LlynupHelp

LEGAL

Privacy Policy

Effective date
September 16, 2026
Last updated
September 16, 2026
Version
1.0

This Privacy Policy explains how Lynup, operated by Brendon Baugh collects, uses, discloses, and retains information when you use Lynup.

For questions or privacy requests, contact support@lynup.xyz.

1. Information you provide

Depending on how you use Lynup, you may provide the following information:

  • Account and contact information, including email address, display name, artist or page name, password hash, public username, profile biography, profile links, and marketing preference.
  • Public profile media and settings, including avatars, banners, featured tracks, social links, creator-page settings, stream rules, goals, overlays, and alert designs or media.
  • Submissions and uploads, including links or files, artist and title information, notes, genre, email, connected community usernames, saved submission presets, and content-rights confirmations.
  • Community activity, including votes, nominations, challenges, competition participation, awards, recaps, Twitch chat messages and replies, and Vault or Twitch-related activity.
  • Payment and support information, including amount, currency, purchase type, Stripe Checkout or payment identifiers, transaction status, timestamps, creator recipient, and refund or dispute state. Raw card number and CVC data are entered into Stripe surfaces and are not collected into Lynup’s local database by the current implementation.
  • Creator payout information exposed through Stripe Connect, such as connected-account identifier, onboarding and capability status, requirements, balance and payout information, and transaction metadata. Stripe may collect identity, tax, business, banking, or verification information directly.
  • Private creator and administrator information, including saved-artist notes, moderation decisions, account tags or notes, blocks, support requests, feedback, deletion requests, copyright cases, and inbound support email.

2. Authentication, device, and security information

Lynup stores login sessions, session hashes, user-agent-derived device labels, signed device identifiers, hashed network identifiers, security-event records, email-verification and password-reset token hashes, and, if enabled, encrypted authenticator secrets and hashed recovery codes.

If you connect Twitch or Discord, Lynup receives provider user ID, username, email when supplied and verified by the provider, avatar URL, authorization scopes, and encrypted access or refresh tokens. A creator who connects Twitch bot features may also authorize chat, moderation, EventSub, reward, follow, subscription, gift, Bits, and related stream functions.

For breached-password screening, Lynup’s current integration sends only the first five characters of a SHA-1 password hash to the Pwned Passwords range service, with padding requested. It does not send the plaintext password or full hash.

3. Information collected through use of Lynup

Lynup records queue and session activity, playback and moderation states, creator analytics, page presence, referral and share attribution, integration events, API-token metadata, push-subscription details, notification delivery state, email delivery and engagement events, application errors, client error reports, and security logs.

Google Analytics loads on Lynup pages when a measurement ID is configured. The current implementation does not place Google Analytics behind an in-app consent gate. Google may receive browser, device, page, and interaction information under Google’s own policies and property settings.

First-party browser identifiers support presence and referral analytics. Interface preferences, current dashboard state, and notification settings may be stored in localStorage. Stripe, Google, Twitch, embedded media providers, and browser push services may set or use their own browser storage under their policies.

4. How Lynup uses information

Lynup uses information to:

  • Create and secure accounts; authenticate sessions; verify email; support password reset and optional MFA; prevent abuse; and investigate incidents.
  • Operate creator pages, queues, submissions, uploads, playback, embeds, chat, moderation, contests, votes, challenges, Vault features, overlays, integrations, recaps, and notifications.
  • Process purchases, confirm payment state, calculate and display creator balances and platform fees, enable Stripe onboarding and payouts, review refunds, and reconcile disputes, reversals, and fraud signals.
  • Provide creator and platform analytics, referrals, audience history, service monitoring, troubleshooting, backups, and product improvement.
  • Send transactional, security, queue, support, and service messages; send marketing messages where the account is not opted out; and honor unsubscribe choices.
  • Enforce creator rules and Lynup policies, handle copyright reports, comply with legal obligations, and protect users, providers, Lynup, and the public.

5. Public and private information

Public information may include creator pages, display or artist names, usernames, biographies, social links, profile media, featured content, live queue titles and positions, submitted artist/title/source information, priority label, connected Twitch or Discord community name, public chat, votes, competition results, awards, and published recaps.

Submission email addresses and submission notes are not included in the normal public queue projection. Creators, moderators, and administrators receive information needed for their roles. Private creator notes, raw security records, encrypted provider tokens, and most account and payment administration data are restricted to authorized interfaces.

