Legal
Privacy Policy
Last updated: September 21, 2026
This Privacy Policy explains how XFrame Live (“the App,” “we,” “us”) handles information when you use the Android application and the website xframelive.com (together, the “Service”).
We designed XFrame Live so that most streaming work happens on your device and with the platforms you choose. We do not operate a separate XFrame Live user-account database for your streams, and we do not sell personal information.
1. Who is responsible
XFrame Live is operated for the XFrame Live project. For privacy questions or requests:
- Email: support@xframelive.com
- Website: https://xframelive.com
2. What this App does
XFrame Live captures camera and microphone on your phone and can broadcast live to destinations you configure (Twitch, Kick, YouTube, or a custom RTMP/RTMPS server). Optional features include dual camera / picture-in-picture; live chat on the phone and on the stream; stream overlays you compose (text, scrolling text, browser sources, and images); Pro live-data overlays (speed, clock, steps, distance goal, on-stream chat, and a GPS map); local recording; background capture while streaming; on-device AI denoise (Pro); optional Disconnect Protection via XFrame relay servers (including a custom hold still or short loop); and Google Play purchases.
3. Information we process
3.1 Device permissions & capture
- Camera — video for preview, live stream, and optional local recording (including dual-camera / PiP where the device allows).
- Microphone — audio for streaming and recording, including built-in, USB, and Bluetooth microphones when selected.
- Network / Internet — to send your stream, refresh ingest keys, load chat/audience stats where supported, and talk to Google Play / OAuth providers.
- Notifications & foreground service — Android may require a persistent notification while you stream or record so capture can continue reliably.
- Photos / media (optional) — when you save or access local recordings on your device.
- Nearby devices / Bluetooth (as needed) — to discover or route to wireless microphones on supported Android versions.
- Location (optional, foreground only) — asked only when you turn on a live-data overlay that needs it (speed, distance goal, map, or a clock that shows sunrise/sunset). The App does not request background location.
- Physical activity (optional) — asked only when you add the step-counter overlay. The count is read from the phone’s sensor on device.
- Advertising ID — used by Google’s analytics / ads libraries so we can measure installs and in-app conversions. See section 3.10.
3.2 Credentials you connect (stored on device)
If you connect Twitch, Kick, YouTube (Google), or enter a custom RTMP URL and stream key, related tokens, keys, and settings are stored locally on your device so you can go live. Protect your device; never share stream keys. Disconnecting a platform in Settings removes that connection from the App’s local storage.
3.3 Google / YouTube access
When you connect YouTube, XFrame Live uses Google Sign-In / OAuth to obtain access needed to help you create and manage a YouTube live broadcast (for example ingest URL / stream key, binding a broadcast, and transitioning it live). That access is used only to provide the YouTube streaming features you request.
XFrame Live’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, and we do not use it for advertising or unrelated AI/ML training. You can disconnect YouTube in the App and revoke access in your Google Account permissions.
3.4 Purchases, Pro, and add-ons
Pro features (such as multistream, Custom RTMP, dual camera PiP, 2K / 4K, AI Denoise, and the live-data overlays) may require a Google Play subscription (monthly, half-year, or yearly). Text, scrolling text, browser, and image overlays stay on the Free tier. Disconnect Protection is a separate monthly add-on and is not included in Pro. Payments are processed by Google Play Billing. We receive purchase/entitlement status needed to unlock features; payment card details are handled by Google, not by us.
3.5 Overlays, images & live data
Overlay text, positions, sizes, colors, image files you pick, and any browser-source web address you add are stored locally on your device with your other settings. They are not uploaded to us, except a custom Disconnect Protection still or loop you choose (see 3.9).
An image overlay uses the system photo picker. The App does not request gallery-wide photo access. The picture you pick is kept on device and drawn into your outgoing stream.
