StreamerVitals is a public statistics site with no accounts and no visitor tracking. This policy describes precisely what is recorded, what is not, and who else is involved — in specifics rather than in the usual reassuring generalities.
Last updated .
StreamerVitals has no user accounts, no registration, no login, no profile, no newsletter and no comment system. Nothing on the site asks who you are, and no feature requires it. If you email us, we hold that correspondence in order to answer it — that is the only route by which we would come to hold your name or email address, and it exists because you chose to write to us.
Two counters, both aggregated to the day, neither attached to an individual.
| Record | Exactly what a row contains | Why it exists |
|---|---|---|
| Profile views | A channel identifier, a calendar date, and a count. Nothing else — no visitor reference of any kind. | Channels people actually read about are sampled more frequently, so the pages that get used are the pages with the best data behind them. |
| Search demand | A normalised search term, a calendar date, a count, a count of times it returned nothing, and the channel it resolved to if it resolved to one. | Repeated searches for a channel we do not yet track tell us what to start collecting. Misses are counted separately for exactly that reason. |
Both are pure counters. A row saying a channel was viewed 412 times on a given day cannot be decomposed into who did the viewing, because that information was never collected in the first place — not hashed, not truncated, not “anonymised later”. Search terms are normalised and are only recorded when they are between 2 and 64 characters long; they are channel names and search phrases, and if you type something personal into a search box on any website you should assume it is logged, here included.
Stated explicitly, because absences are the part policies usually skip:
Our hosting provider and content delivery network necessarily process the IP address of every request in order to deliver a response and to protect the service, and their infrastructure logs are retained on their own schedules. That is true of every website on the internet; what is in our control is whether any of it reaches our database, and it does not.
Two public endpoints — site search and the on-demand channel lookup — are rate limited, because an unmetered lookup endpoint is a way to exhaust our Twitch API quota and to enumerate the account namespace. Counting requests per client requires some notion of “client”, and here is exactly what that is:
The purpose is to count requests, not to keep a record of who visited. If our cache is unavailable, requests are allowed through unmetered rather than blocked — a degraded cache must not become a broken site.
One item, in localStorage, under the key sv-theme. It holds the string light or dark so the site does not flash the wrong colour scheme on your next visit. It is not a cookie, it is never transmitted to our servers, it contains no identifier, and clearing your browser storage removes it with no consequence beyond losing that preference.
StreamerVitals sets no cookies of its own. No session cookie, no preference cookie, no analytics cookie.
Google Analytics is loaded only when a measurement ID has been configured for the deployment. When it is loaded, IP anonymisation is enabled and the script is deferred until after the page is usable. Google may set cookies in that case, and Google’s own privacy terms then apply in addition to this policy.
On this deployment, Google Analytics is currently not enabled, and no analytics script is loaded.
The AdSense script is loaded only when advertising has been switched on and a client ID has been configured. Google and its advertising partners may then set cookies or use similar technologies to serve and measure ads, subject to Google’s own policies.
On this deployment, advertising is currently not enabled, and no advertising script is loaded.
With neither configured, a default deployment of this site makes zero third-party requests from your browser. That is enforced in the code rather than promised in prose: the third-party loaders render nothing at all without those settings, and the site’s content security policy only permits the corresponding hosts when they are configured.
Display advertising is the intended way to fund the service, and it is not yet switched on. When it is, the ad slots already present in the layout will begin rendering advertisements, this policy will be updated before that happens, and the about page will state it plainly.
Advertising will never determine who appears on a ranking, in what order, or with what figures. The ranking formulas are published so that this is verifiable rather than merely asserted.
Warning: Operator note: consent is required before advertising is enabled
Personalised advertising, and the cookies and identifiers that come with it, require a valid consent mechanism in the European Economic Area, the United Kingdom, Switzerland and a growing number of other jurisdictions — including a Google-certified consent management platform for AdSense traffic from those regions, plus opt-out handling under US state privacy laws.
No such mechanism is implemented on this site today, because no advertising is served today. One must be implemented, tested and shown to visitors before advertising is enabled in any region that requires it. This notice is deliberately left in place as a standing reminder that the two changes ship together, never separately.
The complete list of outside parties involved in running this site:
There are no others. No customer-data platform, no session-recording tool, no heatmap script, no chat widget, no A/B testing service.
Most of what this site publishes is about Twitch channels rather than about visitors: display names, avatars, channel descriptions, broadcast titles, and the viewer measurements we recorded. All of it originates from the official Twitch API and describes public broadcasts made to a public audience.
Where that information relates to an identifiable person, we process it on the basis of our legitimate interest in publishing aggregated, factual statistics about public broadcasting activity — a purpose that is served by the numbers, not by anyone’s private life. We publish nothing that requires authentication to see, nothing about a streamer’s viewers, and nothing about chat participants.
Cached Twitch material is refreshed on a schedule and purged when Twitch reports a channel as deleted. Streamers who want their information corrected or removed should read data removal, which sets out what we can remove, what we may retain as our own measurements, and how we verify a request. The methodology page lists every stored field, its retention class and its maximum cache age.
Depending on where you live, you may have rights to access, correct, delete, port or object to the processing of personal data about you, and to complain to a supervisory authority. We honour those rights, with one honest practical caveat:
For site visitors, we almost never hold any personal data to act on. With no accounts, no cookies of our own and no stored identifiers, there is usually no record that could be linked back to you, so an access or deletion request will generally be answered with a truthful “we hold nothing about you”. That is the intended outcome of the design, not an evasion.
For streamers, whose channels are the subject of the published statistics, the rights are substantive and the process is documented at data removal. We verify that a request comes from the channel owner before acting, because acting on an unverified request would itself be a failure to protect that person’s data.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in United States state privacy laws.
The service is operated from a single region and served worldwide through a content delivery network, so a request may be handled by infrastructure outside your country. Because the site stores no visitor identifiers, the personal data crossing a border in that process is limited to what is inherent in making an HTTP request — principally your IP address, processed transiently by our hosting and CDN providers to deliver a response.
This site is a statistics reference, not a service directed at children. We do not knowingly collect personal data from anyone, of any age, because we do not collect personal data from visitors at all. If you believe a page contains personal information about a minor that should not be published, write to [email protected] and we will review it promptly.
The site is served over HTTPS with a strict content security policy that blocks scripts from hosts we have not explicitly configured. Twitch API credentials are held server-side only and are never exposed to the browser. Because we hold no visitor accounts and no visitor identifiers, the most damaging category of breach — loss of a user database — does not apply to us, which is a reason to keep it that way.
When this policy changes materially — in particular, before advertising or third-party analytics is enabled — we will update the date at the top of this page and describe what changed. Continued use of the site after a change means the revised policy applies, but the substantive protections above are design decisions rather than promises, and weakening them would require changing the code as well as this page.
Privacy questions, data-subject requests and complaints: [email protected]. We aim to respond within 30 days and usually much sooner. For anything else, see contact; for channel data specifically, see data removal.