and companion game at https://chatmons.com. The Service lets chat appear as playable avatars on a livestream, lets viewers play from a phone or browser, and lets streamers run the overlay, stage tools, and (if they opt in) receive payouts from paid Boosts.

The registered legal name, entity type, and mailing address of the operator are available on request at legal@chatmons.com until they are published in this policy. Governing law for business users is described in the Terms.

For privacy questions, access, correction, deletion, or a complaint, email privacy@chatmons.com. For contract or terms questions, email legal@chatmons.com. General product mail: hello@chatmons.com. These inboxes are monitored. We will need enough information to verify that you are the account holder (usually your Twitch or Kick username and the platform you signed in with).

Who this policy covers

This policy applies to anyone who visits the website, signs in, joins a channel in Play, appears on a stream overlay, uses the streamer panel, or connects payouts.

It does not control how Twitch, Kick, Stripe, streaming software, or a streamer’s own channel handle your data. Those services have their own terms and privacy notices. If you watch a stream on Twitch or Kick, that platform — not Chatmons — is the primary controller of your viewing session there.

Information we collect

We collect only what we need to run the Service. We do not buy marketing lists. We do not run advertising pixels or third-party analytics on the Chatmons website.

Account and login (Twitch and Kick)

You create a Chatmons account by signing in with Twitch or Kick. We receive identifiers the platform shares after you approve OAuth, typically: user id, login / slug, display name, profile image URL, platform, and the OAuth scopes you granted. We store access and refresh tokens so the Service can stay connected (for example so a streamer bot can send chat, or so a viewer can post from Play). Those tokens are encrypted at rest with AES-256-GCM when the Service is running in live mode.

Twitch login currently requests `user:read:email` (and, for streamers and moderators, additional chat, channel, and moderation scopes). Kick login currently requests `user:read` for viewers and additional channel, chat, event, and moderation scopes for streamers. Kick may return an email address on the user object. We request the Twitch email scope as part of identity verification; we do not persist a dedicated email field on viewer or streamer profiles, and we do not use email for newsletters, ads, or sale to third parties. If an email is received during OAuth, it may pass through the login flow in memory. Stripe separately collects whatever contact details it needs for payments and payouts.

  • Viewers: identity plus permission to write chat from Play (`user:write:chat` on Twitch; `chat:write` on Kick).
  • Streamers: channel identity, chat read/write, bot/channel bot permissions on Twitch, follower/chatter/subscription reads used for audience features, and the moderation scopes needed to run Chatmons tools from the panel.
  • Moderators: scopes needed to confirm they moderate the channel and to take platform actions the streamer has allowed (timeout, ban, delete message, and related tools). Moderators never receive the streamer’s OAuth tokens.
  • App bot (Twitch): a Chatmons-owned bot account may be connected by an app owner so the bot can write chat as ChatmonsBot. That is an internal operator account, not a viewer profile.

Gameplay, house, and inventory

When you play, we store a passport-style game account keyed to your platform user id: username, level, XP, coins, owned and equipped styles and cosmetics, equipped pet, streaks, achievements, house layout and owned furniture, pets (including the name you give them), fish journal and inventory, and per-channel stars / badges / boss stats. This is the data that lets your Chatmon, house, and progress persist after a stream ends.

Channel, overlay, and moderation

For connected channels we store overlay and gameplay settings (command language, welcome messages, whether fishing or jump events are on, directory visibility, and similar switches), custom chat commands and automations the streamer writes, overlay token epochs (so a leaked overlay URL can be rotated), which moderators may use Chatmons tools, Chatmons-only sanctions (for example a stage timeout that does not necessarily equal a Twitch ban), and a moderation audit log (who did what, when, on which channel).

We also store overlay-usage metrics (time the overlay has been connected, session counts) so the live directory can rank channels by Chatmons use — not by Twitch/Kick viewer count. Directory visibility defaults on when a streamer connects; they can turn it off in the panel.

Chat and overlay presence

Chatmons is designed so chat is visible on stream. Display names, avatars, equipped cosmetics, pets, speech bubbles, emotes, and gameplay actions are shown on the overlay and may be captured on VODs, clips, and screenshots that we do not control.

We process chat messages in real time to spawn avatars, show bubbles, grant coins/XP, and run commands. We do not operate a public, permanent Chatmons chat archive of every message. Short-lived copies exist in the live room so the overlay and Play can stay in sync, and fragments may appear in operational logs if needed to debug abuse or outages. Custom command text the streamer saves is stored until they delete it or disconnect.

