Stream Game Lab

Privacy policy

Updated September 20, 2026

Scope and contact

This covers stream-game-lab.com and Stream BINGO / Stream Roulette. Contact the operator through the contact page.

Game data

Cloudflare D1 stores room names, display names, random player IDs, cards, draws, round state, expiry times, hashed host keys and room-level blocks for sharing, authorization and participation management. Anyone with the room URL can view names, cards and results; these may appear on streams. Do not enter real names or contact details.

Optional Twitch connection

When a host grants user:read:chat, the host browser receives Twitch chat events. For an exact !join (bingo) or !join (roulette) command, it sends the participant’s Twitch ID, login and display name to the game server for storage in D1, duplicate prevention and participation management. The connected broadcaster’s ID and login are also stored and included in public room information. Participant IDs and logins are excluded from the public card API. Ordinary chat text is not stored.

To maintain the connection, Twitch access and refresh tokens and the broadcaster ID and login are encrypted in server-side D1 storage for up to 30 days. A Secure, HttpOnly cookie holds an opaque random session identifier. Refresh tokens never reach the browser. Access tokens are used in browser memory for chat, not local storage. Pending authorization state lasts up to 10 minutes and is consumed on completion. Expired records are removed during cleanup. Forgetting the connection deletes this browser’s server-side session; Twitch permissions may also be revoked at Twitch. Closing the host page stops chat entry. Provider backups may retain records under their retention practices. See the Twitch privacy notice.

Browser storage and retention

The host key and entered display name are saved in browser local storage. Same-browser synchronization sends only a version number, with a local-storage fallback in unsupported environments; these notifications never contain host keys or Twitch tokens. Clear site data to remove them. Rooms become inaccessible 24 hours after creation. Expired records are removed during cleanup, including when another room is created. Hosts can delete rooms earlier. Provider backups may retain records under the provider’s retention practices.

Abuse prevention and hosting

Cloudflare may process IP addresses, access times and other technical information for delivery and protection. The game hashes the connection IP with a time bucket for temporary rate limiting; records are cleaned after the window expires. We still treat these hashes as identifying information. See Cloudflare’s privacy policy.

Advertising and analytics

No advertising or analytics scripts currently run. An ads.txt ownership file is published for an AdSense review; it does not itself set advertising cookies. Required disclosures and consent management will be prepared before ads are introduced.

Inquiries and requests

Email content and addresses are used to respond and resolve issues. We aim to delete them within one year of resolution unless legal or dispute-related retention is necessary. Gmail is used, subject to Google’s privacy policy. Contact us to request access, correction or deletion.

Browser room management

A random room-owner secret and any pending creation request are saved in browser local storage to recover from connection failures without duplicate creation. The server stores the secret hash, current room ID, revision and creation request ID. Raw host keys are never included in public listings. Rooms expire after 24 hours and ownership records are removed by cleanup after expiry. Clearing site data may prevent recovering your room list.

Find your card with Twitch

Open the shared my-card URL and sign in with the Twitch account used to enter. Your existing card opens enlarged, matched by account ID from !join or Channel Points; signing in does not enter the game. Manually added or name-only cards remain selectable from the list. Other cards remain viewable. Viewer sign-in requests no chat-reading or reward-management scopes. A separate essential cookie identifies the viewer session. Access tokens, account IDs and login names are encrypted on the server for up to 24 hours or the shorter token lifetime; refresh tokens are not retained. Expired records are periodically cleaned up. Sign out as viewer deletes the session. Revocation or connection issues may require signing in again.

Channel Points records

Optional Channel Points entry stores the broadcaster ID, reward ID/title/cost, room and round, and entry start time. Redemption IDs, admission decisions, processing status and timestamps support duplicate prevention and refund retries. These records become eligible for cleanup no later than 30 days after reward setup. Twitch credentials use the existing encrypted connection storage. Background checks continue when the host page closes. Before forgetting a connection, pause entry and reconcile pending exchanges. Revocation, expiry or service failure may prevent automatic processing; cancel pending redemptions in Twitch in that case. Participant display names, cards and results are public to participants and stream viewers.

Fixed OBS URLs

After connecting Twitch, copy a fixed OBS URL and set it once in an OBS Browser source. It automatically follows a newer room connected to the same Twitch account. Bingo, BINGO X7 and Roulette each have separate fixed URLs. Valid saved Twitch authorization can be reused; a different browser or an expired session may require sign-in again. Room changes are checked about every 10 seconds. With no active room, the display is blank. OBS copy buttons now provide fixed URLs only; previously configured room-specific URLs still work.

To keep these URLs stable, the Twitch account ID, game type, read-only identifier and target room information are retained separately from the authorization session (which lasts up to 30 days). Disconnecting or room expiry does not delete this mapping. Contact the operator to request deletion. Fixed URLs contain no host key or Twitch authentication token, but anyone with a URL can view future stream displays, so do not share it publicly.

Event history and usage statistics (added September 22, 2026)

To understand usage and improve the service, the first draw records the date, connected host Twitch ID and login, game, mode, round and participant count. Unconnected hosts are not identified. These history records do not include participant names, IDs, comments or cards. Only the site operator can view the history. Identifiable event records are retained for 365 days, then host and room identifiers are removed and only daily totals by game and mode are retained. Counts include repeat participation. Contact the operator to request deletion or discontinuation of use.