TOGGL3 TV — Privacy Policy
Draft — under legal review; not yet in effect.
This Privacy Policy explains how [LEGAL ENTITY NAME] (“TOGGL3,” “we,” “us”) collects, uses, discloses, retains, and otherwise processes personal information when you use TOGGL3 TV — toggl3.tv, creators.toggl3.tv, id.toggl3.tv, our mobile and television applications, and related services (the “Service”). It is part of the agreement described in our Terms of Service.
TOGGL3 is a community for adults; we do not knowingly collect information from anyone under 18 (see Section 8).
We are committed to collecting only the information the Service needs and to processing it in ways that respect your privacy. In particular, we do not sell personal information and we do not share it for cross-context behavioral advertising, and we embed no third-party analytics, advertising, or session-recording technology on the Service.
1. Information we collect
We collect the categories of information below. The table in Section 1.11 lists each category against the purposes we process it for and the legal basis for doing so.
1.1 Account information. When you create an account we collect your email address and username. When you first visit the Service we ask for your date of birth to confirm you meet our age requirement:
- If you are not signed in, the date of birth you enter is used only in your browser to confirm your eligibility and is not sent to, or retained by, TOGGL3.
- If you enter it while signed in, or when you create an account, we store your date of birth as a full calendar date (month, day, and year — not a year only). This is stored in the same way as your other account information, as described in our Privacy Policy and the table in Section 1.11.
Sign-in credentials (password, passkeys, authenticator enrollment, recovery codes) are held by our identity service; TOGGL3’s application systems store an account identifier and your username/email and an email-verified flag, never your password.
1.2 Information you provide when you act on the Service. This includes chat messages, follows, saves, reports you file, appeals, reactions, poll/prediction participation, and your activity in guilds and tournaments (including any free-text messages you submit, guild announcements, and application answers). We also receive messages and information you provide when you contact support or file a copyright, safety, or intimate-image removal request.
1.3 Purchases and payments. When you buy a Membership, channel subscription, tip, or gift, our payment processor (Stripe) collects your payment details; TOGGL3 does not receive full card numbers. We keep transaction records: what was purchased, amounts, timestamps, subscription status, processor identifiers, and — for gifts — the recipient contact information needed to deliver the gift. Purchases through app stores are processed by the store, which shares transaction confirmations with us. For gifted channel subscriptions and tips, we do not store the recipient’s name or shipping address.
1.4 Creator payout information. Creators who enable monetization complete onboarding directly with our payment provider, which collects identity, tax, and bank information under its own hosted onboarding and privacy policy — not on TOGGL3. TOGGL3 receives only that the creator has onboarded, capability flags, and payout account identifiers; it does not receive your bank details, social security number, or tax forms.
1.5 Viewing and usage information. While you watch, we record playback usage to meter free viewing and to understand aggregate retention. While signed in, this is recorded against your account. For anonymous viewers we use a signed first-party token (a cookie) rather than any account identifier. We also collect product-usage events (for example, which discovery surfaces led to a purchase) using a first-party anonymous visitor identifier stored in your browser.
1.6 Device, network, and log information. IP addresses, browser/device type, and request logs are processed to deliver the Service, secure it, enforce rate limits, and investigate abuse. For security records (for example, abuse and fraud signals) we store IP addresses in hashed form. Our infrastructure and content delivery are fronted by Cloudflare, which processes IP addresses and request metadata as our service provider to route, cache, and protect traffic.
1.7 Cookies and local storage. We use strictly necessary cookies and browser storage:
- the terms-acceptance cookie (
toggl3_age_ack); - a once-per-device onboarding marker (
toggl3_onboarded); - a viewer identifier used to account for live viewing without a Membership (
t3_viewer); - a visitor identifier stored in your browser to credit creator referrals and measure signup funnels;
- sign-in session state.
We do not use third-party advertising cookies. We do not currently require a consent banner for strictly necessary cookies.
