ALTIKOEarly Access
EN
Sign in

Privacy policy

An English version of this page is provided for convenience. Only the German version is legally binding.

As of 21 September 2026

1. Controller

Nils Dieters
Hradeker Straße 6, 16761 Hennigsdorf, Germany
Email: info@altiko.de

2. What ALTIKO is

ALTIKO is a tool for streamers. It receives events from streaming platforms — new followers, subscriptions or chat messages, for instance — and triggers the reactions defined by the user: alerts and self-designed overlays on stream, chat messages, notices in Discord or counter values.

3. Two groups of data subjects

This policy concerns two different groups of people whose data is treated differently:

  • Users — people who sign in to ALTIKO and connect their channel.
  • Viewers — people who write in the chat of a connected channel or trigger events there. They do not sign in to ALTIKO, but their data passes through the service.

4. Data of users

4.1 Signing in via a platform

Signing in is possible only through an existing account at Twitch, YouTube, Kick or Discord. ALTIKO requires no password of its own and stores none. After signing in, the following are stored:

  • id, login name and display name at the platform
  • address of the profile image
  • access and refresh tokens of the platform
  • the permissions granted

The tokens are stored encrypted (AES-256-GCM). They allow ALTIKO to act in the user’s name within the permissions granted — for instance to write a message in their chat.

Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).

4.2 Content created by users

Rules, alert and overlay settings, channel name, counter values and uploaded sounds are stored for as long as the account exists. For your own files in the overlay editor, section 4.7 applies.

Legal basis: Art. 6(1)(b) GDPR.

4.3 Sign-in session

When signing in, a technically necessary cookie (altiko_sitzung) is set. It contains nothing but a random identifier; the associated data is held on the server and deleted after 30 days without use. The cookie is inaccessible to scripts and is transmitted only over encrypted connections. No consent is required for this (§ 25(2) no. 2 TDDDG). ALTIKO sets no cookies for advertising or analytics purposes.

4.4 Connecting a YouTube channel (Google user data)

If a user voluntarily connects their YouTube channel, they sign in via „Sign in with Google“ and grant ALTIKO the permission https://www.googleapis.com/auth/youtube.force-ssl. Only the following are stored in doing so:

  • Google account id, channel id and channel name
  • address of the channel image
  • access and refresh tokens from Google

What the permission is needed for: it is the only permission that allows the live chat of a running stream to be both read and written to. ALTIKO uses it

  • to determine the running livestream and its live chat id,
  • to receive chat messages, Super Chats and memberships and trigger alerts and rules from them,
  • to write chat messages and the answers of their rules into their own live chat in the user’s name.

A narrower permission is not sufficient for this: youtube.readonly does not allow writing, and there is no separate write permission for the live chat.

The Google tokens are stored encrypted (AES-256-GCM) and used exclusively for the features named above. They are not passed on to third parties, not used for advertising and not used to train artificial intelligence models. Videos, subscriber lists or account data of the Google account are neither retrieved nor stored.

Ending access: the connection can be undone in ALTIKO at any time under Setup → Connections → YouTube → Disconnect; the stored Google tokens are then deleted immediately and revoked at Google. Independently of that, access can be withdrawn at any time at myaccount.google.com/permissions.

Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).

4.5 Connected Discord servers

If a user connects Discord, they invite AltikoBOT into one or more of their own servers. Per server the following are stored: the server id, the server name and the id of the server icon, so that the dashboard can show the server recognisably. Up to three servers are free, further ones are part of Premium.

When Premium ends, surplus servers are deactivated, not deleted: ALTIKO no longer posts there, and the settings are preserved. If Premium is not active again after 12 months, the deactivated entries are deleted. If the user disconnects a server in the dashboard, its entry is removed immediately and the bot leaves the server.

Legal basis: Art. 6(1)(b) GDPR.

4.6 Automatic highlights

If a user with Premium switches on automatic highlights, ALTIKO creates a clip in the user’s channel through Twitch’s interface on a raid, a Hype Train or a sudden burst of chat messages, and posts its address into the chosen Discord channel. The clip itself is held at Twitch and is subject to their terms; ALTIKO stores no copy of it. How a burst of chat messages is detected is described in section 5.3.

Legal basis: Art. 6(1)(b) GDPR.

4.7 Your own files in the overlay editor

In the overlay editor users can upload their own images, GIFs, videos, sounds and fonts, currently up to 2 GB per channel. Stored are the file itself along with its name, file type, size and the time of upload.

The files are held on ALTIKO’s server (section 7.1) and are not published. They are delivered to the browser source in OBS — via a random address that cannot be guessed. That address is at the same time the protection: whoever knows it can fetch the file. The files are deleted as soon as the user deletes them in the editor or removes their account.

