Legal
Privacy Policy
ChatPiP is designed to provide its features locally. The developer does not receive your streams, chats, browsing history or saved settings.
Developer and contact
Developer/controller: shown with JavaScript on
Contact: shown with JavaScript on
Legal address, where required: shown with JavaScript on
For help, feedback or privacy questions, see the ChatPiP support page.
1. Scope and purpose
ChatPiP is a browser extension whose single purpose is to keep user-selected YouTube and Twitch video plus the relevant live chat or YouTube comments visible in customizable picture-in-picture windows, including Dual Chat, favorites, streamer profiles, Stream Armory and multistream workflows with several selected streams.
This policy covers ChatPiP’s extension code, this website and purchase licensing. YouTube, Twitch, Google, Apple, Freemius and the browser or app stores process data under their own policies when you use their services.
2. Data processed locally
On supported pages, ChatPiP may process the following information on your device solely to deliver the feature you request:
- the current supported YouTube or Twitch URL, channel identifier, page title and browser-visible channel status;
- the video and audio of the stream a picture-in-picture window is opened from; further streams play in the platform’s own embedded player, described in section 5;
- visible public chat messages or YouTube comments and display names for discussion rendering, Dual Chat and read-only fallback;
- active YouTube subtitle cues for the transient subtitle overlay;
- possible third-party emote code strings used for the limited provider lookup described in section 5;
- the public channel name or handle of a saved favorite, used for the live-status lookup described in section 5;
- on macOS Safari, if the native workspace is open, a bounded snapshot of visible public chat or YouTube comments, source title and supported URL passed locally to the containing ChatPiP app;
- on macOS Safari only, local aggregate chat-activity counts (such as messages per five seconds) that the native ChatPiP app uses for its automatic focus rules; the Chrome build does not sample chat activity.
ChatPiP does not send this runtime information to the developer or to a ChatPiP server. Apart from the two limited lookups described in section 5 — the emote code and the live status of a saved favorite — mirrored messages, media streams and activity samples stay on the device, are transient and are not permanently stored by ChatPiP.
3. Information saved on your device
Chrome or Safari extension storage may hold your selected settings, including:
- chat position, chat zoom, overlay size, position and opacity;
- favorites with platform, channel identifier, URL, thumbnail and last browser-visible title or status;
- YouTube/Twitch Dual Chat pairings and chat arrangement;
- per-streamer layouts and Stream Armory squads;
- an older local Chrome trial record, if that trial had already started before the Freemius trial was introduced;
- a random device UID and, after Chrome trial or purchase activation, the Freemius license key, installation/license/plan identifiers, bounded installation API token and validation/expiry state;
- temporary picture-in-picture and Boss Key session state.
- the Safari app’s local trial-clock high-water timestamp and the Safari extension’s latest sanitized Apple trial/lifetime entitlement state.
The Chrome license record remains in local extension storage and is never copied to Chrome Sync. Activation and at-most-daily validation transmit the key and bounded installation/license metadata to Freemius as described in section 6; a previously validated license has a seven-day offline grace period. A legacy local trial may retain its old start and last-seen timestamps in Chrome Sync until that record is removed. New Chrome trials use Freemius and do not create a new synced trial clock. The Safari app separately obtains verified trial/lifetime transactions from Apple and sends only sanitized entitlement status and dates to its extension.
4. Permissions
YouTube and Twitch site access
Used to add ChatPiP controls and locally read the selected video, channel information and visible chat needed for the requested feature.
No tab capture
ChatPiP does not capture or record tabs and requests neither tabCapture nor activeTab. Content scripts run only on the YouTube and Twitch hosts named in the manifest.
Storage
Used to remember the preferences listed in section 3.
Native messaging
Only the macOS Safari build declares this permission, and it uses it exclusively to talk to the containing ChatPiP app on the same Mac. The Chrome build does not request native messaging at all — not even optionally.
Safari loopback host access
When the native ChatPiP workspace is open in macOS Safari, the extension sends bounded snapshots of up to 80 currently visible public chat messages or YouTube comments, allowlisted emote image URLs and up to six selected supported stream descriptors to the local app at 127.0.0.1:47831. Requests and responses are HMAC-authenticated with timestamps and replay-resistant nonces; the locally generated pairing secret is delivered through Apple’s containing-app extension channel and is never sent over loopback.
