Privacy Policy for D1 Arena
Last Updated: September 9, 2026
Privacy Commitment
D1 Arena Inc. operates an esports tournament, live-streaming, creator-monetization, and community platform. This Privacy Policy explains how D1 collects, uses, discloses, retains, and protects personal information. Privacy rights and obligations vary by location and circumstance; references to laws describe D1's intended handling and do not claim that every law applies to every user or feature.
Introduction
This policy should be read with the Terms of Use, Community Guidelines, Cookie Policy, and feature-specific notices. D1 uses age and location controls, but those controls do not replace a user's or organizer's responsibility to follow applicable law.
Registration & Contact Data
- Phone Number: For SMS verification and two-factor authentication via Twilio
- Geographic Location: Country, state, and city for compliance with regional regulations and tournament eligibility
- Stream Key: Unique identifier for streaming authentication (encrypted and never shared)
- Known Locations: Trusted login locations for security verification
Information We Collect
Account Information
- Personal Info: Name, email, date of birth, contact details
- Account Credentials: Username and password (password stored using industry-standard hashing)
- Profile Data: Avatar, bio, social links, gaming preferences
Two-Factor Authentication (2FA) Data
- Authentication App: TOTP secret key (encrypted, used to generate verification codes)
- Recovery Codes: One-time backup codes (hashed and stored securely)
- 2FA Status: Whether 2FA is enabled on your account
- Authentication Logs: Timestamps of successful/failed 2FA attempts for security monitoring
Identity, Parent/Guardian, and Provider Verification Data
D1 uses Stripe Connect and Stripe Identity for relevant creator, payout, parent/guardian, advertiser, and account-verification flows.
- Stripe-hosted collection: Stripe may collect government ID, selfie, address, bank, tax, and related information through Stripe-hosted flows.
- D1 records: D1 stores provider account or session identifiers, verification status, timestamps, limited verified outputs needed by the product, and audit records. D1 does not store full identity-document files or full payment-card numbers.
- Stripe retention: Verification data is handled under Stripe's terms and privacy policy. Successful verification does not automatically delete Stripe-held identity data. When appropriate, D1 or the user may use Stripe's supported redaction, deletion, or support processes.
- Biometric processing: Stripe may use selfie or facial matching when configured. See the Biometric Data Notice below.
Tax and Connected-Account Data
Stripe may collect tax and bank information for connected accounts. D1 may receive account status, requirements, balances, transfers, payouts, tax-form status, and limited identifiers needed to operate the feature. Users remain responsible for their own tax obligations; reporting forms, thresholds, reporting party, and retention depend on the transaction and provider configuration.
Wallet and Financial Records
- Wallet PIN: A six-digit PIN stored using one-way hashing.
- Payment records: Stripe customer, checkout, payment, connected-account, transfer, refund, dispute, and payout identifiers and statuses.
- Wallet ledger: Eligible earnings, tournament refunds or prizes, adjustments, and payout activity. D1 does not offer a general consumer wallet deposit or add-funds product.
- Provider data: Full card, bank, identity-document, and tax values are collected and retained by the applicable payment or verification provider rather than in D1's application database.
Tips & Donations Data
- Tip Transactions: Amount, recipient (streamer/team), timestamp, and payment method
- Tip Messages: Optional messages attached to tips (up to 200 characters)
- Display Preferences: Whether you chose to show or hide your name on tips
- Team Tip Splits: For team tips, records of how the tip was distributed among members
Platform Usage Data
- Membership Info: Subscription tier (Starter, PRO, Ultimate, or Partner) and billing history
- Usage Data: Game stats, preferences, tournament history
- Device Info: IP address, browser, operating system
- Streaming Data: Ingest and playback protocol data (including RTMP, SRT, WHIP, WHEP, and HLS where used), VOD recordings, clips, and stream analytics
AI Data Processing
Depending on the feature, D1 may process prompts, chat context, uploaded text or images, stream or clip frames, account or feature context, AI outputs, moderation results, user corrections, ratings, and engagement signals. Some inputs can contain personal information or user-generated content. D1 limits context by feature where practical, but does not represent that every AI request is anonymous.
