Admin note: some details on this page haven't been filled in yet. Add them in the admin panel → Site details. Only admins see this note.
Privacy Notice
Last updated 25 September 2026
The short version: we keep only what Zylfr needs to work and stay safe, we don't sell anything or track you, and you can download or delete your data any time in Settings.
1. Who we are
Zylfr is run by the people who run Zylfr. We're responsible for your personal data on Zylfr (in data protection terms, the "controller"). For anything about your data, contact the site's admins.
2. What we keep, and why
We only keep what Zylfr needs to work and to keep the community safe.
Your account
- Your name, a scrambled (hashed) password, when you joined, and when you agreed to the Terms. If you log in with Discord, your Discord ID. We don't ask for your email address or real name.
- Your profile picture, if you add one. We crop it and remove hidden details like the location your phone may have saved in it.
Why: to run your account and the service you've signed up for.
What you do on Zylfr
- Chat messages: the most recent 100 in each channel. Older ones are removed automatically.
- Who you follow and when (new followers wait a few minutes before they can post links), your sparks balance and total watch time, rewards you redeem, and your poll votes (kept until the channel's next poll replaces them).
- If you stream: your channel settings, stream key, emotes, rewards, your offline image, when you first went live (for the one-year frame), snapshots of your live stream for the home page, and stats about your past streams (when and how long you streamed, titles, viewer counts, new followers, sparks, and how many people chatted, but not who).
- The profile frames you own and which one you wear.
- If you turn on notifications, an address from your browser's notification service (run by Google, Mozilla, Apple or Microsoft, depending on your browser) for each device, so we can tell it when a channel you follow goes live. Turning notifications off, or uninstalling, removes it.
- If you turn on two-step login, the secret your authenticator app uses, and scrambled (hashed) versions of your recovery codes.
- If you make bot tokens: their names, when they were made and last used, and scrambled (hashed) versions of the tokens.
Why: these are the features themselves. Watch time, for example, is how sparks are earned.
Safety and moderation
- Bans, timeouts and the mod log in each channel (its latest 200 entries). Messages with links that are held for a mod to check are kept for up to 15 minutes.
- Reports: who sent them, what was reported, and a copy of the reported message or picture, so admins can review it even if it's deleted.
- Your IP address, used briefly to stop abuse such as repeated login attempts. It may also appear in the server's logs.
Why: to keep Zylfr safe and to meet our legal duties, including dealing with illegal content. For the rest, our reason is a legitimate interest in running a safe community.
3. What other people can see
- Everyone: your name, profile picture and frame, and your messages in a channel's chat. While you have a channel open and are logged in, people in that chat can see your name in its list of who's there, unless you turn that off in Settings → Account. If you stream: your channel, title, schedule, emotes, offline image and follower count.
- Streamers can see the names of their followers, and who's banned or timed out in their channel.
- Mods and site admins can see the moderation tools and records for the channels they look after. Site admins can see reports, and your sparks and watch time.
4. Who we share it with
- We don't sell your data or show ads.
- The company that hosts our server stores it for us, as part of running the site.
- If you log in with Discord, Discord tells us your Discord ID and name. Discord's own privacy policy covers what happens on their side.
- Go-live announcements: if the site's admins, or you yourself, have connected a Discord channel for announcements, then when you go live your name, profile picture, stream title and category, and a snapshot of your stream are posted there.
- We'll share information with the police or other authorities when the law requires it, for example about child sexual abuse material.
5. How long we keep it
- Your account and channel: until you delete your account.
- Chat: the latest 100 messages in each channel. Older ones are removed as new ones arrive.
- Reports and their copies: deleted one year after the report is closed.
- Password reset links: expire after 24 hours. Login sessions: last 30 days.
- Backups: we keep a daily backup of the site for up to two weeks, in case something goes wrong. They're stored securely and only used to restore the site.
When you delete your account, we remove your account, channel, emotes, profile picture, offline image, follows and chat messages. Reports you made about others stay until they're deleted as above, but no longer show your name. Copies in backups disappear as older backups are replaced, within about two weeks.
6. Your rights
Under UK data protection law you can:
- Get a copy of your data: use Download my data in Settings → Account, or contact us.
- Correct it: change your name, picture and channel details in Settings.
- Delete it: delete your account in Settings, or ask us.
- Object, or ask us to restrict how we use it, and take it elsewhere (the download is a standard format).
Contact the site's admins. We'll reply within a month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to sort it out first.
7. Cookies and your browser
- One cookie keeps you logged in. It's essential, so there's nothing to accept. A second, short-lived one is used only while logging in with Discord.
- Your browser also remembers a few settings on your device: your theme, whether mention sounds are on, announcements you've dismissed, and a random ID so several open tabs count as one viewer. These stay on your device.
- No tracking, advertising or analytics cookies.
8. Age
You need to be at least 13 to make an account. If we learn that someone younger has one, we'll delete it.
9. Keeping it safe
Passwords are stored hashed, so nobody can read them, not even us. Logins use a secure cookie, and login attempts are limited. Stream keys act like passwords and can be reset any time. No system is perfect, but if something goes wrong that puts your data at risk, we'll tell you and the authorities as the law requires.
10. Changes
If we change this notice, we'll update the date at the top, and for bigger changes we'll let people know on the site.
See also our Terms of Service and Community Guidelines.