Skip to content
PrismaBot Back to overview

Hosted Twitch and Discord service

Service privacy notice.

How information is processed while PrismaBot operates its managed application, bots, workspaces, overlays, and provider integrations.

Effective August 12, 2026 Controller Christopher Schmidt Model Managed SaaS
On this page 1. Scope 2. Controller and roles 3. Hosted service model 4. Information processed 5. Purposes and legal bases 6. Customer-directed processing 7. Storage and retention 8. Recipients and transfers 9. Automated actions 10. Your rights 11. Security 12. Children 13. Changes

1. Scope

This notice applies to the hosted PrismaBot service, including its administration interfaces, Discord and Twitch bots, workspaces, OAuth connections, overlays, browser sources, automation, and support operations.

This is the service notice. Processing associated only with the public pages at prismabot.org is described separately in the Website Privacy Notice. Discord, Twitch, YouTube, and other connected providers publish their own privacy notices.

2. Controller, contact, and privacy roles

PrismaBot is owned and operated by Christopher Schmidt. Privacy questions and requests can be sent to [email protected].

Christopher Schmidt is responsible as controller for service access, account and workspace administration, security, support, abuse prevention, and the operation of PrismaBot. A customer or community administrator may separately determine why PrismaBot processes community content and member activity through features that they configure. For that customer-directed processing, the customer is normally the controller and PrismaBot acts on its instructions as a service provider or processor where applicable.

Customers remain responsible for identifying their own lawful basis, providing required community notices, selecting proportionate features and permissions, and responding to requests that depend on their decisions. Where a data-processing agreement is required, it must be completed before the relevant processing begins; contact [email protected].

3. Hosted service model

PrismaBot is a managed online service operated on infrastructure controlled by PrismaBot. Customers authorize Discord, Twitch, and optional providers and configure their workspaces through the service; they do not receive or operate the PrismaBot application runtime.

Tenant and workspace boundaries separate the settings, credentials, content, permissions, and operating records of different customers and communities. Provider credentials are encrypted and made available to the relevant service component only when needed for an authorized provider operation.

Access by PrismaBot personnel is restricted to authorized operational, security, legal, and support purposes. Administrative activity is recorded where the service provides an audit trail.

4. Information PrismaBot may process

The exact information depends on the platforms and features a customer connects or enables. PrismaBot may process:

  • account and identity information such as platform user IDs, usernames, display names, avatars, email addresses when supplied, roles, permissions, memberships, and authentication records;
  • Discord server, channel, role, interaction, member, message, reaction, moderation, and event information needed for configured Discord features;
  • Twitch channel, user, chat, stream, follower, subscriber, reward, moderation, and EventSub information needed for configured Twitch features;
  • workspace settings, commands, responses, notification rules, schedules, moderation rules, polls, giveaways, automation, and related execution history;
  • overlay and Live Canvas documents, browser-source state, uploaded media, sounds, alert settings, and other content supplied through the service;
  • OAuth access and refresh tokens, bot credentials, API keys, webhook configuration, and other secrets required for authorized provider connections;
  • service logs, audit records, job and delivery state, usage and quota records, errors, security events, device and request information, and support correspondence; and
  • subscription, transaction, and billing-contact information if paid plans are introduced, with payment details handled by the selected payment provider.

PrismaBot does not sell personal information, use workspace content for third-party advertising, or use private customer content to train general-purpose machine-learning models.

5. Purposes and legal bases

PrismaBot processes information to provide requested service features, authenticate users, maintain workspace access, connect authorized providers, execute commands and automation, deliver notifications and overlays, operate subscriptions and quotas, answer support requests, secure the service, prevent abuse, diagnose faults, maintain backups, and meet legal obligations.

Where the GDPR applies, service access and requested features are generally processed to perform a contract or take requested pre-contractual steps under Article 6(1)(b). Security, reliable operation, support, abuse prevention, and proportionate product administration may rely on legitimate interests under Article 6(1)(f). Legal records may be processed under Article 6(1)(c). PrismaBot relies on consent under Article 6(1)(a) only where a feature or applicable law specifically requires it, and consent can then be withdrawn for future processing.