Third-Party AI Services
- Provider: D1 uses the xAI/Grok API for moderation assistance, support, game detection, diagnostics, analysis, and optional content generation.
- Provider retention: xAI states that standard API requests and responses may be retained for up to 30 days for abuse monitoring. Zero-data-retention treatment applies only when enabled for the applicable xAI team.
- Training: xAI states that API inputs and outputs are not used to train its models without permission.
- D1 retention: D1 may retain prompts, responses, corrections, support history, moderation evidence, and audit results for the purposes described in this policy.
AI Improvement and Choice
D1 may compare generated and edited outputs, use ratings or engagement, and maintain game or policy references to improve D1 features. Optional content-generation tools can be avoided; security, moderation, fraud, and support processing may still apply when needed to operate or protect the Platform.
Retired Third-Party Connection Data
\nD1 Arena has retired its former Discord account connection. Historical connection records may include the external user identifier, username, avatar URL, email returned by the prior authorization flow, encrypted connection tokens, preferences, and audit history. D1 does not use those records or tokens for current product notifications, roles, voice rooms, or tournament casting. Historical records are retained or deleted under the account, security, legal-hold, and data-deletion rules in this policy. Contact Support or use the account data tools to request access or deletion where applicable.
\nAge Requirements & Parent/Guardian Controls
- Under 13: Accounts are not permitted. If D1 learns that an under-13 account or information was collected contrary to policy, D1 may close the account and delete or otherwise handle the information as required.
- Ages 13–17: Parent/guardian verification is required under D1 policy. Youth accounts may join free tournaments but may not enter paid tournaments or receive cash tournament prizes.
- Youth creator monetization: A separate parent/guardian monetization-consent and Stripe setup path may allow eligible tip or supporter-subscription earnings. It does not enable paid-entry tournaments or cash tournament prizes.
COPPA generally applies to covered online collection from children under 13. D1's controls for users ages 13–17 are additional platform safety and eligibility rules.
How We Use Your Data
- Account Security: 2FA verification, login protection, fraud prevention
- Identity Verification: Confirming user identity for wallet access and payouts
- Tax Compliance: IRS Form 1099-K reporting for payment processors
- Tournament Management: Registration, matchmaking, results
- Tip Processing: Processing tips to streamers and teams, calculating fee splits, and crediting wallets
- Tip Notifications: Notifying streamers of incoming tips and showing tip alerts during streams
- Prize Distribution: Secure payment processing to verified accounts
- Membership Services: Managing your Starter, PRO, Ultimate, or Partner tier and related access
- Communication: Updates, support, security alerts, notifications
- Legal, safety, and eligibility: Applying age, location, contest, payment, fraud, sanctions, provider, and other legal or policy controls
- Platform Improvement: Analytics and feature development
Data Protection - We Do NOT
- Sell your personal information, including identity documents or SSN
- Rent your data to third parties
- Share data for marketing without consent
- Collect data from children under 13
- Store passwords, PINs, or 2FA recovery codes in plain text
- Display full SSN/TIN in any user interface (only last 4 digits shown)
Data Sharing (Limited)
- Stripe Connect Express: Primary payment processor - handles identity verification, SSN collection, tax form generation (1099-K), and payouts. Stripe is PCI-DSS Level 1 certified and SOC 2 compliant. View Stripe Privacy Policy
- Note: All creator payouts are processed via Stripe Connect (as of January 2026).
- Tax Authorities: Stripe reports to the IRS on your behalf via Form 1099-K for qualifying payouts
- Legal Requirements: Court orders, law enforcement requests, subpoenas
- Platform Protection: Fraud prevention, terms enforcement
Security Measures
Encryption & Data Protection
- Transport Encryption: Supported web and API communications use TLS in transit
- AES-256 Encryption: D1 Arena uses AES-256 for protected configuration vaults and encrypted backups stored on our self-hosted MinIO object storage. D1 does not store full payment-card numbers or full identity-document files in its application database. Stripe or the applicable provider collects and retains full payment, bank, identity, and tax values under its own controls and policies.
