Privacy Policy

Last updated: June 2026

Overview

SheevChat is a free Windows desktop application that aggregates live chat, events, moderation tools, bot commands, loyalty features, text-to-speech, and OBS browser sources for Twitch, YouTube, Kick, TikTok, and Spotify into a single unified interface.

SheevChat is local-first: SheevChat does not operate a database or backend that stores your account data, chat history, credentials, or activity. The only thing that ever touches a SheevChat-operated server is a short-lived, one-time handshake token used to complete sign-in — and that token is deleted automatically within minutes, whether or not it's claimed. Everything else — your OAuth tokens, settings, points, watchtime, quotes, counters, exports, and any other durable data — is stored exclusively on your own device.

This policy explains exactly what is stored locally, what passes through our infrastructure in transit, and your rights as a user.

What's Stored Locally

Depending on which features you use, SheevChat may store the following on your device, under your operating system's application-data directory (AppData\Roaming\SheevChat\ on Windows):

  • config.json — app preferences, OAuth access/refresh tokens, connected platform and bot-account identifiers, OAuth scope version, integration settings, and (if you use migration tools) your StreamElements JWT and Account ID.
  • sheevchat.db (SQLite) — viewer records, usernames, loyalty point balances and history, watchtime and presence state, quotes, counters and their audit history, giveaway data, and moderation references created by the app.
  • exports/ — JSON/CSV files you generate, and data downloaded through migration tools.
  • models/ — optional local text-to-speech models (Piper, Kokoro) if you choose to install them.
  • tts-cache/ — locally generated speech audio from local TTS engines.
  • User-selected alert sounds and other local assets you add.
  • Local UI preferences such as your recent-emote list.
  • Application/updater logs, where enabled.

None of this is transmitted to or stored on any SheevChat-operated server. It exists only on your computer until you delete it, reset a feature, clear credentials, or remove the application data folder. Anyone with access to your operating system account, device, or backups could potentially read these files, so OAuth tokens and any migration credentials (StreamElements JWT, Streamlabs session values) should be treated as sensitive — do not share them with anyone, including people claiming to be SheevChat support.

What Touches SheevChat's Servers

SheevChat operates one piece of server-side infrastructure: a Cloudflare Worker OAuth relay at auth.sheevchat.com. Its only job is to complete the OAuth handshake for each platform without embedding platform Client Secrets in the distributed app. Full detail in the "OAuth Authentication & The Auth Relay" section below. Outside of that relay, SheevChat does not operate any database, analytics service, or backend that stores your data. No analytics, telemetry, crash reporting, or usage tracking SDKs are bundled with the app.

Twitch API Data

SheevChat requests a broad set of Twitch scopes covering chat (reading and sending), channel and account information, subscriptions, bits, redemptions, hype trains, polls, predictions, goals, charity events, VIPs, ads, followers, and chatters; moderation data and actions including bans, timeouts, AutoMod, blocked terms, chat settings, shield mode, warnings, and announcements; and channel management including moderators, VIPs, raids, and limited broadcast/commercial actions. The exact scopes are shown on Twitch's authorization screen when you connect.

This data is never transmitted to a SheevChat-operated server beyond the transient OAuth relay, and is never sold or shared with third parties. SheevChat supports connecting a separate bot account in addition to your broadcaster account; both are subject to the same handling described here.

Google API Data

SheevChat's use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data Accessed. SheevChat requests the following Google API scopes:

  • youtube.readonly — used to identify your active YouTube livestream, retrieve the live chat ID, and read live chat messages including message text, author display names, member/moderator status, super chat and super sticker amounts, membership events, and author badges via the YouTube Data API v3.
  • youtube.force-ssl — used to send chat messages to your active YouTube livestream on your behalf, perform moderation actions (timeouts, bans, message deletion), manage moderators, and update the active stream's title and category. Messages are only sent when you manually type and explicitly submit them; moderation and metadata actions only occur when you explicitly trigger them.
  • openid profile email — used to retrieve your Google account display name and email address for display in the app's connected account indicator.

Data Usage. Google user data accessed by SheevChat is used solely to provide the live chat aggregation, moderation, and participation features of the application. Your livestream and chat data is fetched in real-time and displayed locally within the app. Your display name and email are stored locally to show "Connected as [name]". No Google user data is used for advertising, analytics, profiling, or any purpose beyond the functionality described above.

