XFrame Live

Legal

Privacy Policy

This Privacy Policy explains how XFrame Live (“the App,” “we,” “us”) handles information when you use the Android application and the website xframelive.com (together, the “Service”).

We designed XFrame Live so that most streaming work happens on your device and with the platforms you choose. We do not operate a separate XFrame Live user-account database for your streams, and we do not sell personal information.

1. Who is responsible

XFrame Live is operated for the XFrame Live project. For privacy questions or requests:

2. What this App does

XFrame Live captures camera and microphone on your phone and can broadcast live to destinations you configure (Twitch, Kick, YouTube, or a custom RTMP/RTMPS server). Optional features include dual camera / picture-in-picture; live chat on the phone and on the stream; stream overlays you compose (text, scrolling text, browser sources, and images); Pro live-data overlays (speed, clock, steps, distance goal, on-stream chat, and a GPS map); local recording; background capture while streaming; on-device AI denoise (Pro); optional Disconnect Protection via XFrame relay servers (including a custom hold still or short loop); and Google Play purchases.

3. Information we process

3.1 Device permissions & capture

3.2 Credentials you connect (stored on device)

If you connect Twitch, Kick, YouTube (Google), or enter a custom RTMP URL and stream key, related tokens, keys, and settings are stored locally on your device so you can go live. Protect your device; never share stream keys. Disconnecting a platform in Settings removes that connection from the App’s local storage.

3.3 Google / YouTube access

When you connect YouTube, XFrame Live uses Google Sign-In / OAuth to obtain access needed to help you create and manage a YouTube live broadcast (for example ingest URL / stream key, binding a broadcast, and transitioning it live). That access is used only to provide the YouTube streaming features you request.

XFrame Live’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, and we do not use it for advertising or unrelated AI/ML training. You can disconnect YouTube in the App and revoke access in your Google Account permissions.

3.4 Purchases, Pro, and add-ons

Pro features (such as multistream, Custom RTMP, dual camera PiP, 2K / 4K, AI Denoise, and the live-data overlays) may require a Google Play subscription (monthly, half-year, or yearly). Text, scrolling text, browser, and image overlays stay on the Free tier. Disconnect Protection is a separate monthly add-on and is not included in Pro. Payments are processed by Google Play Billing. We receive purchase/entitlement status needed to unlock features; payment card details are handled by Google, not by us.

3.5 Overlays, images & live data

Overlay text, positions, sizes, colors, image files you pick, and any browser-source web address you add are stored locally on your device with your other settings. They are not uploaded to us, except a custom Disconnect Protection still or loop you choose (see 3.9).

An image overlay uses the system photo picker. The App does not request gallery-wide photo access. The picture you pick is kept on device and drawn into your outgoing stream.

A browser source loads the web address you enter inside the App so it can be drawn over your video. That page is fetched directly from the site you chose, so — exactly as in a normal browser — that site can see your IP address, approximate location derived from it, and anything its own scripts or cookies collect. Its content is rendered on your device and composited into your outgoing stream. We do not proxy, log, or inspect that traffic. Only add sources you trust, and review that site’s privacy policy.

Live-data overlays (Pro) draw changing values on the stream: speed, clock, steps, distance toward a goal, on-stream chat, and a GPS mini-map. Those readings are computed on your device and leave it only as pixels in the video you send to destinations you choose — not as a separate location or fitness feed to XFrame Live.

3.6 Location, map tiles & steps

If you enable speed, distance goal, map, or a clock with sunrise/sunset, the App reads precise location while the App is in use so those overlays can update. Location is not requested to open the camera, and it is not used in the background. We do not upload your coordinates, routes, or a location history to XFrame Live servers.

The map overlay downloads nearby street tiles from CARTO (OpenStreetMap data) so the mini-map can be baked into your broadcast. Those tile requests include the map area you are in (and your IP address, as any website request does). Attribution (“© OpenStreetMap © CARTO”) is drawn on the overlay. CARTO’s processing is described in CARTO’s privacy policy.

