Privacy
Last updated: September 8, 2026 (Google sign-in removed again; the site no longer requests YouTube access from viewers)
This page explains what elliottmorgan.com collects when you visit, why we collect it, who else sees it, and how to get in touch about your data. We try to keep this short and actually true to what the site does.
Who runs this site
The site is built and maintained by Jesse on Elliott Morgan's behalf — Elliott doesn't run the day-to-day operation. The site is hosted on Cloudflare. For privacy questions, reach out via the contact form.
What we collect
If you're just browsing
- Page views and basic visit info via self-hosted analytics (see "Third parties" below). No cookies are set on your device by analytics. Aggregated only — we don't see individual people.
- Standard server logs from Cloudflare (IP, user agent, request URL). Used for security and debugging. Cloudflare retains these per their own policy; we don't store them ourselves.
If you sign in
Sign-in is optional and required only for submitting links and managing your own account. The public signs in with Twitch; site operators use a magic-link email. We store:
- Your email address (from the sign-in provider). Used to recognize you on return visits and to contact you if a moderation issue requires it.
- Your display name / handle (from Twitch). Shown in moderation tools and, if your submission is featured, possibly on stream.
- Your linked chat identity. Signing in with Twitch links your Twitch user ID and login. This is what lets the chat avatar perk match you in Elliott's Twitch chat, and it appears on your Account page under "Linked platforms". We no longer offer Google sign-in and do not request access to your YouTube account; YouTube channel identities linked while it was offered (channel ID, handle, title, and thumbnail URL) remain on the account until deleted.
- An opaque user ID issued by Supabase. Used internally to link your submissions to your account.
We do not store passwords (Supabase handles that, and Twitch handles its own). We don't see your Twitch or YouTube chat history or anything beyond your basic profile info.
If you submit a link
- The URL you submitted, your optional description, and the time of submission.
- Your account ID, email, and display name as the submitter.
- Submissions denied by moderation are removed within 14 days. Approved submissions remain stored and may be discussed publicly on stream or in clips.
If you call the show line
- Your phone number, the audio of your message, and an automatic transcript of it. Phone numbers are stored unredacted in our database but masked in the moderation UI by default; only Elliott and his moderation team can reveal the full number.
- We also record an approximate region (a U.S. state or Canadian province) derived from your phone number's area code. This reflects where the number is registered, not your live location, and may be inaccurate for mobile numbers. We do not ask for, or separately store, your name — if you say it in your message it is part of the recording and transcript like anything else you say.
- Calls denied by moderation are flagged for deletion and removed within 14 days (both the database row and the audio file). Approved calls remain stored and may be played publicly on stream or on the site (anonymized — no phone number).
If you add a phone number to your account
Adding a phone number is optional and only required if you want to call into the live show (not for leaving a voicemail). Any signed-in user can attach a phone; no SMS verification code is sent — the number is saved as you enter it. We store:
- Your phone number in E.164 format, the time it was saved, and which provider (Twitch or magic-link email) your account uses.
The phone number is used only to match incoming live calls to your account so we know who's calling. You can remove the phone number from your account at any time on the Account page; removal is immediate.
A site admin can also attach a phone number to your account on your behalf (for example, if you're an invited guest and arranged it directly). The same storage and removal rules apply. Admins see the number in the admin user list with all but the last four digits masked.
Separately, you can opt in to occasional marketing texts from Elliott (live shows, special appearances) on the Account page. This is off by default and never required. We store whether you opted in and when. The consent is tied to the saved number: removing or changing your phone number clears it. You can opt out at any time by unchecking the box on the Account page or replying STOP to any message.
If Elliott picks up your call, we keep an internal log entry recording your phone number, your account email and display name (as they were at call time), the start and end timestamps, and the call duration. The audio is not recorded. This log is only visible to Elliott and other admins; it is not shown to other users and is never published. Removing your phone number from your account does not delete prior log entries — request deletion via the contact form if you want them removed.
Elliott (or another admin) can also block a phone number from calling either line. A blocked number is recorded in an internal list along with who blocked it and when. Blocked callers hear a short "this number has been blocked" message and the call ends. Blocks remain until manually removed by an admin; there is no automatic expiry. Request removal via the contact form if you believe you've been blocked in error.
If you upload a chat avatar
If you've signed in with Twitch, you can optionally upload a small image on your Account page to use as a chat avatar — a perk for Twitch subscribers and YouTube channel members. We store:
- The image, after we automatically crop and resize it to a small square using Cloudflare's image-processing service. The resized copy is kept in our Cloudflare R2 storage (we don't retain your original full-size upload), keyed to your account and matched to your chat messages through your linked Twitch and/or YouTube identity, along with its review status.
Every avatar is reviewed by a moderator before it can appear on stream. As part of that review, the image is sent to Elliott's team in a private Slack channel for approval. Once approved, the avatar is shown publicly next to your messages in the stream chat overlay while your Twitch subscription or YouTube membership is active. You can replace your avatar at any time on the Account page (which sends the new one back through review); request deletion via the contact form.
If you use the contact form
Your name, email, subject, and message are emailed directly to Elliott via Resend. We don't store contact-form submissions in our database — they live in Elliott's inbox after delivery.
Cookies and similar technologies
This site sets a small number of cookies, all strictly necessary for it to work:
| Cookie | Purpose | Lifetime |
|---|---|---|
em_session | Keeps you signed in between visits. Set only if you sign in. | 30 days |
Cloudflare cookies (e.g. __cf_bm) | Bot management and DDoS protection. Set automatically by Cloudflare. | Up to 30 days |
We don't use advertising cookies, tracking pixels, or third-party analytics that profile you across sites. Our analytics is cookieless.
