Security, in plain words
What Spectator may do with your channel, what is stored, what is not, and how you stay in control at all times. The short paragraphs are enough to understand it. If you want the specifics, expand the details below each one.
1. You sign in with Twitch, not with us
Spectator has no password of its own. You click "Sign in with Twitch", Twitch asks whether Spectator may manage your channel, and you say yes or no. Spectator never sees your Twitch password.
If you no longer want the bot, revoke its permission directly at Twitch. From that moment it cannot enter your channel, no matter what is stored on our server.
In detail
Sign-in uses Twitch OAuth 2.0 with a server-side state parameter (valid for 10 minutes). Twitch issues an access token and a refresh token for exactly the permissions listed below. You can revoke them at twitch.tv/settings/connections.
2. What the bot may do and what it may not
It may: write in chat, delete messages or time people out when you set that up in a rule, count your followers, subs and viewers, change title and category when you trigger it with a command, create clips, and react to channel points, polls and predictions.
It may not: see your password, stream in your name, move money, delete your channel, change your Twitch settings, or read messages while it is not in your chat.
In detail: every permission and why it is needed
- Read and write chat
channel:bot, moderator:manage:announcements, moderator:manage:chat_settings. Answering commands, announcements, chat modes such as followers-only. - Moderation
moderator:manage:chat_messages, moderator:manage:banned_users, moderator:manage:shield_mode. Only for Auto-Mod rules you create yourself. - Read followers, subs, viewers
moderator:read:followers, channel:read:subscriptions, moderator:read:chatters. Announcements, watchtime, statistics. - Channel points, bits, hype trains, goals
channel:read:redemptions, channel:manage:redemptions, bits:read, channel:read:hype_train, channel:read:goals. Linking rewards to actions, analytics. - Polls and predictions
channel:read:polls, channel:manage:polls, channel:read:predictions, channel:manage:predictions. The !poll and !prediction commands. - Stream info, clips, ads
channel:manage:broadcast, clips:edit, channel:read:ads, channel:edit:commercial, channel:manage:ads, moderator:manage:shoutouts. The !title, !game, !clip, !so commands and ad announcements. - Email address
user:read:email. Provided by Twitch at sign-in and used to match the account.
3. What is stored and what is not
Stored: your channel name, your settings and commands, how long each person watched, who follows or subscribes to you, and events such as raids or bits. Also who changed what in the dashboard and when.
Not stored: the chat. Every message is checked briefly in memory, for links for example, and then discarded. There is no chat transcript anyone could read later. No profiles of your viewers either, only numbers tied to their Twitch id.
In detail
- Channel record: Twitch id, login, display name, avatar, language, settings.
- OAuth tokens with expiry and list of granted permissions.
- Watchtime as a minute counter per Twitch user id, first-seen timestamp per chatter.
- Follower and subscriber lists as delivered by Twitch, for announcements and statistics.
- Stream sessions with per-minute viewer counts, chat activity per hour as counters.
- Events: follow, raid, sub, bits, channel points, hype train, poll, prediction.
- Activity log: who changed which setting and when. Auto-Mod log: which message was removed by which rule.
- Login log: time, IP address, browser and result of every sign-in attempt.
The complete list, retention periods and legal bases are in the privacy policy.
4. Where your data lives
On a server in Germany. There is no resale, no ad network and no sharing with third parties. The only exception is services you connect yourself, such as Spotify for the music player. Then Spectator talks to that service on your behalf, and you can disconnect it at any time.
5. Who else may touch your channel
Nobody, unless you invite them. Moderators or friends can help as managers, and you decide per area what they may see and change. A manager never sees your Twitch tokens. Everything they change is logged with their name and the time, and you can revoke their access with one click.
In detail
Rights are granted per module (commands, Auto-Mod, watchtime, song requests, channel points, overlays, analytics, activity). Every writing API request checks the session and the module right. The activity log cannot be deleted from the dashboard by anyone, not even the channel owner.
6. How the dashboard is protected
After sign-in your browser receives a single key that travels only over an encrypted connection and that no website or script can read. It is valid for 30 days and is deleted on the server when you sign out. Anyone who requests too often in a row is slowed down. Every sign-in attempt is recorded with time and origin, and a watchdog on the server spots suspicious access.
In detail
- Session cookie: HttpOnly, Secure, SameSite=Lax, 30 days, stored server-side and deleted on logout.
- Content Security Policy: scripts only from our own domain and the embedded players (YouTube, SoundCloud, Spotify). The site cannot be embedded in foreign pages.
- Separate rate limits for the API, cheap lookups and sign-in.
- Login log with status (success, blocked, invalid code), IP and user agent.
- Watchdog middleware that detects suspicious patterns and reports to an internal overview.
- Overlay URLs contain a secret token that can be regenerated in the dashboard at any time. Custom widgets run in a sandbox.
7. What you can do yourself, any time
- Revoke the bot's permission at Twitch. Takes effect immediately.
- Sign out of the dashboard. The session is gone from the server.
- Request deletion of your data. An email is enough, the privacy policy states the deadlines.
- Revoke a manager's access.
- Generate a new overlay token if a link was ever visible on stream.
- Read every change in the activity log.
8. Found something?
If you notice a security problem, write to hey@mutebefehl.de. You will get a reply, and the issue is fixed before it is discussed publicly. For automated reports there is security.txt.
Last reviewed 3 September 2026