Privacy Policy
This Privacy Policy explains what data ProvenAudience collects, why, how long we keep it, and the choices you have. It covers two very different kinds of data: the little we hold about you, our account holder, and the public Kick.com data we sample to produce audits.
1.Who we are
ProvenAudience is operated by [PLACEHOLDER: legal entity name], registered at [PLACEHOLDER: registered address] (“ProvenAudience”, “we”, “us”). We are the controller of the personal data described in this policy. If you have any questions or wish to exercise your rights, contact [email protected].
2.Data we collect about you (account holders)
We deliberately collect as little as possible about our own users:
- Account data — your email address, an encrypted password hash, and, if you enable it, two-factor authentication data. This is handled by our authentication layer (Better Auth).
- Subscription & usage data — your plan, your metered audit/API usage, and a record of billing events needed to run your subscription. We do not receive or store your wallet keys or payment credentials (see §7).
- Operational logs — standard server logs (such as IP address and request metadata) used to keep the service secure, enforce rate limits, and debug problems.
3.Public Kick.com data we process
To perform audits and maintain the market ledger, ProvenAudience processes data that is already public on Kick.com. This may include personal data relating to streamers and to people who post in public chat:
- Channel and stream statistics — viewer counts, followers, hours watched, stream titles, sponsor mentions read from titles, VOD stats, and social links, snapshotted over time.
- Public chat data — during a live audit we sample a channel’s public chatroom for roughly ten minutes. This includes chat usernames, public account identifiers, message text and message timing. We use this only to compute forensic signals (for example chatter-to-viewer ratios, timing patterns, duplicate-phrase and cross-channel overlap analysis).
We do not sample private messages, and we do not attempt to identify, contact, or build marketing profiles of individual chat participants. Chat data is processed as evidence for an aggregate audience assessment, not to evaluate any individual person.
4.Lawful basis
Where data-protection law applies, we rely on our legitimate interests (and those of our business customers) in verifying whether publicly promoted streaming audiences are genuine, in preventing advertising fraud in the iGaming sector, and in operating a market-intelligence service — using only data that has been made public by the individuals concerned on a public platform. We have weighed these interests against the rights of the individuals whose public data we process, and we mitigate the impact through data minimisation, the retention limits in §5, and the public-surface boundary in §6. For your own account and billing data, our basis is the performance of our contract with you and our legitimate interest in security. You may object to processing based on legitimate interests (see §10).
5.Retention & anonymisation
Raw chat transcripts (usernames + message text stored with a probe) are stripped after 30 days. Chatter usernames retained for cross-channel matching are anonymised after 90 days — the username is deleted and only a pseudonymous account identifier is kept for fraud-pattern math. A scheduled job runs this prune every day.
In practice this means the identifying content of public chat has a short life in our systems: after 30 days the raw transcript text is gone, and after 90 days the usernames themselves are removed, leaving only the anonymised, aggregate signals that make the audit useful. Permanent, non-identifying market history (such as per-channel hours-watched totals and category-level aggregates) is kept to provide the long-run intelligence the service exists to offer. Account and billing records are retained for as long as your account is active and for a reasonable period afterwards to meet legal, tax and accounting obligations.
6.The public-surface boundary
Individual chat participants are never identified on any public ProvenAudience surface. Public certificates, the verified directory and any shared or API output carry aggregate audience measurements and verdict-level reasoning only. Chat usernames, account identifiers, raw transcripts, and any reasoning that names other channels are stripped by construction before anything crosses a public boundary. This boundary is enforced in code, not merely by policy.
7.Payments
Subscription payments are processed in cryptocurrency by our third-party provider, OrbChain. We receive confirmation that a payment succeeded and the metadata needed to manage your subscription, but we do not collect or store your wallet keys, private keys, card numbers or other payment credentials. OrbChain’s handling of your payment data is governed by OrbChain’s own privacy policy and terms.
8.Cookies
We use only the cookies necessary to run the service — principally a session/authentication cookie to keep you signed in, and cookies set by our anti-abuse captcha (Cloudflare Turnstile) on sign-up and sign-in. We do not use third-party advertising or cross-site tracking cookies. See our Cookie Policy for detail.
9.Sharing & no sale of data
We do not sell your personal data. We share data only with the service providers that make ProvenAudience work — our hosting/infrastructure, our payment provider (OrbChain), our anti-abuse provider (Cloudflare) and our transactional email provider — each acting on our behalf under appropriate terms, and only with what they need. We may disclose data where required by law or to protect our rights, and we may transfer data as part of a corporate transaction, subject to this policy.
10.Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to our processing of your personal data, and to data portability. This includes people whose public chat data we have processed. To exercise any right — including a request that we remove or correct data relating to you or to a channel — contact [email protected] and we will respond within the time required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.
11.Security & international transfers
We take reasonable technical and organisational measures to protect data, including encryption in transit, hashed credentials, access controls and enforced retention limits. No system is perfectly secure, and we cannot guarantee absolute security. Our infrastructure and service providers may process data in countries other than yours; where required, we put in place appropriate safeguards for such transfers.
12.Contact
Privacy enquiries and data-subject requests: [email protected]