Privacy policy
Last updated September 28, 2026
BloxLobby helps game studios plan Steam launches and lets creators show studios the channels they run. This page says what we collect, why, who helps us run the service, and how you can see, change or delete your data. Questions go to hello@bloxlobby.com.
What we collect
- Your account. Your email address, your name, and your password, which is stored only as a secure hash by our authentication provider. If you sign in through Steam, we receive your Steam ID from Steam, and with it your public Steam name and avatar.
- Your studio and games. Studio names, team members and their roles, the games you add, and what you enter about them. For each game we read its public Steam store page and keep a history of it.
- Creator profiles. If you join as a creator: your handle, name, headline, bio, languages, the Steam tags you cover and, if you choose, your country, website, X handle, profile photo and banner. We store the photo and banner ourselves after cropping them and removing their metadata. For each channel you verify, we keep its name, address, avatar, the audience numbers the platform reports, and the titles, links, thumbnails, dates, lengths and public view, like and comment counts of its latest public videos, refreshed once a day. We keep a daily history of those numbers so your public page can show how your channels and videos grow. We work out figures such as typical views, posting frequency and engagement rate from them, and match the games named in your video titles against Steam. For a Steam curator page or press site, we keep its address and the code we gave you to verify it.
- Public Steam store data. Release dates, tags, prices and review counts of games on Steam, which power the release calendar and market meta. It is about games, not people.
- Emails. Account emails we send you (confirmations and password resets), and anything you send us.
- Technical data. The cookies listed below, and the server logs our hosting provider keeps (such as IP address and pages requested) to run and secure the service. We don't use analytics trackers or advertising cookies.
YouTube
BloxLobby uses YouTube API Services to verify creators' channels. By verifying a YouTube channel on BloxLobby, you agree to be bound by the YouTube Terms of Service, and Google's use of your data is described in the Google Privacy Policy.
- What we ask for: read-only access to your YouTube account (the
youtube.readonlypermission), used once, to see which channels your Google account owns. That is how we know a channel is yours. - If you choose to share your audience: separately, and only if you ask, read-only access to your channel's YouTube Analytics (the
yt-analytics.readonlypermission). We use it once a day to read what share of your viewers fall in each age group and gender, and which countries your views come from, over the last 28 days, and show these on your public page for studios. We read nothing else from YouTube Analytics. - What we keep: each channel's ID, name, address and avatar, its public subscriber, view and video counts, and the titles, links, thumbnails, dates, lengths and public view, like and comment counts of its latest public videos, with a daily history of those counts. When you verify, we read these once with your access; after that, once a day with our own API key, not with your access. If you share your audience, we also keep the daily age, gender and country shares described above.
- What we don't keep or read: for verification we don't store your Google access token. If you share your audience, we keep the refresh token Google gives us, encrypted on our server before it is stored, and use it only to read those audience shares. We don't read your videos' contents, comments, messages, watch history or any private data.
- Removing it: choosing Stop sharing on your creator page revokes the key at Google and deletes it and your saved audience shares; the channel stays verified. Removing a channel deletes it, its key, its saved audience history and its saved videos from BloxLobby. You can also revoke BloxLobby's access at any time in your Google account's third-party access settings.
BloxLobby's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Twitch and TikTok
Creators can also verify a Twitch channel or a TikTok account by signing in with it.
- Twitch: we ask for no permissions. Signing in tells us your Twitch account ID, login and display name, which proves the channel is yours. We read the channel's follower total, its avatar, and its latest videos (titles, links, thumbnails, dates, lengths and views), with a daily history of those counts.
- TikTok: we ask for your basic profile, your public profile details, your account statistics and your list of public videos. We keep your TikTok ID, display name, avatar, profile link, follower and video counts, and the titles, links, covers, dates, lengths and view, like and comment counts of your latest public videos, with a daily history of those counts.
- The key we keep: both platforms share these numbers only with a signed-in account, so to save them once a day we keep the refresh token the platform gives us. It is encrypted on our server before it is stored, only our server can read it, and we use it for nothing else.
- Removing it: removing the channel on your creator page deletes it, its key, its saved audience history and its saved videos from BloxLobby. You can also disconnect BloxLobby in Twitch's connections settings or in TikTok under Settings and privacy, Security, Manage app permissions.
How we use it
- To run BloxLobby for you: your studio's dashboards, calendars, scores and alerts, and your creator profile.
- To show your creator page to anyone who opens it, if you keep it public: your profile and verified channels with their audience numbers. You can hide it at any time.
- To send the emails your account needs, and to answer you when you write to us.
- To keep the service secure and working.
We don't sell personal data, we don't use it for advertising, and we don't share it with anyone except the providers below, who process it on our behalf.
Who helps us run BloxLobby
- Supabase: our database and sign-in. Your data is stored in the United States.
- Vercel: hosts the website and keeps its server logs.
- Microsoft (Microsoft 365): sends our account emails.
- Google (YouTube API Services): channel verification, audience numbers and, if you share it, audience demographics, as described above.
- Twitch and TikTok: channel verification and audience numbers, as described above.
- Valve (Steam): signing in through Steam, and the public store data we read.
Cookies
We use only cookies BloxLobby needs to work:
- Sign-in cookies from our authentication provider, which keep you signed in.
- Which studio and which game you last had open, so the app opens where you left off.
- Short-lived cookies (up to 10 minutes) that protect signing in through Steam and verifying channels from being tampered with, and one that shows a welcome after you add a game.
How long we keep it
We keep your data while your account exists. Audience history is kept while the channel stays on your profile. When you ask us to delete your account, we delete it and the data that belongs only to you within 30 days; a studio's shared history stays with the studio, with your name removed from it.
Your choices and rights
You can see and change most of your data in BloxLobby itself: your profile in Settings, your creator page, and your studio. To get a copy of your data, correct something, or delete your account, write to hello@bloxlobby.com and we'll do it within 30 days. Depending on where you live, you may also have the right to object to or restrict how we use your data, and to complain to your data protection authority.
Security
Data travels encrypted. Each studio's and each creator's data is separated in the database itself, so nobody can read another's. Keys for the services we use stay on our servers and never reach your browser.
Children
BloxLobby is for people making or covering games professionally. It isn't meant for anyone under 16, and we don't knowingly collect their data.
Changes
When we change what we collect or who helps us process it, we update this page and its date first. For a significant change, we also email account holders.