CrossMod brings chat moderation on Twitch and Kick together. To do that, it needs to know your account on both platforms and to read your channel's chat. This page says plainly what we store, why, for how long and what you can do about it. No legal jargon.
Last updated: 15 September 2026
This is a translation. In case of doubt, the Polish version of this document is the binding one.
In short
We do not sell data and we do not pass it to advertisers. There are no tracking or advertising tools here.
CrossMod stores what the bot needs to work: your Twitch and Kick accounts, the chat messages from your channel and the history of moderation actions.
Your Twitch or Kick password never reaches us. You log in on the platform's side and CrossMod only receives an access token from it.
IP addresses of people visiting the site are deleted automatically after 48 hours.
You can disconnect a platform at any time on the "Enable bot" page in the dashboard, and ask for your account and history to be deleted entirely in a single message.
Who runs CrossMod
CrossMod is run by one person, a streamer known as Grithn. She is responsible for the data described on this page, which makes her its controller under the GDPR.
For anything about your data, and for everything else on this page: send a private message on Twitch to @Grithn. A reply may take a few days, because CrossMod has no support team.
Where the data comes from
CrossMod does not collect data on its own. Everything it has comes from three places:
From you - when you log in through Twitch or Kick and when you type something into the dashboard: automod phrases, commands, recurring messages, overlay settings.
From Twitch and Kick - when you agree, while logging in, to let CrossMod work on your channel. The platform then sends chat messages, information about bans and rewards, and an access token that lets it carry out commands on your behalf.
From your browser - on every visit to the site the server writes a short technical entry, described below.
Your account data
Once your channel is connected, this is what sits about you in CrossMod's database:
The identifier, name and display name of your Twitch and Kick account.
Access tokens issued by Twitch and Kick. They are what lets the bot read chat and apply penalties. They are not your password and your password cannot be read from them.
The date your CrossMod account was created and the date you last logged in.
Your settings: automod phrases, commands, recurring messages, overlay appearance, VTube Studio assignments, and video files if you use the video overlay.
The private key in the overlay address, which tells the OBS window whose data it should display.
When you log in through Twitch, the consent also covers the account's email address, because that is how this login method is built. CrossMod neither reads it nor stores it in the database.
Chat and moderation data
This is data about other people, about your channel's viewers. It reaches CrossMod because the bot has to see chat in order to react to it, and you have to be able to see what it did.
Chat messages from your channel: the sender's name, their identifier on the platform, the message text and the time. This is what the chat preview in the dashboard and in the overlay is made of.
Channel events, for example subscriptions, raids and channel point rewards, if you turn on features that use them.
Moderation history: who was banned or timed out, for how long, for what reason, who issued it and which message triggered it. This is the Mod Log and the list of moderation actions.
The viewer points counter, if the points feature is enabled on your channel.
What you do with this data on your channel is your responsibility. CrossMod is a tool here, just like Twitch's or Kick's own moderation panel.
Technical data about visits
Every visit to the CrossMod site leaves one entry in the database: IP address, country, the address of the page visited, the type of request, the response code, how long it took to prepare and the browser name. The same entry is created for visits from the browser window inside OBS.
The country is recognised by the server itself, from a local list of address ranges. We do not query any external service for it.
On top of that the server keeps an ordinary technical log, that is messages about what happened inside the program and what failed. It is used solely for tracking down faults.
Why we need this data
So the service works at all: the bot has to read chat in order to react to phrases, and it needs an access token in order to ban someone or send a message.
So you can see what happened: the Mod Log, the chat preview and the statistics are simply the same data shown in the dashboard.
So faults can be fixed: technical entries and the server log show which part stopped working and when.
So the service can be protected: the IP address reveals attempts to flood the server with requests. That is also why these entries exist in the first place.
In GDPR terms, the first two points are the performance of the service you use, and the next two are a legitimate interest in keeping that service running and secure.
How long we keep it
Technical entries about visits: 48 hours. An automated job deletes them, with nobody involved.
Twitch and Kick access tokens: until you disconnect the platform on the "Enable bot" page in the dashboard. They disappear from the database immediately.
Your account, settings, moderation history and chat messages: for as long as your CrossMod account exists. We do not delete them after a set time, because moderation history is sometimes needed months later.
Phrases, commands and recurring messages: until you delete them yourself in the dashboard.
Disconnecting a platform deletes the access tokens but keeps the account and the history, so that everything is in place when you connect again. If you want it gone completely, write to us - see the section on your rights below.
Who else gets the data
We do not sell data and we do not share it for advertising. It leaves CrossMod only where it has to:
Twitch and Kick - moderation commands and bot messages go there, and chat comes from there. Those platforms' privacy rules apply.
Cloudflare - all traffic to CrossMod passes through this service, which protects the server from attacks. It therefore sees the addresses you visit the site from.
Emote providers - overlays in OBS download emote images from 7TV, BetterTTV and FrankerFaceZ. This happens in the OBS browser and concerns images only; nothing about your viewers is sent there.
The support link on the home page leads to PayPal. If you use it, the payment happens entirely on PayPal's side, and CrossMod neither sees nor stores any payment data.
Cookies
CrossMod has no advertising or analytics cookies. It uses only the ones without which the dashboard would not work:
The login cookie - digitally signed, valid for a week, invisible to scripts on the page. It holds your identifier, name and avatar so the dashboard knows who is looking at it.
The chosen theme - light or dark, valid for a year. Nothing beyond that single piece of information.
Login-time cookies - they live for 10 minutes and make sure the return from Twitch or Kick lands on the same device the login started from.
The OBS dashboard pairing cookie - created when you pair an OBS dock with your account.
Cloudflare cookies - set by the service protecting the server, to tell human traffic from automated traffic.
Your rights and deleting your data
You have the right to know what data we hold about you, to receive a copy of it, to correct it, to restrict its use, to object to that use and to request its deletion. To exercise these rights, write on Twitch to @Grithn.
Some things are quicker to do yourself, from the dashboard:
Disconnecting Twitch or Kick on the "Enable bot" page deletes the access tokens, so the bot immediately stops doing anything on your channel.
Phrases, commands and recurring messages are deleted on their own pages.
You can save your automod phrase list to disk before deleting anything.
Deleting your account together with its history still requires a message to Grithn, because the dashboard has no such button yet. After such a request, everything concerning your channel disappears from the database.
If you believe your data is being processed unlawfully, you can lodge a complaint with the President of the Polish Personal Data Protection Office.
CrossMod is not intended for children under the age of thirteen. Using it requires a Twitch or Kick account, and both platforms set their own age requirements.
Security
The site works only over an encrypted connection, and the login cookie is cryptographically signed, so it cannot be forged or altered in the browser. Twitch and Kick access tokens are not shown in your dashboard and never leave the server other than in a request to the platform they belong to.
One thing is up to you: the overlay address you paste into OBS contains your account's private key. Do not show that address on stream or in screenshots. Anyone who sees it will also see your chat in that window.
CrossMod is in beta and is run by one person. There is no security team here and no guarantee that nothing will ever happen. If you find a vulnerability, write on Twitch to @Grithn instead of describing it publicly.
Changes to this policy
CrossMod keeps growing, so this page will change along with it. The date of the last change is at the top and the bottom of the document, and larger changes are described in the changelog. Continuing to use the dashboard after a change means the new version applies to you.