Slay the Spire 2 Twitch Extension Privacy Policy

Effective date: September 18, 2026.

This policy covers the Slay the Spire 2 Companion extension for Twitch (the “extension”), operated by Mega Crit. Our general privacy policy at megacrit.com/privacy-policy covers the website and the games themselves.

What the extension is

The extension shows a viewer the streamer’s current Slay the Spire 2 run on top of the video: the cards in hand, the draw, discard and exhaust piles, relics, potions, and the contents of shops, events, relic choices and the act boss, with hover descriptions. When the streamer allows it, viewers can vote on choices the streamer is about to make.

Data we process

From the streamer

When a streamer links the game to Twitch, the streamer signs in with Twitch in a browser. Our server stores the resulting Twitch access and refresh token, keyed by the streamer’s Twitch user id, so that it can check whether the channel is live in the Slay the Spire 2 category. The token is kept until the streamer asks us to remove it or until Twitch stops honouring it. The game receives a signed token naming the channel id and keeps it in the game’s local settings. The browser sign-in session on our server expires five minutes after its last step. The overlay reads the streamer’s public Twitch profile through Twitch’s API to show the channel’s display name; it stores nothing from it.

While the streamer is live in the Slay the Spire 2 category with the extension enabled, the game sends the current run state to our server: cards, relics, potions, shop, event and relic choice contents, the act boss, and the on-screen position of those elements. This is game state, not personal data. It is kept for up to 24 hours after the last update. The game normally clears it when the channel goes off air; if the game is closed first, it expires on its own.

Our server also keeps a list of the Twitch channel ids that are currently live in the Slay the Spire 2 category, refreshed every minute from Twitch’s public directory, whether or not the channel uses the extension. It is used only to decide which channels the overlay shows data for.

From viewers

Every request the overlay makes carries the token Twitch issues to the extension, which names the channel and a viewer identifier: the viewer’s Twitch user id if the viewer has shared their identity with the extension, otherwise a per-viewer opaque id assigned by Twitch. We use it to count each viewer once per poll and to limit abuse. We do not read the viewer’s Twitch profile and store no name, email or avatar.

A vote stores that viewer identifier and the option chosen, for up to 30 minutes. The list of votes for a poll is sent to the streamer’s game so it can show vote counts on the streamer’s screen.

The overlay stores one value in the viewer’s browser (local storage) to remember that the first-run tutorial was dismissed.

Our server keeps a short-lived count of requests per viewer, channel and route to limit abuse. It is held in memory, expires after one minute, and is never written to storage.

Error reports

The overlay and our server report errors to Sentry, a monitoring service. An error report can include the browser type, the page URL and a technical description of the fault. We do not attach viewer or channel identifiers to error reports.

Bug reports

The overlay has a Report a Bug button that opens a form with a description field and optional name and email fields. What you enter is sent to Sentry with the same technical context as an error report. Name and email are optional; leave them blank if you prefer.

How long we keep it

Data Retention
Streamer’s Twitch token Until removal is requested or Twitch revokes it
Browser sign-in session 5 minutes after the last step
Run state 24 hours after the last update; normally cleared when the channel goes off air
Live channel list Rewritten every minute
Votes and polls 30 minutes
Rate limit counters 1 minute, in memory
Error and bug reports 90 days

Deletion requests

Run state, votes and counters expire on their own within the periods above. A streamer can have their stored Twitch token removed by emailing [email protected] from the email on their Twitch account. To have an error or bug report deleted sooner, email [email protected] with the approximate time and channel. We respond within 30 days.

Who we share with

Twitch (the extension platform), Render (hosting), Cloudflare (network and image delivery) and Sentry (error monitoring) process data on our behalf. We do not sell data and do not use it for advertising.

Children

The extension is available only through Twitch and follows Twitch’s age requirements.

Changes

We will post changes to this page and update the effective date.

Contact

Support questions: [email protected]. Privacy questions: [email protected].