The user is responsible for the content of the files. If they contain personal data of third parties — photos of other people, for instance — the user needs their own legal basis for that.

Legal basis: Art. 6(1)(b) GDPR.

4.8 Premium, trial and grants

For Premium, ALTIKO stores per channel where it comes from and how long it runs: a trial, a subscription (section 7.5) or a grant by the operator, for instance as a thank-you or as a prize. A grant comprises its start, its end or “unlimited”, who issued it and an internal note on the occasion. The entry of a trial remains after it has ended, because it proves that it has already been used. All entries are deleted with the account.

Legal basis: Art. 6(1)(b) GDPR.

4.9 Wish board

On the wish board (altiko.de/en/wuensche) signed-in users can post wishes and ideas and vote for other people’s wishes. Stored are the title and text of the wish, the time, the id of the channel it came from, and the votes cast. Publicly visible are the title, text, number of votes, status and an answer from ALTIKO. Who voted is never visible. The channel name of whoever posted a wish appears only if they explicitly choose that when posting (Art. 6(1)(a) GDPR); consent can be withdrawn at any time by email, after which the name is removed. Please do not put personal data into a wish.

Wishes and votes are deleted when the user deletes their account. The operator can hide or delete wishes, for instance in case of duplicates or unsuitable content.

Legal basis: Art. 6(1)(f) GDPR (developing the service further along the wishes of its users).

5. Data of viewers

As soon as a channel is connected, ALTIKO receives events from that channel. In doing so it processes:

  • display name and platform id of the person triggering it
  • for chat messages, their content
  • type of event, time and associated details (such as the number of bits donated or viewers in a raid)
  • counter values that a rule assigns to this person

This data is needed for the streamer’s rules to work — a command such as !cookie cannot be answered without the name of the person writing.

The event log is deleted automatically after 30 days. Counter values remain until the streamer deletes them or removes their account.

5.1 Loyalty points

If a streamer switches on the points system, ALTIKO keeps a viewer list for that channel: display name, platform id, point total, number of messages and the time of the last message. It is the basis for points and the leaderboard and comes into being only while the points system is switched on — if it is off, none of this is stored.

The list is accessible only to the respective streamer, is not published and is not merged across channels. Entries without points are deleted once a year has passed without activity; beyond that they remain until the streamer changes them or deletes their account. Viewers can request deletion through the streamer or directly from us (section 11).

Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is the operation of the features set up by the streamer. The data comes exclusively from publicly visible chats.

5.2 Linking Twitch and Discord

Viewers can link their Twitch and their Discord account so that they automatically receive a role in their streamer’s Discord server when they subscribe to the channel. This link is voluntary and happens solely through an explicit action by the viewer on the page /verknuepfen.

Only the following are stored:

  • the Twitch id and the Twitch display name
  • the Discord id and the Discord display name
  • the time of the link

Not stored are email addresses, contact lists, messages or any other details from either account. For signing in, no permission whatsoever is requested at Twitch, and at Discord only identify — that is, the information of who is signing in.

The display names are only there so that viewers can tell on their own page what they have linked; a bare numeric id does not answer that question.

The link is stored once, not per channel: a person has one Twitch and one Discord account, and the mapping is the same everywhere. It is not published, not passed on to third parties and not evaluated for other purposes. It is used solely to grant or withdraw a role in the Discord server of the respective streamer.

Viewers can delete the link themselves at any time — on the same page /verknuepfen, without giving a reason and without asking us or the streamer. The entry is removed completely. A Discord role already granted remains; it is merely no longer adjusted automatically and can be removed by the streamer.

Legal basis: Art. 6(1)(a) GDPR (consent). Consent is given by signing in to both services on the linking page and can be withdrawn at any time with effect for the future by deleting the link there.

5.3 Detecting chat waves

For automatic highlights, ALTIKO counts per channel how many chat messages arrive in windows of ten seconds. Only these numbers are stored — no names and no content — and only in a cache of the service; every window expires by itself after about eleven minutes.

Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is the operation of the feature set up by the streamer.

5.4 Queue, chat games and counters

Whoever joins with a command such as !join appears in the channel’s queue with their display name, platform and the time. It is held only in the cache (Redis) and is deleted when the streamer ends it, after 12 hours at the latest. In chat games, stakes and winnings are settled against the loyalty point total (section 5.1); an open duel or a running heist is cached for a few minutes at most. Counters store only a number per channel, no names.

Legal basis: Art. 6(1)(f) GDPR (features switched on by the streamer in the chat).

