PRIVACY

Privacy Policy

Last updated August 30, 2026 · Version 2026-08-30.1

1. Scope and current privacy practices

This Privacy Policy explains how TheSQRLs.com handles information in connection with the site-wide Account system, Store, Acorns, community features, supporter features, Account Cloud Saves, browser tools, xxSQRLxx, SQRLFather, support, and related integrations. It should be read together with the Terms of Use.

This Policy describes the site's current practices. Third-party services have their own privacy policies and may independently collect or process information when you use, load, embed, or connect to them.

We do not sell Account data to advertisers. The site does not currently operate a site-owned behavioral advertising or cross-site advertising profile. Third-party embeds and external services may perform their own measurement, personalization, or advertising under their policies.

2. Information you provide when creating or managing an Account

If you create or maintain an Account, we may store information such as your internal user ID, transferable Account Number, username, display name, email address, password hash if you use a site password, email-verification state, profile information you choose to provide, Account preferences, notification preferences, and Account status.

We maintain records showing acceptance of applicable Terms and the required 18+ age certification, including acceptance/certification timestamps and version identifiers. The Account service does not currently require a date of birth.

Optional profile information may include pronouns, Pride/identity/community badges, interests, approximate location, public links, biography text, avatars, banners, and similar self-described information. You do not have to provide optional profile fields to maintain an Account.

Some optional profile selections or content may reveal or suggest information that some laws treat as sensitive personal data, including sexual orientation, gender identity, beliefs, or other identity-related information. We use these optional fields for the profile/community purposes you select, site administration, safety, and legal compliance; we do not use them to sell advertising profiles. Public visibility depends on the settings associated with the feature.

Passwords are stored as one-way password hashes rather than readable passwords. Do not send passwords, full payment-card numbers, card security codes, 2FA/authentication codes, OAuth secrets, recovery codes, or other sensitive credentials through support tickets, community messages, or Cloud Saves.

3. Email changes, recovery, sessions, and security records

If you request an email-address change, we may store the current email, requested new email, verification-token hash, verification expiration, verification state, related support-ticket ID, request and review timestamps, and the staff Account involved in review. The new email may be contacted to verify that the address is controlled by the requester before the Account email changes.

Password-reset and email-verification flows may temporarily store one-time token hashes and expiration data. Security activity may include login, logout, failed-login, session, remembered-login, password, email, linked-identity, moderation, export, Account-deletion, rate-limit, and network-enforcement events.

For security, fraud prevention, abuse prevention, spam prevention, and enforcement, the site may process the IP address presented by your connection. Ordinary audit records generally use a keyed one-way hash rather than displaying a raw IP address. When IP enforcement is enabled, the site may also retain an encrypted recoverable copy of an exact IP address and associate it with an Account, community-media submission, or enforcement record so authorized staff can apply, review, expire, or lift an IP Media Submission Ban, IP Account Ban, or IP Site Block. Exact IP data attached to a submission is restricted to authorized enforcement functions and is not displayed publicly.

IP-related records may include first/last-seen timestamps, a related Account or submission, the staff actor, reason, duration, and enforcement history. IP addresses can be shared, reassigned, masked, or changed and are treated as a security signal rather than proof of a person's identity.

4. Connected accounts and identity providers

You may be able to sign in with Google, Twitch, or Discord. Patreon may be connected after sign-in for supporter verification but is not currently an Account-creation or sign-in method. When you authorize a connection, we may receive a provider-specific user identifier and available profile information such as username, display name, email address, email-verification state, avatar, or other information included in the permission you approve.

Connected providers may also send or expose authorization tokens, refresh tokens, expiry information, permission scopes, membership/subscription information, or other data required for the enabled integration. Supported authorization tokens may be stored encrypted where the site needs them to maintain the connection.

Disconnecting a provider removes or disables the site's continuing use of the supported connection to the extent implemented, but it does not necessarily delete records already required for Account identity, transactions, fraud prevention, audit history, or legal compliance.

