Your information

Privacy Policy

RockList stores the information needed to run stream requests, playlists, connected-platform features, and supporter benefits. We do not sell personal information or use it for targeted advertising.

Effective July 27, 2026

At a glance

What we collect
Account and channel details, request activity, connected service data, payments, and diagnostics.
Why we use it
To provide RockList, keep it reliable, process support, and protect users and the service.
Your controls
Manage settings, export data, disconnect services, or ask us to correct or delete information.

This policy applies when you use the RockList website, chat bots, desktop tools, integrations, and related services. The streamer who runs a channel also controls how their playlist, played history, and moderation tools are used.

Information we collect

Account and channel information

When you sign in with Twitch or connect another platform, we receive identifiers and profile details such as your username, display name, profile image, channel identifier, and language. We also store your RockList preferences, feature access, and channel settings. RockList does not receive or store your Twitch, Google, Kick, or TikTok password.

Requests, playlists, and chat commands

We process commands and messages sent to RockList, including the requested text, the service it came from, your platform identifier and display name, request status, moderation actions, queue benefits, and timestamps. Songs added to a playlist and played-song history are stored so the streamer can run and review their stream.

Connected platforms

If you connect Twitch, Kick, TikTok tools, or YouTube, we store the account and channel details needed for that connection. Where a service uses OAuth, we store encrypted access credentials, granted permissions, and expiry information. We also process the chat messages and replies needed to operate the commands you enable.

Payments and supporter features

If you support RockList, we store transaction or subscription identifiers, payment status, amount, currency, and the supporter options you choose. Stripe and PayPal process payment credentials. RockList does not store your full card or bank account number.

Imports, desktop tools, and support

We process files and catalog ownership information that you choose to import, along with the results of those imports. RockList Desktop may send the status and diagnostic information needed for the features you use. If you contact us or report a problem, we receive your message and may receive your account, page, browser, and error details.

Technical information

Our systems receive ordinary service information such as IP address, browser and device type, requested pages, dates, security events, performance data, and errors. We use this information to operate, secure, and improve RockList.

How we use information

We use information to:

  • authenticate users and connect accounts and channels;
  • receive requests, manage playlists, send replies, and provide moderation and streamer tools;
  • process payments and provide supporter benefits selected by the user;
  • maintain, troubleshoot, secure, and improve the service;
  • prevent spam, abuse, fraud, and unauthorized access;
  • answer support requests and communicate about the service; and
  • meet legal, accounting, and safety obligations.

Depending on where you live, we rely on the need to provide the service you request, your consent, our legitimate interests in operating a safe and useful service, and our legal obligations.

What other people can see

RockList playlists and played history are public. Those pages may show request text, your display name, platform badge, request status, and related playlist activity. Chat replies are visible in the streaming platform where they are sent. Streamers and authorized moderators can see additional request, moderation, queue, and channel-management information.

Do not include private or sensitive information in a request, chat command, public profile field, or issue report. Streamers and authorized moderators can remove playlist entries and manage played history.

Connected services

RockList works with services selected by users, including Twitch, Google and YouTube, Kick, TikTok-related tools such as TikFinity and Streamer.bot, Stripe, and PayPal. Your use of those services is also governed by their own terms and privacy policies.

We use Cloudflare for hosting, networking, storage, and security, and Sentry for error and performance diagnostics. When you submit a support report, its contents may be sent to the tools used by the RockList team to respond to and manage that report.

Google and YouTube data

If a streamer connects YouTube, RockList accesses the connected channel's identifier and name, the active live broadcast and live chat, and live-chat messages and author details needed to recognize RockList commands. RockList sends command replies to that same live chat using the connected channel.

RockList uses this information only to provide the YouTube live-chat integration the streamer enables. We do not use Google or YouTube data for advertising, sell it, or use the connection to upload, edit, or delete videos. OAuth tokens are encrypted at rest and are not shown publicly.

RockList's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can also review and remove RockList's access from your Google Account connections.

When we share information

We share information only as needed:

  • with the streaming platforms and integrations you connect or direct RockList to use;
  • with service providers that host, secure, diagnose, support, or process payments for RockList;
  • with streamers, moderators, and viewers through the playlist, chat, and channel features described above;
  • when required by law or reasonably necessary to protect RockList, its users, or others; or
  • as part of a merger, acquisition, financing, or sale of the service, subject to appropriate confidentiality and notice.

We do not sell personal information or share it for cross-context behavioural advertising.

How long we keep information

We keep account, channel, playlist, played history, and request information while it is needed to provide the service and maintain the records selected by the streamer. Playlist and history entries may remain until the streamer removes them or a deletion request is completed.

When you disconnect an optional platform, RockList removes its connection credentials and stops using the connection. RockList removes YouTube live-chat message text and viewer identity from retained request records within 30 days. Short-lived YouTube delivery records are also kept for no more than 30 days. Payment records may be kept longer when needed for accounting, dispute, fraud-prevention, and legal obligations. Security, support, and diagnostic records are kept only as long as reasonably needed for those purposes.

Backup copies may remain for a limited period before routine deletion. We may retain information when the law requires it or when it is needed to establish, exercise, or defend legal claims.

Cookies and browser storage

RockList uses essential cookies to keep you signed in, protect sign-in and connection flows, and remember the service state needed for your session. Browser storage remembers choices such as language, recently viewed playlists, and interface preferences. RockList does not use advertising cookies.

Security

We use technical and organizational safeguards designed to protect information, including encrypted connection credentials, access controls, secure transport, and service monitoring. No online service can guarantee absolute security.

Your choices and rights

You can change your available channel settings, remove playlist or history entries where controls are available, export channel data, and disconnect optional services. You can revoke Google access through your Google Account.

You may ask us to access, correct, export, or delete personal information, or to restrict or object to certain processing. You may also withdraw consent where processing is based on consent. These rights vary by location, and we may need to verify your identity before completing a request. You may have the right to complain to your local privacy or data protection authority.

For a privacy request, email support@rocklist.live. Requests to delete personal information associated with YouTube API data are completed as soon as possible and within seven days.

International processing

RockList and its service providers may process information in Canada, the United States, and other countries. Privacy laws may differ from those where you live. Where required, we use appropriate safeguards for international transfers.

Children

RockList is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to RockList, contact us so we can remove it.

Changes to this policy

We may update this policy as RockList changes. We will update the effective date and provide additional notice when a change materially affects how personal information is used.

Contact us

Questions or requests about this policy can be sent to support@rocklist.live.