Privacy Policy
Oshi Alert (推し通知) / Last updated: August 4, 2026 / 日本語版はこちら
1. Who we are
This policy covers the Chrome extension "Oshi Alert" (Japanese name: 推し通知) and this website, oshialert.com. The provider below is the controller of the data described here.
- Provider: Zen Works
- Responsible person: Yosuke Yamashita
- Contact: contact form
2. What we collect, and why
Below is every category of data we handle and the purpose it is used for. We do not use it for any other purpose.
- Email address (only if you choose to sign in)
Purpose: creating and authenticating your account so your tracked channels can sync across devices. Handled by Firebase Authentication. Passwords are hashed by that service and are never visible to us in plain text.
- Tracked channel information (platform name, channel ID, channel name, icon image URL)
Purpose: monitoring those channels for live streams, sending notifications, and displaying your list in the settings page. When signed in, this is also stored in the cloud so it syncs across devices.
- Live status (whether a tracked channel is currently live, and the stream ID)
Purpose: sending the notification and opening the correct stream page when you click it.
- Plan information (free or Pro, and the Stripe customer ID)
Purpose: determining whether the Pro plan is active and providing the cancellation flow.
- Anonymous usage events (a random identifier generated by the extension, event names, and the platform name involved)
Purpose: understanding which features are used so we can improve them. Sent to Google Analytics 4. This identifier is not linked to your name, email address or any other identifying data, and we cannot identify individuals from it.
3. Where data is stored, and for how long
- In your browser (chrome.storage.local): tracked channels, plan information, sign-in state, and the anonymous usage identifier.
Retention: until you uninstall the extension. Uninstalling deletes it.
- Google Cloud (Firebase Authentication / Cloud Firestore): if you sign in, your email address, tracked channels and plan information.
Retention: until your account is deleted. We erase it within 7 days of a deletion request.
- Our API server (Vercel) and cache (Upstash Redis): a short-lived cache of live status.
Retention: automatically discarded after at most 180 seconds. The cache is keyed by channel only — it does not record which user is following whom.
Because of how these services operate, data may be stored and processed on servers outside Japan, including in the United States.
4. What is sent to our server
To check whether a stream is live, the extension sends the IDs of your tracked channels to our API server (oshicheck.vercel.app). The server uses them to query each streaming platform's API and returns whether the channel is live. Only channel IDs are sent — never your email address or anything you browse.
5. Sharing with third parties
We never sell your data. We share it only where necessary to provide the service:
- The streaming platforms listed in section 6: channel IDs are sent in order to read public live status. Nothing that identifies you as a user is sent.
- Google (Firebase / Google Analytics): account authentication, data storage, and anonymous usage analysis.
- Stripe: processing payments for the Pro plan.
- Lawful requests: we comply where required by law.
6. Third-party services we use
Please also review each provider's own privacy policy.
7. How to delete your data, and your rights
You can do all of the following at any time:
- Remove a tracked channel: use the delete button next to it in the settings page. If you are signed in, the cloud copy is removed at the same time.
- Delete all local data: uninstall the extension. Everything stored in your browser is removed.
- Delete your account and cloud data: request it through the contact form. We erase your registered email address and synced data within 7 days.
- Access or correct your data: request it through the same form.
- Cancel the Pro plan: use "Manage / cancel plan" in the settings page.
8. Security
- All traffic between the extension and our server, and between our server and each streaming platform, is encrypted over HTTPS.
- Access to cloud-stored data is restricted to the signed-in account it belongs to, enforced by Firebase Authentication. Users cannot read each other's data.
- API keys and other secrets for the streaming platforms are held in server-side environment variables and are not bundled with the extension. This is why you never need to supply an API key.
9. What we do not collect
- Your browsing or search history, or the contents of your open tabs
- Your location
- Card numbers or other payment details (handled by Stripe; we never hold them)
- Your viewing history or chat messages on any streaming platform
10. Children
This service is not directed at children under 13. If we learn that we have inadvertently collected data from a child under 13, we will delete it promptly.
11. Changes to this policy
We may update this policy as the service changes. When we make a significant change, we update the "Last updated" date at the top of this page.
12. Contact
For questions about this policy or to request deletion of your data, please use our contact form.