Winku
  • Services
    • WinkuStore
    • CueUp
    • Dubster
    • Luvia
    • Vidono
    • Vetra
  • About
  • Support
  • Status
DEEN Sign in View Services

Privacy

Privacy Policy

Last updated: 12 September 2026 (the question about the age group for older accounts under section 4 applies from 20 September 2026)

This is a translation for convenience. In case of doubt, the German version applies.

1. Controller

The operator named in the imprint is responsible for the processing of personal data on winku.de.

2. Visiting the website

When you visit the site, technically necessary server logs are stored (IP address, time, page requested, amount of data transferred, browser identification). They serve the operation and security of the site and are deleted automatically after 14 days at the latest, the logs of the game path (section 15c) after seven days. Before that, we aggregate requests for update files into daily totals without IP addresses (section 12). The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). We do not use tracking cookies or advertising networks.

2a. Hosting and delivery via Cloudflare

winku.de and the associated services run on our own server in Germany, which we operate ourselves; no hosting provider is involved. The emails we send are also dispatched directly from this server.
The pages are delivered through the network of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA); this applies to winku.de and all services operated under it as well as to vidono.de. Every request first passes through Cloudflare's servers and only then reaches our server. Cloudflare processes your IP address, the requested address, technical details of your browser and – because the encrypted connection ends at Cloudflare and is re-encrypted from there to us – also the transmitted content, such as form entries. This serves reliable availability and protection against attacks; our server is thus not directly reachable from the internet. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Cloudflare processes this data on our behalf under a contract pursuant to Art. 28 GDPR. Data may be transferred to the USA in the process. Cloudflare is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR); the European Commission's standard contractual clauses apply in addition. Cloudflare does not set any advertising or analytics cookies for us. More information: https://www.cloudflare.com/privacypolicy/

3. Cookies

We only use technically necessary cookies: a session cookie after you sign in, a cookie for the language you selected and — if someone bypasses maintenance mode using a key — a cookie for that exemption. No consent is required for these.
So that you do not have to enter your credentials again on every visit, we also set a cookie after sign-in that keeps you signed in. It contains a random identifier, no password and no details about you; only a non-reversible check value of it is stored on our server. The identifier is renewed on every use, so an intercepted older value no longer works. It expires after 180 days without use and becomes invalid immediately when you sign out, change your password or delete your account. If you do not want this, sign out after your visit.
A complete list of all cookies with purpose and duration is available at winku.de/cookies.