Google and YouTube API data used by xxSQRLxx Unified Chat

TheSQRLs.com uses YouTube API Services for certain xxSQRLxx Unified Chat features. When a signed-in user with access to Unified Chat chooses Connect YouTube Chat, the site requests Google identity permissions and the YouTube authorization needed by Google's API for authorized YouTube actions. The Google consent screen may describe that YouTube scope as permitting broader channel actions than the Unified Chat feature actually uses.

For a member's Unified Chat connection, the site is intended to access and use Google/YouTube user data only to: (1) associate the authorization with the user's existing TheSQRLs.com Account; (2) identify the YouTube channel that will be used to send chat, including a channel identifier and display title when available; (3) maintain the OAuth authorization so the user does not have to reconnect for every message; and (4) send the text message the user expressly submits to the active xxSQRLxx YouTube live chat the user selects. The feature is not intended to use the authorization to upload or delete videos, change ratings, edit ordinary comments or captions, read watch history, or manage unrelated YouTube content.

To maintain the authorized connection, TheSQRLs.com may store the provider identity record, OAuth scope and expiration metadata, and supported OAuth access and refresh tokens. Supported authorization tokens are stored encrypted on the server. A message submitted through Unified Chat passes through TheSQRLs.com to YouTube so the requested message can be posted. The site does not intentionally create a separate permanent archive merely because the send control was used, although the resulting live-chat message can appear in the normal Unified Chat feed/runtime cache and on YouTube as part of the live chat.

Google/YouTube user data obtained for this feature is used only to provide or protect the user-facing connected-chat functionality described here, for security/abuse investigation, or where disclosure is required by law. It is not sold to data brokers or advertisers, used for interest-based advertising, used to determine creditworthiness, or used to train or improve a generalized artificial-intelligence or machine-learning model. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable.

The Chat Connections area lets you disconnect YouTube Chat from Unified Chat. That application-level disconnect stops Unified Chat from using the connection to send YouTube chat messages while allowing the site's ordinary linked-account/sign-in relationship to remain where applicable. Because provider authorization can exist independently of the site's application-level switch, you may also revoke TheSQRLs.com's Google access through your Google Account. Unlinking the Google identity, deleting your Account, or submitting an applicable deletion request can remove associated stored authorization data subject to legitimate security, audit, legal, and other retention requirements described in this Policy.

YouTube API Services are provided by Google/YouTube. Google's handling of information on its services is governed by the Google Privacy Policy, and use of YouTube is subject to the YouTube Terms of Service.

5. Supporter, membership, donation, and access information

To recognize supporters and apply Account benefits, we may store or receive information such as provider name, provider-specific user ID, username/display name, membership or subscription tier, entitlement state, supporter start/end or verification times, contribution/payment references, manually reviewed mappings, and the TheSQRLs.com Account to which a supporter record is linked.

Supporter records may be used to display recognition where enabled, award badges or Acorns, grant access, calculate Store discounts, maintain supporter history, prevent duplicate grants, and correct records when a payment or membership is refunded, reversed, charged back, expired, duplicated, or otherwise invalid.

6. Acorn wallet, rewards, and Store-economy information

The Account system may store purchased/loaded Acorn balances, earned/bonus Acorn balances, combined balance displays, wallet-ledger transactions, reasons, references, source/payment provenance, transfer or trading holds, unresolved liabilities, reward ownership, reward reservations, reward use, benefit/discount eligibility, and administrative adjustments.

Acorn Gift Cards may require storage of card identifiers, secure hashes or encrypted values used to validate redemption credentials, amount/status, purchaser and recipient information when available, transaction/source references, issue/redemption timestamps, and the Account that redeemed the card. The public-facing redemption code and CV should be treated as credentials by the purchaser and recipient.

