Skip to content
crossfeed
FeaturesPricingDocsBlogRoadmap
Dashboard Join the beta
FeaturesPricingDocsBlogRoadmap Bluesky ↗ Dashboard ↗ Join the beta
ImprintPrivacyTerms

Privacy Policy

Last updated 3 October 2026

What data crossfeed.live and the Crossfeed dashboard process, where it goes, and the rights you have over it.

Crossfeed is a dashboard for streaming to stream.place and Twitch at once. This page covers the website at crossfeed.live, the dashboard at app.crossfeed.live, and the overlay relay at overlay.crossfeed.live.

Who is responsible

The controller under Article 4(7) GDPR is Entropic Software, owned by Louis Escher, Marsweilerstrasse 20, 88255 Baindt, Germany. Entropic Software builds and runs Crossfeed. Reach the controller at privacy@crossfeed.live. There is no statutory data protection officer, because the thresholds in section 38 BDSG are not met.

The website

Analytics

crossfeed.live uses Rybbit, a cookieless analytics tool, on an instance run by the operator at rybbit.lou.gg. It records page views, the referring page, your browser, operating system, device type, screen size, language, and the country derived from your IP address. Rybbit sets no cookies and stores nothing in your browser. Your IP address isn't stored. This rests on legitimate interests under Article 6(1)(f) GDPR: knowing which pages people read, to improve the site and the docs.

The dashboard at app.crossfeed.live runs no analytics.

Beta waitlist

Crossfeed is in private beta. There are two ways onto the waitlist.

With your AT Protocol account. You sign in through AT Protocol OAuth with the transition:email permission. You enter your password on your own PDS, and it never reaches Crossfeed. The site's server receives your DID, your handle, the email on your account, and whether your PDS has confirmed that email. It stores these with the time you joined in Cloudflare Workers KV. The OAuth tokens are used once to read those details and are then discarded. During sign-in, a random state value and a temporary key sit in Workers KV for up to 10 minutes. If your PDS hasn't confirmed your email, Crossfeed sends a confirmation mail first.

With your email. The site stores your address as unconfirmed and sends a confirmation link. Only a confirmed address gets an invite. The link expires after 7 days. Signing in to the dashboard with an email sign-in link also confirms your address on the list.

The list exists to invite you to the beta by email, or through @crossfeed.live on Bluesky. This rests on your consent under Article 6(1)(a) GDPR, given by joining. Write to privacy@crossfeed.live to be removed at any time. Entries are deleted once the beta ends.

To limit abuse, the site also keeps a salted hash of your IP address with a count of sign-ups for one hour. It then expires on its own.

Email sign-in

You can sign in to the dashboard with your email instead of an AT Protocol account. The site mails you a link that works once, for 15 minutes. To make the link single-use, the site keeps a hash of a random value from the link in Workers KV for 16 minutes.

Access cookie

Signing in sets one cookie, crossfeed_access, on crossfeed.live, app.crossfeed.live, and overlay.crossfeed.live. After an AT Protocol sign-in it holds your DID, your handle, and your email if it's confirmed. After an email sign-in it holds your email. It also holds an expiry 30 days out, and it's signed so it can't be altered. The dashboard reads it to check whether your beta spot is open. It's strictly necessary for the access you asked for, under section 25(2) TDDDG, so there's no cookie banner. Clear your cookies for crossfeed.live to remove it.

Browser storage

The mode switch stores your choice of light or dark in local storage under the key crossfeed:mode. It never leaves your browser.

Fonts

Both typefaces are served from crossfeed.live. Your browser makes no request to Google Fonts.

The dashboard

What stays in your browser

The dashboard keeps its data in your browser, in IndexedDB and local storage:

  • your Twitch and AT Protocol sign-ins, including the OAuth tokens
  • your settings, including the OBS address and password
  • your layouts and color mode
  • your stream history, up to the last 100 streams
  • pending stream.place timeouts that Crossfeed still has to lift

Clearing site data for app.crossfeed.live deletes all of it from that browser. The data and privacy docs explain how to export and delete it from the dashboard.

Your Crossfeed account

The first time the dashboard sees your access cookie, it creates a Crossfeed account in a Cloudflare D1 database: a random account ID with your DID, your email, or both. Settings sync, overlays, and subscriptions are keyed to this account ID. Linking an AT Protocol account to an email account adds the DID to the same account. Write to privacy@crossfeed.live to have the account erased.

Settings sync

With settings sync on, the dashboard stores a copy of your settings, layouts, color mode, and stream history in the same D1 database, keyed to your Crossfeed account. The synced settings include your chat and bot commands, go-live text, overlay styles, and the overlay link key. They never include your sign-ins, OAuth tokens, or the OBS address and password. The copy stays until you select Delete synced data in the dashboard, or until you ask for it to be erased. Sync is on by default and can be turned off in each browser.

Overlays

Chat and alert overlays run through the overlay relay at overlay.crossfeed.live, a Cloudflare Durable Object per overlay link. It keeps your overlay styles and the last 50 chat messages, with each author's display name, color, and message text, so an overlay that reloads shows recent chat. Replacing your overlay links deletes them.

With Keep overlays live when the dashboard is closed on, which is the default, Crossfeed also feeds your overlays from its servers:

  • D1 stores your account ID, an ID derived from your overlay link, your Twitch user ID, and your DID.
  • Crossfeed subscribes to your Twitch channel's chat, follows, cheers, subs, and raids through Twitch EventSub. It reads chat as its bot account, crossfeedbot. Twitch sends these events to overlay.crossfeed.live.
  • While you're live on stream.place, the relay connects to your public stream.place chat.

