Effective date: October 24, 2025 · Version: 1.0.0
Who we are
Data controller: Blazing Cacti LLC (Nevada, USA)
Address: 9750 W. Skye Canyon Park Dr., Ste. 160 – #161, Las Vegas, NV 89166, USA
Phone: +1 (702) 799‑9989
General inquiries: info@mixitup.bot
Privacy contact: privacy@mixitup.bot
Security contact: security@mixitup.bot
Scope
This Policy applies to personal information processed by us in connection with the Services, including our websites under *.mixitup.bot, *.mixitupbot.com, and mixitup.bot, Windows desktop applications (.NET WPF), desktop and cross-platform applications (including mobile builds when released), browser extensions, public APIs/SDKs/CLIs, developer documentation, and support channels. It does not apply to third‑party services that have their own privacy practices.
Where we operate
Blazing Cacti LLC is a United States company. The Services are operated from, and information we process is stored in, the United States. Our compliance program is designed to United States federal and state law. Nothing in our documents limits any non-waivable rights you may have under the mandatory consumer-protection law of your place of residence.
Creators may use the Services to receive and retain information about their audiences. Where audience data is processed through a hosted feature such as Cloud Sync, we act as the creator’s service provider/processor at the creator’s direction, and creators are responsible for any notices or consents their audiences require.
Products & Roles
Desktop (local). The application connects from the user’s device to platforms the user authorizes (e.g., Twitch, YouTube, Discord, Kick, and Velora) and stores resulting data locally on the user’s device. Blazing Cacti does not host this content.
Cloud Sync (hosted). Qualifying Patreon members may back up settings and, where offered, selected audience/event data to our U.S. servers. Cloud Sync data is associated with your linked platform identity and encrypted at rest.
Retention
Retention (Desktop). Application content (including audience/chat history, overlays, logs) is stored on the user’s device and remains until the user deletes the files or uninstalls/cleans the application data. Blazing Cacti cannot access or delete local data.
Retention (Cloud Sync). Cloud Sync data is retained until you delete it and, in any event, deleted 180 days after your qualifying Patreon membership lapses. Disaster-recovery backups age out within 365 days.
Requests from Non-U.S. Authorities
We respond to valid U.S. legal process. We do not produce data directly to non-U.S. governmental authorities; such requests must proceed through applicable U.S. mechanisms.
Privacy Disclosures by Category
The table below summarizes the categories of personal information we collect, sources, purposes, retention, and disclosures. It is provided as a courtesy to all users and serves as our California notice at collection to the extent the CCPA applies to us.
Retention periods reflect our current practices. Some records may be kept longer where required by law, to establish or defend legal claims, prevent fraud, or ensure security and service continuity.
| Category | Examples | Sources | Purposes | Retention | Disclosed to | Sold/Shared |
|---|---|---|---|---|---|---|
| Identifiers | name, email, account ID; IP addresses in logs; device IDs | you; automatically from your device | account creation; login; security; support; notifications | Until account/link deletion for identifiers; up to 365 days for IPs in security logs | cloud hosting; auth and support providers | Sold: No; Shared: No |
| Patreon membership data | Patreon user ID, email, membership tier/status, pledge amount, transaction history (we do not receive card numbers or billing addresses) | you; Patreon | billing; fraud detection; tax; receipts | 7 years for transaction records | — (received from Patreon; not further disclosed) | Sold: No; Shared: No |
| Internet activity | website/app page views, events, app logs, crash data | automatically from your device | security; analytics; product improvement | up to 365 days | analytics; security; crash reporting | Sold: No; Shared: No |
| Geolocation (coarse) | city/region from IP | automatically | localization; compliance; abuse prevention | up to 365 days (within analytics/security logs) | analytics; security | Sold: No; Shared: No |
| User content | overlays, commands, scripts, files, settings, feedback | you | provide and improve Services; troubleshooting | Cloud Sync (if enabled): until deletion / 180 days after membership lapse; Desktop app: stored locally under your control | cloud hosting (Cloud Sync); none (desktop, local) | Sold: No; Shared: No |
| Audience/visitor data | viewer usernames, chat messages, channel events | from connected platforms with your authorization | overlays, alerts, moderation, analytics for creators | Cloud Sync (if enabled): until deletion / 180 days after membership lapse; Desktop app: stored locally under your control | hosting (Cloud Sync); none (desktop, local) | Sold: No; Shared: No |
| Cloud Sync data (Patreon members) | settings; and, where offered, audience/event data you choose to back up, including event payloads received through your connected platform pipelines (which may include incidental data relayed from other services) | you; your connected platforms | backup and sync at your direction | until you delete it; deleted 180 days after your qualifying Patreon membership lapses; encrypted at rest | cloud hosting | Sold: No; Shared: No |
| Inferences | usage segments, feature cohorts | derived from usage | product improvement; personalization where permitted | up to 365 days | analytics | Sold: No; Shared: No |
| Sensitive PI (if provided) | OAuth refresh tokens, authentication tokens | you; device | authentication; fraud prevention; legal compliance | Purged immediately on unlink or account deletion; otherwise retained as needed to provide the Service | security providers; payments | Sold: No; Shared: No |
We use Sensitive Personal Information only for permitted purposes such as authentication, security, fraud prevention, and legal compliance, and not for inferring characteristics about you.