Payments

If you buy Boosts (Spotlight, Super Kick, UFO, Clear the Stage, and similar overlay moments) or USD shop items (styles, cosmetics, furniture), Stripe processes the card or wallet. Chatmons stores order records: payment intent / checkout ids, channel, buyer user id, SKU, amounts, streamer vs platform shares for Boosts, status, and timestamps. We do not store full card numbers, CVC, or bank account numbers. Those stay with Stripe.

If a streamer connects payouts, we store a Stripe Connect account id and status flags (payouts enabled, charges enabled, onboarding complete, disabled reason, country). Identity documents, tax IDs, and bank details are collected by Stripe during Express onboarding, not by Chatmons forms.

Technical and security data

Our servers see IP addresses (including `X-Forwarded-For` behind our reverse proxy) to apply rate limits, stop abuse, and keep the Service up. We may log request paths, channel ids, user ids, error traces, and coarse user-agent data. Optional server error reporting (Sentry) may be enabled by operators; it is configured not to dump secrets. The website itself does not load advertising pixels or third-party product-analytics SDKs (no Google Analytics, Meta Pixel, or similar).

In your browser we use localStorage and sessionStorage (not advertising cookies) for session tokens, overlay/play preferences, language, and similar UI state. See “Cookies and local storage” below.

First-party product analytics

We record first-party events on our own servers (for example overlay sessions, Play joins, shop and Boost checkouts, and similar product actions). Event rows can include a user id and channel id. We keep those event-level rows for about 180 days, then drop them. Aggregated daily totals (for example overlay hours used to rank the live directory) may be kept longer. This is not advertising measurement and is not sent to a third-party analytics SDK.

Information we do not try to collect

  • Precise GPS location.
  • Government ID photos (except whatever Stripe collects for payouts, under Stripe’s control).
  • Health, biometric templates, or special-category data as a product feature.
  • Payment card PAN/CVC on Chatmons servers.

How we use information

We use personal information to:

  • Create and authenticate your account, keep you signed in, and honor the OAuth permissions you granted.
  • Run the overlay, Play, house, pets, fishing, boss/heist, shop, leaderboards, and live directory.
  • Show you — and the stream audience — your Chatmon, bubbles, and paid Boosts.
  • Let streamers configure the channel, rotate overlay tokens, and (if they choose) run moderation tools.
  • Process USD purchases, fulfill or auto-refund failed overlay actions, split Boost revenue, and enable streamer payouts.
  • Apply rate limits, detect bots, cheating, fraud, chargebacks, and terms violations.
  • Record first-party product analytics (about 180 days at event level) so we can operate, debug, and improve the Service.
  • Provide support, fix outages, and improve reliability and security.
  • Comply with law, platform rules, and valid legal process.
  • Communicate about the account or a transaction (not marketing lists).

Legal bases (EEA, UK, and similar)

Where GDPR / UK GDPR applies, we rely on:

  • Contract: creating the account, running the game, showing you on the overlay you joined, fulfilling a purchase.
  • Legitimate interests: keeping the Service secure, preventing economy abuse, operating a public live directory the streamer can switch off, debugging, and understanding coarse usage of overlay connections. You may object where the law allows.
  • Consent: OAuth permissions you grant on Twitch or Kick; Stripe checkout you start; optional payouts onboarding. You can revoke platform access in your Twitch or Kick settings; we will stop using new tokens once they are invalidated, and you can ask us to delete the Chatmons account.
  • Legal obligation: tax, accounting, fraud, and responding to lawful requests.
  • Stripe as an independent controller / processor: card data and Connect identity checks are processed by Stripe as described in the Stripe Privacy Policy and Stripe’s Data Processing Addendum. When you provide personal data in connection with payouts or checkout, Stripe receives that personal data and processes it in accordance with Stripe’s Privacy Policy.

