HPHellPing

Privacy Policy

Last updated: July 12, 2026

HellPing is a Telegram bot and Telegram Mini App for streamers. This Privacy Policy explains what data HellPing processes, why it is processed and how users can request deletion.

Data we process

  • Telegram account data received from Telegram Mini Apps or the bot, such as Telegram user ID, username, first name and last name.
  • Streamer configuration, including Twitch login, Twitch user ID, Telegram channel or chat ID, live-post templates, schedules, social links and public profile settings.
  • Stream data collected from Twitch APIs, including stream title, category, viewer count samples, start time, end time and thumbnail URL.
  • Anonymous messages sent by viewers, moderation status and an HMAC hash of the sender Telegram ID for anti-spam and abuse prevention.
  • Community participation data, including a pseudonymous viewer name, an HMAC hash of the Telegram ID, point balances and ledger entries, daily streaks, quest progress, reward redemptions and prediction wagers. Streamers do not receive the underlying Telegram ID through these features.
  • Click and usage metadata, including click source, user agent and an HMAC hash of IP address where needed for rate limiting and abuse prevention.
  • OAuth connection data for supported integrations, including encrypted access/refresh tokens, token scopes, expiry time and connected profile display data.
  • Aggregate Twitch follower count and the time it was refreshed. HellPing does not request or store the follower identity list.
  • Uploaded media files, including schedule images and short videos uploaded for Telegram, YouTube Shorts or TikTok workflows.
  • Billing records, including the selected plan, payment provider, amount, currency, payment and subscription status, provider charge identifiers, billing period dates, cancellation and renewal timestamps, accepted Terms version and an encrypted billing email where required for an external checkout.
  • Support tickets, including category, subject, message history, status and timestamps.
  • Creator publication metadata used by Content Pulse, including platform, public post ID, title, URL, thumbnail, publication time and Telegram notification status.
  • Messages processed by an enabled chat connection, including display name, message text or masked text, risk score, platform roles and moderation outcome. Provider user IDs are encrypted for moderation actions and represented by HMAC hashes elsewhere.
  • Chat Arcade participation, game answers, pseudonymous winners and HellPoints ledger entries.

How we use data

  • To operate the Telegram bot and Mini App.
  • To publish and update stream alerts in Telegram channels or chats selected by the streamer.
  • To provide anonymous message moderation, OBS overlay output and anti-spam controls.
  • To operate channel points, viewer passports, rewards, quests, predictions, leaderboards and community OBS widgets selected by a streamer.
  • To calculate lightweight stream analytics based on HellPing samples. These stats may differ from official Twitch Analytics.
  • When external AI is enabled for an eligible plan, to generate live/end-post copy and post-stream recommendations from aggregated HellPing stream metrics.
  • To support optional video publishing and crossposting workflows when a user connects an external platform through OAuth.
  • To secure the service, prevent spam and diagnose operational issues.
  • To receive, answer and retain support requests submitted by users.
  • To detect new public creator posts, merge notifications and publish the configured Content Pulse message.
  • To moderate connected Telegram, Twitch and YouTube chats, deliver trusted-moderator text to OBS TTS, run chat games and answer enabled AI Host commands.

Sharing with third-party services

HellPing sends data only when needed to provide requested functionality. For example, HellPing may call Telegram Bot API to send messages and process Stars payments, Twitch APIs to read stream status or an enabled chat, YouTube APIs to upload Shorts or process an enabled live chat, TikTok APIs to upload/list videos, YooKassa to process an external SBP payment, and DeepSeek to generate optional AI copy or analysis. When AI moderation or AI Host is enabled, relevant message text may be sent to DeepSeek without Telegram/Twitch/YouTube IDs, OAuth tokens or internal sender hashes. HellPing does not sell personal data.

Payment data

Bank credentials, card data and access to the payer's bank account are processed by the selected payment provider and are not stored by HellPing. HellPing stores only identifiers and status data needed to activate access, reconcile renewals, process cancellations or refunds, prevent duplicate charges and maintain an audit trail.

OAuth tokens

OAuth tokens are stored encrypted and are used only for the connected feature selected by the user. Twitch OAuth proves channel ownership and refreshes the aggregate follower count. YouTube/TikTok OAuth is used for publishing workflows. Users can disconnect integrations in the Mini App.

Anonymous messages

Anonymous messages are not anonymous to the system. HellPing stores a technical HMAC hash of the sender Telegram ID for anti-spam and blocking. The streamer does not see the real Telegram ID in the Mini App moderation interface.

Community participation

HellPoints and similarly named channel points are internal engagement counters. HellPing separates public pseudonyms from HMAC-hashed Telegram identifiers and does not expose the hash or the original Telegram ID in channel leaderboards, streamer interfaces or public APIs.

Data retention and deletion

Streamers can export or delete their HellPing data, including their support-ticket history, from the Mini App settings where available. Uploaded clips can be deleted from the clips panel. Allowed or ignored chat records are normally removed after seven days; review and action records are normally removed after thirty days. Users can also request deletion through HellPing support. Payment and accounting records may be retained for the period required by applicable law, fraud prevention and payment dispute handling even after other account data is deleted.

Security

HellPing uses environment-based secrets, Telegram Mini App init data validation, HMAC hashing for sensitive identifiers, encrypted OAuth tokens and rate limiting. No internet service can be guaranteed perfectly secure.

Contact

For privacy requests, open the Telegram bot: https://t.me/Hellpingstreambot.