Last updated: June 11, 2026
Privacy Policy
This Privacy Policy describes how Metallium L.L.C. (hereinafter "Metallium", "we") collects, uses and protects the personal data of users of the service metallium.app (hereinafter the "Service"). We comply with Regulation (EU) 2016/679 ("GDPR") where it applies, in particular when our users reside in the European Union.
1. Data Controller
The data controller is Metallium L.L.C., a Delaware (United States) company — EIN 38-4339357, registered office: 1111B S Governors Ave, STE 25638, Dover, DE 19904, United States. Contact: via the contact form or from the Dashboard.
EU Representative: Metallium L.L.C. has not designated a representative under Article 27 of the GDPR as of the date of publication of this Policy. Any request relating to your data may be addressed directly via the contact channels above.
2. Data We Collect
We collect only the data necessary for the operation of the Service.
2.1 Account data
Email address and password (passwords are hashed and never stored in plain text). Display name, preferred language, account type (creator or fan).
2.2 Creator profile data (where applicable)
Public profile information: display name, avatar, biography, category, country, declared links and social networks, videos, streaming platforms.
2.3 Data from third-party connections (OAuth)
When you connect a third-party account, we receive certain data from that service:
- Google (sign-in): email address, name, profile picture.
- Twitch: channel ID, username, and — if you enable the corresponding features — live events (subscriptions, follows, etc.) via the API.
- Spotify (Song Requests): account ID and playback data required for the music queue.
2.4 Live event data (Studio module)
When you use the Studio module during a live stream, our infrastructure processes your broadcast's public events in real time (gifts, chat messages, follows, likes, subscriptions, shares). These events may contain data about your viewers (public usernames). This data is processed to power overlays, alerts and statistics, and is retained only in a limited manner (see §6).
2.5 Payment data
Payments are handled by Stripe. We never store your payment card numbers. We retain only a Stripe customer ID, your subscription plan and associated billing history.
2.6 Technical and usage data
- Connection and security data (IP address, device type, logs), for security and fraud-prevention purposes.
- Audience measurement and diagnostic data (via PostHog and Sentry).
- Push notification preferences (via OneSignal), if you enable them.
3. Purposes and Legal Bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6.1.b) |
| Providing Service features (profile, directory, Studio, messaging) | Performance of a contract (Art. 6.1.b) |
| Managing subscriptions and billing | Performance of a contract + legal obligation (Art. 6.1.b and 6.1.c) |
| Security, fraud and abuse prevention | Legitimate interest (Art. 6.1.f) |
| Service improvement and audience measurement | Consent (analytics cookies) / legitimate interest (Art. 6.1.a / 6.1.f) |
| Push notifications | Consent (Art. 6.1.a) |
| Service-related communications | Performance of a contract / legitimate interest |
4. Recipients and Processors
We engage processors who handle data on our behalf in connection with the provision of the Service:
| Provider | Role | Main location |
|---|---|---|
| Supabase Inc. (AWS) | Database, authentication, storage | EU (Frankfurt) / United States |
| Vercel Inc. | Web application hosting | United States |
| Stripe, Inc. | Payment processing | United States / Ireland |
| Resend | Transactional email sending | United States |
| OneSignal | Push notifications | United States |
| PostHog | Audience measurement | European Union |
| Sentry | Error monitoring | United States |
| Cloudflare, Inc. | DNS / network security | United States |
| Fly.io | Real-time processing of live events | European Union (Paris) |
We never sell your personal data to third parties.
5. Transfers Outside the European Union
Some of our providers are located outside the European Union, in particular in the United States. Where a transfer of data outside the EU occurs, it is governed by appropriate safeguards within the meaning of the GDPR, such as the European Commission's standard contractual clauses or applicable certification mechanisms.
6. Retention Periods
- Account data: retained for as long as your account is active. Upon account deletion, data is erased within a reasonable period, subject to technical backups and legal obligations.
- Billing data: retained for the duration required by applicable accounting and tax obligations.
- Live event data: retained in a limited manner (session duration and a short statistics window).
- Audience measurement data: retained in accordance with the settings of our analytics tools.
- Inactive accounts: may be deleted after an extended period of inactivity, with prior notice.
7. Your Rights
Under the GDPR, you have the following rights: access, rectification, erasure, restriction, portability, objection, and the right to withdraw your consent at any time (without retroactive effect).
To exercise these rights, contact us via the contact form. We may ask you to verify your identity.
You also have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL (www.cnil.fr).
8. Security
We implement appropriate technical and organisational measures to protect your data: password hashing, encryption of sensitive secrets, row-level security (RLS) on the database, encrypted communications (TLS), and restricted data access.
9. Minors
The Service is reserved for persons aged 18 and over. We do not knowingly collect data about persons under 18. If you believe a minor has provided us with data, please contact us so that we can delete it.
10. Cookies and Trackers
The Site uses cookies and trackers necessary for its operation and, subject to your consent, audience measurement trackers. A consent banner lets you accept or refuse non-essential trackers on your first visit, and change your choices at any time.
- Strictly necessary cookies (authentication, security, preferences): exempt from consent.
- Audience measurement and diagnostic cookies (PostHog, Sentry): subject to your consent.
- Push notifications (OneSignal): enabled only upon your explicit request.
11. Changes
We may update this Privacy Policy. Any material change will be communicated to you by an appropriate means. The last-updated date appears at the top of this document.