Who is responsible
We have not yet published the entity responsible for this data. Until we do, this policy describes what the service holds and why, but does not name a controller you could address a formal request to. Requests sent to Hypeory support will still be answered.
What we collect
Only what running the board needs.
- Your account. The email address you sign in with, a display name and Hypeory handle if you choose one, and identifiers linking you to our sign-in provider and payment processor. There is no password to store — sign-in is a one-time code.
- Payments. The amount, currency, the processor's payment identifiers, and which creator and month the boost was for. We never receive or store card numbers; those go to the payment processor directly.
- Channels. For any listed channel: the platform's own account id, handle, display name, link, and profile picture, taken from the platform's public data.
- Verification. When you connect a platform we receive the channel's id, handle, name, picture, and the verified email on that account. We never see your password, we ask for no permission to post or change anything, and the access token is revoked as soon as the check finishes — we keep no standing access to your platform account.
- Profile visits. A daily count per channel, split only by whether the visitor arrived from the leaderboard, elsewhere on Hypeory, another site, or directly. No address, device, cookie or account is attached to it, so it cannot be traced to a person, including by us.
- Abuse controls. To rate-limit sign-in codes, checkout, reports and submissions we keep short-lived counters keyed on the network address a request arrived from, and nothing else about it.
- Reports and messages. What you write in a report, and any contact address you choose to add — reporting needs no account, and leaving that field blank means we hold nothing identifying you. Support email is kept as long as needed to answer it.
- Staff actions. Decisions taken in the admin console are recorded with who took them and the address they were taken from, so a moderation decision can be accounted for.
Cookies and local storage
Hypeory sets no advertising or tracking cookies and runs no third-party analytics.
hypeory_session— your signed-in session. Strictly necessary; it exists only once you sign in.hypeory_oauth— a short-lived token that protects the round trip to Twitch or Google against forgery. It is cleared the moment the round trip finishes.hypeory-theme— your light or dark preference, kept in your browser's local storage. It never reaches us.
The human check in front of sign-in codes is provided by Cloudflare Turnstile, which sets what it needs to tell a person from a script.
Why we use it
Where the law asks us to name a basis for processing:
- To perform our agreement with you — taking a payment, creating the placement, showing the position, running your studio, letting you sign back in.
- Our legitimate interests — keeping the board honest (rate limits, bot filtering, fraud and chargeback handling), counting visits in aggregate, diagnosing outages, and defending legal claims. You can object to processing on this basis; see below.
- Legal obligations — keeping payment, tax and complaint records for as long as the law requires.
- Consent, where we ever ask for it, which you may withdraw at any time.
We do not sell personal information, and we do not profile you for advertising.
What is public
A listed channel's name, handle, link, picture, division, Hype Points, position and verification mark are public to anyone, including search engines, and closed months stay published as an archive. Who paid is never public: a creator sees how many people backed them, never which people, and the public boost timeline names the creator, never the payer. If you are a creator and you do not want to be listed at all, opt out — it is permanent and blocks re-listing.
Who else sees it
- Our payment processor, for checkout and payment confirmation. Its own privacy notice covers the card details it collects.
- Our hosting, database and sign-in providers, so the site can run and send you a code.
- Twitch and Google, when you verify a channel — the round trip happens on their login, under their policies.
- Advisers, authorities, or a buyer of the service, where the law requires it or the service changes hands.
Some of these operate outside your country. Where data moves, we rely on the safeguards those providers offer for such transfers.
Platform connections and YouTube API Services
Hypeory uses YouTube API Services to confirm channel ownership and read public channel information such as a title and profile image. By verifying a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy.
You can review or revoke Hypeory's access at any time from Google's permissions page, or for Twitch from your Twitch connections settings. Because we revoke the token ourselves as soon as a check finishes, there is usually nothing left there to remove.
How long we keep it
- Your account stays until you ask us to close it.
- Payment records and the Hype Points ledger are kept for accounting, tax, fraud and dispute handling. The ledger is the board's own arithmetic and is never rewritten — a closed month must still add up.
- Rate-limit counters expire on their own, within hours.
- Visit counts are daily totals with no identity in them, kept as history for the studio.
- Reports and moderation records are kept as long as needed to act on them and to show a decision was accounted for.
- An opt-out is kept permanently on purpose: it is the record that stops the channel being listed again.
Your rights
Depending on where you live, you may ask for access to your data, correction, deletion, a portable copy, restriction, or to object to processing based on legitimate interests, and you may withdraw consent where we relied on it. Write to Hypeory support; we may need enough detail to find your records, and we answer within the period the law sets. You may also complain to your local data protection authority. Note that a public channel's own information does not become private by being listed — the remedy there is to remove the listing, which opting out does.
Children
Hypeory is for adults. Paying for a placement and managing a profile are limited to people aged 18 or over, and we do not knowingly collect data from children. If you believe a child has used the service, write to Hypeory support and we will delete what we can identify.
Changes
We update this policy when the service or the law changes, and the date at the top is the current version. When a change is material we will say so rather than letting it pass quietly.