SKWAD Pulse · Privacy
Privacy policy
EFFECTIVE 27 SEP 2026 · LAST UPDATED 8 OCT 2026
This policy explains what personal data SKWAD Pulse handles, why, how long we keep it, and the choices you have.
Who we are
SKWAD Pulse (Pulse) is operated by SKWAD GG LLP, India (we, us) at skwad.ai.
Pulse is an internal operations tool for live esports broadcasts that we produce or support. It is used by our staff and crew and by the event organisers we work with. It is not a consumer product and is not directed at children.
What Pulse does
During a live broadcast, Pulse watches the public YouTube live streams of the event and shows our crew live viewer counts, stream problems (for example a stream that goes off air) and possible unauthorised re-streams. After the event it produces an aggregate report for the organiser.
Live chat monitoring is currently switched off. When it is switched on for an event, Pulse also shows the overall mood and topics of public live chat and stream problems viewers report in chat (for example "no audio" or "buffering").
YouTube API Services
Pulse uses YouTube API Services. By using Pulse you agree to be bound by the YouTube Terms of Service. YouTube data is also subject to the Google Privacy Policy.
Pulse reads public data only, server-side, with an API key. It does not ask you to sign in with Google or YouTube, does not use OAuth, and never posts, comments, likes, moderates or uploads anything to YouTube. Because Pulse holds no authorisation to any YouTube account, there is nothing to revoke; if that ever changes, you will be able to revoke access at any time through Google's security settings page.
What we collect
1. Public YouTube data
- Live stream details: title, channel, live status, scheduled and actual start and end times, concurrent viewer count.
- Channel details: name, handle and ID of the channels we are asked to monitor.
- Public live chat messages on those streams, only when chat monitoring is switched on for an event. It is currently switched off.
- Search results for public live streams whose titles match the event, to find possible unauthorised re-streams.
Chat authors. When chat monitoring is switched on, we do not store chat authors' names, channel IDs or profile pictures. Each author is replaced by a one-way hash, used only to count how many different people are chatting and to avoid counting one person's repeated messages as many reports. Raw chat text is deleted after 30 days (see How long we keep it).
2. Accounts and sign-in
Since 8 October 2026 everyone who uses Pulse has their own account. An admin creates it by sending a personal invite link, which works once and expires after 48 hours. For each account we store:
- your name and email address;
- your password, as an argon2id hash only (we never store the password itself);
- the secret for your authenticator app, encrypted at rest;
- your sign-in sessions, which expire after 12 hours without activity (and after 7 days at most) and can be revoked at any time;
- an activity log of sign-ins and account changes, such as invites, role changes and resets.
We also record your name against actions you take in Pulse (for example, who confirmed a channel or closed an issue). Accounts for event organisers (clients) are read-only.
Pulse sets a session cookie to keep you signed in. If you tick "Don't ask for a code on this device", it sets a second cookie that skips the authenticator step on that browser for 8 hours. We use no advertising or cross-site tracking cookies.
3. Crew reports (optional)
If a broadcast team turns it on, crew can send stream-quality reports to Pulse from a Slack channel or a WhatsApp Business number. WhatsApp phone numbers and message IDs are stored only as keyed hashes, never in plain text, together with the report text and any attached screenshot. For Slack we store the sender's display name and the report.
4. Share links
Organisers can receive a report through a private share link. Anyone with the link can view that one report until it expires (90 days) or is revoked.
5. Report emails (coming)
We are adding email delivery of reports. When it is switched on, reports can be emailed from pulse-noreply@skwad.gg to the organiser contacts that an admin enters for an event, after an admin approves each email. Those email addresses are stored with the event. Replies go to the SKWAD project management office (PMO) mailbox, not to the sending address.
6. Technical data
Our servers and our network provider (Cloudflare) process IP addresses, browser type and request logs to deliver the service, keep it secure and investigate abuse. We use IP addresses to rate-limit sign-in attempts. Access logs keep request paths and are used only to run and secure Pulse.
Why we use it
| Purpose | Data |
|---|---|
| Show a live broadcast's reach and stream problems (and, when chat monitoring is on, chat mood) to our crew and the organiser | Public YouTube data |
| Detect unauthorised re-streams to protect the organiser's broadcast rights | Public YouTube search results |
| Give each person their own access, run Pulse securely and know who did what | Account, sign-in and technical data |
| Fix stream problems reported by crew | Crew reports |
| Share a post-event report with the organiser | Aggregate report data, share links |
| Email reports to the organiser's contacts (coming) | Organiser contact email addresses |
We do not sell personal data, use it for advertising, build profiles of individual viewers, or report unique viewers, demographics or audience retention.
Automated analysis
When chat monitoring is switched on, Pulse classifies chat messages automatically — mood, topic, and whether a message reports a stream problem — using our own rules and, only when switched on for an event, a third-party AI text-classification service. Only message text is sent, with no author information. Results are used in aggregate (totals, trends and stream alerts); no decision is made about any individual viewer.
How long we keep it
| Data | Kept for |
|---|---|
| Raw live chat message text (when chat monitoring is on) | 30 days, then deleted automatically |
| Short chat quotes in a report | 30 days, then removed automatically; the report keeps numbers only |
| Aggregates (viewer counts, mood and topic totals, issue counts) | For the life of the event record |
| Organiser contact email addresses entered for an event | For the life of the event record |
| Share links | Until they expire (90 days) or are revoked |
| Invite links | Until used once, or 48 hours |
| Sign-in sessions | Until 12 hours without activity, 7 days at most, or until revoked |
| Account details (name, email, password hash, encrypted authenticator secret) | While your account exists. An admin can turn an account off at any time, and you can ask us to delete it (see Your rights) |
| Crew reports, account activity and technical logs | Only as long as needed for the event, its report and security, then deleted |
YouTube data we no longer need is deleted, and data we keep is refreshed or deleted in line with the YouTube API Services policies. You can ask us to delete data at any time (see Your rights).
Who we share it with
We share data only with the organiser of the event a report is about, and with service providers that process it for us under contract:
- Amazon Web Services — hosting and backups (Mumbai region, India)
- Cloudflare — network and security
- Google / YouTube — the source of public YouTube data, through YouTube API Services
- Slack and Meta (WhatsApp Business) — only if crew reporting is turned on for an event
- Microsoft (Microsoft 365) — sends report emails from pulse-noreply@skwad.gg, once email delivery is switched on
- An AI text-classification provider — only if switched on for an event
We may disclose data where the law requires it.
Security
Data is encrypted in transit (HTTPS) and at rest. Every account signs in with its own password and an authenticator code, and sign-in attempts are rate-limited. Secrets are kept in a managed secret store, server access is restricted and logged, and chat authors and WhatsApp numbers are stored only as hashes.
Your rights
Under India's Digital Personal Data Protection Act, 2023 and other applicable laws you can ask us to tell you what personal data we hold about you, correct it, delete it, withdraw consent where we rely on consent, and nominate someone to act for you.
Because chat authors are stored only as a hash, we usually cannot link a chat message back to a specific person. If you believe a message of yours is in our records and want it removed, contact us with the stream and approximate time and we will delete matching messages.
Contact and grievances
Grievance Officer: Gowtham Reddy
Email: hello@skwad.gg
Company: SKWAD GG LLP, India
We aim to reply within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Changes
We will post any changes on this page and update the "Last updated" date. For significant changes we will tell the staff and organisers who use Pulse.