1.8 Communications. Support requests, reports (including copyright and safety reports, which may be filed without an account and include the contact details the filer provides), and email interactions (delivery/bounce status for messages we send).
1.9 Information we collect about the Service you use. This includes media metadata about streams and recordings (titles, tags, visibility, durations) and aggregated retention and viewer counts. We do not store any maturity or age classification for media.
1.10 Information about other users. When you follow, block, report, or otherwise interact with other users, we record that activity, and other users may see your public profile (handle, display name, and any public information you add).
1.11 What we collect — purposes and legal basis.
| Information we collect | Purpose(s) | Legal basis |
|---|---|---|
| Email, username, handle, account id | Create and manage your account; send transactional/security messages | Contract (account) and our legitimate interests in operating the Service |
| Date of birth (full calendar date) | Confirm you meet our 18+ requirement; enforce eligibility | Our legitimate interest in legal compliance and safety |
| Chat, follows, saves, reports, guild/tournament activity | Operate the social features of the Service; enforce our rules; investigate abuse | Our legitimate interests in operating the Service and enforcing its rules |
| Contact/support and safety report details | Respond to your requests and legally required removals | Our legitimate interests in responding to you and complying with the law |
| Purchase/payment records, gift recipient contact | Fulfil your purchases; deliver gifts; manage billing and refunds | Contract (your purchase) |
| Creator payout/onboarding status (not bank or tax data) | Let creators be paid and comply with tax reporting obligations | Contract; legal obligations |
| Viewing usage, metering token, visitor identifier | Deliver viewing; measure free allowances; understand aggregate usage and funnel | Our legitimate interests in operating and improving the Service and in billing; contract |
| IP address (hashed for security records) | Deliver and secure the Service; enforce rate limits; investigate abuse and fraud | Our legitimate interest in security and our legal obligations |
| Device/network/log data (via Cloudflare) | Deliver and protect the Service | Our legitimate interest in operating and securing the Service |
| Media metadata (titles, tags, durations, visibility) | Deliver streams, recordings, and clips; support discovery | Our legitimate interests in operating the Service |
| Your public profile as visible to others | Enable social discovery and participation | Your consent (you choose to make it public) or our legitimate interest in operating social features |
| Tournament Host Terms acceptance (version and time) and per-tournament publish confirmations | Let creators host community tournaments; evidence what a host agreed to; enforce the Host Terms | Contract (the Tournament Host Terms) and our legitimate interest in enforcing our rules |
| Player registration confirmation (version and time) | Register you for a community tournament; evidence what you agreed to, including that the host may see and broadcast your feed | Contract (the Community Tournament Terms) and our legitimate interest in enforcing our rules |
| Feed-key records (hashed key and its last characters, issue and revoke times, revoke reasons) | Admit only a current player’s feed; stop feeds when a player’s participation ends; investigate misuse | Our legitimate interest in security; contract |
| Control Room credential records (hashed credential, channel, tournament, and when it was created, expires and was revoked) | Admit only the host’s current Control Room broadcast; investigate misuse | Our legitimate interest in security; contract |
| Player-feed technical data (picture size, frame rate where available, bitrate, connection times, sending IP address) | Admit feeds, enforce feed limits, show the host a feed’s status | Our legitimate interest in operating and securing the Service; contract |
1.12 Community tournaments. When creators host tournaments on their channels (“community tournaments”), we process the following in addition to the information above:
- Host records. When a creator accepts the Tournament Host Terms we record the version accepted, the points confirmed, and when. Each time they publish a tournament we record the three confirmations made for it (not competing; no money through TOGGL3; player feeds used only in the broadcast) and when.
- Player registration records. When you register for a community tournament we record the three points you confirmed, the version of the Community Tournament Terms, and when.
- Feed-key records. If the host uses player feeds, we issue you a temporary feed key at check-in. We store only a one-way hash of the key and its last few characters (so you can recognise it), with when it was issued, revealed and revoked and why it was revoked (for example elimination, withdrawal, disqualification, or the tournament ending). We never store the key itself.
