This is a translation. The Italian text is the reference version.
SocialBot is ANDRYXify's bot for Twitch and Kick, with its own panel for your streams and socials.
It is open to every streamer who signs up with Twitch, Kick, YouTube or Discord: the Essenziale plan is free, and
the rest opens up with a paid plan or by being enabled as a member of the andryxify.it community.
It talks in chat from the streamer's own account (no anonymous bot account) and collects only
what it needs to work. No paid third-party AI: the "brain" is a
procedural/statistical model that runs entirely on our server. No data sold to third parties.
Data controller: ANDRYXify. For any request, you can write to us through the
official andryxify.it channels.
Cookies
We use a single technical session cookie (andrybot), which is needed to keep you
signed in after you log in. It is signed, httpOnly and SameSite=Lax.
- No analytics, advertising or profiling cookies.
- No trackers or third-party services that set cookies.
Since it is strictly necessary for logging in, this cookie does not require consent: the banner you see
is for information only.
What data we process
- Accounts on the platforms the streamer connects: Twitch and, if the streamer connects them,
Kick and YouTube too (login, display name, user id), and authorization
tokens (OAuth): these are needed to act through the streamer's account: writing in chat, creating clips,
managing VIPs, moderating, receiving events (follows/subs/raids). They stay on the server and are never
exposed to the browser.
- If you sign up with Kick, that account is your login: we keep your Kick name and
user id to recognize you when you come back (even if you change your name), and the channel we create is called
kick.<name>, a name that can never match that of a Twitch channel, so two people with the
same name on different platforms never end up on the same channel. No Twitch account is required, and no Twitch
data is collected.
- Public chat messages from the channel: stored so the bot can learn and reply, and
automatically deleted after 14 days. The local AI only derives statistics from them (single
words, with how often they appear) and numeric vectors, and that is what it keeps: once the 14 days are up, it
does not keep the text of the messages.
- Questions the bot couldn't answer: for these, the text of the question is kept, so the bot
can learn to answer it next time. Before it is stored, it is stripped of mentions, email addresses and
links, and it is not linked to who wrote it: it is not someone's message, it is
something the bot didn't know. You can have it deleted, like everything else.
- Knowledge and settings entered by the streamer; coins and VIPs (loyalty).
- Who has followed the channel: the Twitch ID (or the name on Kick) and when we saw them
follow, so that someone who unfollows and follows again isn't treated as a new follower. It goes away with the account.
- The review of SocialBot, if the streamer leaves one: the stars, the text if they write one,
the language and, only if they choose to, the channel name. It is public on the home page: the
stars right away, the text after we have read it. They can change or remove it whenever they want from Your
account, and it goes away with the account.
- "Friends" affinity: a simple global score per user, kept strictly
compartmentalized: never the content of the messages, nor which channel they were in.
- Birthday, only if the person enters it themselves (in the Telegram group or in chat with
!compleanno) or if the streamer adds it by hand: day and month; the name to
use in the greeting, that is, the one the person shows up with in the Telegram group or in chat when they add
their birthday (or the one the streamer writes, when they add the birthday themselves); to recognize the person,
the id of their Telegram account or the name of their chat account; and the year of the last birthday greeting,
so it isn't repeated. No full date of birth,
and therefore no age. It stays until it is removed, with !compleanno via or from the streamer's panel.
- Optional integrations turned on by the streamer: the token of their Telegram
bot + the group id (both provided by the streamer), their public TikTok username for the live
notification, and the restricted key for their Stripe account for donations, stored
encrypted; if they connect Satispay, the key we create just for their online store with the
activation code they generate (the code works only once and we don't keep it): we use that key
to sign payments and any refunds, and it is stored encrypted; if they connect Ko-fi, the address of their Ko-fi page and the fingerprint of
the token Ko-fi uses to sign its notifications (not the token itself: the fingerprint lets us recognize it, but
the token can't be derived from it); if they connect Instagram, the name and id of their
professional account and the token Instagram gives us, stored encrypted, for notifications about new posts and,
when they ask for it, to publish the Story with their week. If they remove the app from their Instagram, or ask
Instagram to delete their data, Instagram tells us and we immediately delete the token and the name.
- Messages and events from the other connected platforms (Kick, YouTube): they come only
from the channels the streamer has connected themselves, and they are handled exactly like those from
Twitch: same retention, same automatic deletion after 14 days. A new platform never widens what we
keep: it only widens where it comes from.
