• Who we are
  • Scope
  • Where we operate
  • Products & Roles
  • Retention
  • Requests from Non-U.S. Authorities
  • Privacy Disclosures by Category
  • Information we collect and sources
  • Information you provide directly
  • Information collected automatically
  • Information from third parties
  • How we use personal information
  • Sharing and disclosure
  • Data location
  • Data retention
  • Your rights and choices
  • Cookies, DNT, and opt‑out preference signals
  • Children’s privacy
  • Data security and breach notification
  • Marketing communications (CAN‑SPAM)
  • California and Nevada privacy rights
  • Changes to this Policy
  • Contact us
  • Changelog
  • Privacy Policy


    Effective date: October 24, 2025 · Version: 1.0.0

    Who we are

    Data controller: Blazing Cacti LLC (Nevada, USA)
    Address: 9750 W. Skye Canyon Park Dr., Ste. 160 – #161, Las Vegas, NV 89166, USA
    Phone: +1 (702) 799‑9989
    General inquiries: info@mixitup.bot
    Privacy contact: privacy@mixitup.bot
    Security contact: security@mixitup.bot

    Scope

    This Policy applies to personal information processed by us in connection with the Services, including our websites under *.mixitup.bot, *.mixitupbot.com, and mixitup.bot, Windows desktop applications (.NET WPF), desktop and cross-platform applications (including mobile builds when released), browser extensions, public APIs/SDKs/CLIs, developer documentation, and support channels. It does not apply to third‑party services that have their own privacy practices.

    Where we operate

    Blazing Cacti LLC is a United States company. The Services are operated from, and information we process is stored in, the United States. Our compliance program is designed to United States federal and state law. Nothing in our documents limits any non-waivable rights you may have under the mandatory consumer-protection law of your place of residence.

    Creators may use the Services to receive and retain information about their audiences. Where audience data is processed through a hosted feature such as Cloud Sync, we act as the creator’s service provider/processor at the creator’s direction, and creators are responsible for any notices or consents their audiences require.

    Products & Roles

    Desktop (local). The application connects from the user’s device to platforms the user authorizes (e.g., Twitch, YouTube, Discord, Kick, and Velora) and stores resulting data locally on the user’s device. Blazing Cacti does not host this content.

    Cloud Sync (hosted). Qualifying Patreon members may back up settings and, where offered, selected audience/event data to our U.S. servers. Cloud Sync data is associated with your linked platform identity and encrypted at rest.

    Retention

    Retention (Desktop). Application content (including audience/chat history, overlays, logs) is stored on the user’s device and remains until the user deletes the files or uninstalls/cleans the application data. Blazing Cacti cannot access or delete local data.

    Retention (Cloud Sync). Cloud Sync data is retained until you delete it and, in any event, deleted 180 days after your qualifying Patreon membership lapses. Disaster-recovery backups age out within 365 days.

    Requests from Non-U.S. Authorities

    We respond to valid U.S. legal process. We do not produce data directly to non-U.S. governmental authorities; such requests must proceed through applicable U.S. mechanisms.

    Privacy Disclosures by Category

    The table below summarizes the categories of personal information we collect, sources, purposes, retention, and disclosures. It is provided as a courtesy to all users and serves as our California notice at collection to the extent the CCPA applies to us.

    Retention periods reflect our current practices. Some records may be kept longer where required by law, to establish or defend legal claims, prevent fraud, or ensure security and service continuity.

    Category Examples Sources Purposes Retention Disclosed to Sold/Shared
    Identifiers name, email, account ID; IP addresses in logs; device IDs you; automatically from your device account creation; login; security; support; notifications Until account/link deletion for identifiers; up to 365 days for IPs in security logs cloud hosting; auth and support providers Sold: No; Shared: No
    Patreon membership data Patreon user ID, email, membership tier/status, pledge amount, transaction history (we do not receive card numbers or billing addresses) you; Patreon billing; fraud detection; tax; receipts 7 years for transaction records — (received from Patreon; not further disclosed) Sold: No; Shared: No
    Internet activity website/app page views, events, app logs, crash data automatically from your device security; analytics; product improvement up to 365 days analytics; security; crash reporting Sold: No; Shared: No
    Geolocation (coarse) city/region from IP automatically localization; compliance; abuse prevention up to 365 days (within analytics/security logs) analytics; security Sold: No; Shared: No
    User content overlays, commands, scripts, files, settings, feedback you provide and improve Services; troubleshooting Cloud Sync (if enabled): until deletion / 180 days after membership lapse; Desktop app: stored locally under your control cloud hosting (Cloud Sync); none (desktop, local) Sold: No; Shared: No
    Audience/visitor data viewer usernames, chat messages, channel events from connected platforms with your authorization overlays, alerts, moderation, analytics for creators Cloud Sync (if enabled): until deletion / 180 days after membership lapse; Desktop app: stored locally under your control hosting (Cloud Sync); none (desktop, local) Sold: No; Shared: No
    Cloud Sync data (Patreon members) settings; and, where offered, audience/event data you choose to back up, including event payloads received through your connected platform pipelines (which may include incidental data relayed from other services) you; your connected platforms backup and sync at your direction until you delete it; deleted 180 days after your qualifying Patreon membership lapses; encrypted at rest cloud hosting Sold: No; Shared: No
    Inferences usage segments, feature cohorts derived from usage product improvement; personalization where permitted up to 365 days analytics Sold: No; Shared: No
    Sensitive PI (if provided) OAuth refresh tokens, authentication tokens you; device authentication; fraud prevention; legal compliance Purged immediately on unlink or account deletion; otherwise retained as needed to provide the Service security providers; payments Sold: No; Shared: No

    We use Sensitive Personal Information only for permitted purposes such as authentication, security, fraud prevention, and legal compliance, and not for inferring characteristics about you.

