Privacy policy
This policy covers the Cx Live Android app, the website at cx-live.com and the API at api.cx-live.com (together, "Cx Live"). Questions and requests go to privacy@cx-live.com.
What we collect
Your Kick account
You sign in with Kick. We store your Kick user ID, username, display name, avatar URL and the stream title you last set in the app. We store the Kick access and refresh tokens that Kick issues, encrypted, so the app can read and post chat, moderate, manage rewards and edit your channel on your behalf. We never see your Kick password.
Things you create
Custom chat commands, overlay scenes, images you upload to scenes, the people you allow to manage your scenes, and remote-camera device names and pairings.
Linked services
If you link IRLToolkit, we store your IRLToolkit account ID, display name, username, email address and encrypted tokens. If you link Streamable, we store encrypted Streamable tokens. We use these only to list and configure your ingests for you.
Stream diagnostics
While you stream, the app sends technical measurements: bitrate, frame rate, resolution, packet loss, round-trip time, network type and link count, camera and zoom in use, battery level and temperature, charging and power-saving state, thermal state, CPU use, app version, Android version and device model. It also sends the stream settings you used, with stream keys, passwords and ingest credentials removed. If you stream while signed out, these are tied to a random install ID instead of an account.
The app reports errors and crashes. Error reports include the app version, device model, Android version, your IP address and user agent. Crash reports contain the crashed program state and no account details. If you choose to send a diagnostic log from the app, we store it with credentials removed.
Security data
We use IP addresses to rate-limit requests and to block abusive clients.
Public chat
For channels that use Cx Live chat commands, we receive and archive the channel's public Kick chat events (messages, usernames and badges) to run commands and to diagnose problems. This is chat that is already public on Kick.
What stays on your phone
Camera and microphone: the app captures video and audio only to send your stream to the destination you configure (for example your RTMP, SRT or SRTLA server). Cx Live servers do not receive or record your stream. Remote camera video is relayed peer-to-peer or through Cloudflare Realtime between your own paired devices and is not stored.
Phone state permission: used only on the device to find your SIM cards so the app can bond more than one mobile connection. No phone number, SIM or call data leaves the device.
Screen capture: used only when you choose to stream your screen, and sent only to your own destination.
App settings, stream destinations and stream keys are stored on your phone and are not backed up to us. Text-to-speech runs on the device using your installed speech engine.
How we use it
- To run the features you use: sign-in, chat, moderation, rewards, overlays, remote camera.
- To find and fix streaming problems and crashes.
- To keep the service secure and prevent abuse.
We do not sell your data, show ads, or use your data for advertising or profiling.
Who we share it with
- Kick: requests you make through the app go to Kick using your Kick tokens.
- IRLToolkit and Streamable: only if you link them.
- Cloudflare: hosts our website, API, database and file storage, and relays remote-camera video.
- Our own servers: an emote image proxy and the chat event archive run on a server we operate.
We share data with anyone else only when the law requires it.
How long we keep it
- Sign-in sessions: up to 60 days after they are created.
- Error reports and stream measurements: 30 days.
- Rate-limit records: 1 hour. Abuse blocks: 30 days after the last offence.
- Account data, things you create, linked accounts, stream settings history and diagnostic logs: until you delete your account.
Deleting your account
You can delete your account and its data at any time:
- In the app: open settings and choose Delete account.
- On the web: sign in and go to cx-live.com/me/account.
- By email: write to privacy@cx-live.com from any address and tell us your Kick username.
Deletion is immediate and removes your account, sessions, tokens, chat commands, scenes and uploads, scene manager access, linked IRLToolkit and Streamable accounts, remote-camera pairings, stream measurements and settings history, error reports tied to your account and your diagnostic logs. It also cancels the Kick event subscriptions the app created. Data that was never tied to your account (crash reports, telemetry sent while signed out, public chat archives) is not linked to you and expires or stays as described above. Deleting your Cx Live account does not delete your Kick account.
Children
Cx Live is not directed at children under 13, and we do not knowingly collect their data.
Security
All traffic uses HTTPS. OAuth tokens are encrypted at rest. Stream keys and passwords are stripped from anything the app sends us.
Changes
We will update the date above when this policy changes, and tell you in the app for significant changes.