- Voice and audio, with the «Comandi Vocali» add-on. Voice commands and
forfeits are heard by the listening page the streamer opens: the streamer's browser turns the
voice into text (on Chrome and Edge with the recognition service of the browser's maker, elsewhere with an engine
that runs on the streamer's device), and the audio never reaches us. We only get the recognized phrase, to fire
the command or count the forfeit, and we don't keep it. For highlights the server listens to the
public audio of the stream only to measure its loudness and make a clip when it jumps: it doesn't record it and
doesn't turn it into text.
- The streamer's own words, to learn how they talk: the phrases they say with the listening page
open, if they turn on «Learns while I talk», and the messages they write from their linked Telegram account. We
keep their last 60 phrases. Only theirs: the bot doesn't learn anyone else's way of talking. From other people's
messages in the Telegram group the bot keeps no text: it takes from them what it takes from the chat.
- The streamer's email address, optional: the streamer enters it in the Streams tab to receive
the end-of-stream report; it only takes effect after they confirm it from the message we send them, and they can
remove it from there whenever they want. The emails are sent from our own server, not by an outside service, and
contain nothing about their viewers beyond the stream's numbers and the names of the people who chatted the most.
- Passkeys: only the public key. No biometric data ever leaves your
device.
- Donations to a streamer. From the streamer's page, the payment is handled by
Stripe or Satispay, into the streamer's account, and card details are seen
only by Stripe and the bank, never by us. If the streamer has connected Ko-fi, the donor pays
on the streamer's Ko-fi page and Ko-fi notifies us: the name, the message (unless the donor keeps it private),
the amount and the currency. Ko-fi also sends us the donor's email address: we don't save it. For tips that
come from another service (for example Streamlabs, StreamElements or PayPal) and that the streamer forwards to us
through an automation of their own with their channel's API key, we read only the name, the message, the amount,
the currency and the id that service gives the tip, so it isn't counted twice: nothing else. What we keep is the name
chosen by the donor (which can be none), the message, the amount and the time: these are needed for the
on-stream alert and for the streamer's log. The name and the message may appear on stream and, if the streamer
adds the «Who donated» block to their page, the name appears there too (the form says so before you donate).
If the streamer allows it, the donor can attach an image: we keep it, recompressed, until the streamer decides;
if they discard it, we delete it right away; if they put it on stream, it stays with the donation in their log
and they can remove it themselves. If the payment is never completed, the image is deleted when the payment
expires, a little over an hour after it was opened.
- Support for the project given through socialbot.live/sostieni: this
is different from donations to a streamer, and it goes into ANDRYXify's Stripe account, the
same one subscriptions are paid into. Here too, card details are seen only by Stripe and your bank, never by us.
What we keep is the amount, the time and, if you write them, the name and the message: they don't appear
anywhere, there is no supporters page, and only the data controller, ANDRYXify, reads them. You don't need an account to support the project.
- City campaigns: if a channel owner claims the free year from an ad
(socialbot.live/nyc, /milano or /napoli), we record which campaign and when. This is used to count the spots
left and to avoid giving the free year twice to the same channel in the same campaign; it is deleted along with
the channel.
- Minimal technical logs for operation and security.
Why we process it (legal bases)
- Performance of the contract (Article 6(1)(b) GDPR): the service the streamer asks us for,
with the features they turn on and their subscription if they have one; and, for anyone who donates or supports
the project, the payment they chose to make.
- Legitimate interest (Article 6(1)(f)) of the channel, and ours, in moderating the chats,
keeping them safe and interacting, on messages already made public by users: in the Twitch, Kick
and YouTube chats the streamer connects and in their Telegram group, where, if the streamer turns it on,
newcomers can't write until they press the welcome button. On Discord the bot doesn't read messages: the filter
is applied by Discord itself, with the rules the streamer has us write. The minimal technical logs needed for the
security of the service fall here too.
- Consent (Article 6(1)(a)) for what is optional and given by the person by their own choice:
the streamer's email address, for the stream report and the confirmation emails, which only takes effect once
they have confirmed it; birthdays; the integrations the streamer decides to connect; the Discord account a viewer
links to get roles. It can be withdrawn at any time, by removing the data or disconnecting.
- Legal obligation (Article 6(1)(c)): support for the project is income, and the law requires
its records to be kept for ten years.