4. User account

For an account we store your email address, chosen name, password (only as a non-reversible hash), the time of registration and of the last sign-in, and the update channel you selected; in addition — only if you set one — the game name for our browser game together with the time of its last change (section 15c). The legal basis is the performance of the user relationship (Art. 6(1)(b) GDPR). If the account is deleted, we delete this data and the content associated with it.
A single sign-in applies to all Winku programs on the same device: the session token is stored locally on your device so that you do not have to sign in to each program separately. This means that any Winku program on that device can act on behalf of your account. The token does not leave your device; signing out removes it everywhere. This does not apply to our browser game in that form: the game server never receives your session token. It learns something about your account only if you open the game page while signed in — and even then only the account identifier and your game name, via a separate, short-lived token (section 15c).
Two-factor sign-in: If you wish, you can additionally protect your account with a one-time code from an authenticator app. For this we store a random secret in encrypted form with your account, the time of setup and the time window of the last code used (so that a code cannot be used twice), plus ten recovery codes only as a non-reversible check value and whether they have been used. We keep failed code entries with their time for at most one day to slow down guessing. If you confirm a sign-in on a device and ask us to remember it, we note on the persistent sign-in of that browser (section 3) until when the confirmation is valid – at most 30 days. We send you an e-mail when two-factor sign-in is turned on or off and when a recovery code is used. Services that sign in with your Winku account (such as Wecko) can pass a code to winku.de for checking; they only learn whether it is correct, never the secret. The legal basis is the performance of the user relationship (Art. 6(1)(b) GDPR) and our legitimate interest in keeping accounts secure (Art. 6(1)(f) GDPR). If you turn off two-factor sign-in or delete your account, we delete this data immediately.
Age and consent of parents or legal guardians: When an account is created using the form on winku.de, we ask for the year of birth — only the year, not the full date. We do not store the year itself. It is immediately converted into one of three groups — "under 16", "16 to 17" or "18 and over" — and only that group and the date on which it was stated are held with your account. We need the group because a user agreement with a minor requires the consent of their parents or legal guardians (sections 107 and 108 of the German Civil Code) and because we may only accept consent from children with that approval (Art. 8 GDPR). The legal basis is the initiation and performance of the user relationship (Art. 6(1)(b) GDPR) and our legitimate interest in valid contracts and in protecting minors (Art. 6(1)(f) GDPR).
If you are under 16, we additionally ask for the email address of a parent or legal guardian and send a message with a confirmation link to that address. Until consent has been given, your account exists but is locked — you cannot sign in yet. You can request the message again. We use this address solely for that consent and as a record of it (Art. 7(1) GDPR). It receives no advertising, we do not use it for anything else, we do not pass it on, and we delete it together with the account. For this purpose we store the address, whether consent has been given, and the times of the message and of the consent.
If you are 16 or 17, we do not ask for an address. When creating the account you confirm with a checkbox that your parents or legal guardians agree; we only store that you confirmed this and when.
We send no advertising to accounts held by minors, and we do not evaluate their use to build profiles.
Accounts without an age entry: For accounts created before 5 September 2026 and for accounts created through "Sign in with Twitch", we initially have no age entry; there it reads "unknown". We expressly do not treat "unknown" as "18 and over".
If an account is created through "Sign in with Twitch" on or after 5 September 2026, we ask for the entry once before the account can be used. Twitch does not tell us your age; without that question this sign-in route would be a way around the consent of parents or legal guardians.
Accounts created before 5 September 2026 continue unchanged. The next time you sign in, we ask once for the age group. That answer is voluntary: you can skip the question, it will not be put to you again, and your account remains fully usable. For these accounts the entry only becomes mandatory when you wish to use a service that requires an account; we point this out at the relevant place.
If an account in this group answers "under 16", we do not lock it. We then ask — again voluntarily — for the email address of a parent or legal guardian and request consent there. Until consent has been given, only those services that require an account remain closed; everything you have used so far remains available to you. What we store is the same as described above: the group, the date on which it was stated and — if provided — the address of the parent or legal guardian together with the times of the message and of the consent.
If an age entry is incorrect, we will correct it at your request (Art. 16 GDPR); a message through the support form is sufficient.

5. Settings stored with your account

On request, the programs store their settings with your account so that they are the same on several devices. Only settings of the respective program are stored — for example volume and export defaults, keyboard shortcuts, templates for chat messages, the appearance of overlays and moderation rules. Details about other people do not belong there: lists that may contain third-party names — such as block lists used for moderation — are not synchronised with your account. They stay on the device and never reach our server, neither in plain text nor in encrypted or converted form. Anyone who wants to move such a list to another device can export it in the respective program and import it there. The legal basis is Art. 6(1)(b) GDPR. The settings are deleted along with the account.

6. Reviews and profile pictures

Reviews are published with your chosen name and are checked before publication. Profile pictures are also checked and only shown publicly afterwards; before approval only the person who uploaded them can see them. The legal basis is Art. 6(1)(b) GDPR. Both can be deleted from your account at any time.

7. Shared files

Files uploaded through the share function are stored for as long as the link is valid (currently three days) and can be accessed publicly via that link. They are deleted afterwards. You are responsible for the content you upload there; do not upload third-party works to which you hold no rights. You can revoke this at any time by deleting them in your account.

8. Support requests

When you send a support request we store the details you provide and the message history in order to handle the request (Art. 6(1)(b) and (f) GDPR). We delete them once they are no longer needed.

