Privacy Policy
ASSA is a service that lets streamers who broadcast to YouTube, Twitch and Kick at the same time manage their moderators' permissions in one place. This policy explains what personal data ASSA processes, why, and what rights you have over it.
ASSA is a preunec GmbH product. Because the company is an EU entity and the service is also offered to users in Türkiye, both the General Data Protection Regulation (GDPR) and Turkish Law No. 6698 on the Protection of Personal Data (KVKK) apply.
Data controller
The data controller is preunec GmbH. [preunec GmbH — registered address to be added]
For any request or question about your personal data: [privacy contact address to be added]
What we process
ASSA collects only what it needs to provide the service. The table below lists every category of data we hold, what it is for, and the legal basis for holding it.
| Data | What for | Legal basis |
|---|---|---|
| Email address, first and last name | Creating your account, verifying your sign-in, and sending you service notifications | Performance of a contract |
| Your password | Stored only as an irreversible argon2id hash. The password itself is never recorded | Performance of a contract |
| Linked platform accounts (platform id and username) | Matching your account on a streaming platform to your ASSA account | Performance of a contract |
| Platform access and refresh tokens | Assigning moderators and reading the moderator list on your behalf. Stored encrypted with AES-256-GCM | Performance of a contract |
| Workspace, memberships and granted capabilities | Determining who holds which permission — the core of the service | Performance of a contract |
| Audit events | A record of moderator actions taken on the streaming platforms. Contains data about third parties — see the separate section below | Legitimate interest |
| IP address and security logs | Detecting abuse and rate-limit violations | Legitimate interest |
Third parties affected by a moderation action
This is the part of ASSA that needs the most care, and it deserves its own explanation.
ASSA observes moderator activity on the streaming platforms. When a moderator times out or bans a viewer, that action is recorded in ASSA's audit trail — and that viewer never signed up for ASSA and in most cases does not know it exists.
We deliberately keep what we hold about those people to a minimum: their platform user id and display name, and nothing else. We do not store message history, conversation content or profile information.
The legal basis is legitimate interest: a broadcaster needs to know what happens on their own channel and to be able to detect actions taken outside somebody's permissions. Audit events are deleted after 12 months.
If you believe you appear in such a record and want your data removed, contact us at [privacy contact address to be added].
Google user data
When you link your YouTube account, ASSA accesses it through Google APIs. ASSA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: we use data from your Google account only to do the job ASSA does for you — identifying your channel and, when you ask for it, assigning moderators. We do not use it for advertising, do not sell it, do not allow humans to read it, and do not process it for any other purpose.
How we protect platform tokens
Platform access tokens carry the authority to act on your behalf, so they get special treatment.
Tokens are stored encrypted with AES-256-GCM and the encryption key is held outside the application. They never appear in a log line, an error message or an API response.
When you unlink a platform, ASSA forgets the token. There is a limit to what that means and we would rather say it plainly: ASSA deleting the token does not withdraw the permission the platform granted. To remove it completely you also need to revoke ASSA's access in that platform's own account settings.
How long we keep it
We do not keep data for longer than it is needed.
- Account data — for as long as your account exists; fully deleted 30 days after a deletion request
- Audit events — 12 months
- Security and rate-limit logs — 90 days
- Verification codes — 10 minutes
- Incomplete sign-up sessions — 24 hours
Your rights
Under GDPR and KVKK you have the following rights over your personal data:
- To know what data about you is processed, and to access it
- To have inaccurate or incomplete data corrected
- To have your data erased
- To have processing restricted
- To receive your data in a portable format
- To object to processing based on legitimate interest
- To lodge a complaint with a supervisory authority
How to exercise them
You can change your account details — your name, email address, password and linked platform accounts — directly in the account settings screen inside the application.
For full deletion of your account, or a copy of your data, write to [privacy contact address to be added]. We will respond within one month.
What ASSA cannot do
We state this as part of the policy because setting the right expectation is part of privacy.
ASSA is a governance layer: it decides who is permitted to do what, projects that intent onto the platforms, and records what happened. It cannot **prevent** an action that takes place on a streaming platform. Platforms grant moderators full native powers and ASSA cannot narrow them. When an action falls outside somebody's permissions, ASSA detects and reports it — it does not stop it in advance.
Changes to this policy
We may update this policy from time to time. If a change is significant we will notify the email address on your account. The date at the top of the page is when the text was last updated.