Privacy policy
Perklet privacy policy
Perklet is an independent Android companion for monitoring Twitch Drops. This policy explains the data handled by Perklet and the choices available to you. Perklet does not sell personal data, run advertising, or use Firebase Analytics.
This policy covers builds with optional Google sign-in as well as builds without accounts. Subscription features are available only in subscription-enabled builds; signing in alone never starts a purchase.
Data kept on your device
Perklet stores the following in its private app storage so that it can operate:
- your watched-game choices and order;
- cached games, campaigns, rewards, and artwork;
- current monitoring, progress, and pending-claim state;
- claimed-reward history and notification bookkeeping;
- preferences such as onboarding, monitoring, and restart choices;
- sign-in state and cached subscription-access information, when those features are enabled; and
- a bounded technical event log used for diagnostics.
Twitch session credentials and cookies are encrypted with a key protected by the Android Keystore. They are stored in Android's no-backup area and excluded from cloud backup and device transfer. Other operational data is held in app-private storage, but it is not separately encrypted by Perklet.
Twitch connection and monitoring
When you choose Connect Twitch, authorization takes place through Twitch. Perklet then communicates directly with Twitch over encrypted connections to:
- validate the authorized session and retrieve basic Twitch account information;
- retrieve eligible games, campaigns, rewards, progress, and channel information;
- select eligible channels and advance Drop progress while Monitoring is on; and
- submit completed reward claims.
The developer does not operate a Perklet server for these Twitch features. Perklet does not upload your Twitch credentials, session, watched games, campaign data, or reward history to a developer-operated server. The app displays your Twitch profile picture and may request campaign artwork from addresses supplied by Twitch. Twitch and those image hosts receive ordinary network information, such as your IP address, when the app connects to them.
Twitch may omit public campaigns from account-specific responses. To keep the campaign list complete, Perklet also retrieves public campaign metadata from the open-source SunkwiBOT Twitch Drops API over an encrypted connection. Perklet does not send Twitch credentials, cookies, account identifiers, watched-game choices, progress, or reward history to this service. Its operator receives ordinary network information, such as your IP address and the Perklet user-agent, when the catalog is refreshed.
Perklet is not affiliated with, endorsed by, or sponsored by Twitch or any game publisher. Twitch processes data under its own Privacy Notice.
Google sign-in and your Perklet account
In account-enabled builds, choosing Continue with Google creates or signs in to a Perklet account through Google Firebase Authentication. Google sign-in is optional for exploring the app and is required before starting a new subscription purchase. Your Twitch connection is managed separately.
Google and Firebase Authentication process your Google account identifier, email address, name, profile-picture information, and authentication tokens to sign you in and maintain your session. The developer can view your Perklet account record in Firebase Authentication. Perklet uses basic Google sign-in and does not request access to your Gmail messages, Google Drive files, or Google password.
The app displays your account label and Google profile picture. It downloads the picture from Google's image hosts and caches it on your device. Those hosts receive ordinary network information, such as your IP address. Account profile pictures are not sent to RevenueCat.
Signing out of Perklet ends the app's signed-in session. It does not delete your Google account, disconnect Twitch, delete retained account or purchase records, or cancel a subscription.
Subscriptions and complimentary access
Subscription-enabled builds use RevenueCat to check and maintain subscription or complimentary access. RevenueCat receives:
- an app-specific customer identifier based on your Firebase account identifier when you are signed in;
- your verified Google sign-in email as a customer lookup attribute for support and manually granted complimentary access;
- store purchase and subscription records, transaction identifiers, and access status; and
- technical information such as app and SDK versions, device and operating-system information, and network information needed to provide the service.
RevenueCat may also create an anonymous customer identifier when you are not signed in. Test Store builds use a separate customer-ID namespace so simulated access is not treated as a real Google Play purchase. Your email is a support lookup attribute, not the billing identifier or proof of access.
This information is used to validate purchases, recover access, prevent duplicate purchases, provide support, and manage manually granted complimentary access. The developer can view the associated customer, subscription, and complimentary-access records in RevenueCat. Perklet does not send your Google name, profile pictures, Twitch identity, Twitch credentials, watched games, or reward history to RevenueCat. See RevenueCat's privacy policy.
Google Play processes real subscription payments and renewals. Perklet does not receive your payment-card or bank-account details. The Google account used to sign in to Perklet can differ from the Google Play account used for payment. Any subscription price and recurring-payment terms are shown before you confirm a purchase.
Signing in does not buy a subscription or automatically grant complimentary access. Complimentary access is granted manually by the developer and does not start a paid subscription. Builds with subscriptions disabled do not initialize RevenueCat.
Builds clearly marked TEST MODE use RevenueCat's Test Store for simulated purchases. These purchases do not charge real money and do not grant access in Google Play builds.