Do Not Sell or Share. We do not sell personal information and we do not share personal information for cross‑context behavioral advertising.
GPC. We honor Global Privacy Control (GPC) signals as an opt‑out for sale/sharing (even though we do not sell/share) and treat them as a request to restrict such processing for that browser.
Information we collect and sources
We collect the information described in the table above from: you (including through forms, prompts, files, and support requests); automatically from your device (cookies, SDKs, logs); third‑party platforms you connect; and service providers acting on our behalf.
Information you provide directly
- Account and contact information. When you create an account or contact us, we collect identifiers such as display name, email address, and other details you choose to provide.
- Platform authentication tokens and permissions. To integrate with Twitch, YouTube, Discord, Kick, and Velora, you provide OAuth tokens or API keys so we can read chat messages (including private messages and private channels if you explicitly grant that scope), send messages on your behalf, and configure alerts and automation. You can revoke these permissions at any time in the relevant platform and you can unlink within Mix It Up. Private messages accessed via granted scopes are used only to provide requested features (for example, moderation or automation) and are retained under the same rules as audience/visitor data. Creators can request export and bulk deletion of message logs for their account, and data is deleted when the account is deleted.
- Configuration and user‑generated content. You may upload or create scripts, commands, overlays, community guides, or other settings (“User Content”). Such content may include metadata or personal information depending on what you include.
Information collected automatically
- Usage data and analytics. Feature interactions, log files, timestamps, time on screens, error reports, IP addresses, device identifiers, browser type/version, operating system, and other diagnostic data.
- Cookies and similar technologies (website). We use Google Analytics on our website for analytics only.
- Telemetry (desktop app). OS version, hardware profile, app version, feature flags, crash traces, anonymized IDs, and linked‑account metadata (not credentials).
- Location data. Approximate location derived from IP.
Information from third parties
- Connected platforms. If you link a platform account (e.g., Twitch or YouTube), we receive information like channel IDs, chat messages, and follower or channel events. We use this data solely to provide the Services and subject to the platform’s terms and your settings.
How we use personal information
We use personal information to:
- Provide and secure the Services; authenticate and manage accounts; deliver alerts and overlays; process commands and automation; personalize settings; provide support.
- Improve and develop the Services by analyzing usage patterns and feedback to fix bugs, add features, and enhance performance.
- Communicate about updates, security, and support; and, with your consent or where permitted, send marketing or promotional emails.
- Comply with law and enforce agreements; detect, investigate, and prevent fraud, abuse, or security incidents.
- Analytics only. We use analytics to understand usage; we do not use cookies for marketing or cross‑context behavioral advertising.
Sharing and disclosure
We share personal information only as described below:
- Service providers. Vultr (cloud hosting), Google LLC (Google Analytics 4 for website analytics; Google Workspace for email), Microsoft (Azure Application Insights for crash/telemetry), and Cloudflare (CDN and network security) process data on our behalf under contracts that limit their use. Our self-hosted monitoring tools (Prometheus, Seq, OpenTelemetry collector) run on our own infrastructure and are not third-party recipients.
- Optional speech services. Some features let you configure third-party text-to-speech or speech services (for example, Amazon Polly or Microsoft Azure Speech). When you use such a feature, the text you submit is sent to the provider you configured and is processed under that provider’s terms and privacy policy.
- Third‑party platform partners. When you integrate with a platform (for example, Twitch, YouTube, Discord, Kick, and Velora), we share data as necessary to deliver functionality, subject to each platform’s policies and your settings.
- Legal compliance and protection. To respond to lawful requests, enforce our rights, or protect users and the public.
- Business transfers. In connection with a merger, acquisition, reorganization, or sale of assets, we may transfer data. We will notify you of any material changes in ownership or use of personal information.
Law-enforcement requests. We may disclose information in response to lawful requests. Where permitted by law, we may notify affected users before producing data so they can seek remedies, unless doing so would be futile or the request prohibits notice.
Service provider role. For creators’ audience data processed through integrations, we act as a service provider/processor to the creator to the extent permitted by law and our agreements. Creators are responsible for providing any required notices and obtaining any required consents from their audiences. A Data Processing Addendum (DPA) is available upon request.
