Privacy Policy Your stream stays on your computer.
CroStream has no accounts, and the app has no analytics. Here's exactly what it keeps, where it keeps it, and the few things that ever leave your machine.
Effective October 11, 2026 contact@crostream.io
At a glance
- Cookie-free site analytics No accounts, forms or cookies. Cloudflare serves the pages and counts visits without cookies.
- Your data stays on your PC Settings, secrets, viewer records and history live in your own folders.
- One check-in, for updates A release build asks our server whether a newer version exists, and downloads it only if you choose.
- Crash reports only if you opt in Release builds send nothing to Sentry unless you turn crash reporting on. Development builds always do.
- Viewer records are yours They're stored only on your machine. You decide what to keep, and you can delete it at any time.
- Straight to your services Twitch, OBS, Discord and the rest talk to the app directly. We don't sit in the middle.
A plain-language summary to help you find your way. The full text below is what applies.
Privacy Policy
This policy is published by Steven Crothers ("we", "us"), the developer of CroStream. It covers two things: this website (crostream.io) and the CroStream desktop app. Questions go to contact@crostream.io.
The short version: CroStream keeps your stream on your computer. It has no accounts. A release build contacts us only to ask whether a newer version is available and, if you choose to install one, to download it. It never sends usage statistics or the contents of your stream, and it sends crash reports and diagnostic logs to Sentry only if you turn crash reporting on, for example so we can help with a problem. A development build always sends crash reports and diagnostic logs to Sentry so we can fix that build. The Discord login that allows local RPC stays on your computer. We do not keep a copy of it. Everything else the app sends goes directly to Twitch and the other services you connect.
1This website¶
crostream.io is a static documentation site. It has no accounts, forms, comments or advertising, and we set no cookies. The site is dark only. It does not offer a theme choice and does not save one.
The site is served by Cloudflare. Like any web host, Cloudflare processes your IP address and request details to deliver pages and protect the service, and may keep standard server logs. We do not receive these logs as personal data tied to you. See the Cloudflare privacy policy.
We use Cloudflare Web Analytics
to count visits and see how fast pages load. When a page loads, a small
script from Cloudflare (static.cloudflareinsights.com) reports to
Cloudflare the page's address (without any query string), the site that
linked you to it, your browser, operating system and type of device, and
how long the page took to load. Cloudflare works out your country from the
connection. Cloudflare states that Web Analytics does not use cookies or
local storage and does not fingerprint visitors by IP address, browser
details or other data. What we see are totals, such as visits per page,
referrer and country, not individual visitors. Cloudflare keeps the
detailed reports for 7 days, then keeps only a sample of about 10% of
them; we can view the last six months. We do not combine this with other
data and do not use it for advertising. A content blocker that stops the
script does not affect the site. See the
Cloudflare privacy policy.
If we add forms or accounts, we will update this policy first.
2The CroStream desktop app¶
Release builds and development builds¶
A release build is the app you install from the download page, on the Stable or Beta channel. A development build is a test build. The app marks it Development build next to its version number. The two builds do not send the same things.
Version checks¶
The app asks a server we operate whether a newer version is available.
On a release build, with Check for updates automatically on (the default), that check runs shortly after the app starts and then about every 6 hours while it runs. Turn automatic checks off in Settings → Updates and the app checks only when you click Check now. Check now always contacts the server.
The request tells the server the version you are running and the channel you selected, Stable or Beta, so it can answer. As with any connection, the server sees the IP address of the computer that asked. A new version is sometimes offered to some installations before it is offered to everyone. The answer is used to tell you an update exists. We do not use the check to record what you stream, who watches, or how you use the app.
Nothing installs by itself. If you click Install and restart, the app downloads that update from our server and checks its signature on your computer before it installs. The download request identifies the version being fetched, and the server sees the IP address of the computer that downloads it.
A development build does not check on its own. It checks only when you click Check now, and it will not download or install an update. A build that says Updates aren't set up in this build does not contact the update server. In browser mode, updates are installed by the CroStream desktop app, and the Updates panel says so.
Crash reports and Sentry¶
The app can send crash reports and diagnostic logs to Sentry (Functional Software, Inc.), a service that receives them over the internet and stores them for us to read. See the Sentry privacy policy.
- A development build always sends them. Crash reporting cannot be turned off in a test build; that is what it is for.
- A release build sends them only if you turn crash reporting on. It is off by default, and while it is off a release build sends nothing to Sentry or to us. You might turn it on to help us track down a problem you have reported. You can turn it off again at any time; from then on nothing more is sent.
A crash report is the failure itself: the error, the stack trace, the build version, and the operating system it was running on, plus the diagnostic detail Sentry attaches to that kind of event. Diagnostic logs are the messages the app writes about what it was doing. Those messages are about the app. A log line can include text the app recorded while handling an error.
While crash reporting is off on a release build, its logs stay on your computer.
We use crash reports and diagnostic logs to fix problems in CroStream and to help you with problems you report. We do not sell them and we do not use them to advertise. To ask us to delete a report Sentry still holds, email contact@crostream.io.
What the app stores on your computer¶
Everything the app keeps is stored in your own config and state folders (see Settings, secrets and files for locations):
- Settings (
config.json): your triggers, actions, overlays and integration settings. - Secrets: your Twitch login token and your OBS password, in a
secrets/folder readable only by your user account. The app does not store a Twitch client secret, and it does not store a Discord login. - Viewer records (
viewers.db): for people who chat or interact in your channel, the app can keep their Twitch user ID, login and display name, earlier names, role, first and last seen times, watch time, points and the history of how they changed, activity, and optionally their chat messages. - History (
history.db): a log of chat, events (follows, bits, raids and so on) and what your triggers did in response. - Media and caches: files you add to the media library, fonts and emote images the app downloaded, and backups of your settings and viewer data.
