← NONSTOPVOD

Privacy Policy

1. Controller

The controller responsible for the processing of personal data on this service (the “Service”) within the meaning of the General Data Protection Regulation (GDPR) is the operator of the Service. Contact details are provided in the Legal Notice (Impressum).

2. Overview

NONSTOPVOD archives a streamer's own Twitch VODs, plays them back on this site, and republishes them to a second Twitch channel the same streamer controls. This policy explains what personal data we process when you visit the site or hold an account, the purposes and legal bases of that processing, how long we keep it, and the rights available to you.

Two things are worth stating up front, because they shape everything below. We do not run advertising, and we do not use any analytics, tracking or profiling of any kind: there is no third-party script on this site, no advertising network, no cross-site tracking and no visitor measurement. And the video we store is content our own customers recorded on their own Twitch channels; a channel can only be archived once the person holding the account has proven they control it by signing in to Twitch with it.

3. Data We Process

3.1 Server log and connection data

When you access the Service, our servers process the technical connection data required to deliver it and keep it secure: the IP address of the requesting device, the date and time of the request, the requested resource, the HTTP status code and amount of data transferred, and information about your browser and operating system (user agent).

3.2 Account data

If you register, we process your email address, its verification status, and a securely hashed password. We never store your password itself. If you sign in with Twitch instead, we process the Twitch account id, login and display name that Twitch returns.

We record the time at which you accepted the Terms of Service and the version accepted, so that acceptance can be evidenced.

3.3 Session data

Signing in creates a session. The token your browser holds is never stored by us: what we keep is a SHA-256 hash of it, together with the time it was issued and expires. Sessions last 30 days unless you sign out, which revokes them immediately.

3.4 Workspace and team data

An account belongs to one or more workspaces. If you invite someone to a workspace we process the email address you invite, the role you assign, and the state of that invitation.

3.5 Channel and Twitch integration data

To archive a channel and to broadcast to your replay channel we process the Twitch account identifiers and the OAuth access and refresh tokens you grant us, together with the stream key of the channel you broadcast to. These are credentials, held only to operate the features you enabled, and are never displayed back to you in full or shared with anyone.

3.6 Archived video and its metadata

For each VOD you choose to archive we store a byte-identical copy of the video segments Twitch published, together with metadata: title, duration, recording date, size, the ranges Twitch muted, chapter and category information, and any title you set yourself. Video is stored on storage operated for us in the EU. It is served only to you and to people you share a playback link with, and it is deleted when you delete it or when your account is deleted.

3.7 Broadcast and queue data

If you run a 24/7 replay channel we record which VODs streamed and when, session start and end times, how many VODs a session streamed, and peak viewer numbers reported by Twitch for your own channel. If you enable the chat bot, we store the commands you configure; chat messages from viewers are processed transiently to answer a command and are not stored.

3.8 Billing data

Payments are handled by Stripe. We never see or store your card details. What we store is the Stripe customer and subscription identifiers, your plan, subscription status and current period end, purchased storage capacity, and a ledger of the billing events Stripe has sent us, so that a webhook is never applied twice. We also take daily samples of how many bytes your workspace stores, which is what capacity is measured against.

3.9 Email delivery data

Transactional email (address verification, password reset, team invitations, billing notices) is sent through our email provider. We keep a queue of messages to be sent and their delivery state, and a suppression list of addresses that have bounced or reported a message as spam, which is checked before every send so that we stop mailing an address that does not want it.

4. Purposes and Legal Bases

5. Cookies and Local Storage

We use strictly necessary storage only. There is no advertising cookie, no analytics cookie and no cross-site tracking, which is why this site does not ask you to accept or reject cookies.

6. Recipients and Hosting

Personal data is processed on servers operated for us by our hosting providers acting as processors under Art. 28 GDPR. We do not sell personal data. The recipients we rely on are:

7. International Transfers

Our own infrastructure is operated within the EU. Where a recipient named above processes data outside the European Economic Area, the transfer is based on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Retention

9. Your Rights

Subject to the conditions of the GDPR, you have the right to:

To exercise these rights, contact us using the details in the Legal Notice. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

10. Obligation to Provide Data

Providing certain data is necessary to use the Service: without connection data we cannot deliver it, and without account data we cannot create or authenticate an account. Connecting a Twitch account is voluntary, but the archiving and replay features cannot work without it.

11. Automated Decision-Making

We do not use automated decision-making that produces legal or similarly significant effects concerning you within the meaning of Art. 22 GDPR. Automated measures such as rate limiting and abuse detection are used solely to keep the Service secure and functioning.

12. Changes to this Policy

We may update this Privacy Policy to reflect changes to the Service or legal requirements. The “last updated” date above indicates the current version.