- Control Room credential records. When a host’s Control Room sends their broadcast, we issue it a short-lived publishing credential. We store only a one-way hash of it, with the channel and tournament it is for and when it was created, expires and was revoked.
- Player-feed technical data. While your feed is being sent we process its technical characteristics (picture size, frame rate where available, bitrate) and connection details (connection times and the sending IP address) to admit the feed, enforce per-tournament feed limits, and show the host whether your feed is being received. These are used while the feed is live and are not stored beyond our ordinary service logs.
- Raw feed media is not stored. Your feed is sent to the host’s Control Room only. TOGGL3 does not publish or record your raw feed. The host’s broadcast, including any part of your feed the host shows in it, is recorded like any other stream on the host’s channel and kept under the same recording and retention rules.
- Control Room camera and microphone. A host’s Control Room runs in the host’s browser and may use the host’s camera and microphone if the host allows it. That audio and video is composed in the browser into the host’s broadcast; TOGGL3 stores nothing from it beyond the broadcast itself and its recording.
2. How we use information
- Provide and operate the Service: accounts, playback, chat, guilds, tournaments, subscriptions, gifts, payouts, and notifications.
- Process payments, prevent fraud and abuse, and keep financial records.
- Enforce our Terms and Community Guidelines: moderation, rate limiting, security investigation, sanctions and export compliance.
- Comply with law: tax, financial reporting, copyright and safety processes, lawful requests, and legal holds.
- Improve the Service using first-party usage measurements.
- Communicate with you: transactional, security, and billing messages always; marketing messages per your preferences and applicable law.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
3. How information is shared
- Service providers: payment processing (Stripe), identity hosting (Keycloak), infrastructure and content delivery and CDN (Cloudflare), email delivery (our own in-house SMTP relay, not a third-party provider), app stores where you purchase through them, mobile push services (Apple, Google, browsers), and the analytics and authorization infrastructure we operate; each is bound to process information for us.
- Other users: your public profile (handle, display name, avatar, bio, member-since), public streams and chat messages, guild membership where public, and official tournament results (which form part of the public competitive record and may persist as described in Section 6). Community tournament brackets, entrants and results are public in the same way.
- Creators: creators see audience aggregates and subscriber/gifter identity as the feature displays it (for example, a subscriber badge or gifter name in chat) — not your payment details.
- Community tournament hosts: if you register for a community tournament, its host sees your display name, your registration and entrant status and, if the host uses player feeds, your feed and its status (for example whether it is being received and its picture size). The host never sees your feed key. The host may show your feed in their broadcast, which is seen by its viewers (everyone, or only the host’s channel subscribers) and recorded as described in Section 1.12.
- Legal and safety: to comply with law or valid legal process; to make legally required reports (for example, statutory child-safety reporting); to protect users, the public, or TOGGL3; or in connection with a merger, acquisition, or sale of assets, subject to this policy.
4. Your choices and rights
- Settings: profile visibility, notification preferences, privacy toggles, and playback preferences are in Settings. You can unfollow, unsubscribe, and cancel subscriptions online.
- Access, correction, deletion, portability: you may request a copy of your data or deletion of your account through the mechanisms we provide . Deletion is subject to Section 6 (what survives).
- Marketing: opt out anytime via the message’s unsubscribe link or Settings; transactional and security messages are not optional while you hold an account.
- Regional rights: depending on where you live, you may have additional rights (e.g., GDPR, UK GDPR, CCPA/CPRA), including the right to complain to a supervisory authority.
4.1 CCPA/CPRA
For residents of California: we do not sell personal information and we do not share personal information for cross-context behavioral advertising. We have collected and do not currently collect “sensitive personal information” beyond what is necessary, except a hashed IP address held for security and abuse purposes as permitted under California law. You have the right to know what personal information we collect, use, and disclose about you; to correct inaccurate personal information; to delete personal information (subject to Section 6); and to limit or use sensitive personal information. We will not discriminate against you for exercising these rights. We do not use or disclose personal information for determining a person’s eligibility for credit, insurance, or financial or employment purposes.
