Privacy Policy
Last updated: 13 September 2026
Who is responsible
PreChat (prech.at) is operated by Noah Larsen, who is responsible for the personal data described here. PreChat sends email alerts about streamers chatting in their own offline Twitch chat.
What we use and why
We use your email address, account ID, chosen streamers, watch settings, and sign-in and delivery records to provide the subscriptions you request. Providing your email and verifying it are necessary to use the service. We use network information, including your IP address, for security checks and rate limits; persistent email and IP rate-limit keys are stored as keyed hashes.
We obtain public streamer profiles, stream status, and broadcaster message identifiers and timing from Twitch to decide when to send alerts and prevent duplicates. We do not store Twitch chat text. Searches are sent to Twitch through our server; profile images load from Twitch’s image service, which receives your IP address and browser request information.
Our reasons for processing
We process account and watch data to provide the service you request. We rely on our legitimate interests in protecting PreChat and its users to prevent abuse, secure sign-in, and avoid duplicate or unwanted email. Optional analytics rely on your consent. The signup checkbox acknowledges this policy; it does not enable optional analytics.
Email and service providers
Amazon SES receives the recipient address and email content to deliver sign-in codes and alerts. We process delivery feedback, bounces, and complaints to prevent unwanted email. Our hosting infrastructure processes requests to serve the website. Twitch supplies streamer information; we do not send it your email address.
Processing locations
We use PostHog’s EU service. Our providers operate internationally, so some processing may take place outside your country, including outside the European Economic Area. Contact us for information about processing locations and applicable transfer protections.
Essential cookies and browser storage
A sign-in challenge cookie lasts 10 minutes, and a session cookie keeps you signed in for up to 30 days. When Cloudflare Turnstile is enabled, an IP-bound browser-check cookie lasts 15 minutes. These cookies support authentication and abuse protection.
We also save your accept or reject choice in your browser’s local storage and honour it for 365 days before asking again. You can change it sooner in Cookie settings or clear it through your browser. The signup checkbox is kept only in the current page’s memory and resets when you reload.
Cloudflare Turnstile
Turnstile checks browser and network signals, including your IP address, to detect bots. It runs independently of analytics consent. We do not send Cloudflare your email, searches, or watch list. Cloudflare also uses these signals to improve its bot detection; see its Turnstile Privacy Addendum.
Optional analytics
Only after you accept optional analytics, we send PostHog EU events for opening the site, signing in, and adding, pausing, resuming, or removing a watch. Events include a timestamp and a random identifier held only in page memory. We do not attach account details, emails, codes, tokens, page URLs, searches, or watch lists. We do not use session recordings or automatic click tracking. Network requests still involve connection information such as your IP address; the event payload disables geolocation enrichment.
Rejecting optional analytics does not limit subscriptions. Withdrawing consent in Cookie settings stops future events and cancels pending requests; it does not erase events already received. Analytics events are not linked to your PreChat account. We use PostHog’s Free plan, which retains analytics events for up to one year.
How long we keep data
Your account and watches remain until you remove them or delete your account. Sign-in codes expire after 10 minutes, sessions after 30 days, and single-use alert management links after seven days. Expired authentication records and rate-limit records older than one hour are removed during cleanup.
Email delivery records are normally removed after seven days, except while a send is in progress. Email payloads are encrypted while queued and cleared after sending or cancellation. Hashed bounce and complaint suppression records have no automatic expiry, so deleting an account does not accidentally restart unwanted mail.
Shared streamer timing and conversation state can remain after you remove a watch because it supports monitoring for other viewers and safe restarts. Backup copies may retain deleted data until those copies are removed; an automatic backup expiry schedule has not yet been confirmed.
Your choices and rights
Sign in to pause or remove watches, or select Delete account to remove your account, watches, sessions, sign-in links, and queued emails. A message already being sent may still arrive. “Manage my subscriptions” in an alert signs you in using a private, single-use link valid for seven days. An email client’s unsubscribe action stops that watch without signing you in.
You can contact Noah Larsen to request access, correction, deletion, or a portable copy of your personal data, or to request restriction or object to processing where applicable. You can withdraw analytics consent at any time without affecting earlier lawful processing. You can also complain to your local data protection authority.
Privacy contact: [email protected]