← Back to TwitchApp
Privacy Policy
Last updated: September 15, 2026
TwitchApp ("we", "our", or "the application") is a desktop streaming tool for Twitch streamers. This Privacy Policy explains what data we access, how it is used, and your rights.
1. Data We Access
TwitchApp may request access to the following services and data:
- Twitch — your channel name, chat messages, channel point redemptions, and stream information, solely to power dashboard features.
- YouTube — your YouTube channel name, live chat messages, live broadcast status, and viewer count, solely to display stream information and live chat within the app.
- OBS WebSocket — local connection to OBS Studio for scene and source control. No data leaves your machine via this connection.
- Donation services — read-only access to donation events from DonationAlerts, StreamElements, and DonatePay to display alerts and statistics.
- Donation voice-over (optional) — if you enable text-to-speech for donation alerts, the donor's name and message text are converted to speech. Windows voices are processed locally on your computer. If you connect your own Yandex SpeechKit or ElevenLabs account, the text is sent from your computer directly to that provider using your API key, under that provider's terms; nothing passes through our servers and we never see the text, the audio, or your key.
2. How We Use Your Data
- All data is processed locally on your device. We do not collect, store, or transmit your personal data to our servers.
- OAuth tokens (access tokens and refresh tokens) are stored only on your computer, encrypted with Windows Data Protection API (DPAPI) under your Windows user account, and are never sent to anyone other than the respective service APIs (Google, Twitch, Kick). See section 4, "How We Protect Your Data".
- YouTube chat messages and Twitch chat messages are displayed in real time within the app and are not logged or stored by us.
3. Google / YouTube Data
TwitchApp uses the YouTube Data API v3 to access your live broadcast and live chat data. By connecting your YouTube account, you grant the app the following OAuth scopes:
https://www.googleapis.com/auth/youtube.readonly — read your YouTube account and channel data
https://www.googleapis.com/auth/youtube.force-ssl — read and send live chat messages on your behalf
TwitchApp's use of YouTube data is limited to: displaying your live stream status and live chat within the application; posting chat messages that you or your chat bot send from the application to your own live chat; and reading the stream key of your own channel so the application can restream your broadcast to YouTube when you enable that feature. The stream key is kept only in the application's memory on your computer (and, if you enable your own relay server, sent only to that server, which you control). We do not share YouTube data with any third parties, do not use it for advertising, and do not allow humans to read it except with your explicit consent for support purposes.
TwitchApp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your use of the YouTube API is also subject to YouTube's Terms of Service and Google's Privacy Policy.
YouTube data (chat messages, broadcast status) is processed in real time and is not stored beyond the current session, except for the last 50 chat messages kept locally so the chat window is not empty after a restart. OAuth tokens are stored on your computer only, encrypted with Windows DPAPI (see section 4). You can revoke TwitchApp's access to your Google account at any time by visiting Google Account Permissions or the Google security settings page; disconnecting YouTube inside the application also deletes the stored tokens.
4. How We Protect Your Data
TwitchApp is a desktop application: your data is processed on your own computer and does not pass through our servers. The following mechanisms protect sensitive data, including Google user data obtained through the YouTube API:
- Encryption in transit. All communication with Google, YouTube, Twitch, Kick, donation services and our license server uses HTTPS (TLS 1.2 or newer). The application never sends tokens or user data over unencrypted connections.
- Encryption at rest. OAuth access and refresh tokens, and any API keys you enter, are stored in a dedicated secrets file inside the application's private data folder and encrypted with the Windows Data Protection API (DPAPI). The encryption key is bound to your Windows user account: the file cannot be decrypted by another user of the computer or after copying it to another machine.
- Access control. The secrets file lives in your user profile (
%APPDATA%) and is protected by Windows file permissions of your account. Only the TwitchApp process running under your account reads it. Tokens are held in memory only while the application is running.
- Least privilege. We request only the YouTube scopes needed for the features you enable (reading and posting live chat, reading broadcast status and your own stream key for restreaming). Tokens are used exclusively to call the YouTube Data API on your behalf.
- No server-side storage. We do not collect, log, transmit to, or store Google user data on our servers. Chat messages and broadcast data are processed in memory and displayed in real time; the last 50 chat messages are cached locally only for the chat window.
- No third-party sharing. Google user data is never shared with, sold to, or transferred to third parties, advertising networks or analytics services, and is never used to train AI or machine-learning models.
- Deletion. Disconnecting YouTube inside the application immediately deletes the stored Google tokens. Uninstalling the application and removing its data folder removes all remaining local data. You can also revoke access at any time in your Google Account Permissions.
- Secure development. The application is built from a version-controlled source tree with automated checks, updates are delivered over HTTPS and every update is cryptographically signed; the application refuses updates whose signature does not match.
- Incident notification. Should we ever become aware of a security incident affecting user data, we will notify affected users through the application and on probeno.me without undue delay and no later than 72 hours after confirming it.
5. License Verification
When you activate a license key, the key is sent to our server (probeno.me) for validation. We store only the license key hash and activation status — no personal identifying information is collected.
6. Analytics and Tracking
TwitchApp does not use any analytics, tracking, or advertising SDKs. We do not track usage behavior or install telemetry.
7. Auto-Updates
The app periodically checks for available updates in the background. This process is handled entirely within the application and contains no personal data.
8. Data Retention and Deletion
All data (OAuth tokens, settings) is stored locally on your device. To delete all app data, uninstall the application and delete the app data folder. Revoking OAuth access via Google or Twitch account settings will immediately invalidate stored tokens.
9. Children's Privacy
TwitchApp is intended for users aged 13 and older. We do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this Privacy Policy occasionally. The "Last updated" date at the top will reflect any changes. Continued use of the application after changes constitutes acceptance.
11. Contact
If you have questions about this Privacy Policy, please contact us via the TwitchApp community or at probeno.me.