Data Sharing. SheevChat does not share, sell, transfer, or disclose Google user data to any third party. Data retrieved from Google APIs is used only within the application on your local device. It is not transmitted to any SheevChat-operated server, and is not shared with any analytics, advertising, or data broker services.

Data Storage & Protection. Google OAuth tokens (access token and refresh token) are stored locally on your device at AppData\Roaming\SheevChat\config.json. They are never permanently stored on any SheevChat-operated server. All communication between SheevChat and Google APIs occurs over HTTPS. During the OAuth login flow, tokens pass through the secure relay at auth.sheevchat.com for a maximum of 5 minutes before being claimed by your device and permanently deleted from the relay.

Data Retention & Deletion. Google user data (tokens and display name) is retained locally until you disconnect your YouTube account within SheevChat, or manually delete the config file. Live chat messages are never stored — they are displayed in real-time and immediately discarded. To revoke SheevChat's access to your Google account at any time, visit myaccount.google.com/permissions.

SheevChat uses YouTube API Services. By using the YouTube integration, you also agree to the YouTube Terms of Service. Google's Privacy Policy explains how Google processes information.

Kick API Data

SheevChat requests Kick scopes covering user and channel information, chat, channel management, channel point rewards, stream key access, event subscriptions, moderation (bans and chat message management), and KICKs-related data. The exact scopes are shown on Kick's authorization screen when you connect.

Some Kick event types are received through a legacy/undocumented connection method and may be unstable or change without notice — this does not affect what SheevChat stores, but availability of certain live events (such as follow notifications) is not guaranteed. Kick data is never transmitted to a SheevChat-operated server beyond the transient OAuth relay, sold, or shared with third parties.

TikTok API Data

SheevChat requests the following TikTok scopes: user.info.basic (returns your TikTok Open ID, a unique anonymous identifier) and user.info.profile (returns your display name and bio description).

SheevChat does not post content, send messages, or perform any actions on TikTok on your behalf. TikTok OAuth data is stored locally on your device and is never transmitted to any SheevChat-operated server beyond the transient OAuth relay. It is never shared with third parties.

TikTok Chat

TikTok live chat is read using an open-source library (tiktok-live-connector) that connects to TikTok's public live stream WebSocket infrastructure. This is the same method used by most TikTok chat reading tools, and is distinct from TikTok's official chat-send API — TikTok chat in SheevChat is receive-only. SheevChat does not store, transmit, or process TikTok chat data beyond displaying it locally in real-time, except that gift events with value information may be used to calculate local loyalty points, which are stored only in your local database. SheevChat cannot send messages or execute bot commands on TikTok.

Spotify API Data

SheevChat requests the following Spotify scopes: user-read-currently-playing (returns the track name, artist, album, artwork URL, and playback progress of the song currently playing), user-read-playback-state (returns the current playback state including device, shuffle, and repeat status), and user-modify-playback-state (allows playback control such as play, pause, skip, and seek). This data is displayed locally in real-time and is never stored, logged, or transmitted anywhere beyond fetching the artwork image itself from Spotify's content delivery network.

Unlike other platforms, Spotify integration in SheevChat requires you to create and own your own Spotify developer app. Your Spotify Client ID and Client Secret belong to you — SheevChat does not own or operate a shared Spotify app on your behalf. These credentials, along with your Spotify access and refresh tokens, are stored exclusively on your local device. They are never transmitted to or stored on any SheevChat-operated server. During the OAuth flow, your Client ID and Client Secret pass through our secure relay only to complete the token exchange, and are immediately discarded — they are not logged or retained in any form.

SheevChat polls the Spotify API at a rate of approximately once every 5 seconds while the overlay is active. Polling stops when the overlay is not in use. No Spotify data is retained between sessions — track information is fetched live and discarded when no longer displayed. SheevChat does not control playback, access your library, playlists, or listening history. Spotify data is never shared with third parties.

To revoke SheevChat's access to your Spotify account at any time, visit spotify.com/account/apps and remove the app, or disconnect Spotify within SheevChat.

StreamElements, Streamlabs, Nightbot & Moobot Migration

SheevChat includes optional, user-initiated tools to migrate loyalty points, commands, quotes, timers, and watchtime data away from StreamElements, Streamlabs, Nightbot, and Moobot. These are one-time export/import tools, not ongoing connected integrations — once your data is imported into SheevChat, no further connection to these services is required or maintained.