The step counter reads the phone’s pedometer when you add that overlay. The count stays on the device except as drawn on your stream. We do not store a step history on our servers.

3.7 On-device AI Denoise

If you enable AI Denoise (Pro), microphone audio is processed on your device in real time to reduce background noise before encoding. This processing is for the live stream / recording path you control. We do not upload your mic audio to an XFrame Live cloud for model training. Denoised (or raw) audio still leaves your device only as part of the stream or file you send to destinations you choose.

3.8 Live chat & audience

If you connect a platform, the App can fetch chat messages and viewer / follower counts from that platform’s APIs so you can see them on the phone HUD and, if you enable it, draw chat on the outgoing stream. Those requests go to Twitch, Kick, or YouTube / Google — not to an XFrame Live chat server. We do not store your chat history or audience numbers on our servers. Chat you put on the stream is part of the video those platforms (and their viewers) receive.

3.9 Disconnect Protection hold stills

If Disconnect Protection is on, your live video and audio are sent to XFrame relay servers for that session (see section 6). You may also choose a custom “be right back” still (JPEG) or a short loop (MP4). That file lives on your device until you go live with protection on; then it is uploaded to the relay for that session only, so viewers see it if your phone drops. We process it in real time to hold the destination stream. We do not keep a VOD library of your streams or hold stills after the session ends.

3.10 Analytics

The App uses Google Analytics for Firebase to understand which features are used and to measure Google Ads conversions (for example connecting a platform, going live, starting a trial, or completing a Play purchase). That SDK may read the device’s Advertising ID and send event names plus coarse parameters such as platform (twitch / kick / youtube), whether AI Denoise or Disconnect Protection was on, and overlay kind ids (for example map or streamChat).

We do not send chat text, GPS coordinates, stream keys, destination URLs, account names, or overlay wording to Analytics. You can reset or limit the Advertising ID in Android settings. Google’s processing is described in Google’s privacy policy.

3.11 Website, newsletter & Discord

Our marketing website may receive standard server or hosting logs (for example IP address, browser type, and pages requested) as operated by our hosting provider.

If you subscribe to the newsletter, your email address is sent to Mailchimp (Intuit) so we can send product updates. You can unsubscribe from any email, or write support@xframelive.com. Mailchimp’s processing is described in Mailchimp’s privacy policy.

If you join our Discord community, that use is between you and Discord. We do not require a Discord account to use the App. See Discord’s privacy policy.

4. Why we process information (purposes)

5. Legal bases (EEA / UK and similar)

Where applicable privacy laws require a legal basis, we rely on:

6. Where data goes (third parties)

By default we do not host your live video. When you go live or use chat, audience, map, analytics, or newsletter features, data is processed by the parties below, under their own terms and privacy policies:

Google also processes OAuth and Play Billing under Google’s policies.

7. Retention

8. Security

We use reasonable technical measures appropriate for a mobile client (including on-device credential storage practices and HTTPS for API calls). No method of transmission or storage is 100% secure. You are responsible for securing your phone and stream keys.

9. Children

The Service is intended for users 13+ (or the higher digital-consent age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child provided information, contact us and we will take appropriate steps.

10. Your choices & rights

You can:

Depending on where you live (for example EEA, UK, California), you may also have rights to access, correct, delete, or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise rights regarding information we hold (such as support email content), contact support@xframelive.com. We may need to verify your request. Because most App data stays on your device, many requests are fulfilled by using in-App controls or clearing App data.

California: We do not “sell” or “share” personal information as those terms are commonly defined under the CCPA/CPRA for cross-context behavioral advertising.

11. International users

The App is used globally. Third-party platforms you connect may process data in other countries. Use of those platforms is subject to their rules and transfer mechanisms.

12. Changes

We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes may also be noted on xframelive.com. Continued use after an update means you accept the revised Policy.

13. Contact

Privacy questions: support@xframelive.com