Twish! Privacy Policy
This Privacy Policy explains how the developer of Twish! (“Twish!”, “we”, “us”) collects, uses, and protects information when you use the Twish! Twitch Extension, the Twish! hosted chat bot, or the Twish! game servers (together, the “Service”).
Twish! is a fishing minigame that runs inside Twitch. It is not affiliated with or endorsed by Twitch Interactive, Inc. Your use of Twitch itself is governed by Twitch’s own Terms of Service and Privacy Notice.
1. What we collect
We collect the minimum data needed to run the game:
| Data | Source | Notes |
|---|---|---|
| Twitch user ID | Twitch Extension helper / Twitch chat | Your numeric Twitch ID, used as your persistent player identity. Extension gameplay begins only after you grant Twitch identity sharing; recognized chat commands already include your Twitch user ID through Twitch Chat. Before identity sharing, Twitch supplies a signed opaque identifier to the extension, but Twish does not create a new player profile or gameplay records from it. Legacy prerelease opaque profiles are retained only so their progress can merge into the same viewer’s identified profile after consent. |
| Twitch display name | Twitch Extension helper / Twitch chat | Shown on leaderboards, catch announcements, and tournament results. |
| Twitch chat events and recognized command metadata | Twitch EventSub / hosted IRC fallback | When a broadcaster connects Twish Chat and enables command replies, Twish receives channel chat through EventSub; the temporary hybrid fallback receives chat in legacy opted-in channels through Twitch IRC. Twish immediately ignores and does not store non-command messages. For a recognized EventSub command, Twish temporarily stores only delivery and message IDs, channel and chatter IDs, chatter display name, command name, processing timestamps/status, and the generated bot reply text/type needed for crash-safe delivery. For !fish on either transport, it also temporarily stores an at-most-once processing marker and cached gameplay outcome. It does not retain the full incoming message or a chat log. This metadata becomes eligible for deletion at 24 hours and is removed by the next scheduled pruning pass (normally within about one additional hour); resulting gameplay records are retained separately as described below. |
| Gameplay records | The Service | Casts, catches, fish collection, inventory, XP/level/coins, equipment, quests, achievements, tournament scores, and game settings. |
| Bits transaction records | Twitch Extension Bits API | The Twitch transaction ID, product SKU, Bits amount, and the channel where the product was used. Required to deliver the item you unlocked and to prevent duplicate processing. |
| Technical logs | The Service | IP addresses and request metadata appear in short-lived server logs used for rate limiting, abuse prevention, and debugging. |
What we do NOT collect: email addresses, real names, postal addresses, phone numbers, passwords, or any payment details. All payments (Bits purchases) are handled entirely by Twitch; we never see your payment information.
2. How we use it
- Run the game — resolve casts, record catches, persist your collection and progression across channels and sessions.
- Display gameplay — show your display name on leaderboards, catch cards, tournament standings, and chat bot replies.
- Fulfil Bits products — credit items unlocked with Bits and use the Twitch transaction ID to guarantee each transaction is honored exactly once.
- Keep the Service healthy — rate limiting, anti-abuse, and debugging.
- Comply with law — retain records where legally required.
Where the GDPR applies, our legal bases are performance of a contract (running the game you chose to play) and legitimate interests (service integrity, abuse prevention).
3. What we never do
- We do not sell Twitch user data.
- We do not share Twitch user data with third parties for their own purposes, including advertising or marketing.
- We do not use your data for advertising, profiling, or tracking outside the Service.
- We do not transfer your data to anyone except the infrastructure providers that host the Service (acting as processors on our instructions) or where disclosure is required by law.
4. Where your data is stored
Game data is stored on servers operated for us by our hosting provider (Hetzner) in the United States (Oregon). If you access the Service from another region — including the EEA or UK — your data is transferred to and processed in the United States.
5. How long we keep it
- Gameplay records and player profile — kept while your player account is active, so your collection and progression persist. Deleted on request (see Section 6).
- Bits transaction records — kept for as long as needed for accounting, dispute resolution, and legal compliance, then deleted.
- Technical logs (including IP addresses) — automatically rotated; kept no longer than 30 days.
- Recognized chat-command metadata, temporary
!fishoutcome, and generated reply — becomes eligible for deletion at 24 hours and is removed by the next scheduled pruning pass (normally within about one additional hour). It is used solely to prevent duplicate execution and support reliable processing and reply delivery. Non-command messages are never stored.
6. Deletion and your choices
To have your player data deleted, email privacy@twish.fish from a means that lets us verify you control the Twitch account (for example, include your Twitch username and respond to a verification whisper or a code we ask you to place in your Twitch bio). We will delete your player profile, gameplay records, and collection within 30 days of verification. Bits transaction records may be retained where required for financial or legal compliance, dissociated from your deleted profile where possible.
You can also limit collection up front:
- Identity sharing — extension gameplay requires a one-time Twitch identity-sharing grant so progress and public leaderboard names belong to the correct account. If you decline, Twish receives only Twitch’s signed opaque identifier for that session and does not create a new player profile or gameplay records. You may still use enabled chat commands, where Twitch Chat supplies your normal chatter identity.
- Chat fishing — chat access is off until a broadcaster explicitly selects Connect with Twitch and grants
channel:bot. A broadcaster can disable command replies at any time, which stops local processing immediately and requests deletion of the active EventSub subscription while preserving the connection for later re-enabling. Selecting Disconnect from Twitch also forgets Twish’s stored grant state. Broadcasters may additionally revoke the bot application from their Twitch Connections settings. - Uninstall — broadcasters can disconnect Twish Chat and then uninstall the extension at any time; viewers can simply stop interacting with it.
7. Your rights (GDPR / CCPA summary)
If you are in the EEA, UK, or a similar jurisdiction, you have the right to access, rectify, erase, restrict, or port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority.
If you are a California resident, you have the right to know what personal information we collect (Section 1), to request deletion (Section 6), and to non-discrimination for exercising those rights. We do not sell or share personal information as defined by the CCPA/CPRA.
To exercise any of these rights, email privacy@twish.fish.
8. Children
The Service is available only through Twitch, which requires users to be at least 13 years old (or older where local law requires). Twish! is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has used the Service, contact us and we will delete the associated data.
9. Security
Data is transmitted over TLS and stored in access-controlled databases. Requests to the game API are authenticated with Twitch-signed tokens. No system is perfectly secure, but we design for least data: the less we collect, the less can go wrong.
10. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected here with a new effective date; this page is always the current version.
11. Contact
Operator: the developer of Twish!
Email: privacy@twish.fish
See also the Twish! Terms of Service.