When we share information

We do not sell personal information. We do not share it for cross-context behavioral advertising. We disclose it only as follows:

  • The stream and other players. Overlay presence, usernames, avatars, cosmetics, pets, speech bubbles, Boosts, and public leaderboard rows are visible to the streamer, mods, other players in that room, and anyone watching the livestream or a recording of it.
  • Twitch and Kick. We call their APIs with the tokens you authorized (chat, moderation, live status, identity). Their use of data is governed by Twitch’s Privacy Notice and Kick’s privacy terms.
  • Stripe. Checkout, Payment Element, webhooks, refunds, Connect Express accounts, and payouts. See stripe.com/privacy and Stripe’s Connected Account Agreement.
  • Infrastructure. Railway hosts the website and API (chatmons.com and api.chatmons.com). Postgres (and optionally Redis) store account, gameplay, and session data. Optional Sentry receives error traces. Webfonts are served from our own domain. These vendors process data on our instructions and are not permitted to use it for their own advertising.
  • Discord. We operate an optional community Discord server. Discord’s own privacy policy applies there. If a streamer sends panel feedback, the Chatmons team sees it in the product; if a private Discord webhook is configured for operators, a copy of that note (display name, login, channel, message) may also be posted there for the team — not to public chat.
  • Legal and safety. If required by law, to protect rights and safety, or in a merger or asset transfer (the new operator must honor this policy or notify you).
  • With your direction. For example a streamer leaving live-directory visibility on (the default) or turning it off in the panel, or a viewer sending a chat message knowing it will appear on stream.

Stripe, Boosts, and streamer payouts

Boosts are paid overlay actions. Of the listed USD price, 70% is credited to the connected streamer in full — Chatmons does not deduct a hidden fee from that share. The remaining 30% is Chatmons’ platform fee, used to operate servers, run the overlay, and keep the Service available. Chatmons is the merchant of record for the checkout you see in Play. Stripe processes the charge. We record the order so we can fulfill the action on the overlay and show the streamer an earnings summary (including public supporter identity: username and avatar, not your card).

USD shop items (styles, cosmetics, furniture) are sold by Chatmons. They are not split with the channel unless we clearly say so at checkout.

Streamers who turn on payouts create a Stripe Express connected account. Stripe collects identity and payout details. Chatmons stores the Connect account id and whether payouts are enabled. Payouts are currently scheduled weekly (Monday) with a minimum of USD $20 once Stripe has enabled payouts. Connecting a channel to Chatmons is free; payouts are optional.

We may see Connect status (country, whether charges/payouts are enabled, a disabled reason). We do not get to download your bank password or full government ID from Stripe. Connected Account Data is used only to provide payouts and related support, fraud prevention, and legal compliance — not for unrelated marketing.

Canadian streamers: our payment processor can obtain information from credit agencies to verify your identity. That information will be used for the purposes described in Stripe’s Privacy Policy.

What is public by design

Please treat the overlay as a stage. If you would not say it on stream, do not send it through Chatmons.

The landing live directory lists streamers who have Chatmons connected, are live, and have not turned directory visibility off in the panel. Visibility defaults on when you connect; you can switch it off anytime. Cards use public channel info (name, avatar, game, language, viewer counts from the platform, and Chatmons usage rank). Directory cards never include overlay tokens, emails, or session secrets.

Fishing and similar leaderboards show usernames and scores. Streamer earnings views show supporter usernames and avatars for Boosts on that channel.

Cookies, local storage, and similar tech

Chatmons does not set advertising cookies and does not use third-party analytics cookies on the website. We do not currently show a cookie-consent banner because Chatmons itself does not set non-essential HTTP cookies; that does not waive any ePrivacy/cookie rules that a lawyer may later require for third-party embeds.

We use browser localStorage / sessionStorage to keep you signed in (HMAC session or streamer tokens), remember language (EN/ES), overlay scale and floor prefs, Play UI prefs, and similar settings. These are first-party, functional stores. They are not HTTP cookies in the classic “tracker” sense. Clearing site data signs you out.

Third parties may set their own cookies when their surfaces load: Stripe (Payment Element and Connect onboarding), and Twitch and Kick (OAuth and embedded players). Those cookies are governed by those providers.

If a future version adds non-essential cookies, we will update this policy and, where required, ask for consent. Twitch requires developer cookies that we *do* set to be Secure, HttpOnly, and SameSite where they are HTTP cookies, and persistent cookies to expire within 13 months. Our current session model prefers short-lived signed tokens in localStorage rather than long-lived tracking cookies.

How long we keep data

We keep account and gameplay data for as long as the account exists, because that is the product (your house, coins, and cosmetics would otherwise vanish).

OAuth tokens are kept until you disconnect, they are revoked by the platform, or we rotate/delete them after inactivity or a security event. Log out / disconnect in Play or the panel revokes Chatmons OAuth tokens for that session or channel. It does not wipe your passport, house, pets, fish, cosmetics, or purchase history.

