Effective Date: July 21, 2026 Last Updated: July 21, 2026
Live Infinite ("we", "our", or "Data Controller") recognizes the importance of protecting the personal data of our users ("you" or "User") and is committed to maintaining your privacy in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and internationally recognized data protection principles.
This Privacy Policy ("Policy") explains in detail how we collect, use, disclose, transfer, store, and secure your personal data when you access or use our desktop application (Electron App), website (live-infinite.netlify.app), and all related services.
This Policy forms an integral part of the Terms and Conditions of Live Infinite and is legally binding between you and us.
By accessing or using Live Infinite, you consent to the practices described in this policy. If you do not agree with this policy, please refrain from using our services.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, whether directly or indirectly, as defined under the PDPA.
- "Data Controller" means Live Infinite as the entity that determines the purposes and means of processing personal data.
- "Data Processor" means any person or entity that processes personal data on behalf of the Data Controller, such as cloud hosting providers and authentication services.
- "Processing" means any operation performed on personal data, including collection, recording, storage, modification, retrieval, use, disclosure, transfer, deletion, or destruction.
- "Software" means the Live Infinite application, including the desktop application (Electron App for Windows and macOS) and all related websites.
- "Service" means all services provided under the Live Infinite Software, including the live stream management system, Overlay system, Event Triggers system, game automation, and profile sync system.
2. Personal Data We Collect
We collect personal data as necessary for providing our services and in accordance with applicable law. The data is categorized as follows:
2.1 Data You Provide Directly
- Account Registration Data: Email address used for registration via Firebase Authentication, including the hashed password. We cannot read or recover your actual password.
- Display Name: The username you set in the application, which is displayed in the app instead of your email.
- Payment Data: Transaction reference numbers, subscription plan status (Free/Light/Pro/Ultra), coin purchase and usage history, and redeem code records. We do NOT collect credit card numbers or financial account information directly, as payments are processed through licensed third-party payment providers.
- Support Data: Messages you send through our support channels, such as our Discord server, for technical assistance.
2.2 Data Collected Automatically
- Unique Identifiers: Firebase User ID (UID), a 28-character alphanumeric string that links your account with data in our cloud system.
- IP Address: Collected to detect unauthorized access attempts and prevent abuse.
- Session Data: Session IDs, device type, software version, and Desktop Login Pairing IDs.
- Technical Data: Operating system (Windows/macOS), CPU architecture (x64/arm64), software version, and technical error logs (Crash Logs/Error Logs).
- Usage Data: API endpoint call logs, timestamps, and non-personally identifiable statistical data.
2.3 TikTok Live Stream Data
If you connect your TikTok account through our Software, we may receive and process specific live stream data from your TikTok account via unofficial APIs. This includes data such as live chat messages, gift transactions, usernames of live stream viewers, follow events, like events, and share events during your live streams. This data is used solely for processing within Live Infinite to provide you with Event Trigger actions, overlays, and game automation features.
We do not permanently store TikTok live stream data. This data is processed in real-time within the desktop application and is not transmitted to or retained on our cloud servers.
2.4 Profile Synchronization Data
- Profile Data: Profile names, profile status (Active/Inactive), and all configuration settings within each profile, such as Overlay settings, Sound Alert settings, and timer configurations.
- Event Trigger Data: Condition details and actions you configure for responding to live stream events.
- Game Profile Data: Game automation command sets, game automation settings, and shared game profile data between users.
- Profanity Filter Lists: Words you or the system configure to filter from chat messages.
- Last Updated Timestamps: Used for comparing and synchronizing data between desktop and cloud using the Last-Write-Wins strategy.
2.5 Data We Do NOT Collect
We explicitly state that we do NOT collect the following:
- Racial or ethnic origin, political opinions, religious or philosophical beliefs
- Genetic data, biometric data, or health data
- Data concerning disabilities, labor union membership, or criminal records
- Sexual behavior or sexual orientation data
- Credit card numbers, debit card numbers, or your direct financial account information
- TikTok account passwords or login credentials
3. How We Use Your Information
We use your information for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Creating and maintaining your user account, verifying authentication and authorization | Contractual Necessity (Section 24(3)) |
| Synchronizing profile settings between desktop and cloud server | Contractual Necessity (Section 24(3)) |
| Processing payments, subscription renewals, and coin system management | Contractual Necessity (Section 24(3)) |
| Processing TikTok live stream data for Event Triggers, overlays, and game automation | Contractual Necessity (Section 24(3)) |
| Detecting unauthorized access, preventing double-spend, and preventing abuse | Legitimate Interests (Section 24(5)) |
| Maintaining system stability and security, recording Crash Logs and Error Logs | Legitimate Interests (Section 24(5)) |
| Providing technical support, answering questions, and troubleshooting | Contractual Necessity (Section 24(3)) |
| Limiting concurrent Active Sessions per subscription plan to prevent account sharing | Legitimate Interests (Section 24(5)) |
| Enforcing bans, suspensions, and account restrictions | Legitimate Interests (Section 24(5)) |
| Complying with applicable laws such as the Computer Crimes Act and tax/accounting laws | Legal Obligation (Section 24(6)) |
4. Disclosure of Personal Data to Third Parties
4.1 General Principle
We will NOT sell, trade, or rent your personal data to third parties for marketing purposes whatsoever.
