Legal · Last updated 28 September 2026
Privacy policy
StackLive is built to know as little about you as possible. This page lists everything we keep, why, and for how long.
- No passwords: you log in on Twitch or Kick, never on our site. pump.fun streamers do not log in at all; they sign a message with their wallet.
- No emails: Kick returns an email address with the login; we discard it immediately and never store it.
- No platform tokens: the access token is revoked right after we read your user ID.
- No ad trackers and no third-party analytics cookies.
- Wallet addresses and transactions are public on Solana by nature. We cannot make them private.
We look up Twitch and Kick channels through the platforms' official APIs. Platform data is cached for no more than 24 hours, always shown with a link back to the channel, and never re-published in bulk through our API.
pump.fun has no official public API. For pump.fun live streamers we read public profile data from the same public web endpoints the pump.fun site uses: username, profile ID, the wallet that owns the profile, avatar URL, follower count, and the live status, title and viewer count of their coin's stream. We cache profiles for at most 5 minutes and the live list for 30 seconds, always link back to pump.fun/profile/<username>, and never re-serve that data in bulk. We never ask for a pump.fun login or password.
| Data | Why | How long |
|---|---|---|
| Platform and user ID | Derives the vault address; public on-chain. Numeric for Twitch and Kick; the profile UUID (32 hex characters) for pump.fun | Permanently (it is part of the vault address) |
| Login (channel name) | Links to the channel and finds the streamer page | Refreshed at least every 24h; deleted on full opt-out |
| Display name | Shown on the streamer page | Refreshed at least every 24h; deleted on full opt-out |
| Avatar URL | Hotlinked from the platform CDN; we never copy the image | Refreshed at least every 24h; deleted on full opt-out |
| pump.fun profile wallet, follower count, live status | Public on the pump.fun profile; the wallet can become the payout address and signs pump.fun claims | Cached for up to 5 minutes (live list: 30 seconds); the wallet stays in the evidence record if it is bound |
| Payout evidence records | Public proof of why a payout address was bound (excerpt, source link, hashes; for pump.fun the signed message, signature and signer wallet) | As long as the vault exists; public by design |
| Bound wallet address | Enforced by the program; public on-chain | As long as the vault exists |
| Attestation records | Public log that makes misuse visible | Permanently; contains no personal data beyond the above |
| Hashed IP of claim requests | Rate limiting and abuse prevention | Up to 30 days |
When you log in with Twitch or Kick, we receive a one-time code, exchange it for a token, read your numeric user ID, login and display name, and revoke the token immediately. We ask for no permissions beyond reading your own basic profile. The result is a signed session cookie that expires after 15 minutes.
pump.fun streamers prove ownership with Sign-In With Solana instead: their wallet signs a plain-text message that names the profile and the payout wallet. Signing moves no funds and gives us no access to the wallet. We keep the message, the signature and the signer address as a public evidence record, because they are what makes the binding checkable by anyone.
| Name | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you logged in during a claim or opt-out (HTTP-only, signed) | 15 minutes |
| OAuth state cookie | Protects the login redirect against forgery (HTTP-only, encrypted) | 10 minutes |
| Last wallet | Remembers which wallet app you connected, not its keys (localStorage, never sent to us) | Until you clear it |
| Launch draft | Keeps an unfinished launch form (localStorage, never sent to us) | Until you clear it |
Our hosting provider keeps standard request logs (IP address, user agent, time) for security and debugging, for a short period. We do not build profiles of visitors.
Streamers can request deletion by choosing full opt-out on the opt-out page, after logging in with the same account (pump.fun streamers sign with their profile wallet instead). We then delete everything except the public on-chain facts: the platform, the user ID and the vault address, and any evidence behind a binding that already moved funds. We also delete cached data when a platform tells us an account was deleted, and when you revoke our app in your Twitch or Kick settings.
We do not sell data. We share it only with the processors that run the service (hosting, database, RPC and key management), under their standard data-protection terms, and when the law requires it.
Depending on where you live you may have rights to access, correct, delete or object to processing of your data. A privacy contact address is coming soon; until then, the opt-out page handles deletion.