Third parties that may receive your data
The site uses these services, each of which has its own privacy policy:
- Cloudflare — hosting (Workers), CDN, D1 database, R2 storage, KV cache, Workers AI for transcription, bot management. Receives your IP and request metadata for every visit.
- Supabase — authentication and user profile storage. Receives your email and display name when you sign in.
- Twitch — if you sign in with Twitch. Twitch receives the fact that you signed in to this site and provides us your Twitch handle and email. Separately, when Elliott features a message in his stream chat overlay, the server asks Twitch's API whether the message author is subscribed to his channel and when they followed. No Twitch data is stored long-term — these are read-only lookups shown only in the operator interface, never on a public page.
- Google / YouTube — Elliott's own YouTube live chat is read by our server
through the YouTube Data API so it can appear in his stream chat tools; that reads public chat
messages (your YouTube display name, channel ID, message text, and member/moderator status)
which are kept in a short rolling buffer and, for a message Elliott features, in the
featured-messages log. The bio page also shows a YouTube clip thumbnail loaded from
i.ytimg.com; the video itself only loads fromyoutube-nocookie.comafter you click play, and only then does YouTube receive your IP for that single embed. - Kick — Elliott's Kick live chat is delivered to our server by Kick's official API (webhooks) so it can appear in his stream chat tools alongside Twitch and YouTube. That carries your Kick display name, user ID, message text, and subscriber/moderator badges, kept in the same short rolling buffer and featured-messages log described above. We do not offer Kick sign-in and never receive your Kick credentials.
- Resend — outbound email (contact form, magic-link delivery via Supabase). Receives your email address and message contents.
- Podbean — hosts Elliott's podcast. The episode list is fetched from Podbean's RSS feed by our server (Podbean never sees your visit for that), but when you press play on the podcast page or the homepage player, your browser streams the audio (and loads episode artwork) directly from Podbean's CDN, which receives your IP address and standard request metadata for that download. See Podbean's privacy policy for details.
- Telnyx — if you call the show line. Telnyx receives your phone number, your call audio, and call metadata. Audio is uploaded from Telnyx into our Cloudflare R2 bucket and is no longer stored on Telnyx after that handoff. If you opt into marketing texts, Telnyx Messaging delivers them and receives your number. When Elliott takes calls live in his browser, his browser also opens a WebRTC connection to Telnyx (rtc.telnyx.com) so the call audio can flow both ways — that connection only exists while he's online.
- Slack — Elliott's production team uses a private Slack workspace to triage incoming submissions. When you submit a link, the URL, your optional description, and your display name + sign-in provider are mirrored into a private Slack channel only the team can see. When you leave a voicemail, the audio recording, the transcript, the approximate location derived from your area code, the call duration, and your phone number with everything but the last four digits masked are mirrored into a separate private channel. The full phone number stays on our servers — it is not sent to Slack. When you upload a chat avatar, the image is posted to a private channel so a moderator can approve or reject it. The reverse also happens: messages the production team posts in a designated Slack channel are mirrored back into Elliott's private streaming dashboard so he can read the crew while live — this mirrors the team's own internal chat, not visitor data. Slack also processes its normal account telemetry for the workspace members who view the channels.
- Umami — self-hosted, cookieless analytics running on
analytics.jesse.id(operated by the same person who maintains this site, not a third-party analytics company). A small script loads in your browser and sends an aggregated page-view event — the page path, referrer, and coarse details like browser, device type, and country. It sets no cookies, stores no identifier on your device, and can't track you across other sites. We see totals, not individual people. - Cloudflare aggregates anonymized request metrics (page paths, response status, country) at the edge. No JavaScript runs in your browser for this; it doesn't set cookies or track you across sites.
- Cloudflare Turnstile — bot/abuse protection on the sign-in and contact forms.
Turnstile loads a small script from
challenges.cloudflare.comand may set a short-lived cookie to verify your browser. It's a privacy-respecting CAPTCHA replacement: no user-tracking pixels, no behavioral profiling across sites. See Cloudflare's privacy policy for details.
Public leaderboard
The site shows a public leaderboard of top supporters of Elliott's stream. The leaderboard ranks chat participants by featured chats, favorited chats, bits cheered, current subscription tier, and sub gifts. The data is read from Twitch's public API each time someone visits the page (cached for ~15 minutes), plus rows from the site's own featured messages log (which may include older entries from a YouTube chat).
What appears for each row is your platform display name (e.g. your Twitch login, or a YouTube channel name on older entries) and the relevant number. On the Featured chats tab, a row can also expand to show the text of the chat messages Elliott starred — messages that were already posted publicly in the stream chat. These are values that are already public on the platform. We don't display your email, phone number, or any site account details on the leaderboard. The leaderboard does not link rows to site profiles in this version.
Your rights
You can ask us to:
- Tell you what data we hold about you.
- Correct anything that's wrong.
- Delete your account and any submissions or call recordings linked to it.
Use the contact form for any of the above. We aim to respond within 7 days.
Children
The site isn't aimed at children under 13 (or under 16 in the EU). We don't knowingly collect data from anyone in those age groups. If you believe a child has given us data, contact us and we'll delete it.
Changes to this page
If we change what we collect or who sees it, we'll update this page and bump the date at the top. There's no email notification — check back if you want to know.