COMMUNITY INFORMATION · SEPTEMBER 2026
Privacy notice
Updated September 15, 2026.
This notice describes how The Rollin Fox website and Fox Den community use personal information. The Rollin Fox operates this site. For privacy questions, account requests or moderation appeals, contact therollinfox@gmail.com.
Information the website uses
- Google sign-in: your Google account identifier, verified email address and name. These identify your membership and determine whether you can access creator tools. Your Google password is not received or stored by this website. Sign-in does not request access to your Gmail inbox.
- Website password accounts: a username, display name, salted password hash and hashed recovery code. No email is required. Plain-text passwords and recovery codes are not stored. Temporary hashed network and username identifiers with attempt counts help limit repeated sign-in attempts; these expire after 15 minutes and are cleared during later password authentication activity.
- Your Fox Den profile: username, display name and optional bio, along with account and profile timestamps.
- Community activity: chat messages, song and other requests, poll votes, gaming signups and saved notification preferences.
- Safety and administration: reports, membership status, moderation notes and action history. The site also maintains authentication records and first/last-seen timestamps.
- Technical information: hosting and embedded-service providers receive connection information such as IP address and browser details when your browser contacts them.
Profile pictures
You may upload an optional profile picture from your device. The website crops and resizes it to a 256-pixel square and stores the processed PNG in private Cloudflare R2 storage. Optional image metadata is removed. Signed-in members can see the picture beside your chat messages. Replacing or removing it replaces or deletes the stored picture; removing a member through creator tools also removes their picture. Other members may save copies they have already seen. Use an image you have permission to share and avoid sensitive content.
Why this information is used
We use account information to provide the member service, save your preferences and participation, maintain security, investigate reports and handle support requests. You can browse the public entry and information pages without signing in. Member features require a website account or Google sign-in; optional profile text and participation are your choice.
What other people can see
Other members can see chat messages, the names attached to them and recent member activity shown by the community panel. Choose a display name before posting and avoid putting private details in your profile or messages. The creator and authorized administrators can see verified emails, profiles, requests and moderation records needed for administration. Do not treat community posts as confidential: other participants can copy or share them.
Hosting and external services
Cloudflare hosts the website and database. Google handles Google sign-in; the website handles username/password authentication. Gaming pages embed Kick content, and media pages may embed players selected by the creator. Loading an embedded player can connect your browser to its provider, which may use its own cookies and collect technical information. Discord and No Name Radio links take you to separate services. Creator announcements and event details may be sent to Discord when that integration is configured; the website’s member chat is separate from Kick and Discord chat.
Providers may process information in countries other than yours. Their services have separate policies: Cloudflare, Google, Kick and Discord.
Facebook Page connection and comments
Rollin Fox Streaming Control uses Facebook Login for Business so the creator can connect the Facebook Page they manage. This is separate from website member sign-in: visitors do not need to connect Facebook to join the Fox Den. The integration is restricted to the configured Rollin Fox Page and creator-only controls.
Meta provides the connecting Facebook account identifier, the Page identifier and name, authorization permissions, access-token validity information, broadcast details and comments on a selected Page-owned broadcast. Comment data includes the comment identifier, text, time and the author name when Meta makes it available. If Meta withholds a name, the panel shows “Facebook viewer”; we do not infer or look up a hidden identity.
This information is used to verify Page access, display broadcast status and comments, and carry out title/description updates or Page comments that the creator explicitly confirms. Facebook comments are displayed in the creator-only streaming workspace, not republished into the website’s member chat. A comment sent through these controls is published on Facebook as the connected Page.
The website stores the connecting account identifier, Page identifier/name and an encrypted user access token in its Cloudflare database. Page access tokens are obtained on the server when needed and are not sent to browser JavaScript. Pending connection attempts use hashed security values and expire after ten minutes. Unique action-attempt identifiers and timestamps are retained to prevent duplicate sends; those records do not contain comment text or author names.
Facebook broadcast details and comment text/names are fetched for display and are not saved as a Facebook comment archive in the website database. Unified Chat keeps up to 200 recent messages across connected platforms in the open page’s memory. Closing or reloading that page clears this viewing buffer; pausing alone does not erase the messages already displayed. Facebook retains the original comments under its own policies. Hosting infrastructure and backups may retain technical or earlier connection records as described below.
The creator can disconnect Facebook in Creator Studio → Streaming Control → Facebook. This removes the saved website connection and pending Facebook connection attempts. It does not delete Facebook posts/comments or revoke the app’s grant at Meta; remove Rollin Fox Streaming Control in Facebook’s Business Integrations settings to revoke that access too. Revocation does not itself guarantee immediate removal of the website’s saved connection. Viewers and the connecting account holder can request deletion using our data deletion instructions. Meta’s own handling of information is described in the Meta Privacy Policy.
Other streaming chat connections
The creator-only Unified Chat can also show Kick and Twitch messages, author names, identifiers and timestamps. When Kick collection is enabled, the website keeps a limited recent-message buffer for up to one hour; stopping collection clears that buffer. Twitch messages are received for the open viewing session. These streams are separate from member chat and are not a permanent website chat archive. Each platform retains its own original messages and applies its own rules.
Cookies and email
The website uses essential sign-in cookies: a login-attempt cookie valid for up to 10 minutes and a session cookie valid for up to 24 hours. Creator service connections also use short-lived security cookies during authorization. Logging out ends the website session; it does not log you out of Google or other platforms or disconnect saved creator integrations. Blocking these cookies prevents member sign-in. The desktop and mobile sites use separate sign-in sessions. Choosing Desktop site also saves a device preference cookie for up to 30 days; it is not used for advertising or tracking. Automated website emails are currently switched off. Saving an email preference does not currently trigger email delivery.
Community Hub and stream reminders
The hub stores event follows, clip URLs and submission notes, your display name, review status and creator responses. Pending or declined clips and responses are visible only to their submitter and the creator; approved clips, notes and display names are shared with signed-in members. You can withdraw your clip submissions and unfollow events. Calendar downloads are saved in your own calendar app; schedule changes and unfollowing do not update or remove an imported event automatically. Recaps are published to members only after creator approval. OBS scene favorites are saved in your browser, not your member profile. These records follow the community retention policy below and are removed with permanent account deletion, except creator-written recaps and retained safety history.
Storage and retention
Profiles and community records remain stored until removed or reviewed by the creator; there is currently no automatic deletion schedule for these records. Expired login attempts and sessions cannot be used and are cleared during later authentication activity. Safety records may be retained to investigate abuse and enforce restrictions. Private database backups can contain earlier records after a change or deletion. Retention is reviewed according to account activity, operational recovery needs, unresolved reports and applicable obligations; a fixed backup-expiry schedule has not yet been set.
Your choices and requests
You can edit your profile, change notification preferences and log out. To request access to, correction of or deletion of your information, contact the address above. Google members should use their registered email; website-account members should include their username, never their password or recovery code. We may need to verify your identity. Removing a profile is not the same as erasing every security record or backup. We will explain any information that needs to be retained when responding. Depending on where you live, you may have additional rights, including objection, restriction or portability, and the right to complain to your local data-protection authority.
Notice updates
This notice will be updated when the site’s data practices change. Please avoid sharing sensitive personal information in the community.