Privacy Policy
Last updated: September 21, 2026
This policy explains what data Aux Battles collects, why, who we share it with, how long we keep it, and your rights over it. Playing a regular room needs no account, so we collect as little as we can. Streamers and viewers who use Twitch Battles or friends battles do connect a real Twitch account, described in section 3.
The short version
- No email, no real name, no payment details. Ever.
- Game data is deleted 24 hours after the room was created.
- Analytics cookies and session replay are off in the EEA, UK and Switzerland until you accept, and you can switch them off anywhere.
- We don’t sell your data and there are no ads on this site.
1. Who is responsible for your data
Aux Battles is a hobby project run by one person, Emilis Mikalajunas, based in Lithuania, who is the data controller for the processing in this policy. You can reach them at mikalajunas.emilis@gmail.com. Aux Battles is not required to appoint a data protection officer, so that address handles every privacy question.
2. What we collect, why, and for how long
Everything we process, the reason for it, the legal basis under the GDPR, and how long it is kept:
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Game data: room code, the nickname you type, songs you submit, votes and ratings, scores | Running the game you joined | Providing the service you asked for (Art. 6(1)(b)) | Deleted 24 hours after the room was created |
| An anonymous session id (a random id, no name or email attached) | Keeping you in your room across reloads, and stopping one browser voting twice | Providing the service (Art. 6(1)(b)) | Deleted after 30 days without use |
| Twitch account details, if you sign in with Twitch (see section 3) | Hosting a Twitch or friends battle, submitting through a submit link, mod-view | Providing the service (Art. 6(1)(b)) | Until you disconnect Twitch or ask us to delete it |
| A Twitch chatter’s username, when they paste a song link in a streamer’s chat | Showing whose song it is during the battle | Legitimate interest of the streamer and us in running the battle (Art. 6(1)(f)) | Deleted with the room, within 24 hours |
| Rating of the game and optional feedback note you write at the end | Improving the game | Legitimate interest (Art. 6(1)(f)) | 12 months |
| Prompts you invent with the prompt generator | Finding good new prompts for everyone | Legitimate interest (Art. 6(1)(f)) | Unlinked from your session after 30 days, then kept as anonymous text |
| Usage analytics, session replay and error reports (see section 4) | Understanding how the game is played and fixing what breaks | Your consent where the law requires it (Art. 6(1)(a)); otherwise legitimate interest (Art. 6(1)(f)) | Set by each tool, see section 4 |
| Server request logs, including IP address | Delivering the site and protecting it from abuse | Legitimate interest (Art. 6(1)(f)) | Short-term logs kept by our host, Vercel |
| Emails you send us | Answering you | Legitimate interest (Art. 6(1)(f)) | Until the conversation is resolved |
We also keep aggregate statistics (how often a song or a prompt has been played and how it was rated on average), a catalogue of songs that have been submitted, and a cache of song-search results keyed on the search text. None of these contain a nickname, a session id, a room code or anything else that points back to a person, so they are not personal data and are kept without a time limit.
We don’t use your data for automated decisions that affect you, and we don’t build advertising profiles.
3. Twitch sign-in, Twitch chat and friends battles
A streamer can connect a Twitch channel so chat can vote and submit songs live. Voting by typing a number in chat needs no account: votes are counted in the streamer’s browser and only the totals are saved.
If you sign in with Twitch (to host, to submit through a submit link, to request a seat in a friends battle, or to use mod-view), Twitch’s own login, handled by our authentication provider Supabase Auth, gives us:
- Your Twitch user ID, login, display name and avatar URL.
- An access token. We use it only to ask Twitch who moderates a channel (the moderator list in setup, and mod-view access). It stays in your browser; when a Twitch check needs it, it is passed to our server for that one request and is not stored there. We never see your Twitch password.
We don’t receive your Twitch email. If a viewer pastes a song link in the streamer’s chat, the streamer’s browser saves that viewer’s public Twitch username next to the song so the battle can show whose pick it is; it is deleted with the room. Streamers who save a battle setup have it kept against their account until they delete it.
You can disconnect Twitch from the room lobby, or revoke Aux Battles in your Twitch connections settings. To have your linked account and saved settings deleted from our side too, email us.
4. Analytics, session replay and error tracking
We use a few tools to see how the game is played and what breaks. What they may do before you answer the cookie banner depends on where you are:
- In the EEA, the UK and Switzerland, no analytics cookie is set and no session is recorded until you accept.