9. Program updates

The programs retrieve update information from winku.de on their own and download installation files. This produces the same server log data on our side as visiting the website. No user account is required for this.

10. Error reports from the programs

If an installation or update fails, the programs transmit a technical error report: the program affected, version, the step being performed, the type of error, a short technical message and the operating system designation. The programs sanitise the message beforehand; file paths, user names and credentials are replaced. No connection to an identified person is intended. This report is sent automatically, without any action on your part, and only when an error occurs; at most one report is created per error. The sole purpose is fixing the error (Art. 6(1)(f) GDPR).

11. Usage figures from the programs

Some programs transmit usage figures to winku.de so that the evaluation is also visible in your account on the website. Only figures are transmitted and — where the purpose requires it — music data such as title and artist. The following are expressly NOT transmitted: names or identifiers of viewers, third-party profile pictures, chat content, credentials and identifiers of third-party services. The server rejects submissions containing such fields.
The figures are associated with your account so that they can be displayed there; the legal basis is the performance of this function (Art. 6(1)(b) GDPR). Since this transmission is part of using the service, there is no separate opt-out for it. This does not affect your right to delete your account — which also deletes the stored figures — or your statutory data subject rights under section 16.

12. Anonymous usage statistics from the programs

The programs additionally report anonymous figures to winku.de automatically, without any action on your part, so that we can see how many installations are running on which version, how reliably updates complete and which programs are being used. Only the following are transmitted: program name, version, update channel, type of operating system (Windows, macOS, Linux), processor type, language code, the event (start, installation, update succeeded, update failed, uninstall) and plain counts that the respective program keeps.
So that an installation is not counted more than once per day, the program generates a random identifier once. This identifier is not stored on the server: together with the program name, the date and a secret known only to us it is turned into a daily hash. On the following day the same identifier produces a different value. An installation can therefore neither be tracked across several days nor be linked to a person. The daily hashes are deleted after 40 days; only daily totals remain. No IP addresses are stored in this process.
In addition, we condense the requests for update files from the server logs into daily totals (program, version, type of file, origin of the request). Here, too, no IP address is stored.
The legal basis is our legitimate interest in maintaining the programs, detecting faulty deliveries and aligning further development with actual usage (Art. 6(1)(f) GDPR). Since this data cannot be attributed to any person, there is no separate opt-out for it; no connection to an identified person arises. Not to be confused with section 11: the figures described there belong to your account, the ones described here do not.

13. Streamer mode

Streamer mode hides personal details in the programs while you are streaming. It works entirely on your device: the live state is detected locally and stored in a file in your user folder. Nothing is transmitted to winku.de in the process. The placeholder details (name, address, picture) shown instead are retrieved from winku.de without any connection to a person.

15. Third-party services

Some programs connect to third-party services at your request. These connections are made directly between your device and the respective provider; in doing so your IP address is transmitted to that provider. The credentials for them remain encrypted on your device and are not transmitted to winku.de. The privacy notices of those providers apply in addition.
In detail:
- Twitch: sign-in of the streamer, reading chat and channel point redemptions, retrieving display names and profile pictures of the viewers involved, writing replies into your own chat. This information stays on the streamer's device and is not transmitted to winku.de – with one exception that the streamer switches on themselves: the CueUp Twitch panel (section 15f).
- Spotify: search, queue and playback control as well as the account name and profile picture of the signed-in account.
- YouTube and Google: only if you explicitly enter an address from which something is to be loaded.
- OpenAI and Hugging Face: one-off retrieval of the models for local speech and speaker recognition on first start. The processing itself then runs entirely on your device; audio and video content is not transmitted.
- Microsoft and python.org: retrieval of required additional programs during setup.
- OBS: exclusively locally on your device (127.0.0.1); no data leaves the device in the process.
- Stream Deck (Elgato): the CueUp plugin talks exclusively locally to CueUp on your device (127.0.0.1); no data leaves the device in the process. The Stream Deck software itself is covered by the privacy notice of Elgato (Corsair).
On winku.de itself we do not embed any third-party content that sends data to external servers; the fonts we use are hosted on our own server. Exceptions for individual services are set out in their sections (Vidono 15b, CueUp panel 15f). Delivery via Cloudflare is described in section 2a.