Who we share it with, and where
The bot operates on Twitch and, if the streamer connects them, on Kick and
YouTube: each of them receives only the data needed to do what the streamer asked for
(reading their channel's chat, replying, receiving events). The integrations with Telegram,
TikTok and Instagram happen only if the streamer connects them. The streamer's
week goes to the Schedule on their Twitch channel, to the calendar of their Discord server and to the places they
choose, only if they ask for it. Donations go through Stripe
(Stripe Payments Europe, Ireland) or Satispay (Satispay Europe, Luxembourg), into the account the
streamer opens there: what goes to them is the amount, and the name and message chosen by the donor. If the
streamer connects Ko-fi (Ko-fi Labs, United Kingdom), donors give on the streamer's Ko-fi page,
and Ko-fi sends us the notifications for those donations. The data lives on ANDRYXify's server
(Hetzner, Germany, in the EU), over HTTPS.
No selling of data, no advertising tracking, no paid third-party AI.
How long we keep it
- Chat messages: 14 days.
- Tokens: as long as the streamer stays connected (they can be revoked by disconnecting).
- Donations (chosen name, message, amount, time): one year.
- The streamer's email address and stream reports: until the streamer removes them or deletes the channel.
- Images attached to donations: until the streamer decides; after that, the same as the donation, or deleted right away if discarded; those from a payment that was never completed, as soon as the payment expires.
- The week image sent as an Instagram Story: only as long as it takes Instagram to download it, from an address
with a random name; then it is deleted.
- Support for the project (name, message, amount, time): ten years from the payment, because these are cash transactions and the law requires them to be
kept. A support started and never paid is not a cash transaction: it is deleted after a week.
- The streamer's phrases used to learn how they talk: the last 60; when a new one arrives, the
oldest is deleted.
- Everything else: as long as the service needs it, or until the streamer deletes it.
Your rights
You can exercise your rights of access, rectification, erasure and objection. In practice, from the dashboard the streamer can:
- Download all of their data in a single file (Account → Your account → Your data is yours).
- Delete the account and everything in it (Account → Your account → Leaving): commands, modules, effects, points, watch time, chat memory, link page, uploaded files and account connections. This cannot be undone, and the bot leaves the channel.
- Clear the bot's memory (lessons, memories, knowledge learned from chat).
- Disconnect platforms and integrations: the token, key or link they had given us is deleted,
and the bot stops working there. Kick and YouTube from Account → Your account (Your platforms); Discord from
Your communities → Discord, with «Disconnect everything», which also removes the links of the people who had
connected to get roles; the group's Telegram bot, the Telegram account the bot replies to in private and the
Telegram login from Your communities → Telegram; TikTok and Instagram from Your showcase → Your socials;
Spotify from Control room → Music; 7TV from Scene & overlay → Emotes (7TV); Stripe, Satispay and
Ko-fi from Your showcase → Donations. The connected accounts are also all together in Account → Your
account → Your connections, which opens on any plan: disconnecting does not depend on what you pay.
- Revoke the permissions given on Twitch, which can't be disconnected from the panel: they are
revoked from the settings of their own Twitch account, and the server deletes by itself a token that Twitch no
longer accepts.
- Remove passkeys at any time (Account → Your account).
For requests, write to us through the official andryxify.it channels.
Security
Locked-down access
Passkeys
HTTPS
Server-side tokens
Local AI
EU server
- "Maze" access: the dashboard can't be reached from outside. You can only get in with a
throwaway pass minted by the site (256 bits, valid for 2 minutes, single use) or with your
passkey. Anyone who isn't authorized sees only a "Not Found": no information leaks out.
- Passkeys (WebAuthn): you sign back in with your device's fingerprint, face or PIN; the private
key never leaves the device, and we store only the public one.
- Tokens never in the browser: Twitch authorizations stay on the server; the session uses a
signed,
httpOnly cookie.
- The connection to the program you broadcast with doesn't go through us: address, port and
password stay in your browser, on your computer. They don't travel to our server, they don't
end up in the database and they don't show up in backups: we never had them. The page talks directly to
that program, and only if it runs on the same machine: the browser refuses to connect to
another computer. With «Forget it all» they are gone from there too.
- Local brain: no content is sent to external or paid artificial intelligence
services.
- Moderation: the built-in antispam removes spam and unauthorized links and times out
repeat offenders, to protect the chat.
- Everything in the EU, everything over HTTPS, with minimal technical logs.