    Do Not Sell or Share. We do not sell personal information and we do not share personal information for cross‑context behavioral advertising.

    GPC. We honor Global Privacy Control (GPC) signals as an opt‑out for sale/sharing (even though we do not sell/share) and treat them as a request to restrict such processing for that browser.


    Information we collect and sources

    We collect the information described in the table above from: you (including through forms, prompts, files, and support requests); automatically from your device (cookies, SDKs, logs); third‑party platforms you connect; and service providers acting on our behalf.

    Information you provide directly

    • Account and contact information. When you create an account or contact us, we collect identifiers such as display name, email address, and other details you choose to provide.
    • Platform authentication tokens and permissions. To integrate with Twitch, YouTube, Discord, Kick, and Velora, you provide OAuth tokens or API keys so we can read chat messages (including private messages and private channels if you explicitly grant that scope), send messages on your behalf, and configure alerts and automation. You can revoke these permissions at any time in the relevant platform and you can unlink within Mix It Up. Private messages accessed via granted scopes are used only to provide requested features (for example, moderation or automation) and are retained under the same rules as audience/visitor data. Creators can request export and bulk deletion of message logs for their account, and data is deleted when the account is deleted.
    • Configuration and user‑generated content. You may upload or create scripts, commands, overlays, community guides, or other settings (“User Content”). Such content may include metadata or personal information depending on what you include.

    Information collected automatically

    • Usage data and analytics. Feature interactions, log files, timestamps, time on screens, error reports, IP addresses, device identifiers, browser type/version, operating system, and other diagnostic data.
    • Cookies and similar technologies (website). We use Google Analytics on our website for analytics only.
    • Telemetry (desktop app). OS version, hardware profile, app version, feature flags, crash traces, anonymized IDs, and linked‑account metadata (not credentials).
    • Location data. Approximate location derived from IP.

    Information from third parties

    • Connected platforms. If you link a platform account (e.g., Twitch or YouTube), we receive information like channel IDs, chat messages, and follower or channel events. We use this data solely to provide the Services and subject to the platform’s terms and your settings.

    How we use personal information

    We use personal information to:

    • Provide and secure the Services; authenticate and manage accounts; deliver alerts and overlays; process commands and automation; personalize settings; provide support.
    • Improve and develop the Services by analyzing usage patterns and feedback to fix bugs, add features, and enhance performance.
    • Communicate about updates, security, and support; and, with your consent or where permitted, send marketing or promotional emails.
    • Comply with law and enforce agreements; detect, investigate, and prevent fraud, abuse, or security incidents.
    • Analytics only. We use analytics to understand usage; we do not use cookies for marketing or cross‑context behavioral advertising.

    Sharing and disclosure

    We share personal information only as described below:

    • Service providers. Vultr (cloud hosting), Google LLC (Google Analytics 4 for website analytics; Google Workspace for email), Microsoft (Azure Application Insights for crash/telemetry), and Cloudflare (CDN and network security) process data on our behalf under contracts that limit their use. Our self-hosted monitoring tools (Prometheus, Seq, OpenTelemetry collector) run on our own infrastructure and are not third-party recipients.
    • Optional speech services. Some features let you configure third-party text-to-speech or speech services (for example, Amazon Polly or Microsoft Azure Speech). When you use such a feature, the text you submit is sent to the provider you configured and is processed under that provider’s terms and privacy policy.
    • Third‑party platform partners. When you integrate with a platform (for example, Twitch, YouTube, Discord, Kick, and Velora), we share data as necessary to deliver functionality, subject to each platform’s policies and your settings.
    • Legal compliance and protection. To respond to lawful requests, enforce our rights, or protect users and the public.
    • Business transfers. In connection with a merger, acquisition, reorganization, or sale of assets, we may transfer data. We will notify you of any material changes in ownership or use of personal information.

    Law-enforcement requests. We may disclose information in response to lawful requests. Where permitted by law, we may notify affected users before producing data so they can seek remedies, unless doing so would be futile or the request prohibits notice.

    Service provider role. For creators’ audience data processed through integrations, we act as a service provider/processor to the creator to the extent permitted by law and our agreements. Creators are responsible for providing any required notices and obtaining any required consents from their audiences. A Data Processing Addendum (DPA) is available upon request.

    Nevada (NRS 603A). Our designated request address under NRS 603A.345 is privacy@mixitup.bot. Nevada consumers may submit a verified request through that address directing us not to sell covered information (as “sale” is defined in NRS 603A.333). We do not sell covered information. We will respond to verified requests within 60 days of receipt; if reasonably necessary, we may extend that period by up to 30 additional days and will notify you of the extension.