15a. Signing in with Twitch

You can sign in with your Twitch account. In doing so, Twitch transmits to us your Twitch ID, your login and display name, your email address and the address of your profile picture. We request read-only access to this information (user:read:email) and receive no right to act on your behalf. The access token is returned to Twitch immediately after the one-off retrieval and is not stored by us. We download your profile picture once and store it on our server; it is not re-loaded from Twitch, so Twitch does not learn when you visit our pages. The legal basis is the performance of the user relationship at your request (Art. 6(1)(b) GDPR). The provider is Twitch Interactive, Inc., USA; by signing in, data is transmitted there because you explicitly request this connection (Art. 49(1) sentence 1 point (b) GDPR). If a Winku account already exists for your email address, we do not link the accounts automatically; you have to sign in the regular way once to do so.

15b. Vidono — video requests in a stream

Vidono (vidono.de) allows viewers of a channel to suggest a video clip for the stream.
Sign-in: channel owners and moderators sign in with their Winku account; winku.de passes the account ID to vidono.de via a single-use ticket valid for 60 seconds. vidono.de sets a session cookie with a random ID and, after sign-in, additionally the cookie “vidono_bleib”. It contains only the value “1” and no identifier and expires after 180 days; if the session has expired, Vidono uses it to sign you in again via your Winku account without another click. It is deleted when you sign out. Both cookies are technically necessary (§ 25(2) no. 2 TDDDG).
Of the channel owner we process the Twitch channel identity (channel name and Twitch ID), the rules they define and the queue. The legal basis is the performance of the user relationship (Art. 6(1)(b) GDPR).
Of submitting viewers we process the display name they choose themselves, the requested video clip and the associated amount. The chosen display name is shown publicly in the channel's stream; you can choose it freely and do not have to provide a real name. The legal basis is the performance of the user relationship (Art. 6(1)(b) GDPR).
Payments by viewers do not go through us. Payment is made via the method the channel owner has set up themselves; we merely receive the notification that a payment has been received, together with the amount and the name and text provided by the viewer.
To be distinguished from this is paid access for channel owners. At present no such access can be purchased, and no processing takes place for it. If such access is offered later, Lemon Squeezy will handle the payment (Lemon Squeezy, Inc., USA). For this we transmit your email address and the identifier of your channel with us; payment data such as card or account numbers does not reach us and is not stored by us. Lemon Squeezy processes the payment data as an independent controller. A transfer to the USA takes place. Details are set out in Lemon Squeezy's privacy notices.
For previewing and selecting the clip, the YouTube player is loaded as soon as you enter a YouTube link; a notice directly below the input field says so beforehand. In doing so Google (USA) learns your IP address and may store information on your device. Without that input the player is not loaded. The legal basis is your consent given by entering the link (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Video thumbnails are loaded from YouTube once a video is selected. Google's privacy notices apply in addition.
For display in the stream, the overlay maintains a connection to StreamElements (StreamElements Ltd., USA); this concerns only the channel owner, not their viewers. Through this connection we learn of the channel's incoming donations.
Retention: completed queue entries (played, skipped, rejected) are deleted after 30 days, the history of incoming payment events as well as the moderation log and the results of the video checks after 12 months, completed moderator invitations after 90 days. This happens automatically; the channel owner does not have to do anything and cannot extend it. Open queue entries remain until they are completed. If the channel owner deletes an entry or their account, the associated data is removed immediately.