The relay passes these events to your overlays and keeps only the last 50 chat messages, as above. Turning the switch off or deleting synced data removes the D1 entry.

Chat bot

Bot messages go out through the dashboard's server. For stream.place, it writes a chat message record to the bot's repository with your DID as the channel. For Twitch, it checks your Twitch token with Twitch and sends the message as crossfeedbot. The server counts messages per account in memory for rate limiting and stores nothing else.

Error reports

When the dashboard hits an error in your browser, it sends the error message, a stack trace, and the page path to app.crossfeed.live, at most five times per page load. These land in the Cloudflare request logs described under Hosting. Server errors land there too.

Signing in

Signing in with your AT Protocol account uses AT Protocol OAuth. You enter your password on your own PDS, and it never reaches Crossfeed. Your browser resolves your handle through public.api.bsky.app and reads your DID document from plc.directory or your own domain.

Signing in with Twitch uses Twitch OAuth. Crossfeed's server exchanges the sign-in code for an access token and refreshes that token when it expires. It passes the token back to your browser and doesn't store it. The permissions Crossfeed asks for are listed in the permissions reference.

Who your browser talks to

The dashboard connects from your browser directly to the services below. Each of them sees your IP address and handles the data under its own privacy policy.

ServiceWhat it receives
Twitch (api.twitch.tv, id.twitch.tv, eventsub.wss.twitch.tv, player.twitch.tv)Your Twitch token, the messages you send, your moderation actions, and your stream info
stream.placeYour DID, chat messages, moderation records, stream info, and restream target changes
Your PDSThe records Crossfeed writes to your repository, such as chat messages, blocks, and the go-live post
public.api.bsky.appLookups of handles, profiles, and followers
7TV (7tv.io), BetterTTV, and FrankerFaceZ (api.betterttv.net)Your Twitch user ID, to load your channel's emotes. Emote images load from their CDNs and from static-cdn.jtvnw.net.
OBS, on your own computerThe dashboard connects to OBS WebSocket on the address you enter. This connection stays on your machine.

Opening a stream.place user card looks up that chatter's pronouns, Linkat links, and Teal.fm status from public AT Protocol services. Turn this off in Settings under Chatter profiles.

Records in your repository

Actions you take on stream.place are public records in your AT Protocol repository: chat messages, blocks for bans and timeouts, and chat gates for deleted messages. The go-live post on Bluesky is public too. Crossfeed writes these only when you take the action. Delete them with any AT Protocol client.

Subscriptions

A Crossfeed subscription is tied to your Crossfeed account. Subscriptions aren't on sale yet. Before they are, this section names the payment provider and lists what it processes.

Hosting

crossfeed.live, app.crossfeed.live, and overlay.crossfeed.live run on Cloudflare Workers. Cloudflare acts as a processor under Article 28 GDPR and handles connection data including your IP address, and request logs are kept for operational monitoring. Processing can happen on servers outside the EU, covered by Cloudflare's data processing addendum and the standard contractual clauses. Operating the service securely rests on legitimate interests under Article 6(1)(f) GDPR.

Email

Crossfeed sends waitlist confirmations, sign-in links, and beta mails through Proton's SMTP service from a crossfeed.live address.

When you write to contact@crossfeed.live or privacy@crossfeed.live, your message and address are kept for as long as it takes to handle your request, and then for as long as statutory retention rules require. Mail is hosted by Proton AG in Switzerland, which the European Commission recognizes as providing adequate data protection.

Legal bases

  • Running the dashboard for you, including your Crossfeed account, settings sync, overlays, and the chat bot, rests on Article 6(1)(b) GDPR, because signing in and taking actions is how you use the service.
  • The beta waitlist rests on your consent under Article 6(1)(a) GDPR, which you can withdraw at any time.
  • Analytics, hosting logs, and error reports rest on legitimate interests under Article 6(1)(f) GDPR, as described above.
  • Handling your email rests on Article 6(1)(b) or (f) GDPR, depending on what you write about.

Nothing here involves automated decision-making or profiling within the meaning of Article 22 GDPR.

Your rights

You can, at any time:

  • ask for a copy of everything held about you, under Article 15
  • have anything inaccurate corrected, under Article 16
  • have your data erased, under Article 17
  • have processing restricted, under Article 18
  • receive your data in a machine-readable form, under Article 20
  • object to processing based on legitimate interests, under Article 21, on grounds relating to your situation

Clearing site data erases your dashboard data from that browser on the spot, and Delete synced data erases the synced copy. Send any other request to privacy@crossfeed.live. Requests are answered within one month.

Complaints

You can complain to a supervisory authority in the member state where you live, where you work, or where you think something went wrong. The authority responsible for the controller is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

Minimum age

Crossfeed is for people aged 16 and over, the age at which consent under Article 8 GDPR is valid in Germany.

Changes

This policy changes when Crossfeed changes. The date at the top says when it was last revised.

One control room for streaming to stream.place, Twitch, and soon YouTube.

Product
  • Features
  • Pricing
  • Private beta
  • Blog
  • Roadmap
  • Changelog
  • Demo
  • Dashboard
  • Bluesky
Docs
  • Quick start
  • Connect OBS
  • Keyboard shortcuts
  • Data and privacy
crossfeed
Crossfeed by Entropic Software
ImprintPrivacyTerms
Not affiliated with Twitch, YouTube, or stream.place