- Password Hashing: Bcrypt with cost factor 12 for new password storage and automatic rehash on next sign-in for older hashes (OWASP 2024 baseline for high-value accounts).
- PIN Security: Wallet PINs hashed using secure one-way algorithms
- 2FA Secrets: TOTP secrets encrypted, recovery codes hashed
Access Controls
- Role-Based Access: Limited personnel access to personal and financial data
- PII Access Logging: Privileged access to sensitive fields stored by D1 is logged and subject to role controls
- Admin 2FA Required: All administrative accounts require two-factor authentication
- Security Review: Security assessment, monitoring, vulnerability testing, and incident-response processes
Payment Security
- PCI-DSS Compliance: Payment processing through compliant providers
- Secure Payments: We never store full credit card numbers
Data Retention
- Account data: Retained while the account is active and during the current 30-day deactivation/reactivation window, then removed or de-identified subject to the deletion process and exceptions below.
- Ordinary stream chat: Subject to the current 30-day cleanup process. Moderation, dispute, safety, and legal-hold records can be retained separately.
- VOD media: Current tier windows are Starter 10 days, PRO 30 days, Ultimate 60 days, and Partner 90 days, unless content is deleted earlier or retained under a tournament, moderation, dispute, or legal requirement.
- Payments and tax: Transaction, dispute, accounting, tax, fraud, and connected-account records are retained by D1 and/or Stripe for the periods required by their purpose, applicable law, provider rules, and legal holds.
- Identity: D1 retains provider identifiers, status, timestamps, limited verified outputs, and audit records. Stripe retains provider-held verification data under its policy; supported redaction or deletion processes may apply.
- Security and enforcement: Logs and evidence are retained according to security, fraud, abuse, appeal, and legal needs rather than one universal period.
- AI and support: D1 may retain support conversations, prompts, outputs, ratings, moderation results, and ticket history as needed to provide, secure, audit, or improve the service. Standard xAI API retention may be up to 30 days unless ZDR is enabled for the applicable team.
Live Streaming, Chat, and Native Communications
When you stream, watch, chat, or use communications features, D1 processes content and operational metadata needed to provide, moderate, secure, and measure those features.
Streams, VODs, Clips, and Chat
- Stream media, titles, categories, viewer/session events, analytics, VODs, clips, chat messages, moderation actions, and related identifiers may be processed.
- Ordinary stream-chat messages are subject to the current 30-day cleanup process. Bans, timeouts, strikes, reports, dispute evidence, tournament records, and legal holds may be retained separately.
- Watch time, D1 Cred activity, reward redemptions, polls, predictions, alerts, raids/hosts, and customization data are recorded to operate those features.
Watch Parties
D1 processes party membership, host settings, synchronized playback position, chat, presence/activity, and signaling metadata. The host may turn voice off, limit it to friends, or allow signed-in participants. Camera and screen sharing may be available when voice access is enabled.
Friend Calls and Team HQ
Supported messaging surfaces provide friends-only voice/video calls with blocking and age-band controls. Team HQ provides text, voice, camera, and screen sharing to authorized team members. D1 processes account authorization, room/participant identifiers, signaling, roster, safety, and activity metadata. These communication rules also apply to supported multi-person friend conversations and calls, in addition to direct messages, Team HQ and Watch Parties.
WebRTC Media
Real-time voice, video, and screen media uses WebRTC with DTLS-SRTP, peer-to-peer routing when possible, and coturn relay fallback. A relay forwards encrypted media packets when a direct connection is unavailable. The current implementation does not record or store call media. Participants must not record or redistribute another person's voice, video, or screen without authorization and any consent required by law.