15c. Browser game — playing with a Winku account or via an invitation link

On winku.de we offer a multiplayer game that runs in the browser. You can play with your Winku account or — without an account — via an invitation link that we send out ourselves. A user account is not required in order to take part. The game has no chat, no voice connection, no friend lists and no advertising.
Invitation link: The link contains a signed code made up of the expiry time, a random number and a checksum. It contains nothing about the invited person — no name, no email address, no account identifier. We do not store the codes issued and keep no record of who received which link; our server only checks whether the checksum is correct and whether the code has expired. Anyone who passes the link on also passes on access — an individual link cannot be withdrawn, only all of them together.
Playing with a Winku account: The game server never receives your winku.de session cookie; the device-wide sign-in described in section 4 does not extend into the game. If you open the game page while signed in on winku.de, the game page obtains a sign-in token from winku.de and connects you to the game with it without any further click — we treat opening the game page as your wish to play with your account. If you do not want that, sign out on winku.de first; you then play via an invitation link without an account. The token is issued only on a request from the game page itself, not on requests from other websites. It contains solely the internal identifier of your account, an expiry time (at most two minutes) and a random number, plus a checksum — no name, no email address, no age entry, no identifier of a third-party service. The token is valid only once. When the token is redeemed, the game server receives exactly two items from winku.de: the account identifier and your game name (see below) — not your account name, not your email address, nothing else. It keeps both in memory for as long as your connection lasts; nothing remains afterwards. Your account name is never shown to the other players. The other players do not receive the account identifier either. We keep no permanent record of the tokens issued and do not evaluate when or how often you play with your account; that a token has been used is remembered only until it expires. The game does not store the sign-in token permanently on your device. The legal basis is the performance of the game at your request (Art. 6(1)(b) GDPR).
Game name (with an account): If you play with your account, you are called in the game whatever is entered under "Game name" in your account. This is a separate field for the game only: it is never pre-filled, is not derived from your account name or a Twitch name and appears nowhere on winku.de — not with reviews, not with your profile picture, not in any search. Please invent it and do not use details that identify you or anyone else. A word filter checks it when it is saved; a rejected name is neither stored nor recorded. The game name remains stored with your account until you delete it there or delete the account; along with it we store the time of the last change, because a change is possible at most once in 24 hours. We do not keep previous game names. The name is shown only to the other players in the same lobby or round and only while you are connected; it is not recorded in game logs and is not linked to your IP address or to match data. If no game name is set or the game server's word filter rejects it, you are called "Player" followed by a number in the game. The legal basis is the performance of the game at your request (Art. 6(1)(b) GDPR). The game name is covered by your right of access and to data portability (section 16).
Nickname (without an account): If you play via an invitation link, you choose a name before a round that is shown to the other players. Please invent it and do not use details that identify you or anyone else. The name exists only in the memory of the game server while your connection lasts; it is neither stored nor logged. A word filter on the server replaces impermissible and empty names with a number; the rejected name is not recorded in the process. The legal basis is the performance of the game at your request (Art. 6(1)(b) GDPR).
Course of play: Positions, states and results exist only while the round is running and are transmitted only to the players of that same round. Nothing remains after the round ends: no leaderboard, no statistics, no recording and no replay. This also applies to signed-in accounts: no progress, no result and no history is stored with your account.
Connection data: The server logs described in section 2 apply to visiting the game page; for the game path we keep these logs without the invitation code and without the sign-in token, and delete them after seven days at the latest. Inside the game server your IP address is not used in plain text: it is immediately turned into a non-reversible check value using a random key that is generated afresh each time the service starts. Only this check value is held in memory, and only for two purposes — a temporary block after implausible input or attempts at manipulation (at most 24 hours) and a one-hour block if eight attempts to join without a valid invitation code and without a signed-in account are made within ten minutes. All blocks lapse when the service restarts; there is no file and no backup of them. The legal basis is our legitimate interest in operating the game free of disruption and abuse (Art. 6(1)(f) GDPR). The other players do not receive your IP address — the connection runs exclusively encrypted via our server, not directly between devices.
Storage on your device: Only if you explicitly tick the box does the game remember the sensitivity of the controls and — when playing without an account — your nickname in your browser's storage. This information stays on your device, is not transmitted and can be deleted there at any time. Without that tick the game stores nothing on your device.
No third parties: The game loads everything from our own servers. There is no content delivery network (CDN), no external fonts, no tracking pixels and no connections to other providers.
Age: The game is labelled with the age rating 12.

