Privacy Policy
Orchard · Last updated: September 2026
Data controller
The controller for the personal data processed through Orchard is Eren Atolgan (eanexus).
Contact: contact@eanexus.fr
1. Data we collect
Orchard collects only what the game needs to run:
- The streamer's public TikTok profile (display name, username, avatar picture), obtained via TikTok Login Kit when the streamer signs in.
- During a live stream, public interactions relayed by TikTok: viewers' display names and the gifts they send (type and count), likes, and follows.
- The streamer's game records (per streamer: nights played, time played, and diamonds received -- the week view. The evening’s performance itself, the twenty-win bet, is played and told in the game and never leaves it.).
2. How we use it
Collected data is used solely to:
- run the game in real time and update the on-screen display;
- compute the end-of-run recap and the streamer's records;
- display the optional overlays;
- identify the streamer who is signed in.
3. Storage & sharing
Three things, and nothing else. (1) A VIEWER RANK: one number per viewer and per game, raised by what they send during a live, so that a returning viewer is recognised on screen. It holds the TikTok user id and that number -- no nickname, no message, no gift history -- and it feeds no public ranking outside the live it was earned in. (2) A LOG OF YOUR OWN NIGHTS, if you sign in as a streamer: how long you played, how many diamonds came in, and the nicknames of your top supporters for that night. Only you can read it. (3) YOUR FORFEIT LIST, the one you write yourself in your streamer space. All three are erased on request. They are never sold and are not shared with third parties. A viewer may request deletion of their data by contacting the streamer who is running the game, or the contact address below.
4. TikTok
Orchard uses TikTok Login Kit (OAuth 2.0 with PKCE) for the streamer's sign-in, and reads public live events (gifts, likes, follows) while the stream is running.
The OAuth client_secret never leaves our server: the authorization code is exchanged for a token server-side, and that token is never sent to the game client. We do not store viewers' TikTok access tokens. The connection to a TikTok live is always initiated by the streamer.
5. Security
Sign-in uses the OAuth authorization-code flow with PKCE, and the authorization session is short-lived (about 10 minutes). We recommend that streamers keep their credentials private.
6. Contact
For any question about this policy or your data, contact us at contact@eanexus.fr.