5.5 Twitch extension “ALTIKO Panel”

If a streamer has embedded the “ALTIKO Panel” extension on Twitch, the panel below their stream loads data from ALTIKO. Twitch transmits the channel id and a random, non-attributable id of the viewer. We only receive the Twitch user id if the viewer explicitly chooses “Show my total” in the panel and thereby shares their identity with Twitch; that sharing can be revoked at any time in the Twitch settings. We use the id only to show that viewer’s point total and place, and the panel stores no additional data. The panel shows the leaderboard (display name and points of the first ten) if the streamer has switched it on.

Legal basis: Art. 6(1)(f) GDPR (display of the features set up by the streamer); for the personal display after sharing, Art. 6(1)(a) GDPR.

If a viewer triggers a sound through the panel, we store the time, channel, sound, means of payment (loyalty points or bits), amount, Twitch user id and display name, and for bits additionally the transaction id from Twitch. We need this to play the sound, to prevent the same purchase being played twice, and to answer questions about a purchase. The entries are deleted after 90 days. Payment with bits is handled by Twitch; we do not receive payment data.

Legal basis: Art. 6(1)(b) GDPR (carrying out the action triggered by the viewer), and for the retention Art. 6(1)(f) GDPR.

5.6 Sound library

If a streamer shares a sound with the sound library, other signed-in ALTIKO users see the sound together with their channel name. If somebody reports a shared sound, we store which channel reported it, the reason given and the time — until the report has been dealt with.

Legal basis: Art. 6(1)(b) GDPR (feature chosen by the streamer).

5.7 Members in Discord servers

If a streamer invites AltikoBOT into their server, ALTIKO also processes data of the members of that server, depending on the modules switched on. Which ones those are is decided solely by the streamer through their settings; ALTIKO acts as a processor for them.

Only the following are stored permanently:

  • Levels: Discord id, display name, points collected, level and the number of messages. What counts is that somebody has written – not what.
  • Birthdays: only if the member enters it themselves. Day and month are needed, the year of birth is optional and stays empty if nobody gives it. Every member can delete their entry again at any time with the same button.
  • Giveaways: the Discord id of the participants, for as long as the giveaway runs. Whoever presses the button again is out again and is deleted.
  • Voice rooms: the id of the channel and of the person who triggered it — only for as long as the room exists. Once it is empty, it is removed along with the entry.

Message content is not stored. The chat guard, auto reactions and custom commands need the text of a message to recognise whether they should do something. It is checked in memory only, and only against the rules the streamer has entered; afterwards the text is discarded. If the chat guard removes a message, the log channel states only who and why — not the wording.

If the streamer disconnects the server or removes the bot, all member data stored for that server is deleted. Every member can also contact info@altiko.de directly.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the streamer in running their community); for the birthday, Art. 6(1)(a) GDPR (consent given by entering it, revocable at any time).

5a. Former waiting list of the test phase

Until 13 September 2026 you could sign up on the home page for the closed test phase, giving a channel name, email address, platform and optionally a short message. These details served solely to inform you about a free place — no newsletter, no advertising, no sharing.

With the end of the test phase the waiting list is no longer offered, and the stored details have been deleted. We are happy to answer questions about this at info@altiko.de.

Legal basis: Art. 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract).

6. Server logs

With every request the web server stores the IP address, time, the address requested, browser identification and the amount of data transferred. These logs serve secure operation and the defence against attacks and are deleted after 14 days.

Legal basis: Art. 6(1)(f) GDPR (operational security).

7. Recipients and transfers to third countries

7.1 Hosting and internal processing

ALTIKO is operated by us: the application, the database and uploaded files run on a server that we set up and manage ourselves. The server hardware is rented from a hosting provider acting solely on our behalf; a data processing agreement is in place with them. The provider supplies only computing power, storage and network connectivity and does not evaluate the data.

All data and databases of ALTIKO are stored exclusively on servers in Germany or within the European Union. No transfer to third countries outside the EU takes place for hosting. Should that change, we will amend this policy beforehand.

To operate ALTIKO we use no analytics services, advertising networks or tracking tools. Data goes only to the recipients named in the following sections — above all to the platforms that users connect themselves.

7.2 Streaming platforms

To fulfil its purpose, ALTIKO exchanges data with the platforms connected by the user. These are controllers in their own right:

For transfers to the USA, processing relies on the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Art. 46 GDPR. A level of protection equivalent to European law cannot be guaranteed in every case.

7.3 What ALTIKO does not use

No analytics tools, no advertising networks, no sharing with third parties for advertising purposes. Fonts are delivered from our own server, not from Google — so no connection to third parties is made when the page is loaded.