- Logs: diagnostic messages written on your computer. On a release build they stay there unless you turn crash reporting on. On a development build they are always also sent to Sentry, as described above.
Viewer data is yours to manage¶
The records about your chatters are stored only on the streamer's machine. We never receive them as part of a version check, and they are not part of a crash report, although a diagnostic log line can include text the app was handling when an error happened (see Crash reports and Sentry). The streamer using CroStream decides what to keep and is responsible for that data, including telling their community about it where the law requires, answering requests from viewers, and following Twitch's rules for developer and user data. CroStream gives you tools to delete a viewer, clear history and limit how long chat text is kept.
Discord login¶
CroStream logs in to Discord so the Discord desktop app will allow local access to Discord RPC on that computer. RPC is the local connection CroStream uses to set the status on your profile, such as Watching CroStream, with the title, category, timer and buttons you configure.
That login stays on your computer, in the Discord app. We do not receive it, we do not store it on our servers, and CroStream does not write it into its own files. What crosses the local connection is the activity you set. The Discord app on that computer is what shows it on your profile, under Discord's own privacy policy.
Services the app talks to¶
The app connects directly from your computer to the services below. For Twitch, OBS, Discord, Steam, fonts and web requests, we do not sit in the middle. The update server is ours. Sentry receives data from a development build, and from a release build only if you turned crash reporting on. Each other service has its own privacy policy.
| Service | Why | What is sent | Policy |
|---|---|---|---|
| Our update server | Ask whether a newer version exists, and download it if you choose to install | The version you are running, the Stable or Beta channel, and, for a download, which update is being fetched. The server sees the IP address of the request | This policy |
| Sentry (always on development builds; on release builds only if you turn crash reporting on) | Read crash reports and diagnostic logs, to fix problems and help with ones you report | The crash or log text, the build version, the operating system, and the diagnostic detail attached to that event | Sentry privacy policy |
| Twitch (login, API, chat and event feed) | Log in, read chat and channel events, run your actions (chat, moderation, polls, clips and so on) | Your login token and the requests you configure; Twitch returns chatter names, IDs and events | Twitch Privacy Notice |
| Twitch emote CDN | Show emotes in the app and overlays | Emote IDs | Twitch Privacy Notice |
| OBS Studio | Control scenes, sources and recording | Commands and your OBS password, to the OBS instance you choose (default localhost:4455) |
OBS Project |
| Discord | Log in so the Discord app allows local RPC, then set your status | The login stays on your computer. We do not receive or store it. The activity text and images you configure go to the Discord app on that computer, which shows them on your profile | Discord Privacy Policy |
| Steam | Show game art, avatar and screenshots | Nothing is sent; the app reads files from your local Steam folder | Steam Privacy Policy |
| Fontsource and jsDelivr | Font picker and downloads | Font names requested; your IP address is visible to them | Fontsource, jsDelivr |
| Web addresses you configure | The "Send a web request" action | Whatever you put in the request, which can include viewer names or chat text | Set by that site |
Overlays and the web interface open only on your own computer (loopback
address) unless you choose to expose them. Twitch login uses a local callback
on localhost:62689. If you run browser mode on a network address, the
interface has no login, so only do so on a network you trust.
Twitch permissions¶
When you log in, the app asks Twitch for permissions covering chat, channel points, clips, followers, bits, ads, hype trains, moderation, channel management (title, category, polls, predictions, raids, VIPs, moderators) and reading the chatter list for watch time. You can see what is granted on the app's Twitch page and revoke access at any time in your Twitch connections settings.
3Retention and deletion¶
The app keeps data on your computer until you delete it.
- Delete a viewer, clear history, or set a chat-text retention period in the app.
- To remove everything stored locally, quit the app and delete its config and state folders. Locations per operating system are listed in Settings, secrets and files.
- Log out of Twitch in the app, and revoke the app in your Twitch connections settings, to invalidate the login token.
- The Discord login for local RPC is not held by us. Remove CroStream from the Discord app on that computer to revoke it.
- Copies you made yourself (exports, backups) stay until you delete them.
A version check is used to answer whether an update is available. We do not add it to a profile of how you use CroStream. The server may keep ordinary operational logs of the request, including the IP address, the way a web server keeps logs.
Crash reports and diagnostic logs sent to Sentry are stored by Sentry under Sentry's retention. Turning crash reporting off stops new reports; it does not remove ones already sent. Email contact@crostream.io and we will delete what we can still reach.
4Children¶
The website and app are not directed at children under 13 (or the higher age required in your country). Twitch requires its users to meet its own minimum age, and the app relies on your Twitch account. We do not knowingly collect information from children. A version check describes the installation. A crash report describes a crash or a log line. If you believe either includes information about a child, contact us and we will delete it.
5Changes¶
We may update this policy. The effective date above shows the latest version, and material changes will be noted on this page.
6Contact¶
Steven Crothers, contact@crostream.io. Your rights under privacy law (access, deletion and so on) depend on the laws of the United States, unless the law where you live requires otherwise.
Requests about viewer records stored by CroStream go to the streamer who runs the app, because those records stay on that computer. Requests about a version check, or about a crash report or log the app sent to Sentry, come to us.