StreamElements. The migration tool uses a JWT (authentication token) and Account ID that you supply yourself from your own StreamElements account. SheevChat uses these credentials solely to request your own data from StreamElements' API on your behalf — points, commands, quotes, timers, and watchtime — and saves the results locally as JSON files in your exports/ folder. The JWT and Account ID are saved locally in config.json until you clear them. They are never transmitted anywhere other than StreamElements' own API, and never to any SheevChat-operated server.

Streamlabs. The Streamlabs points export is experimental and uses a session cookie, CSRF token, and browser user-agent value that you supply manually from your own logged-in Streamlabs browser session, against an internal/unofficial endpoint. This method may stop working at any time if Streamlabs changes their site, and carries materially higher risk than an official API integration. Treat your Streamlabs session cookie like a password — anyone with it could access your Streamlabs account. Never share these values with anyone, including people claiming to be SheevChat support; SheevChat will never ask you to send these credentials to us.

Nightbot. The Nightbot migration tool uses Nightbot's OAuth sign-in to request a one-time export of your existing commands, timers, regulars, song request settings, and spam protection rules so they can be imported into SheevChat. The scopes requested are: channel, channel_send, commands, commands_default, regulars, song_requests, song_requests_queue, song_requests_playlist, spam_protection, subscribers, and timers. The resulting token is stored locally and used only to complete the export — SheevChat does not maintain an ongoing connection to your Nightbot account or use it to send messages on your behalf.

Moobot. Migration support for Moobot works the same way as the tools above — a user-initiated, one-time export of your existing commands and related data for import into SheevChat.

Imported data becomes part of your local SheevChat database once you complete the import flow; all migration tools provide a preview before any data is committed.

Local Text-to-Speech & Model Downloads

SheevChat's text-to-speech features can use your operating system's built-in voices, or optional local AI voice engines (Piper and Kokoro) that you may choose to install. Speech generation for all of these happens entirely on your device — no text is sent to any cloud TTS provider.

If you install Piper or Kokoro, SheevChat downloads the selected model/runtime files from third-party hosting providers (such as Hugging Face) directly to your device. These are one-time download requests; the hosting provider receives ordinary network metadata (such as your IP address) for that request, governed by their own privacy policy — see Hugging Face's Privacy Policy. Once installed, models run entirely locally. Kokoro-generated speech audio may be cached locally in tts-cache/ to avoid regenerating identical audio; this cache, like all local data, can be cleared from within the app.

Loyalty Points, Watchtime, Quotes, Counters & Giveaways

If you enable these optional features, SheevChat maintains a local SQLite database recording viewer point balances and history, watchtime/presence estimates, quotes, counters and their audit history, and giveaway entries and results. This data is derived from public chat activity and platform events on channels you control, and is used solely to power these features within your own instance of the app. None of it is transmitted to any SheevChat-operated server. Watchtime is an activity/presence estimate based on chat and connection signals — it is not platform-certified viewing data. Loyalty points have no cash value and exist only within your local SheevChat database.

OAuth Authentication & The Auth Relay

When you connect a streaming platform account, SheevChat uses a secure OAuth relay to exchange an authorization code for tokens. This relay:

  • Temporarily holds your tokens in encrypted server-side storage for a maximum of 5 minutes while your device retrieves them.
  • Permanently and immediately deletes the tokens the moment your device claims them — or after 5 minutes if unclaimed.
  • Does not log tokens at any point.
  • Does not store any personally identifiable information.
  • Exists solely to keep platform Client Secrets out of the distributed app binary, and to avoid transmitting tokens in URLs where they could appear in browser history or server logs.

Token refresh requests (used to silently renew expired access tokens) also pass through the relay, but tokens are not stored during this process — they are returned directly to your device.

After any exchange, tokens are stored only locally on your device. The relay retains nothing. This is the only data processing SheevChat performs server-side — every other category of data described in this policy lives exclusively on your computer.

Auto-Update

SheevChat checks for updates automatically on launch by contacting GitHub's API. This request may expose your IP address to GitHub. No personal data beyond a standard HTTP request is transmitted. See GitHub's Privacy Statement. When new platform permissions are added, SheevChat may require a one-time local sign-out for the affected platform — you will need to reconnect and approve the updated permissions shown on that platform's consent screen.