5. Security
We use TLS in transit, role-restricted access, hashed IP storage for security records, multi-factor authentication support (required for creators before broadcasting), short-lived signed credentials for premium playback, and one-way hashing of stream keys, feed keys and Control Room publishing credentials, which are shown to their owner once and never stored in readable form. No system is perfectly secure; we will notify you and regulators of breaches as required by law.
6. Retention — and what survives deletion
We keep personal information only as long as needed for the purposes above, then delete or de-identify it. When you ask to delete your account, it enters a 30-day grace period during which it keeps working and you can cancel the deletion; if you do not, erasure then runs. Because much of our chat and activity data is stored in a durable database, erasure does not delete the underlying message history in place. Instead it works by de-identifying your information — removing or anonymising the fields tied to you — while leaving the surrounding history, and a bounded number of records that law requires us to keep, as described below.
Some records survive account deletion. When you delete your account:
- Your public profile information (handle, display name, avatar, bio) is de-identified.
- Financial records (purchases, payouts, tax records) are retained for legally required periods, keyed by the payment processor’s identifiers rather than your identity.
- Safety and enforcement records (reports, appeals, bans) are retained where required to enforce bans, comply with law (including copyright and intimate-image processes), or protect users.
- Official tournament results may be retained and displayed, pseudonymized where required by applicable privacy law.
- Clips or copies made through features you enabled may persist per the Terms.
- Backups, if any, may retain deleted data for a bounded period before cycling out.
We may pseudonymize or de-identify records rather than deleting them where that is enough to meet the purposes above.
Community tournament records (Section 1.12) are kept as follows. A tournament ends when it is completed or cancelled; a tournament that has not ended keeps every record tied to it.
- Tournament Host Terms acceptances: until three years after the later of the host’s most recent acceptance and the end of the host’s most recent community tournament, and never while the host has a published tournament that has not ended. Every version the host accepted is then deleted together. A tournament that was never published does not extend this period.
- Per-tournament publish confirmations: for three years after the tournament ends. The confirmations and when they were made are then deleted from the tournament’s record; the tournament and its public bracket and results remain.
- Player registration confirmations: for three years after the tournament ends, then deleted.
- Feed-key records: for twelve months after the tournament ends, then deleted. A key that was never revoked is not deleted.
- Control Room credential records: for twelve months after the credential stops working (when it expires or is revoked, whichever is first), then deleted.
- Player-feed technical data: not stored beyond our ordinary service logs, which are kept for the same period as our other service logs.
- The host’s broadcast and its recording: under the recording and retention rules that apply to every broadcast on the host’s channel.
Deletion runs automatically, about once an hour. Records covered by a legal hold (for example, one placed for a report, dispute or enforcement action) are not deleted until the hold is released.
We keep information about your referral attribution permanently where that attribution is entitled you to ongoing compensation, unless it ends.
7. International transfers
TOGGL3 operates from [COUNTRY]. If you use the Service from elsewhere, your information is processed in [COUNTRY/REGIONS] and by service providers that may process data in other countries. When we transfer personal information across borders, we put in place appropriate safeguards such as Standard Contractual Clauses or the equivalent permitted by applicable law.
8. Children
The Service is for adults 18+. We refuse registration to anyone under 18 and do not knowingly collect personal information from minors. If we learn an account belongs to someone under 18, we terminate it and delete associated personal information subject to legal retention duties. Contact us at [SUPPORT EMAIL] to report an underage account.
9. Changes to this policy
We will post updates here with a new effective date and give reasonable advance notice of material changes (and obtain consent where law requires).
10. Contact
Privacy requests and questions: [PRIVACY EMAIL]
Support: [SUPPORT EMAIL]
Postal: [LEGAL ENTITY NAME, ADDRESS]