For community processing configured by a customer, the customer determines the applicable lawful basis. PrismaBot processes that information to deliver the configured feature and according to the customer's lawful instructions.

6. Customer-directed processing

Tenant owners and authorized workspace administrators choose which servers and channels to connect, which users receive access, which features run, what content is supplied, and how automation or moderation is configured. They must connect only communities and accounts they are authorized to administer.

Customers should minimize requested permissions, review automated actions, set appropriate retention and access rules, and provide community members with a practical contact route for questions or challenges. PrismaBot may reject an instruction that is unlawful, unsafe, outside the service, or contrary to connected-provider rules.

7. Storage and retention

Service information is stored in PrismaBot-controlled databases, object storage, logs, and protected backups. Workspace configuration and content are retained while the relevant workspace or feature remains active and until they are deleted, the customer relationship ends, or retention is no longer necessary for the purpose collected.

Provider credentials are retained while the corresponding connection is active and are revoked or deleted when no longer needed, subject to protected backup expiry. Operational and audit records are retained for the period reasonably needed for security, troubleshooting, abuse prevention, service integrity, and legal claims. Account, support, and transaction records may be kept longer where law or a legitimate documentation need requires it.

When live data is deleted, residual copies may remain temporarily in restricted rolling backups until those backups expire or are safely replaced. During pre-release, export and deletion requests can be sent to [email protected].

8. Recipients and international transfers

Information may be available to authorized PrismaBot operations or support personnel, infrastructure and security providers, communication and payment providers where used, and third-party platforms or APIs that a customer deliberately connects. Information may also be disclosed where required by law or necessary to protect users, the service, or another person's rights.

Provider requests are sent only as needed to carry out the relevant connection or action. PrismaBot does not sell service information or disclose it to advertising networks.

Some providers, including connected social platforms, may process information outside the European Economic Area. Where PrismaBot selects a provider that requires an international transfer, applicable contractual or other legally recognized safeguards will be used where required. Connected platforms remain responsible for transfers they conduct under their own terms.

9. Automated moderation and actions

PrismaBot can apply customer-configured rules, such as detecting blocked terms, limiting links, assigning roles, posting notifications, or taking moderation actions. These actions follow the selected workspace configuration; PrismaBot does not independently decide the community rules.

Customers should use proportionate settings, maintain human oversight, and provide a way to challenge mistakes. PrismaBot must not be used as the sole decision-maker for decisions that produce legal or similarly significant effects on individuals.

10. Access, correction, deletion, and other rights

Subject to applicable law, individuals may request access, correction, deletion, restriction, or portability of personal data and may object to processing based on legitimate interests. Where processing relies on consent, consent may be withdrawn for the future. Requests can be sent to [email protected].

If a request concerns a particular Discord server or Twitch channel, contacting that community's administrator may help identify the relevant workspace and customer instructions. PrismaBot may need enough information to verify identity, locate the record, and protect other users.

Removing PrismaBot from a community or revoking a provider grant stops or restricts future platform access, but does not by itself erase every service record or backup. A deletion request can be made separately. Individuals also have the right to lodge a complaint with a competent data-protection supervisory authority.

11. Security

PrismaBot uses organizational and technical measures intended to protect service information, including restricted administrative access, encrypted credential storage, scoped workspace permissions, service monitoring, backups, and auditable operational controls. No online service can guarantee absolute security.

Customers must protect their accounts, grant only necessary permissions, review authorized users, and promptly report suspected compromise to [email protected].

12. Children and age requirements

PrismaBot is not intended to bypass the minimum-age requirements of Discord, Twitch, or any connected provider. Customers must follow the age, consent, and child-safety rules applicable to their communities and jurisdictions.

13. Changes to this notice

This notice may change as PrismaBot's service, providers, features, or legal obligations change. The effective date at the top identifies the current version. Materially new processing will be described before it begins, and additional notice or consent will be provided where required.

PrismaBot
[email protected] Terms of Service Website Privacy Service Privacy