PX Studio · Legal
Privacy policy
Last updated: July 31, 2026.
This notice explains what personal data PX Studio (the product of Pixelroom Studios GbR) processes, why, how long, who receives it, our roles under the GDPR, and your rights. Short version: we run no analytics, no ads and no marketing pixels. We process what is needed to run the studio for you, to bill paid plans, and (if you opt in) to send the newsletter.
1. Controller
Pixelroom Studios GbR
Wittener Bruch 42
58453 Witten, Germany
Email: mail@pxstudio.cloud
Represented by Danny Harms and Steffen Meurer. Contact us at the address above for any privacy request. We are not required to appoint a data protection officer.
2. Roles: when we are controller and when we are processor
We are the controller for personal data of our customers and website visitors that we process to provide the studio itself - for example account registration and login, plan billing, support, security logs, and the newsletter if you subscribe.
You (the streamer / account holder) are the controller for personal data that appears in your stream tooling because you connect a platform or configure widgets - for example chat messages, viewer display names, follower and subscription events, donation names and amounts, and similar stream events. For that processing we act as your processor (Art. 28 GDPR): we process those data only to provide the features you enable, on your documented instructions (your connections, settings and API use), and not for our own marketing.
The streaming platforms (Twitch, Kick, YouTube, Ko-fi, Discord and others) remain independent controllers of their own services under their own privacy notices.
3. Hosting, security and technical logs
The service runs on a server operated by IONOS SE (Germany). When you visit, the server processes technical request data your browser transmits (IP address, date and time, requested URL, user agent, referrer if present) in application and system logs. We use these logs only to operate the service, diagnose faults, measure load and defend against abuse - not to build advertising profiles. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, reliable service). Server logs are rotated on a short operational schedule and are typically retained for no longer than 30 days unless a concrete security investigation requires a short extension.
Connections are encrypted with TLS. Certificates are issued by Let's Encrypt
(Internet Security Research Group). Outbound transactional email (login links,
newsletter confirmations) is sent through our own mailbox on IONOS SMTP
(smtp.ionos.de).
4. Accounts and login
You can open or sign in to an account as follows:
- Email magic link. You enter your email address and we send a one-time login link. We store your email address and a short-lived login token.
- Twitch login. You authorize us through Twitch. We store your Twitch user ID, login name and display name. If you additionally connect your channel for widget data, we also store the login credentials ("OAuth tokens") Twitch issues for that connection and periodically fetch channel data (such as follower or subscriber counts) from Twitch on your behalf.
- Kick login. You authorize us through Kick. We store your Kick user ID and display name. If you additionally connect your channel for widget data, we also store the login credentials ("OAuth tokens") Kick issues for that connection, read your channel's title and category, and receive follow, subscription and gift notifications for your channel automatically (Kick's "webhook" system) on your behalf.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract / pre-contractual steps to provide the service you requested).
Is providing data required? An email address or a Twitch/Kick login is required to create and use an account - without it we cannot provide the studio. Connecting extra platforms (YouTube, Ko-fi, Discord), joining the newsletter, uploading media and creating API tokens are optional; if you do not use them, those features stay unavailable but the rest of the account can still work.
5. What we store for your account
Depending on how you use the studio, we may store:
- Email address and/or Twitch/Kick identity (ID, login name, display name)
- Account profile fields you set (for example a display avatar you upload)
- Your plan tier and related billing references (see §8)
- Widget and overlay configurations, scenes, layouts, notes, media favorites, automations and related studio settings
- Files you upload for use in overlays (images and similar media), stored on our server under your account
- Redeemed unlock codes and the resulting entitlements
- Team / mod access grants you create or accept, and related audit logs of actions taken with those grants
- API tokens you create for programmatic access
- Optional channel connections and the data they deliver (see §6-7)
- Optional Discord account link for community / support features (Discord user ID and username)
Legal basis: Art. 6 (1) (b) GDPR for running the studio for you; Art. 6 (1) (f) GDPR for security, abuse prevention and internal audit trails of privileged support access.
6. Stream platforms and third-party connections
Only when you connect a platform do we process data from it, on your behalf, to power widgets, alerts, chat overlays, bots and related features:
- Twitch / Kick. Channel metadata, follows, subscriptions, gifts, bits/cheers where available, chat messages and moderation events needed for the features you enable. OAuth tokens stay on our servers and are never shown in support views.
- YouTube. If you connect a YouTube channel (for the player, song requests, or a Socials handle), we store the login credentials Google issues for that connection and channel identifiers needed to search and play videos on your behalf. We do not read or write YouTube live chat.
