Back to your account

Privacy policy

Last updated: 23 September 2026

This policy covers the Sunexa account at my.sunexa.xyz. It describes what data is kept there, why, and for how long. StreamPulse and ValCore have their own policies on their own sites.

Who is responsible

Jonas Weder, Switzerland. Reachable at [email protected]. There is no data protection officer; the account is run by one person.

Sunexa is based in Switzerland and also addresses users in the EU. The revised Swiss Data Protection Act applies, and the GDPR where it reaches.

What is stored

  • Account: display name, email address, profile picture URL and the time you signed up.
  • Linked providers: for each linked service the account id at that provider, the permissions granted, and access and refresh tokens. Tokens sit encrypted on the server and are used only for the features you connected.
  • Provider profiles: display name and picture address per provider, so you can pick which one your account shows.
  • Sessions: time, expiry, browser identifier (user agent), the provider you signed in with, the country code from the Cloudflare header, and the IP address of the sign-in. IPv4 addresses are stored in full.
  • Support: if you ever contribute, the tier, its status, the renewal date and the reference at the payment provider. Payment details such as card numbers never reach Sunexa.

Not stored: payment details, the contents of your calendars, messages or streams, and there are no analytics or advertising tools.

Cookies

Sunexa only sets cookies that the service needs or that you trigger yourself. There are none for analytics, advertising or recognising you across other sites.

  • Sign-in: a cookie named __Secure-sunexa.session_token. It holds a random key pointing at your session in the database and nothing else, in particular nothing about you personally. It lasts seven days. Your browser does not hand it to scripts.
  • Language choice: a cookie named sunexa-language holding "de" or "en", lasting a year. It only appears once you change the language.

That cookie covers sunexa.xyz and its subdomains, so signing in on my.sunexa.xyz also counts on dj.sunexa.xyz and you do not have to sign in twice.

There is no consent dialogue here because none of these cookies serve advertising, analytics or recognising you on other sites. Should one ever be added that does, you will be asked first.

Why

Account data is what makes signing in and linking work at all, which is performance of the relationship between us. Session data including the IP address serves security: it shows you in your account where you are signed in, and helps spot abuse. That is a legitimate interest in running the service safely.

For how long

  • Sessions expire and are then removed from the database automatically. You can end them yourself at any time.
  • Account and link data stay while the account exists. Disconnect a provider and its tokens are deleted.
  • Request deletion and the account is removed along with everything named here.

Who else is involved

  • Signing in through Twitch, Discord, Google or Microsoft tells that provider a sign-in happened. What they store about it is covered by their own policy.
  • Traffic passes through Cloudflare, which sits in front as a network and protection layer and handles the connection data that requires.

Beyond that nothing is passed on, sold, or used for advertising.

Your rights

You can ask what is held about you, have it corrected or deleted, and object to the processing. Two of those you do yourself under "Your data" in the account: the full export and the deletion request. For anything else, a message to [email protected] is enough.

You can also complain to a supervisory authority: in Switzerland the FDPIC, in the EU the authority where you live.

Changes

If something substantial changes, this page is updated and the date above with it.

Privacy·Sunexa·Status·Support·© 2026 Sunexa