Service Providers
- Stripe: Payments, connected accounts, identity and parent/guardian verification. Stripe may collect identity and biometric information under its privacy policy.
- Cloudflare: DNS, CDN, WAF, DDoS protection, Turnstile, and request/security metadata.
- AWS Polly: Text submitted for supported text-to-speech synthesis.
- Sentry: Error and reliability monitoring; configured telemetry may include technical context and masked or minimized interaction data.
- Google: GA4/Consent Mode analytics where permitted by consent, and translation processing for supported content.
- SearchAtlas/LinkGraph: Public-page SEO compatibility and crawl/reporting functions.
- D1 Studio Assets: The current GIF picker uses the moderated D1 Studio Assets library. Existing feature and membership permissions determine where the picker is available.
- Steam: Primary importer for the D1-owned game catalog; some legacy rows may retain RAWG assets.
- Real-time transport: D1's WebSocket, WebRTC, and coturn infrastructure operates live events and communications.
- Twilio: Phone verification and SMS two-factor delivery.
- xAI/Grok: AI processing described above.
- Printful: Physical Printful checkout and automatic order submission are currently unavailable. Printful-related records may remain relevant to existing merchandise, fulfillment, support, refund or dispute activity.
- Zernio: Selected eligible public clips or social-promotion content sent to D1-operated social accounts as described below.
Content ID & Audio Fingerprinting
D1 Arena uses an in-house Content ID system powered by AcoustID for audio fingerprinting:
- Audio Fingerprints: Audio from your streams and uploads is fingerprinted to detect copyrighted content
- Content Strikes: Matched content may result in automated strikes under our Content Strike Policy
- Processing: Fingerprinting occurs automatically during stream ingestion and upload processing
Advertising Data
D1 Arena operates a fully in-house advertising system (no third-party ad networks):
- Ad Impressions: We track which ads you see, including timestamps and page context
- Conversion Tracking: If you interact with an ad, the click and any subsequent conversion events are recorded
- Ad Targeting: Ads may be targeted based on game category, geographic region, and membership tier. We do not sell your personal data to advertisers.
- Advertiser Accounts: If you register as an advertiser, additional business information and payment data are collected
- AI Ad Moderation: Ad creatives are reviewed by AI and human moderators before serving
- Fraud Detection: Impression patterns are analyzed to prevent click fraud and invalid traffic
AI-Powered Features & Automated Decision-Making
D1 Arena uses artificial intelligence for the following purposes:
- Content Moderation: AI reviews chat messages, stream content, ad creatives, and user-generated content for policy violations. Automated actions may include message removal, warnings, or flagging for human review.
- Game Detection: AI automatically detects which game is being streamed
- Streaming Troubleshooter: AI-assisted diagnostics for stream quality issues
- FAQ Chatbot: AI-powered customer support assistant
- Content Generation: AI assists with generating titles, descriptions, bios, and tournament rules at user request
- Match Analysis: AI-powered tournament predictions and player insights based on historical performance
- Image Review: AI flags uploaded images for policy compliance review
Human Oversight: Available moderation and enforcement actions can be appealed through D1 support. Optional generated titles, descriptions, bios, and rules can be edited or rejected; security and moderation controls may operate automatically.
Biometric Data Notice
D1 does not itself store biometric templates. Stripe Identity or Stripe Connect may collect and process a selfie, identity-document image, or facial matching data when that verification method is configured. D1 receives the provider session/account identifiers, statuses, timestamps, and limited verified outputs needed by the product rather than the full biometric template.
Stripe-held identity data is governed by Stripe's privacy policy and the choices presented in the Stripe flow. Successful verification does not automatically delete that data. Stripe provides supported redaction, deletion, consent-revocation, or support processes that may apply depending on the request and legal obligations. Contact D1 support for help with a D1-created verification session.
California Consumer Privacy Act (CCPA) Rights
If you are a California resident, you have additional rights under the CCPA:
- Right to Know: You may request details about the categories and specific pieces of personal information we have collected
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: D1 Arena does not sell your personal information. We do not sell data to third parties for monetary consideration.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact our Support Center or use the data tools in your account settings.