A browser source loads the web address you enter inside the App so it can be drawn over your video. That page is fetched directly from the site you chose, so — exactly as in a normal browser — that site can see your IP address, approximate location derived from it, and anything its own scripts or cookies collect. Its content is rendered on your device and composited into your outgoing stream. We do not proxy, log, or inspect that traffic. Only add sources you trust, and review that site’s privacy policy.
Live-data overlays (Pro) draw changing values on the stream: speed, clock, steps, distance toward a goal, on-stream chat, and a GPS mini-map. Those readings are computed on your device and leave it only as pixels in the video you send to destinations you choose — not as a separate location or fitness feed to XFrame Live.
3.6 Location, map tiles & steps
If you enable speed, distance goal, map, or a clock with sunrise/sunset, the App reads precise location while the App is in use so those overlays can update. Location is not requested to open the camera, and it is not used in the background. We do not upload your coordinates, routes, or a location history to XFrame Live servers.
The map overlay downloads nearby street tiles from CARTO (OpenStreetMap data) so the mini-map can be baked into your broadcast. Those tile requests include the map area you are in (and your IP address, as any website request does). Attribution (“© OpenStreetMap © CARTO”) is drawn on the overlay. CARTO’s processing is described in CARTO’s privacy policy.
The step counter reads the phone’s pedometer when you add that overlay. The count stays on the device except as drawn on your stream. We do not store a step history on our servers.
3.7 On-device AI Denoise
If you enable AI Denoise (Pro), microphone audio is processed on your device in real time to reduce background noise before encoding. This processing is for the live stream / recording path you control. We do not upload your mic audio to an XFrame Live cloud for model training. Denoised (or raw) audio still leaves your device only as part of the stream or file you send to destinations you choose.
3.8 Live chat & audience
If you connect a platform, the App can fetch chat messages and viewer / follower counts from that platform’s APIs so you can see them on the phone HUD and, if you enable it, draw chat on the outgoing stream. Those requests go to Twitch, Kick, or YouTube / Google — not to an XFrame Live chat server. We do not store your chat history or audience numbers on our servers. Chat you put on the stream is part of the video those platforms (and their viewers) receive.
3.9 Disconnect Protection hold stills
If Disconnect Protection is on, your live video and audio are sent to XFrame relay servers for that session (see section 6). You may also choose a custom “be right back” still (JPEG) or a short loop (MP4). That file lives on your device until you go live with protection on; then it is uploaded to the relay for that session only, so viewers see it if your phone drops. We process it in real time to hold the destination stream. We do not keep a VOD library of your streams or hold stills after the session ends.
3.10 Analytics
The App uses Google Analytics for Firebase to
understand which features are used and to measure Google Ads
conversions (for example connecting a platform, going live, starting a
trial, or completing a Play purchase). That SDK may read the
device’s Advertising ID and send event names plus
coarse parameters such as platform
(twitch / kick / youtube),
whether AI Denoise or Disconnect Protection was on, and overlay
kind ids (for example map or
streamChat).
We do not send chat text, GPS coordinates, stream keys, destination URLs, account names, or overlay wording to Analytics. You can reset or limit the Advertising ID in Android settings. Google’s processing is described in Google’s privacy policy.
3.11 Website, newsletter & Discord
Our marketing website may receive standard server or hosting logs (for example IP address, browser type, and pages requested) as operated by our hosting provider.
If you subscribe to the newsletter, your email address is sent to Mailchimp (Intuit) so we can send product updates. You can unsubscribe from any email, or write support@xframelive.com. Mailchimp’s processing is described in Mailchimp’s privacy policy.
If you join our Discord community, that use is between you and Discord. We do not require a Discord account to use the App. See Discord’s privacy policy.
4. Why we process information (purposes)
- Provide live streaming, recording, chat, stream overlays (including live-data overlays), and related features;
- Authenticate to platforms you connect and manage ingest / broadcasts;
- Process and restore Pro and add-on purchases via Google Play;
- If you enable Disconnect Protection, forward your live session through XFrame relay servers for that session (including a short hold and any custom still or loop you upload for that session);
- Fetch map tiles around you when the map overlay is on, so the mini-map can be drawn on your stream;
- Keep capture running safely while the App is backgrounded during a live session;
- Measure product use and advertising conversions with Firebase Analytics;
- Send the newsletter if you subscribe;
- Respond to support requests you send us;
- Comply with law and enforce our Terms of Service.