For Acorns-back promotions, the site may retain the eligible merchandise value after Store discounts and eligible one-time rewards, the applicable promotion/rule, the calculated Acorn award, and whether the remaining eligible merchandise value was satisfied using Acorns, real money, or both.

7. Purchases, checkout, Square, PayPal, and transaction records

When you purchase merchandise, Acorns, or other eligible items, the site may process or store order identifiers, cart/line-item data, prices, discounts, rewards, Acorn reservations and usage, shipping/contact details, tax and shipping amounts, storefront, fulfillment status, payment-processor references, payment status, refund/chargeback status, checkout acceptance records, and other information needed to complete and reconcile the transaction.

Payment-card details are generally entered into and processed by the supported payment provider rather than stored as readable card data by TheSQRLs.com. The site may receive processor-generated IDs, status, limited payment metadata, and information necessary to verify or reconcile the transaction.

Checkout acceptance records may include the Terms version, Privacy Policy version, acceptance time, acceptance method, a keyed IP hash, and a hash derived from the browser user-agent string.

If you start or maintain a recurring purchase, the site may store Square customer, subscription-plan, plan-variation, subscription, invoice, order, payment-link, order, and payment identifiers; the subscribed item or Acorn package; recurring price and cadence; subscription and cancellation status/dates; checkout-consent records; successful billing-cycle records; and, for recurring Acorn packages, the Acorns granted for each successfully paid cycle. Square processes the payment method used for recurring billing; TheSQRLs.com does not ordinarily receive or store your full card number or card security code.

If a payment is disputed, reversed, refunded, charged back, reported unauthorized, or suspected of fraud, we may retain and use relevant Account, order, Acorn, security, supporter, and transaction records to investigate, respond to the processor or financial institution, prevent abuse, protect users or the service, and comply with law.

8. Cookies, browser storage, and optional Account Cloud Saves

The Account service uses essential session cookies needed to keep a user signed in and protect Account interactions. If you choose a remembered-login feature, an additional secure remembered-login cookie may be used. These cookies are used for Account operation and security rather than site-owned behavioral advertising.

The Store and browser-based tools may use browser local storage, IndexedDB, or similar browser storage to remember cart contents, display choices, tool settings, tool state, saved loadouts, profiles, timers, or related information on your device. Browser storage is maintained by your browser and can generally be cleared through browser settings. Clearing it can remove locally saved settings or state.

Approved browser tools may also offer an optional Account Cloud Save. Merely opening a supported tool or signing in does not upload that tool's local settings. When you explicitly choose Save to Account, the site may store the approved tool identifier, cloud-save schema and tool version, save/update timestamps, payload size, and a JSON copy of the supported settings or state associated with your Account. The browser copy remains the tool's ordinary live working copy; Account Cloud Save is a manual backup/restore feature rather than automatic synchronization.

Only tools approved in the Owner-managed Cloud Save registry can use the service, and each approved tool has a server-enforced size limit. Cloud Saves are not intended for passwords, authentication tokens, API keys, OAuth secrets, Streamer.bot or OBS passwords, payment credentials, private keys, or recovery codes. Supported adapters are designed to exclude known credential stores, and the service may reject payload fields identified as credentials or secrets. Custom labels or other free-form tool fields can still contain information you enter, so do not place confidential information in them.

When you choose Restore from Account, saved data is returned to the supported browser tool after the restore confirmation shown by the site. Restoring may overwrite supported local settings. Deleting an Account Cloud Save removes that server-side save without deleting the browser's local copy. Account deletion is designed to remove Cloud Saves linked to the Account; browser-local data remains controlled by the browser or device and may need to be cleared separately.

9. OBS/browser-source and direct-access pages

Certain Owner-approved overlay, dock, simple-view, browser-source, or direct-resource pages may be configured to load without the ordinary site navigation or normal Account/site-access restriction so software such as OBS can use them reliably. The exception applies to the approved resource only and does not make private Account or administrative data public.