A public link, livestream, overlay, or third-party embed can be copied or recorded by others. Lynup cannot control copies made outside its systems.

6. When information is disclosed

Lynup discloses information to the creator or moderator whose queue, page, competition, or community feature you use; to the public where a feature is designed to be public; and to administrators who operate, secure, support, and enforce the Service.

Lynup also discloses information to providers that perform the functions described below, to integration clients authorized by a creator, when you direct a share or external link, and when reasonably necessary to comply with law, enforce agreements, investigate fraud or abuse, or protect rights and safety.

  • Stripe for Checkout, payment processing, refunds, disputes, fraud review, connected-account onboarding, balances, and payouts.
  • Twitch for identity, streams, chat, moderation, bot commands, EventSub, rewards, subscriptions, gifts, Bits, and related creator tools.
  • Discord for connected account identity and email. Lynup does not currently operate a Discord server-message ingestion flow.
  • Spotify, YouTube and other Google media services, and SoundCloud for search, oEmbed, players, artwork, previews, and public media information.
  • Google Analytics for site measurement; Resend for transactional and marketing email, inbound support email, and delivery events; Pwned Passwords for range-based password screening; and browser push services for encrypted notifications.
  • Instagram and TikTok for public profile or social information where used; X/Twitter and Facebook when a user opens a share composer; and arbitrary media or website hosts selected by users.

7. Cookies and local storage

Lynup uses a login cookie that normally lasts up to 30 days, a signed device cookie that normally lasts up to 365 days for abuse controls, a session CSRF cookie, and short-lived OAuth state and return cookies that normally last about 10 minutes. Security attributes such as HTTP-only, SameSite, and Secure are applied where appropriate to the cookie’s function and deployment.

Presence and referral browser identifiers and some interface preferences are stored in localStorage without a source-defined automatic expiry. Clearing site data removes those browser copies but does not automatically erase server records already created from prior activity.

8. Retention

Lynup retains information for as long as reasonably needed to operate the Service, maintain account and transaction history, provide public or creator features, secure the platform, prevent abuse and fraud, resolve disputes and chargebacks, handle copyright cases, enforce agreements, meet legal obligations, and maintain backups. Many metadata and transaction tables do not have a fixed automatic expiry.

For queue-upload files, production cleanup begins after the source session has been ended for at least 14 days and runs on a daily schedule. Safeguards can keep a file longer when it remains referenced by another active or recent session. Submission metadata and history remain after the hosted file is removed. Abandoned quarantine files and some unreferenced uploads have separate cleanup paths that run when the relevant service activity occurs.

Twitch chat older than one day is pruned probabilistically when new messages are written, so one day is not a guaranteed deletion deadline. Current presence rows, expired sessions, and rate-limit records are pruned during relevant activity. Application error storage is capped by count. Backups and provider records can persist under separate operational or provider schedules.

9. Your choices and requests

You can edit many profile fields, disconnect Twitch or Discord, revoke login sessions, remove certain profile media or presets, unsubscribe from marketing email, delete a push subscription, and use creator or moderation controls available to your role.

A signed-in user may submit an account deletion request in account settings. Lynup reviews the request and may retain records needed for transactions, refunds, disputes, chargebacks, security, fraud and abuse prevention, copyright cases, agreement enforcement, legal obligations, and backups. Disconnecting a provider or clearing a browser does not delete historical copies already needed for those purposes or copies held by third parties.

You may request access, correction, or deletion of personal information by emailing support@lynup.xyz. Lynup will evaluate the request under applicable law and may need to verify your identity.

10. Security

Lynup uses measures such as salted password hashing, encrypted provider credentials, hashed session tokens, optional authenticator MFA, session revocation, CSRF and origin checks, rate limits, restricted administrator access, and filesystem permissions. No security measure is perfect, and Lynup does not guarantee that unauthorized access or loss can never occur.

11. Age

Lynup accounts, purchases, and creator payouts require an attestation that the user is 18 or older. Lynup does not knowingly offer those features to children and does not currently collect date of birth during signup. If you believe an underage person created an account, contact the privacy email above.

12. Changes and contact

Lynup may update this Privacy Policy as the Service or its data practices change. Material changes will receive a new policy version and effective date, and fresh acknowledgement may be requested where appropriate. Historical acknowledgement records are preserved.

Privacy questions and requests may be sent to support@lynup.xyz. Lynup is operated from Texas, United States.

Version history

Version 1.0September 16, 2026

Initial production policy.