5. Collection, sharing and Limited Use
- No ChatPiP account or developer-operated runtime backend, analytics, advertising or tracking.
- No sale or unrelated sharing of browsing activity, video, audio or chat with the developer, advertisers or data brokers.
- No use for personalized advertising, creditworthiness, lending or unrelated profiling.
- No human access to page content or user data through ChatPiP.
- The Chrome and Safari extensions contain no remotely hosted program code.
To display 7TV, BetterTTV and FrankerFaceZ emotes even when another Safari or Chrome extension has not already rendered them, ChatPiP downloads public global emote catalogs and may look up an emote-shaped code string with those providers. These requests use no browser credentials and no referrer. A provider receives the requested code and ordinary connection metadata such as the IP address under its own privacy policy; it does not receive the surrounding chat message, display name, Twitch cookies or browsing history from ChatPiP.
To show whether a saved favorite is currently streaming, ChatPiP asks the platform directly rather than a ChatPiP server: Twitch through a single bundled request to its public GraphQL route, YouTube through the channel’s public /live page. These requests use no browser credentials and no referrer, carry only the public channel name or handle, run only while a favorites list is on screen — never on a background schedule — and their results are cached for about a minute. A channel you already have open is answered from that tab and is never looked up over the network. Twitch and YouTube receive the requested channel name and ordinary connection metadata such as the IP address under their own privacy policies; they receive no chat content, no account data and no identifier for the user or the device from ChatPiP. When a lookup fails or times out, ChatPiP reports the channel as “unknown” rather than claiming it is offline.
Embedded players
A stream added to a picture-in-picture window plays in Twitch’s or YouTube’s official embedded player, loaded through ChatPiP’s embed page at maf2414.github.io/chatpip-embed on GitHub Pages. The page’s address carries only the channel name or video ID; the page stores nothing and sends nothing except the player’s state (ready, playing, muted) back to the ChatPiP window. GitHub receives ordinary connection data such as the IP address; Twitch and YouTube load their players under their own privacy policies, including their cookies and advertising.
ChatPiP’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information is used only to provide or improve the user-facing ChatPiP feature the user requested.
6. Chrome trial and purchase processing
Starting the Chrome trial requires an email address but no payment method. Freemius processes that address, ordinary connection/device information and risk signals to create the seven-day trial and deliver its key. If you buy the permanent unlock, Freemius may additionally process name and billing/payment details to complete payment, calculate tax, issue a receipt/key, prevent fraud and handle refunds or disputes under its notices.
On activation/validation the extension sends Freemius the license key, a random 128-bit installation UID, installation title, Freemius installation/license/plan identifiers and ordinary request metadata. Freemius returns bounded installation credentials and license state. No stream, chat, browsing history, favorite or setting is included. Safari’s free trial and lifetime unlock are separate Apple Non-Consumable IAPs; Apple processes purchase/account data and ChatPiP receives verified StoreKit transaction status, not full card details.
7. This website
This website does not set ChatPiP cookies and does not include analytics, advertising, tracking pixels, forms or remote fonts. The purchase page loads the Freemius checkout script; visiting that page lets Freemius receive ordinary connection information such as your IP address before you start a trial or purchase. All other pages contain no third-party scripts. The hosting provider may also process standard request information such as IP address, timestamp and requested path under its own policy.
The purchase page can also hand you over to the installed extension. Pages on this website’s origin are the only pages allowed to message ChatPiP, the single accepted message merely opens the extension’s activation view in a new tab, and no license key, page content or other data is exchanged in either direction.
8. Access, deletion and security
ChatPiP does not maintain a runtime browsing profile. You can remove local feature/license settings by deactivating the device or uninstalling ChatPiP; the Freemius portal manages keys and activations. Safari purchases can be restored and managed through Apple. Provider records may be retained where required for fulfillment, support, fraud prevention, tax or disputes.
ChatPiP limits host access to supported YouTube and Twitch pages, limits native messaging to its own local macOS app and avoids remote code. No software can guarantee absolute security; please keep your browser and operating system updated.
9. Children
ChatPiP does not provide accounts or knowingly collect personal information from children. Use of YouTube, Twitch and the relevant browser or app store remains subject to those services’ age requirements and parental controls.
10. Changes
If ChatPiP’s data practices materially change, this page will be updated before the changed practice is released, with a revised effective date. Privacy questions can be sent through the contact method above.