Loading one of these pages can still create ordinary server or hosting logs such as IP address, requested URL, timestamp, browser/user-agent information, and response status. Tool state for these pages may remain in browser storage unless the specific tool expressly uses a server-side feature such as Account Cloud Save.

If you intentionally place a browser-source, overlay, image, message, username, profile element, or other site content into a livestream, recording, or other public output, that publication occurs through your streaming/recording setup. You are responsible for choosing what information you expose in that output.

10. Public profile information

If public profiles are enabled and you choose to keep your profile public, information such as your immutable site ID number, username, display name, optional avatar, optional banner, profile headline, bio, interests, approximate location, public links, join month, public badges, supporter recognition, and friend list may be visible according to the profile information and privacy choices you select.

Your transferable Account Number is not required to be displayed on the public profile. Your Account email, password hash, private connected-account identifiers, OAuth tokens, private support records, Acorn-administration notes, exact enforcement IP information, and payment credentials are not intended to be displayed on the public profile.

Profile location is optional and is intended for a general city, state/region, or country rather than a home address or precise location. Public profile links are supplied by the Account holder and must use HTTPS.

If you choose a custom external avatar or banner URL, the image remains hosted by that third party. Loading it may cause a visitor's browser to contact the external host and disclose ordinary connection information such as IP address and browser headers under that host's privacy practices.

11. Community Activity, comments, friendships, blocking, and messages

If you use The Scurry community features, we may store posts, comments, reactions, direct/private messages, friendship and friend-request records, block relationships, audience/privacy choices, timestamps, read-state information, and the internal Account IDs needed to operate the features.

Activity visibility is affected by public-profile state, Activity settings, the selected post audience, friendship where applicable, blocking, and moderation restrictions. Public Activity content may be visible to people who are not signed in when your settings and the post audience allow it.

Private/community messages are not represented as end-to-end encrypted. Do not use them to transmit passwords, authentication codes, payment-card information, private keys, or other secrets. Authorized staff may access content when reasonably necessary to operate support/moderation functions, investigate a report, protect users or the service, comply with law, or resolve a technical problem.

Deleting or hiding a post, comment, or message from normal view does not necessarily erase every underlying record immediately. Blocking another Account is an interaction/privacy control, not a data-erasure function. Original content and related identifiers may be retained when reasonably necessary for reports, moderation, safety, abuse prevention, disputes, or legal compliance. Authorized moderation staff may review reported material even when it is no longer visible through ordinary community views.

12. Support requests, reports, submissions, and staff administration

If you contact support, open a ticket, reply by web or email, report another user or content, submit community media, request a username or email change, request Account deletion, or otherwise ask staff for assistance, we may store the request, requester contact information, message/content, related Account/content/submission identifiers, category, status, assignment, staff notes, action history, security signals, and timestamps needed to review and resolve the matter.

Staff and Owner actions may be recorded in audit logs, including the acting Account, target Account or record, action type, time, and limited supporting metadata. These records support security, accountability, financial integrity, fraud prevention, abuse prevention, and dispute handling.

13. Server, device, session, and technical information

The Account application may store session identifiers or hashes, remembered-login records, user-agent/browser information used to describe recent sessions, timestamps, rate-limit data, and keyed hashes derived from network/device information for abuse prevention and auditing.

Separately, the web host, web server, firewall, content-delivery/security provider, email infrastructure, or similar systems may maintain standard connection, delivery, or security logs that can include an IP address, requested URL, timestamp, user-agent, response status, mail-delivery information, and diagnostic or abuse-detection information. These infrastructure records may be outside the Account application's audit/session ledger.

14. Embedded media, external links, and third-party content

Pages may include or link to YouTube, Twitch, Discord, PayPal, Square, Patreon, social platforms, external image hosts, or other third-party services. Loading an embed, opening a third-party page, signing in through a provider, or using a third-party widget can cause your browser to communicate directly with that provider. The third party may receive information such as IP address, browser/device information, referring page, cookies, or Account information according to its own policies.