7.4 Google user data — limited use

ALTIKO uses YouTube API services. When you connect a YouTube channel, the YouTube Terms of Service and the Google Privacy Policy apply in addition.

The use and transfer of data that ALTIKO receives through Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. In plain words this means:

  • The data is used exclusively for the features of ALTIKO visible to the user (section 4.4).
  • It is not transferred to third parties except where necessary for these features, for security reasons or because of legal obligations.
  • It is not used for advertising — neither our own nor anyone else’s — and it is not sold.
  • It is not used to train generalised artificial intelligence models.
  • No human reads the data unless the user has explicitly agreed, it is necessary to fix a reported fault or for security reasons, or the law requires it. For troubleshooting, data is anonymised or aggregated beforehand as far as possible.

ALTIKO’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

7.5 Payment processing with Stripe

Whoever subscribes to Premium pays through Stripe — Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (privacy policy). The payment page and the customer portal belong to Stripe; name, email address, where applicable the billing address and the payment details are entered there. ALTIKO never sees card details or bank information.

ALTIKO stores only what is needed for the activation: the customer and subscription ids at Stripe, the status of the subscription, whether it runs monthly or yearly, until when it is paid for and whether it has been cancelled. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Invoices and payment records are kept for up to ten years due to statutory retention obligations (§ 147 AO, § 257 HGB) (Art. 6(1)(c) GDPR).

Stripe also processes data in the USA (Stripe, Inc.); the basis is the EU-US Data Privacy Framework and standard contractual clauses pursuant to Art. 46 GDPR. Stripe itself is responsible for fraud prevention and compliance with financial regulations.

8. Protection of the data

ALTIKO processes access tokens of third-party platforms and chat content. This data is protected by the following measures:

  • Encrypted transmission: all connections to the service and to the platforms run exclusively over TLS (HTTPS/WSS); unencrypted requests are redirected to HTTPS.
  • Encrypted storage: access and refresh tokens of all platforms — including those from Google — are held in the database encrypted with AES-256-GCM and nothing else. The key lives outside the database in the service’s environment and is not part of the source code or of the backups.
  • Separated channels: every user sees only the data of their own channel. Every query is bound to the session on the server side; there is no merging across channels.
  • Restricted access: the database and the event bus are not reachable from the internet and run in an isolated container network. Server access is limited to the controller and uses an SSH key only; password login is switched off.
  • Sessions: sessions are held on the server, the cookie is HttpOnly, Secure and SameSite, contains only a random identifier and expires after 30 days without use.
  • Verified origin: incoming events from the platforms are checked against their signature and discarded if it does not match.
  • Data minimisation: only the permissions needed for the chosen features are requested, and only the data named in this policy is stored. Data no longer needed is deleted automatically according to the periods in section 9.
  • Reporting breaches: if a personal data breach is established, it is reported to the supervisory authority within 72 hours pursuant to Art. 33 GDPR, and to the data subjects where the risk is high.

9. Retention periods

DataDeleted
Account and platform datawhen the account is deleted
Rules, settings, counterswhen the account is deleted
Viewer list of the points systemwithout points after a year without activity, otherwise when the account is deleted
Event logafter 30 days
Daily statistics (numbers only, no names)when the account is deleted
Twitch/Discord linkat the viewer’s request, deletable by them at any time
Connected Discord serverswhen disconnected or when the account is deleted; deactivated ones after 12 months
Content above the free limit after Premium endsafter 12 months, unless Premium is active again
Your own files in the overlay editorwhen deleted by the user, or with the account
Counting window for chat waves (numbers only)after about eleven minutes
Premium grants and trialwhen the account is deleted
Invoices and payment recordsafter up to ten years (statutory retention)
Queue for playing alonguntil it ends, 12 hours at most
Wishes and votes on the wish boarduntil the wish or the account is deleted
Former waiting list of the test phasedeleted at the end of the test phase (13/09/2026)
Sign-in sessionafter 30 days without use
Server logsafter 14 days
Backupsafter 14 days

Backups may still contain deleted data for up to 14 days. They are used only to restore after a failure.

10. Deleting your account

Under Channel & plan → Delete account you can remove the account yourself at any time. All rules, alerts, counters and log entries are deleted, the event subscriptions at the platform are cancelled and access to the platform account is withdrawn. The process cannot be reversed.

11. Rights of data subjects

The following rights exist:

  • access to the processed data (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR) — this concerns in particular viewers whose data is processed through the chat of a connected channel
  • complaint to a supervisory authority (Art. 77 GDPR)

A message to info@altiko.de is enough to exercise them.

12. Competent supervisory authority

Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg
Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany
lda.brandenburg.de

13. Changes

This policy is amended when the service changes. The version published here at any given time is the authoritative one.