First-party analytics event rows are kept about 180 days. Daily overlay-usage totals used for directory ranking may be kept longer.

Payment and payout records are kept as long as needed for fulfillment, refunds, chargebacks, accounting, and tax (often several years under bookkeeping rules).

Moderation audit rows and sanctions are kept to protect channels and to investigate abuse.

Live room state is ephemeral. Operational logs are rotated.

There is no in-app “delete everything” button. To request deletion, email privacy@chatmons.com from a reachable account and include your Twitch or Kick username. After we verify you, we delete or irreversibly anonymize gameplay we control (passport/progress, house, pets, fish, cosmetics, stored OAuth tokens, and first-party analytics events tied to you). We retain payment, payout, and dispute records as required. Content already broadcast on Twitch/Kick (VODs, clips) cannot be un-broadcast by us.

Security

No online service is perfectly secure. We apply industry-standard controls matched to the risk of an overlay game with OAuth and payments:

  • TLS in production (https://chatmons.com and https://api.chatmons.com).
  • HMAC-signed session tokens with expiry; overlay tokens are a separate, limited kind that cannot unlock shop, DevTools, or streamer admin.
  • Kind-bound privileges (a viewer session cannot mint itself as a streamer).
  • OAuth tokens encrypted at rest (AES-256-GCM) in live/production.
  • Production refuses mock auth and weak session secrets.
  • Server-authoritative economy (clients cannot mint coins).
  • Rate limiting by user and IP; webhook signature checks (Kick RSA; Stripe webhooks; Twitch EventSub over authenticated sockets).
  • Content-Security-Policy, locked-down cosmetics paths, and owner allowlists for dangerous admin tools.
  • Overlay URLs contain a secret token. Treat them like a stream key. Rotate them in the panel if they leak.

If you believe you found a vulnerability, email privacy@chatmons.com with details. Do not exploit it against other users.

Children

Chatmons is not directed at children under 13, and we do not knowingly collect personal information from children under 13 (or under the digital-consent age in your country, if higher). Twitch, Kick, and Stripe also restrict under-13 use.

By signing in you confirm you are at least 13 (or the higher digital-consent age where you live) and allowed to use Twitch or Kick. Kick, for example, may require 16+ in some regions. We do not collect a separate parental-consent form. Streamer payouts and Stripe connected accounts require you to be old enough to form a binding contract and to pass Stripe’s identity checks — typically 18+.

If you are a parent and believe a child under 13 created an account, email privacy@chatmons.com. We will delete the Chatmons account data we control.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data; to object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority (for example an EEA DPA, the UK ICO, or your local data-protection body in LatAm).

In Mexico and several other Latin American countries this includes ARCO-style rights (access, rectification, cancellation, opposition). In California and other US states you may have rights to know, delete, correct, and opt out of “sale” or “sharing.” We do not sell or share personal information as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes that require a separate CPRA limit-use right, beyond providing the Service.

To exercise rights, email privacy@chatmons.com. We will verify the request (we may ask you to sign in with the same Twitch/Kick account). We will not discriminate against you for exercising privacy rights.

You can also: disconnect Chatmons in your Twitch or Kick connection settings; turn off live-directory visibility as a streamer; rotate the overlay token; log out and clear site data; and manage cards in your Stripe receipts / Express dashboard.

International transfers

We operate a global Service. Servers, backups, Twitch, Kick, and Stripe may process data in the United States and other countries that do not have the same laws as your home. Where required, we rely on appropriate safeguards (including the contractual terms our processors offer, such as Stripe’s DPA and Standard Contractual Clauses) and on the fact that you are interacting with a livestreaming product that is inherently cross-border.

Changes to this policy

We may update this policy when the product, vendors, or the law change. The “Last updated” date at the top will change. For material changes we will take reasonable steps to notify you (for example a notice on the website or in the panel). Continued use after the effective date means you acknowledge the updated policy. If we need new consent under applicable law, we will ask for it.

Contact

Privacy and data-rights requests: privacy@chatmons.com.

Terms and legal notices: legal@chatmons.com.

Service: https://chatmons.com · API: https://api.chatmons.com.

Related documents: Terms of Service. Third-party notices: Twitch Privacy Notice, Kick Privacy Policy, Stripe Privacy Policy.