We do not control a third party's cookies, tracking, data retention, or use of information on its own service. Review the provider's privacy information if you want to understand those practices.

15. Sources of information

Depending on the feature, we receive information: directly from you; automatically from your browser/device and interactions with the site; from transactions processed through supported payment providers; from identity, supporter, social, or platform integrations you authorize; from staff moderation or support actions; and from other users when they interact with, report, message, or transact with your Account through an enabled feature.

16. How we use information

We may use information to create, authenticate, secure, recover, and administer Accounts; verify email and age certification; operate profiles and community features; deliver messages and notifications; process support requests and media submissions; recognize supporter status; provide badges, roles, discounts, Acorns, rewards, Acorns-back promotional awards, and access; operate Account Cloud Saves; operate the Store; reserve and reconcile checkout value; fulfill purchases; prevent duplicate grants or double spending; detect and investigate fraud, spam, abuse, or security incidents; respond to chargebacks and payment disputes; moderate content; troubleshoot errors; maintain audit and security records; protect the service and its users; enforce the Terms; and comply with legal obligations.

17. When information may be shared

We do not sell Account data to advertisers. We may disclose or transmit information when reasonably necessary to:

  • provide a feature you request through an identity provider, payment processor, email provider, hosting provider, or other service provider;
  • process, verify, fulfill, refund, reconcile, investigate, or dispute a payment or order;
  • maintain a connected Twitch, YouTube, Discord, Google, Patreon, PayPal, Square, or similar integration;
  • deliver an external image, embed, link, browser-source dependency, or other third-party content you choose to use;
  • protect TheSQRLs.com, its users, payment partners, or others from fraud, security threats, abuse, spam, or unlawful activity;
  • respond to lawful legal process, enforceable requests, or legal obligations;
  • establish, exercise, or defend legal claims; or
  • support a reorganization, transfer, sale, or change in operation of the site, subject to applicable law.

Public content and public profile information are shared according to the visibility choices and permissions associated with the feature.

18. Sensitive information and advertising-related uses

Optional profile fields, Pride/identity badges, private messages, support messages, and other user-created content may contain information that is sensitive or that applicable law treats as sensitive personal data. We ask users not to submit credentials or highly sensitive information that is unnecessary for the feature.

TheSQRLs.com does not currently sell this information or use optional Pride/identity selections, private messages, support content, or Cloud Save payloads to build advertising profiles. If the site's advertising or data-sharing practices materially change in the future, this Policy will be updated and any consent or opt-out mechanism required by applicable law will be provided.

19. Retention

We retain information for as long as reasonably necessary for the purpose for which it was collected and for legitimate operational, security, financial, moderation, dispute, audit, fraud-prevention, abuse-prevention, and legal needs. Different records therefore have different retention periods.

Account deletion removes or anonymizes core profile and sign-in information and disconnects linked identities. Account Cloud Saves linked to the Account are designed to be removed as part of Account deletion. If an active Square subscription is recognized, the site attempts to schedule it to stop renewing before final Account deletion and can delay deletion when cancellation cannot be confirmed safely. Some records may remain after Account deletion where necessary to preserve subscription and transaction history, Acorn ledgers, payment and chargeback history, support history, moderation/report evidence, private-message continuity for other participants, media/publication attribution, security/audit/enforcement history, legal obligations, or protection against fraud and abuse. Where possible and appropriate, retained records may use the internal Account ID or an anonymized Account identity rather than the deleted user's former public identity.

Supporter records may be detached from a deleted Account rather than erased when the supporter/donation record represents a separate historical transaction or membership record. Browser-local data is not stored in the Account merely because an Account is deleted and may remain on a device until the browser/user clears it.