Nevada (NRS 603A). Our designated request address under NRS 603A.345 is privacy@mixitup.bot. Nevada consumers may submit a verified request through that address directing us not to sell covered information (as “sale” is defined in NRS 603A.333). We do not sell covered information. We will respond to verified requests within 60 days of receipt; if reasonably necessary, we may extend that period by up to 30 additional days and will notify you of the extension.
Data location
We process and store personal information in the United States.
Data retention
Retention varies by category (see the Privacy Disclosures by Category table). Additional practices:
- Accounts (profile & settings): retained until you delete your account; certain records may be kept up to 12 months in backups and audit logs.
- OAuth tokens: retained until you unlink or delete your account; purged immediately thereafter (subject to backup cycles).
- Billing and transaction records: retained 7 years to meet tax, accounting, and audit obligations.
- Analytics & usage events: retained up to 365 days on our systems.
- Security logs/fraud data: retained up to 365 days to investigate abuse and protect service integrity.
- Backups: retained up to 365 days for disaster recovery; restoration requests trigger the same deletion routines described here.
Deletion requests and holds. Email privacy@mixitup.bot to request deletion, correction, or export. We log each request, verify identity before acting, apply legal exceptions, and document any holds (for example, fraud, disputes, or statutory retention requirements). When a deletion is approved, production systems are updated promptly and backups age out per the cycles above.
For the desktop app, most data is stored locally on your device and is under your control. We cannot access or delete local device data. Uninstalling or clearing the app data on your device removes that local data.
Your rights and choices
Depending on your location, you may have rights under applicable law, which can include the right to access, delete, correct, port, opt out of certain processing (including sale/sharing/targeted advertising), and limit use of sensitive personal information. We respond to requests as required by applicable law.
How to exercise your rights. Submit a request by emailing privacy@mixitup.bot. Include (a) the account email or unique identifier we should look up, (b) the type of request you are submitting (for example, access, delete, correct, portability, restrict/object, limit sensitive personal information), and (c) your region or governing privacy law (for example, EU, UK, California, Virginia). If an authorized agent acts for you, attach evidence of their authority.
We verify identity to a reasonable degree before fulfilling requests, log each request in our compliance tracker, and respond within 30–45 days unless the law allows an extension (in which case we will notify you). We do not discriminate against you for exercising your rights.
Appeals. If we deny your request, you may appeal by replying to our decision email with “Appeal.” We will review and respond within 45 days as required by applicable law.
Cookies, DNT, and opt‑out preference signals
We present a cookie consent banner to all visitors, regardless of location. Analytics cookies are not set until you accept; declining (or simply not accepting) leaves only essential cookies in place. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a declination and the banner is set to declined automatically. You can change your choice at any time through the banner controls or your browser settings.
Our website analytics use Google Analytics 4 in an analytics-only configuration (Google Signals off; advertising data sharing off).
Do Not Track (DNT). Some browsers send DNT signals; there is no industry consensus on how to respond, so we do not respond to DNT. Global Privacy Control (GPC). We honor recognized browser‑level opt‑out signals, including GPC, for sale/sharing where applicable.
Children’s privacy
The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will delete that information and disable the account. Parents or guardians may request deletion by emailing privacy@mixitup.bot with “Children’s Data Request” in the subject line.
Data security and breach notification
We implement administrative, technical, and physical measures designed to protect personal information, including encryption in transit and at rest (for example, OAuth refresh tokens and secrets), role‑based access controls, logging, and vulnerability management. No method of transmission or storage is completely secure. In the event of a data breach, we will evaluate risk and, where required by law, notify affected individuals and regulators.
Marketing communications (CAN‑SPAM)
Marketing emails include an unsubscribe link. We honor opt‑outs within 10 business days and include our physical address in each commercial email. Transactional messages may still be sent. We do not send SMS/text messages or place automated calls.
California and Nevada privacy rights
California and Nevada residents may have additional rights under the CPRA and NRS 603A, including the right to know, correct, delete, opt out of sale, and limit the use of sensitive personal information. We do not sell personal information. To exercise rights contact us at privacy@mixitup.bot.
Financial incentives. We do not offer programs that provide price or service differences in exchange for personal information. If we introduce paid add-ons in the future, we will collect only the personal information necessary to process the transaction and will update this Policy as required.
Changes to this Policy
We may update this Policy from time to time. For material changes, we will provide notice (for example, in‑product or by email) at least 15 days before the changes take effect, unless a shorter period is required by law or for security. The Effective date above reflects the latest version.
Contact us
Blazing Cacti LLC
9750 W. Skye Canyon Park Dr., Ste. 160 – #161
Las Vegas, NV 89166, USA
General: info@mixitup.bot
Privacy: privacy@mixitup.bot
Security: security@mixitup.bot
Changelog
- v1.0.0 (October 24, 2025): Initial published version of the consolidated Mix It Up legal suite.
This version supersedes any privacy policy or terms previously displayed on this site.