15d. Signing in with Discord

You can sign in with your Discord account — on winku.de itself. Discord then transmits to us your Discord ID, your username, the ID of your profile picture and, if you have stored one with Discord, your email address. We request read access only (identify, email, guilds) and receive no right to send messages on your behalf or to read your messages. The “guilds” permission serves solely to determine on which Discord servers you may “Manage Server”; you can see which servers these are in the dashboard.
Where the tokens remain depends on where you sign in: if you sign in on winku.de, we return the access token to Discord immediately after retrieving your account data once and do not store it.
If you sign in with Discord for the first time and Discord transmits an email address, we create a Winku account for that address so that support, legal texts and your other Winku services are held under one account. You will receive an email about the newly created account. If a Winku account already exists for that address, we do NOT link the accounts automatically; to do so, you must sign in normally on winku.de once and connect Discord in your account there. If Discord does not transmit an address, no Winku account is created.
The legal basis is the performance of the user agreement at your request (Art. 6(1)(b) GDPR). For users in the European Economic Area the provider is Discord Netherlands B.V., Amsterdam; Discord's privacy policy (https://discord.com/privacy) applies in addition. You can disconnect Discord from your Winku account in your account at any time.

15f. CueUp — Twitch panel

Streamers who use CueUp can show a panel below their Twitch stream with the current song and the next song requests. The panel stays off until the channel owner switches it on in CueUp.
Of the channel owner we process the Twitch ID of the channel they linked to their Winku account, and what CueUp reports for display: the current song (title, artist, address of the cover image at Spotify), position and volume of playback, the next requests, up to ten further tracks from their Spotify queue, and whether and how requests are currently accepted (chat command, name and price of the channel points reward). The channel owner decides in CueUp which of these are sent; anything switched off is not sent. So that the panel can show a channel that has never used CueUp how to set it up, we also store the channel ID and the day CueUp first reported for that channel. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).
Of viewers who requested a song we process – only if the channel owner switched it on in CueUp – their Twitch display name and the address of their Twitch profile picture, so the panel can show who requested a song. Both are publicly visible on Twitch anyway; the ID of the Twitch account does not reach us. The legal basis is the legitimate interest of the channel owner and their viewers in seeing who requested which song on stream (Art. 6(1)(f) GDPR).
Anyone viewing the panel retrieves the display data from winku.de; this creates the server logs described in section 2. The panel sets no cookies and does not learn who is viewing it. The panel loads cover images directly from Spotify (Spotify AB, Sweden) and profile pictures directly from Twitch (Twitch Interactive, Inc., USA); these providers learn the IP address of the device. The panel itself is delivered by Twitch; Twitch's privacy notice applies in addition.
Retention: every report replaces the previous one – played or deleted requests thus disappear from the panel. If CueUp reports nothing for a day, the display data is deleted. If the channel owner switches the panel off, it is deleted immediately; only the note “switched off” remains for 30 days. The channel ID with the day of the first report is deleted together with the Winku account.

15m. Signing in with accounts from other providers (Google, Microsoft, PayPal and others)

Besides e-mail address and password, Twitch (section 15a) and Discord (section 15d), you can sign in to winku.de with an existing account from the providers listed below. Signing in via a provider is optional; every Winku account can be created and used without it. We list further providers here before enabling sign-in with them.

How sign-in works: when you choose a provider, we redirect you to its site. You sign in there and decide yourself whether to share the requested details with winku.de. We never learn your password at the provider. We only request read access to the basic data listed per provider below — no right to publish, buy or pay anything on your behalf, and no access to messages, contacts, posts, files or payment data. We use the access token issued by the provider exactly once to retrieve these details and do not store it. The connection is protected against forged requests with a random value (OAuth 2.0 with "state" and, where the provider supports it, PKCE).