5. Legal bases (EEA / UK and similar)
Where applicable privacy laws require a legal basis, we rely on:
- Contract / requested service — providing the App features you use (streaming, OAuth connections, billing unlocks);
- Consent — device permissions (camera, microphone, location, activity, notifications) and optional connections you approve;
- Legitimate interests — securing the Service, basic website operations, and measuring how the App is used (including advertising conversions) in ways that do not override your rights;
- Legal obligation — when we must retain or disclose information to comply with law.
6. Where data goes (third parties)
By default we do not host your live video. When you go live or use chat, audience, map, analytics, or newsletter features, data is processed by the parties below, under their own terms and privacy policies:
- Twitch, Kick, YouTube / Google, and/or
- any custom RTMP/RTMPS server you enter,
- any website you load as a browser-source overlay, which your device contacts directly,
- XFrame relay servers, only if you turn on Disconnect Protection. In that case your live video and audio — and any custom hold still or loop you chose — are sent to our relay for the duration of the session, including up to a few minutes of hold if your phone drops, so we can keep the destination stream alive. We process that media in real time to forward it. We do not offer stored VOD of your stream on our servers.
- CARTO, if you enable the map overlay, for nearby street tiles,
- Google (Firebase Analytics), for the events described in 3.10,
- Mailchimp, if you subscribe to the newsletter,
- Discord, if you join the community server.
Google also processes OAuth and Play Billing under Google’s policies.
7. Retention
- On device: settings, tokens, overlay images, custom hold stills, and recordings remain until you change/delete them, clear App data, or uninstall.
- Relay sessions: live media and any uploaded hold still exist only for the active Disconnect Protection session.
- Analytics: Firebase / Google retain events under Google’s retention settings for that project.
- Newsletter: your email stays on the Mailchimp list until you unsubscribe or we delete it.
- Support emails: kept only as long as needed to resolve your request and for ordinary business records.
- Platforms: retention of your live VODs, chat, and analytics is controlled by those platforms, not by XFrame Live.
8. Security
We use reasonable technical measures appropriate for a mobile client (including on-device credential storage practices and HTTPS for API calls). No method of transmission or storage is 100% secure. You are responsible for securing your phone and stream keys.
9. Children
The Service is intended for users 13+ (or the higher digital-consent age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child provided information, contact us and we will take appropriate steps.
10. Your choices & rights
You can:
- Deny or revoke Android permissions in system settings (including location, activity, and Advertising ID);
- Turn off live-data overlays so location, steps, and map tiles stop;
- Disconnect platforms and clear destinations in App Settings;
- Delete local recordings, overlay images, and custom hold stills from your device;
- Manage or cancel Play subscriptions in Google Play;
- Unsubscribe from the newsletter via any email or by writing to us;
- Uninstall the App to remove local App data (subject to Android behavior).
Depending on where you live (for example EEA, UK, California), you may also have rights to access, correct, delete, or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise rights regarding information we hold (such as support email content), contact support@xframelive.com. We may need to verify your request. Because most App data stays on your device, many requests are fulfilled by using in-App controls or clearing App data.
California: We do not “sell” or “share” personal information as those terms are commonly defined under the CCPA/CPRA for cross-context behavioral advertising.
11. International users
The App is used globally. Third-party platforms you connect may process data in other countries. Use of those platforms is subject to their rules and transfer mechanisms.
12. Changes
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes may also be noted on xframelive.com. Continued use after an update means you accept the revised Policy.
13. Contact
Privacy questions: support@xframelive.com
This Policy is provided for transparency. It is not formal legal advice. If you need jurisdiction-specific counsel, consult a qualified attorney.