    Data location

    We process and store personal information in the United States.

    Data retention

    Retention varies by category (see the Privacy Disclosures by Category table). Additional practices:

    • Accounts (profile & settings): retained until you delete your account; certain records may be kept up to 12 months in backups and audit logs.
    • OAuth tokens: retained until you unlink or delete your account; purged immediately thereafter (subject to backup cycles).
    • Billing and transaction records: retained 7 years to meet tax, accounting, and audit obligations.
    • Analytics & usage events: retained up to 365 days on our systems.
    • Security logs/fraud data: retained up to 365 days to investigate abuse and protect service integrity.
    • Backups: retained up to 365 days for disaster recovery; restoration requests trigger the same deletion routines described here.

    Deletion requests and holds. Email privacy@mixitup.bot to request deletion, correction, or export. We log each request, verify identity before acting, apply legal exceptions, and document any holds (for example, fraud, disputes, or statutory retention requirements). When a deletion is approved, production systems are updated promptly and backups age out per the cycles above.

    For the desktop app, most data is stored locally on your device and is under your control. We cannot access or delete local device data. Uninstalling or clearing the app data on your device removes that local data.

    Your rights and choices

    Depending on your location, you may have rights under applicable law, which can include the right to access, delete, correct, port, opt out of certain processing (including sale/sharing/targeted advertising), and limit use of sensitive personal information. We respond to requests as required by applicable law.

    How to exercise your rights. Submit a request by emailing privacy@mixitup.bot. Include (a) the account email or unique identifier we should look up, (b) the type of request you are submitting (for example, access, delete, correct, portability, restrict/object, limit sensitive personal information), and (c) your region or governing privacy law (for example, EU, UK, California, Virginia). If an authorized agent acts for you, attach evidence of their authority.

    We verify identity to a reasonable degree before fulfilling requests, log each request in our compliance tracker, and respond within 30–45 days unless the law allows an extension (in which case we will notify you). We do not discriminate against you for exercising your rights.

    Appeals. If we deny your request, you may appeal by replying to our decision email with “Appeal.” We will review and respond within 45 days as required by applicable law.

    Cookies, DNT, and opt‑out preference signals

    We present a cookie consent banner to all visitors, regardless of location. Analytics cookies are not set until you accept; declining (or simply not accepting) leaves only essential cookies in place. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a declination and the banner is set to declined automatically. You can change your choice at any time through the banner controls or your browser settings.

    Our website analytics use Google Analytics 4 in an analytics-only configuration (Google Signals off; advertising data sharing off).

    Do Not Track (DNT). Some browsers send DNT signals; there is no industry consensus on how to respond, so we do not respond to DNT. Global Privacy Control (GPC). We honor recognized browser‑level opt‑out signals, including GPC, for sale/sharing where applicable.

    Children’s privacy

    The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will delete that information and disable the account. Parents or guardians may request deletion by emailing privacy@mixitup.bot with “Children’s Data Request” in the subject line.

    Data security and breach notification

    We implement administrative, technical, and physical measures designed to protect personal information, including encryption in transit and at rest (for example, OAuth refresh tokens and secrets), role‑based access controls, logging, and vulnerability management. No method of transmission or storage is completely secure. In the event of a data breach, we will evaluate risk and, where required by law, notify affected individuals and regulators.

    Marketing communications (CAN‑SPAM)

    Marketing emails include an unsubscribe link. We honor opt‑outs within 10 business days and include our physical address in each commercial email. Transactional messages may still be sent. We do not send SMS/text messages or place automated calls.

    California and Nevada privacy rights

    California and Nevada residents may have additional rights under the CPRA and NRS 603A, including the right to know, correct, delete, opt out of sale, and limit the use of sensitive personal information. We do not sell personal information. To exercise rights contact us at privacy@mixitup.bot.

    Financial incentives. We do not offer programs that provide price or service differences in exchange for personal information. If we introduce paid add-ons in the future, we will collect only the personal information necessary to process the transaction and will update this Policy as required.

    Changes to this Policy

    We may update this Policy from time to time. For material changes, we will provide notice (for example, in‑product or by email) at least 15 days before the changes take effect, unless a shorter period is required by law or for security. The Effective date above reflects the latest version.

    Contact us

    Blazing Cacti LLC
    9750 W. Skye Canyon Park Dr., Ste. 160 – #161
    Las Vegas, NV 89166, USA
    General: info@mixitup.bot
    Privacy: privacy@mixitup.bot
    Security: security@mixitup.bot


    Changelog

    • v1.0.0 (October 24, 2025): Initial published version of the consolidated Mix It Up legal suite.

    This version supersedes any privacy policy or terms previously displayed on this site.


    Site Settings

    Accessibility

    Choose how the site looks. System follows your device setting.

    Cookies

    Choose which cookies to allow. Your preference is saved for 6 months.

    Necessary
    Required for the site to function correctly. Cannot be disabled.
    Analytics
    Helps us understand how visitors use the site. No personal data is shared with third parties.