- Ko-fi. If you connect Ko-fi: the webhook data Ko-fi sends for your page (such as supporter names and amounts), used only to drive your widgets.
- Discord. If you link Discord (for example for support tickets or community features), we store the Discord user ID and username linked to your account. If you configure a Discord webhook automation, messages you define are sent to the webhook URL you provide.
Stream events we keep for your account (alerts, follows, subs and similar bus events) are pruned after about 30 days, and earlier if your history exceeds an internal cap. High-frequency chat is primarily streamed live and is not kept as a permanent full chat archive. Legal basis for our processing as your processor / for running the features you requested: Art. 6 (1) (b) GDPR in relation to our contract with you; you determine the legal basis toward your viewers under your own responsibility.
7. Data we receive about third parties (viewers and chat) - Art. 14 GDPR
When you connect a platform, we may receive personal data that was not collected directly from the people it concerns (for example viewers). Sources are the APIs and webhooks of the platforms you connect (Twitch, Kick, YouTube, Ko-fi, Discord and similar). Typical categories: display names or usernames, chat message content, follow/subscription/gift/donation events, amounts where the platform sends them, and technical event identifiers and timestamps.
We process these data only to power the studio features you enable (overlays, alerts, bots, moderation helpers). We do not sell them, do not use them for our own advertising, and do not build marketing profiles of your viewers. Retention matches §13 (stream event history about 30 days; live chat primarily ephemeral). If you are a viewer and want to exercise GDPR rights about how a streamer uses our tools, contact that streamer as controller, or the platform; you may also contact us and we will help forward the request where we can identify the account.
8. Payments (Stripe) and unlock codes
Stripe. Paid plans (for example Basic, Pro, Ultra) are billed via Stripe Payments Europe, Limited and affiliated Stripe entities (including Stripe, Inc. in the United States). When you start a checkout or manage billing, you are redirected to Stripe. Stripe processes payment details (card or other payment method), billing address and related fraud-prevention data. We receive and store Stripe customer and subscription identifiers, plan status, and limited invoice/event metadata needed to unlock the plan and handle support - not your full card number. Legal basis: Art. 6 (1) (b) GDPR; where Stripe uses data for fraud prevention, Art. 6 (1) (f) GDPR / Stripe's own notices apply for Stripe's processing. Stripe participates in the EU-US Data Privacy Framework for relevant US transfers; see stripe.com/privacy and Stripe's DPF documentation.
Unlock codes (e.g. Etsy). Some premium widget unlocks may be sold through Etsy or similar. The purchase itself takes place on that marketplace under its terms and privacy policy; we only learn the code you redeem here, never your payment data from that marketplace.
8a. Consumer withdrawal and cancellation requests
If you use our online withdrawal function or request a subscription cancellation from your account, we process your name, email, contract description, account id (if signed in), technical metadata (IP, time) and the resulting correspondence to fulfil statutory consumer rights and to keep evidence of the request. Legal basis: Art. 6 (1) (c) GDPR (legal obligation) and Art. 6 (1) (b) GDPR (contract). Requests are retained as long as needed for compliance and dispute handling (typically up to the statutory limitation periods for the underlying claim).
9. Newsletter
If you join the newsletter on the website, we store your email address, the time of signup, confirmation status, unsubscribe status, an optional plan preference you select, and a technical consent marker (including IP at signup) to prove the double opt-in. We only send product and launch updates after you confirm the subscription link. You can unsubscribe at any time via the link in every newsletter email. Legal basis: Art. 6 (1) (a) GDPR (consent). Withdrawing consent does not affect the lawfulness of processing before withdrawal. Signing up is optional and not required to use the studio.
10. Cookies and similar storage
We only set cookies the site needs to function (§25 (2) TDDDG - Telecommunications Digital Services Data Protection Act; formerly TTDSG / essential cookies). None of them are for tracking, advertising or analytics. Because we only use strictly necessary storage, we do not show a consent banner for cookies:
usess- session cookie that keeps you logged in (about 90 days, sliding while you use the studio; HttpOnly, SameSite=Lax).oauth_state- a few minutes during a Twitch login to protect the login flow against forgery, then expires.kick_oauth- up to 10 minutes during a Kick login, same purpose.yt_oauth- up to 10 minutes during a YouTube connect, same purpose.
There are no third-party cookies, no analytics cookies and no advertising cookies. The editor and widgets may also use your browser's local storage for purely technical UI state (for example layout preferences on this device). That data stays in your browser unless you clear it. Accessing local storage for those UI functions is limited to what is necessary to provide the service you request (§25 (2) TDDDG).