Subscription, purchase, and complimentary-access records can remain with Google Play and RevenueCat for service operation, access recovery, fraud prevention, support, and applicable retention obligations. Signing out, uninstalling, or clearing local app storage does not erase those records. Contact support to request access to or deletion of associated records; see the account and data deletion instructions for the process and retention exceptions.
Optional crash reporting
Crash reporting is off by default. If you enable Share crash reports in the app, Google Firebase Crashlytics may receive:
- crash and app-not-responding stack traces;
- relevant app state at the time of a failure;
- app, operating-system, network-type, and device metadata;
- Crashlytics and Firebase installation or session identifiers; and
- allowlisted, payload-free labels describing a severe Perklet diagnostic event.
Perklet does not set a Twitch or Perklet user ID in Crashlytics and does not intentionally send Twitch account identifiers, access tokens, cookies, authorization codes, private Twitch responses, or the local diagnostic log.
Crashlytics is a service provider acting for the developer. Google states that it encrypts Firebase data in transit. Turning crash reporting off deletes reports that have not yet been sent and takes full effect after Perklet is reopened. Reports already uploaded to Crashlytics are retained by Firebase for up to 90 days. See Firebase privacy and security for more information.
Support and diagnostic sharing
Email beta feedback and Share diagnostic report operate only when you choose them. Perklet prepares a draft or share item, and you review it and choose the receiving app before anything is sent.
If you email perklet.support@gmail.com, the developer receives your sender address, the content and attachments you choose to provide, and technical details included in the draft, such as the Perklet version and Android API level. A shared diagnostic report is bounded and sanitized to omit credentials, account identifiers, and private response bodies, but you should still review it before sending.
Support correspondence is retained only as long as reasonably needed to respond, investigate the issue, protect the project and its users, or meet legal obligations. It is not used for advertising.
Backups and retention
Current campaign and reward cache entries are replaced as Perklet refreshes its catalog. Preferences, watched games, and claimed-reward history remain until you remove them. Cached images are evicted automatically according to the app's cache limits.
If Android backup or device transfer is enabled in your device settings, Android may copy eligible non-secret app data. Perklet explicitly excludes Twitch credentials, all shared preferences (including sign-in and billing identity and the crash-reporting choice), and the diagnostic log from backup and transfer. Appearance preferences may reset after transfer; watched-game records remain eligible for backup.
Clearing app storage or uninstalling removes local Perklet data. It does not delete your Firebase sign-in account, Google Play or RevenueCat records, support email already sent, or Crashlytics reports already uploaded. Restoring an eligible Android backup can restore backed-up non-secret app data.
Your choices and deletion
You can:
- pause Monitoring at any time;
- disconnect Twitch;
- skip Google sign-in while exploring, or sign out of Perklet;
- turn optional crash reporting off;
- decline to send feedback or diagnostic reports;
- request deletion of your Perklet account and associated account data; and
- clear Perklet storage in Android settings or uninstall the app.
Disconnecting Twitch removes the saved Twitch session and current Twitch catalog. Locally stored watched-game choices or claimed-reward history may remain so that a later reconnection can restore useful context. Clear app storage or uninstall to remove all local Perklet data.
In account-enabled builds, open Settings → About app → Request account deletion → Open email draft. Review and send the draft to request deletion of your Perklet account and associated account and support data. Opening the draft does not submit a request, delete an account, or sign you out.
Without the app, email perklet.support@gmail.com with the subject Perklet account deletion and include your Google sign-in email. An internal customer ID is not required. Never send passwords, authentication tokens, payment-card details, or service-account files. Support may ask you to verify account ownership.
We normally complete verifiable deletion requests within 30 days and confirm when deletion is complete. No fixed additional retention period applies. Limited records may need to be retained for legal, security, fraud-prevention, or transaction obligations; support will explain what is retained and for how long. Google Play maintains store transaction records under its own policies. See the account and data deletion instructions for details.
Deleting your Perklet account does not delete your Google or Twitch account. It also does not cancel a paid subscription. Cancel recurring charges separately in Google Play → Payments & subscriptions → Subscriptions → Perklet, using the Google Play account that made the purchase.
Other services
Twitch, the SunkwiBOT Twitch Drops API, Google Firebase, RevenueCat, Android, Google Play, your email or sharing app, and profile-picture or artwork hosts process information under their own terms and privacy policies. Different app builds can enable different features; this policy explains the data handling for the features you choose to use.
Children
Perklet is not directed to anyone who is not permitted to use Twitch or install the app under applicable law and Twitch's terms. Do not connect an account unless you are allowed to do so.
Changes and contact
Material changes will be reflected by updating this policy and its effective date. Questions and privacy requests can be sent to perklet.support@gmail.com.