20. Account export and deletion

Signed-in Account holders can use the Account data area to export available Account information and request Account deletion. The Account export is designed to include available Account Cloud Save records associated with the Account. Self-service deletion uses a 24-hour safety period before final deletion can be confirmed, and a pending request can be canceled during that period.

Deleting an Account is not the same as deleting every historical transaction, moderation record, message received by another participant, infrastructure log, or record we are required or reasonably permitted to retain. Remaining Acorn or reward balances may cease to be usable when an Account is permanently closed, as described in the Terms.

21. Your choices and privacy rights

Depending on the enabled features, you may be able to update profile information; choose whether supported profile details, badges, supporter recognition, friends, links, location, or join month are public; manage Activity audience and comment settings; manage friendships and blocks; disconnect supported external identities when another authentication path remains; change your password; verify or request a change to your email; review and revoke browser sessions; select optional notification categories; save, restore, or delete supported Account Cloud Saves; hide or remove your own supported community content from ordinary view; export Account data; and request Account deletion.

If applicable law gives you additional rights to access, correct, delete, restrict, object to, opt out of certain processing, appeal a privacy decision, or obtain information about personal data, you may submit a request through the contact or support options on TheSQRLs.com. We may need to verify the requester's identity and may retain information where law permits or requires us to do so.

Because TheSQRLs.com does not currently sell Account data to advertisers or operate a site-owned cross-site behavioral advertising program, some sale/share or targeted-advertising opt-out rights may not apply to the site's own processing. This does not affect rights you may have concerning third-party services you choose to use.

22. Age requirement and children

The TheSQRLs.com Account service is intended only for people who are at least 18 years old. New Account creation requires an affirmative 18+ age certification. We store the certification timestamp and version identifier for Account records but do not currently require a date of birth.

The Account service is not directed to children under 13 and children under 13 are not permitted to create Accounts. If we learn that an Account was created by a person who was not eligible to create it, we may restrict or remove the Account and associated information as appropriate, subject to legal and record-retention obligations.

23. Security

We use measures intended to protect Account information, including password hashing, secure sessions, CSRF protections, rate limiting, access controls, administrative auditing, restricted enforcement tools, server-side Cloud Save limits/validation, and encrypted storage for supported authorization tokens and exact-IP enforcement records where implemented. Financially meaningful Owner controls are restricted by role/permission checks.

No internet service, storage system, browser, third-party provider, or transmission method can guarantee absolute security. You are responsible for using a unique password where applicable, protecting connected accounts and recovery methods, signing out of shared devices, and avoiding the submission of secrets to features that are not designed to hold them.

24. Data minimization, accuracy, and service providers

We aim to collect and retain information reasonably related to the features we operate and to limit access according to role and operational need. You can help keep Account information accurate by maintaining current contact information and promptly reporting unauthorized Account or payment activity.

We may use hosting, email, identity, payment, security, and other service providers to operate the site. Information may be processed in locations where those providers operate, subject to their agreements and applicable law. We may correct duplicate or demonstrably inaccurate Account, supporter, Store, security, or Acorn records as reasonably necessary to maintain service integrity.

25. Changes to this Privacy Policy

We may update, revise, replace, or reissue this Privacy Policy as TheSQRLs.com features, technologies, legal obligations, or data practices change. The Last updated date and version shown at the top identify the current Policy.

We may provide an Account alert, site notice, email, checkout notice, or another reasonable notice of a material update, and we will use any notice or separate consent process specifically required by applicable law. Existing Accounts are not automatically required to re-accept every wording clarification unless the site requires renewed acceptance for the affected feature or applicable law requires it.

Continued access to or use of TheSQRLs.com after an updated Policy becomes effective constitutes acknowledgement of the revised Policy to the fullest extent permitted by applicable law. This continued-use provision does not replace separate affirmative consent where applicable law specifically requires it.

26. Contact

Questions, privacy requests, Account-security reports, or concerns about how information is handled can be submitted through the contact and support options provided on TheSQRLs.com.