4.2 Authorized Data Processors
We may disclose your personal data to the following trusted Data Processors:
| Service Provider | Purpose | Server Location |
|---|---|---|
| Firebase Authentication (Google LLC) | Authentication, email verification, Google sign-in, and session management | United States / Global |
| Google reCAPTCHA Enterprise (Google LLC) | Bot detection and prevention on login and registration pages | United States / Global |
| Supabase Inc. (PostgreSQL Cloud) | Primary cloud database for storing account data, profiles, settings, and transactions | Singapore / United States |
| Netlify Inc. | Hosting the website and API Endpoints (Serverless Functions) | United States / Global |
| Licensed payment gateway providers | Processing subscription and coin payment transactions | Varies by provider |
4.3 Disclosure Required by Law
We may disclose your personal data when required by court orders, subpoenas, or legally binding requests from government authorities; investigations by authorized law enforcement agencies; or to protect the rights, property, or safety of the Provider, other users, or the public.
4.4 Cross-border Data Transfer
As our cloud service providers have servers located outside Thailand, your personal data may be transferred to countries with adequate data protection standards. We ensure compliance with Section 28 of the PDPA.
5. Data Retention Period
| Data Type | Retention Period |
|---|---|
| Account and profile data | For the entire duration your account remains active |
| Profile sync and configuration data | Deleted or anonymized within 30 days after account deletion |
| Payment transaction records | Up to 5 years from the transaction date, as required by tax laws |
| Login and session logs | 90 days from the date of the event |
| Technical error logs (Crash Logs) | 180 days from the date of the event |
| Two-factor verification data (2FA Pairing) | Deleted immediately upon completion or expiry (10 minutes) |
| Ban/suspension records | Retained for the duration of the ban; permanent bans are retained indefinitely for enforcement purposes |
| TikTok live stream data | Not retained; processed in real-time only |
6. Account Deletion
6.1 How to Request Account Deletion
You may request deletion of your account and all associated personal data by contacting us through our Discord Support Server. You must verify your identity before deletion can proceed.
6.2 Deletion Process
- Upon receiving a verified deletion request, we will delete or anonymize your personal data within 30 days.
- Profile data, Event Trigger configurations, game profiles, and synchronization data will be permanently removed from our cloud database.
- Your Firebase Authentication account will be deleted.
- Transaction records required by law (tax/accounting) will be retained for the legally mandated period but will be anonymized so they can no longer be linked to you.
6.3 Effects of Account Deletion
- Account deletion is permanent and irreversible. Once deleted, your data cannot be recovered.
- Any remaining subscription time or unused coins will be forfeited and are non-refundable.
- Shared game profiles you created may continue to exist but will be disassociated from your account.
7. Your Rights as a Data Subject
Under the PDPA, you have the following rights:
- Right of Access: Request access to and a copy of your personal data.
- Right to Data Portability: Receive your data in a machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Erasure: Request deletion or anonymization of your data.
- Right to Restriction: Request restriction of processing in certain cases.
- Right to Rectification: Request correction of inaccurate data.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
- Right to Lodge a Complaint: File a complaint with the Personal Data Protection Committee.
Exercising Your Rights: Contact us through our Discord Support Server. We will process requests within 30 days.
8. Data Security Measures
8.1 Technical Measures
- Password Hashing: Passwords are hashed by Firebase Authentication using secure algorithms.
- Transport Encryption: All communications use HTTPS/TLS encryption.
- Row-Level Security (RLS): Supabase database enforces RLS on every table with deny-all backstop.
- API Key Scoping: Every API request requires valid API Key and Bearer Token verification.
- Bot Prevention (reCAPTCHA Enterprise): Login and registration pages use reCAPTCHA Enterprise.
- Two-Factor Verification: New accounts require email link verification.
- Active Session Limiting: Concurrent device limits per subscription plan.
8.2 Organizational Measures
- Service Role Key access restricted to central API system only.
- Personal data not stored client-side beyond operational necessity.
- Security measures regularly reviewed and updated.
While we strive to protect your data, no data transmission over the internet can be guaranteed 100% secure.
9. Cookies and Tracking Technologies
Our website does not use cookies for marketing or cross-site tracking purposes. Third-party services (Firebase Authentication, Google reCAPTCHA) may use cookies according to their own privacy policies.
10. Children's Privacy
Our Service is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete such data promptly.
11. Changes to This Policy
We may update this Policy from time to time. Significant changes will be communicated through our website or application. Your continued use constitutes acceptance of the updated Policy.
12. Contact Information
- Data Controller: Live Infinite
- Primary Contact: Discord Support Server — https://discord.gg/bvnRtPwWgz
- Website: https://live-infinite.netlify.app
This Policy is available in Thai and English. In the event of any discrepancy, the Thai version shall prevail.