11. Support access
If you contact us about a problem, someone from our team may open an internal support view of your account. It shows your plan, your connected platforms, your overlays, your unlocked widgets and the type and time of your most recent stream events. It never shows access tokens, session keys or the names of the viewers in your event history.
To reproduce a display problem we may also open a read-only snapshot of one of your overlays. That snapshot renders the saved state of your widgets. It cannot change anything, it does not join your chat, and nobody ever acts under your name.
Every such view is written to our internal audit log with who looked, at what, and when. Opening one of your overlays additionally writes an entry to your own account activity, so the access is on record for you too. Legal basis: Art. 6 (1) (b) and (f) GDPR (contract support and secure operation).
12. Recipients and processors
We do not sell personal data. We share it only where needed to run the service:
- IONOS SE (Germany) - hosting, server infrastructure, SMTP mail (processor under Art. 28 GDPR)
- Stripe - payment processing for plans (see §8); Stripe acts as independent controller for payment-method data it collects, and as our service provider for customer/subscription fulfilment metadata we need
- Let's Encrypt / ISRG - TLS certificates
- Twitch, Kick, Google/YouTube, Ko-fi, Discord - only when you connect or use those integrations; independent controllers of their platforms
Where a provider processes personal data on our behalf as a processor, we use contracts or terms that meet Art. 28 GDPR.
13. Transfers outside the EU/EEA
Hosting and mail stay in the EU (IONOS, Germany). Stripe, Twitch, Kick, Google, Ko-fi and Discord may process data in the United States or other countries outside the EEA. Where required, transfers rely on:
- an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for US organisations that are certified under it - Stripe is among the providers that participate for relevant processing), and/or
- the European Commission's Standard Contractual Clauses (SCCs) and the provider's additional safeguards,
as described in each provider's privacy and transfer documentation. You can request further information about the safeguards we rely on by emailing mail@pxstudio.cloud.
14. Retention
- Account data - for as long as the account exists; deleted when you delete the account (see §16), unless a legal retention duty applies (for example commercial or tax records related to paid invoices, typically up to 10 years under German commercial/tax law where we hold such records).
- Session cookie / server session - about 90 days of inactivity (sliding while you stay active).
- Magic-link / OAuth state tokens - minutes only.
- Stream event history - about 30 days (and earlier under an internal size cap).
- Newsletter - until you unsubscribe or we erase the address after a failed confirmation window / your erasure request. Proof of consent may be kept as long as needed to demonstrate compliance.
- Server logs - typically no longer than 30 days (see §3).
- Support audit logs - kept as long as needed for security and accountability of privileged access (typically no longer than 24 months unless a concrete dispute or investigation requires longer).
15. Security measures (Art. 32 GDPR)
We implement technical and organisational measures appropriate to the risk, including TLS encryption in transit; access control and authenticated sessions (session tokens stored as hashes); separation of support views so access tokens and viewer names are not exposed; least-privilege admin permissions with audit logging of privileged access; dependency and host maintenance on our production environment; and backups under our operational procedures. No measure is absolute; if a personal-data breach is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, affected users in line with Art. 33 and 34 GDPR.
16. Deletion and how to exercise your rights
You can download a machine-readable copy of your account and studio data yourself in the account settings of the studio ("Download my data" - JSON export under Art. 15 and Art. 20 GDPR). OAuth tokens, session secrets and API token secrets are never included in the file. You can also delete your account yourself there ("Delete account"). You can email mail@pxstudio.cloud from the address linked to the account for any other request (access, rectification, restriction, objection) or if the self-service tools are not enough. Deletion removes stored user data for that account: identity, configurations, uploads, entitlements, grants, connection tokens, Discord link and related studio content. Anonymised operational remnants (for example a support ticket row without personal content, or rotated logs) may remain. Stripe may retain payment records under its own legal duties.
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21), including the right to object to direct marketing where applicable. Where processing is based on consent, you may withdraw consent at any time with effect for the future. We will respond to requests without undue delay and in any event within one month of receipt (Art. 12 (3) GDPR); that period may be extended by two further months where necessary, in which case we will inform you.
You also have the right to lodge a complaint with a supervisory authority. For us, the lead authority is typically:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(LDI NRW)
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
You may also contact the authority at your habitual residence or place of work.
17. No automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR.
18. Children
The service is aimed at streamers and creators. It is not directed at children under 16. If you believe we have stored data of a child without appropriate authority, contact us and we will delete it.
19. Changes
We update this notice when the product or the law requires it. The "Last updated" date at the top always reflects the current version. Material changes will be reflected here; where appropriate we may also inform account holders by email or in-product notice.