Emote & Content Providers

SheevChat fetches emote catalogs and images from Twitch, Kick, 7TV, BetterTTV, and FrankerFaceZ to render emotes in chat. These are ordinary read-only network requests; the providers receive standard request metadata such as your IP address and user agent, governed by their own policies. No data is sent to these providers beyond what's needed to retrieve emote images.

Ko-Fi Donations

SheevChat includes an optional Ko-Fi donation prompt. Donations are processed entirely by Ko-Fi — SheevChat and the developer have no access to any payment information. Ko-Fi's own privacy policy applies. See Ko-Fi's Privacy Policy. The donation prompt can be permanently dismissed within the app.

Third-Party Services

SheevChat connects to the following third-party services depending on which features you use. Their own privacy policies govern data they process:

Data Retention & Deletion

SheevChat retains data only as long as necessary to provide the service, and almost everything it retains lives exclusively on your device:

  • OAuth tokens, account identifiers, and migration credentials stored in config.json are retained until you disconnect the relevant platform within the app, clear the credential, or manually delete the file.
  • Loyalty points, watchtime, quotes, counters, and giveaway records in sheevchat.db are retained until you delete, reset, or clear them through the in-app Data Manager.
  • Exported files, downloaded TTS models, and cached TTS audio are retained until you delete them, either manually or through in-app controls.
  • Tokens temporarily held by the OAuth relay during login are deleted immediately upon claim by your device, or automatically after 5 minutes if unclaimed. Nothing is retained by the relay after this window — this is the only data category SheevChat ever holds outside your device, and it is held only in transit.
  • Chat messages are never stored — they are displayed in real-time and discarded.

To delete all local SheevChat data: disconnect all platforms and clear all credentials within SheevChat, use the Data Manager to clear points/watchtime/quotes/counters/giveaways, delete any installed TTS models and cache, then delete the folder at AppData\Roaming\SheevChat\ or uninstall the application. Uninstalling the application alone does not guarantee removal of this folder, your backups, or files you exported — those require manual deletion.

Data Security

SheevChat takes reasonable measures to protect your data:

  • All communication between SheevChat and the OAuth relay, and between the relay and platform APIs, occurs over HTTPS with TLS encryption.
  • OAuth tokens and migration credentials are stored locally on your device and are never transmitted to any SheevChat-operated server beyond the transient 5-minute relay window described above.
  • Platform Client Secrets (where applicable) are stored exclusively in the OAuth relay's secure environment and are never included in the distributed application binary.
  • The one-time UUID token claim flow ensures that handshake tokens can only be retrieved once and are immediately deleted after retrieval.

While we implement these safeguards, no method of transmission or storage is 100% secure, and local storage is not a substitute for operating-system-level security. You are responsible for the security of your device, your operating system account, and any backups containing your AppData\Roaming\SheevChat\ folder. OAuth tokens and migration credentials (especially the Streamlabs session cookie and StreamElements JWT) should be treated as sensitive and never shared with anyone.

No Sale or Targeted Advertising

SheevChat does not sell your data, and does not use connected-account or chat data for targeted advertising. SheevChat does not bundle any analytics, advertising, or telemetry SDK in the distributed application.

International Data Transfers

Third-party platforms you connect to or use for migration (Twitch, Google/YouTube, Kick, TikTok, Spotify, Nightbot, StreamElements, Streamlabs, Moobot) and infrastructure providers (Cloudflare, GitHub, Hugging Face) may process requests in countries other than your own, governed by their own policies linked throughout this page.

Children's Privacy

SheevChat is not directed at children. Use of SheevChat requires accounts on connected platforms (such as Twitch, YouTube, Kick, or TikTok), each of which has its own minimum age requirements — SheevChat does not knowingly collect data from anyone who does not meet those requirements.

How to Revoke Access

You can disconnect any platform at any time from within SheevChat. You can also revoke access directly on each platform:

Disconnecting locally within SheevChat removes the stored token from your device but does not, by itself, revoke the authorization on the platform's side — use the links above for full revocation.

Changes to This Policy

We may update this policy as the app evolves, particularly as new integrations or data uses are added. The "last updated" date at the top of this page will reflect any changes. Continued use of SheevChat after changes are posted constitutes acceptance of the updated policy.

Contact

Privacy questions, requests, or support: support@sheevchat.com