First sign-in and e-mail confirmation: when you sign in with a provider for the first time, we show you the name and e-mail address from the provider's details; if either is missing, we ask for it. You can change both. We send a six-digit code, valid for 15 minutes, to the e-mail address. Your Winku account is only created with this code — even if the provider already reports the address as confirmed. This ensures that the address belongs to you. If the confirmed address already belongs to a Winku account, we connect the sign-in option to that account and inform you by e-mail. To limit abuse, for every code sent we store a non-reversible check value of the e-mail address, your IP address and the time for at most 24 hours; the code itself is only kept as a check value in your session.

What we store: for each connection we store the provider, your account identifier there, the user and display name, the e-mail address shared, the address of the profile picture and the times of connecting and of the last sign-in. We download a profile picture once and keep it on our server so the provider does not learn your IP address when it is displayed; we do not replace a picture you uploaded yourself. We use this data solely to sign you in and to display your account. We do not share or sell it, do not use it for advertising, profiling, analytics or training AI models, and write nothing back to the providers.

Deletion: you can disconnect a connection at any time under "Connections" in your account; we then immediately delete all data stored for it, including the downloaded profile picture (if it is also your profile picture on winku.de, it remains there until you change it). If the connection is your only way to sign in, we first ask you to set a password or another option so you are not locked out of your account. Deleting your account deletes all connections. You can also request deletion informally at [email protected]. You can additionally revoke access for winku.de in the account settings of the respective provider; data stored there is managed by the provider.