D1 Cred (Channel Points) Data
- Watch Activity: Time spent watching streams is tracked via heartbeat to award D1 Cred points
- Redemption History: Records of channel point redemptions are maintained
- Prediction & Poll Participation: Wagers and votes using D1 Cred are recorded
- Leaderboard Data: Your D1 Cred balance and rank may be publicly visible on channel leaderboards
Account Lifecycle Data
- Deactivation: Account data is retained during the current 30-day reactivation window.
- Deletion: After the grace period, D1 removes or de-identifies personal data subject to fraud, chargeback, tournament, dispute, security, legal-hold, tax, accounting, and other legal obligations.
- Providers: Stripe and other providers retain their records under their own policies and legal obligations; deleting a D1 account does not automatically delete every provider-held record.
- Security sessions: D1 records session, device, IP, risk, and login information needed for account protection and investigation.
Your Rights
- Access: View your personal data anytime via account settings
- Update: Correct inaccurate information (identity re-verification may be required)
- Delete: Request account and data deletion (subject to tax record retention requirements)
- Withdraw Consent: Opt out of optional data processing
- Portability / Data Export: Request and download a copy of your data in machine-readable format via account settings or by contacting our Support Center
- 2FA Management: Enable, disable, or reset 2FA at any time
- Security Alerts: Receive notifications of suspicious account activity
- Communication & Visibility Controls: Choose who can see your profile, who can send you friend requests, who can direct message you, and who can see your chat activity in Account > Privacy Settings. These choices are enforced server-side.
Cookies & Tracking
We use essential cookies for Platform functionality including session management and 2FA verification. For detailed information, see our Cookie Policy. You can manage cookie preferences in your browser settings.
Third-Party Links
External links are not covered by this policy. Review third-party privacy policies separately.
Policy Updates
We may update this policy. Significant changes will be communicated via Platform notification or email. Material changes to how we handle SSN, identity documents, or 2FA data will require explicit re-consent.
Contact
Questions about privacy, identity verification, or data security? Contact us.
For data deletion requests or TDPSA rights: our Support Center
This policy describes D1’s current privacy practices. Where consent is the applicable legal basis, D1 requests it through the relevant account, cookie, verification, or feature flow. Other processing may rely on contract, legitimate operational and safety needs, or legal obligations, depending on the context.
Platform social promotion (Zernio)
D1 Arena may post selected public clips to platform-operated social accounts (for example Facebook, Instagram, LinkedIn, and TikTok as configured) via the Zernio API, under the license you grant in the Terms of Use (User-Generated Content License and Platform social promotion). This is not a post to your personal social accounts.
- Partner clip auto-promo: Only when the clip creator is the VOD owner, the clip is public (not private / not tier-gated), the clip is not an auto-clip, and the streamer is Partnership-tier and/or a Founding Member — subject to daily cadence limits. Starter/PRO/Ultimate users are not generally included unless they meet those rules.
- Clip of the Week (CotW): Winning clips may be posted under a separate CotW program flag with different eligibility than partner auto-promo.
- Go-live social posts: A separate feature flag; may be off even when clip/CotW posting is on.
- Controls: Legal authorization is the Terms UGC / Platform social promotion license — not a separate Privacy consent checkbox. There is no settings toggle to opt out of platform social promo. Making a clip private or otherwise non-shareable is how it fails eligibility. Contact support for privacy questions about CotW selections.
Native Communications Summary
Team HQ, Watch Parties, and supported friend-call surfaces use the WebRTC and metadata handling described above. No external community account is required for these D1-native communications. The current implementation does not record or store call media.
Merchandise (Printful)
Physical Printful checkout and automatic order submission are currently unavailable. Printful-related records may remain relevant to existing merchandise, fulfillment, support, refund or dispute activity. Existing records remain subject to this policy’s retention and deletion provisions.