- Everywhere else, Google Analytics and Microsoft Clarity run by default and the banner’s Decline button switches them off. PostHog cookies and session replay still wait for you to accept.
Change or withdraw your choice at any time.
- Google Analytics, loaded through Google Tag Manager (Google, USA). Counts pages viewed, rough location, device type and which parts of the game are reached. We use Google Consent Mode v2. Without consent, Google receives only cookieless pings with no identifier. Google Signals and advertising features are off, and advertising consent is never granted on this site.
- Microsoft Clarity (Microsoft, USA). Session replay and heatmaps: a reconstruction of mouse movement, clicks, scrolling and what was on screen during a visit, used to find where the game confuses people. It only runs with the consent described above. Clarity masks sensitive text by default, and we do not share Clarity data with Microsoft Advertising. See Microsoft’s privacy statement.
- PostHog (PostHog, data stored in the EU). Measures how the game is played (screens reached, songs submitted and rated) and records errors so we can fix them.
- Before you accept, and if you decline, PostHog stores nothing on your device. It still receives anonymous usage events and error reports, held in memory for the visit and tied to the same anonymous session id the game already uses. We do this on the basis of our legitimate interest in keeping a live multiplayer game working; you can object by emailing us, and we’ll exclude your session id.
- Session replay in PostHog only runs if you accept. Password fields are never recorded.
- Ahrefs Web Analytics (Ahrefs, Singapore). A cookieless page counter used to measure search traffic. It sets nothing on your device and does not identify you, so it runs without consent.
- Vercel Web Analytics and Speed Insights (Vercel, USA). Cookieless measurement of traffic and page speed. It sets nothing on your device and does not track you across sites, so it runs without consent.
Nothing we send to any analytics tool contains your name, email or the contents of your Spotify, YouTube, SoundCloud or Twitch account, and login tokens are stripped out of any web address before it leaves your browser.
5. Who else processes your data
Besides the analytics tools above, these services process data for us or when you use them:
- Supabase (database and sign-in, hosted in Ireland, EU). Stores the game data in section 2.
- Vercel (hosting, USA with servers worldwide). Serves the site and runs our small API; like any host it processes request logs, including IP addresses.
- Song search: Spotify, Deezer, YouTube and SoundCloud. When you search for a song, the text you type is sent from our server to these services to find matches. They receive the search text only, not your IP address, session id or nickname.
- Embedded players: Spotify, YouTube, SoundCloud. Songs play in each service’s own player inside the page. Those players load that service’s scripts, may set their own cookies, and see your IP address like any website you visit. If you are logged in to one of them in the same browser, it knows it is you; we don’t receive any of your account details.
- Twitch. Sign-in, chat and the stream embed, see section 3.
Their own privacy policies apply to what they do: Spotify, Google and YouTube, SoundCloud, Deezer, Twitch.
YouTube API Services. Aux Battles uses YouTube API Services to search for videos and show their titles and artwork. By using those features you are also bound by the YouTube Terms of Service, and Google’s handling of the data is described in the Google Privacy Policy. We don’t access your Google account; if you ever grant access to a Google app, you can revoke it at Google’s security settings.
6. Data transfers outside the EU
Some of the services above are based outside the European Economic Area, mainly in the USA. Where that happens, the transfer relies on the EU-US Data Privacy Framework for recipients certified under it (such as Google, Microsoft and Vercel), or on the European Commission’s Standard Contractual Clauses in the provider’s data processing terms. Our database stays in the EU.
8. Your rights
If you are in the EEA, the UK or Switzerland you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent at any time without affecting what happened before. To use any of them, email us; we’ll answer within one month. Because regular play is anonymous, we may ask for your room code or Twitch username so we can find your data.
You can also complain to a data protection authority. Ours is the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt), and you can also go to the authority where you live.
If you are in the USA: we don’t sell or share personal information for cross-context behavioural advertising, and we don’t use sensitive personal information. You can still ask us what we hold about you, or ask us to delete it, at the address above.
9. Children
Aux Battles isn’t directed at children under 13, and we don’t knowingly collect their data. If you believe a child under 13 has given us personal data, email us and we’ll delete it. See the age requirements in our Terms of Service.
10. Security
Data travels over HTTPS, the database only answers requests its access rules allow, and server keys never reach the browser. No system is perfectly secure; if a breach ever put your data at risk, we would tell the authority and, where the law requires it, you.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date above always reflects the current version, and a material change to how we use cookies re-shows the consent banner.
12. Contact
Questions about your privacy or this policy? Email mikalajunas.emilis@gmail.com.