The providers in detail:
• Google — provider: Google Ireland Limited, Dublin, Ireland. Scopes: openid, email, profile. We receive: Google ID, name, e-mail address, profile picture. Privacy policy: https://policies.google.com/privacy
• Microsoft — provider: Microsoft Ireland Operations Limited, Dublin, Ireland. Scopes: openid, email, profile. We receive: Microsoft ID, name, e-mail address. Privacy policy: https://privacy.microsoft.com/privacystatement
• GitHub — provider: GitHub, Inc., San Francisco, USA. Scopes: read:user, user:email. We receive: GitHub ID, username, name, profile picture and your confirmed primary e-mail address. Privacy policy: https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
• GitLab — provider: GitLab Inc., San Francisco, USA. Scopes: openid, profile, email. We receive: GitLab ID, username, name, e-mail address, profile picture. Privacy policy: https://about.gitlab.com/privacy/
• Amazon — provider: Amazon Europe Core S.à r.l., Luxembourg. Scope: profile ("Login with Amazon"). We receive: Amazon ID, name, e-mail address — no order, address or payment data. Privacy policy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010
• Spotify — provider: Spotify AB, Stockholm, Sweden. Scopes: user-read-email, user-read-private. We receive: Spotify ID, display name, e-mail address, profile picture; Spotify additionally sends country and subscription type, which we neither use nor store. Privacy policy: https://www.spotify.com/legal/privacy-policy/
• PayPal — provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. Scopes: openid, email, profile ("Log in with PayPal"). We receive: PayPal ID, name, e-mail address — no balances, payments or bank details; nothing is paid through this sign-in. Privacy policy: https://www.paypal.com/legalhub/privacy-full
• Kick — provider: Kick Streaming Pty Ltd, Melbourne, Australia. Scope: user:read. We receive: Kick ID, username, e-mail address, profile picture. Privacy policy: https://kick.com/privacy-policy
• Dropbox — provider: Dropbox International Unlimited Company, Dublin, Ireland. Scope: account_info.read. We receive: Dropbox ID, name, e-mail address, profile picture — no access to your files or folders. Privacy policy: https://www.dropbox.com/privacy
• Patreon — provider: Patreon, Inc., San Francisco, USA. Scopes: identity, identity[email]. We receive: Patreon ID, name, vanity name, e-mail address, profile picture — no membership, pledge or payment data. Privacy policy: https://privacy.patreon.com/policies
• Epic Games — provider: Epic Games, Inc., Cary, USA. Scope: basic_profile (Epic Account Services). We receive: Epic account ID and display name; Epic does not share an e-mail address, so we ask for it. Privacy policy: https://www.epicgames.com/site/privacypolicy
• Steam — provider: Valve Corporation, Bellevue, USA. Method: OpenID. We receive: your Steam ID; where applicable we retrieve your public profile name and public profile picture via the public Steam interface. Steam does not share an e-mail address, so we ask for it. Privacy policy: https://store.steampowered.com/privacy_agreement/
• Telegram — provider: Telegram FZ-LLC, Dubai, United Arab Emirates. Method: Telegram Login (confirmation in your Telegram app, signed with our bot's key). We receive: Telegram ID, first and last name, username, profile picture and the time of approval; Telegram does not share an e-mail address or phone number, so we ask for the address. Our bot does not send you messages. Privacy policy: https://telegram.org/privacy
• Lichess — provider: Lichess.org (Association Lichess, France). Method: OAuth 2.0 with PKCE, scope email:read. We receive: Lichess ID, username, the name given in your profile where available, and your e-mail address. We return the access token to Lichess immediately after retrieval. Privacy policy: https://lichess.org/privacy
• Roblox — provider: Roblox Corporation, San Mateo, USA. Scopes: openid, profile. We receive: Roblox ID, username, display name and profile picture; Roblox does not share an e-mail address, so we ask for it. Privacy policy: https://www.roblox.com/info/privacy
• Wikipedia — provider: Wikimedia Foundation, Inc., San Francisco, USA. Scope: identity verification with real name and e-mail address. We receive: the central ID of your Wikimedia account, username, real name where given and — only if confirmed at Wikimedia — your e-mail address; no edits or watchlists. Privacy policy: https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
• itch.io — provider: Itch Corp, USA. Scope: profile:me. We receive: itch.io ID, username, display name and profile picture; no purchases, downloads, payment data or e-mail address, so we ask for it. Privacy policy: https://itch.io/docs/legal/privacy-policy
• X — provider: Twitter International Unlimited Company, Dublin, Ireland. Scopes: users.read, tweet.read, users.email. We receive: X ID, username, name, profile picture and your confirmed e-mail address. X technically requires "tweet.read" to retrieve your own profile; we do not read, store or publish posts. Privacy policy: https://x.com/en/privacy
• TikTok — provider: TikTok Technology Limited, Dublin, Ireland. Scope: user.info.basic. We receive: TikTok ID (open_id), display name, profile picture; TikTok does not share an e-mail address, so we ask for it. Privacy policy: https://www.tiktok.com/legal/privacy-policy-eea

The legal basis is the performance of the user relationship at your request (Art. 6(1)(b) GDPR) and, for limiting abuse, our legitimate interest in a secure sign-in process (Art. 6(1)(f) GDPR). Each provider is itself responsible for processing on its side; its privacy policy applies. Some providers are based outside the European Union (USA, Australia). Your sign-in is transmitted there because you expressly choose this sign-in option yourself (Art. 49(1)(b) GDPR); for certified providers in the USA the EU-US Data Privacy Framework applies in addition. The provider names are trademarks of their owners; there is no business relationship with them beyond the use of their sign-in interfaces.

16. Your rights

You have the right to information, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests (Art. 15 to 21 GDPR). You can withdraw any consent you have given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority. A message through the support form or to the address in the imprint is sufficient for any request.

17. Retention

We store personal data only for as long as it is required for the respective purpose or for as long as statutory retention obligations apply. Account data and the content associated with it are removed when the account is deleted; this also applies to the age group and the email address of the parents or legal guardians referred to in section 4 and to the game name referred to in section 15c, which you can also delete yourself in your account at any time.

← Back

© 2026 Winku
Support Status Legal notice Privacy Cookies Third-party licences Terms
Click image to zoom · click outside to close