The short version: Dual IRL Stream does not collect, store, or transmit
your personal data to us. Your camera and microphone are sent only to the streaming server
you configure. There is no analytics, no telemetry, no advertising, and no account
with us. Your settings and credentials stay on your device and are kept out of Android’s cloud
backup and device transfer. Optional features you turn on — live chat and channel-status
badges — connect to the platforms involved (Twitch, Kick, Rumble, and the services they rely on,
such as Pusher), as detailed below; the one exception is Twitch sender-badge images, which are
fetched from our own api.dualirl.com backend (which relays the
request to Twitch’s official Helix API) whenever Twitch chat is enabled, whether or not
badges are shown on screen — see “Live chat overlay” below. (The website itself
uses a little privacy-friendly, cookieless analytics on every page — see
This website below.)
Who this covers
This policy applies to the Dual IRL Stream Android application (“the app”), distributed under the Dual IRL brand. It explains what the app does and does not do with information when you use it.
It also covers Dual IRL Bro, the free companion monitor app. Bro
captures no camera or microphone and never broadcasts — it only watches. It plays the
public live video of the channels you choose to monitor
locally on your device: Kick and Twitch via their HLS streams, and YouTube through
YouTube’s own embedded player (requests to youtube.com). It also merges those
channels’ public chat — Kick (via Pusher) and Twitch (via Twitch’s IRC service), the
same connections described below; YouTube is video-only (no chat). It can additionally play
audio-only web sources you add, locally. Like the main app, its settings stay on your device, it
has no in-app updater (it cannot install anything and does not request permission to — new builds are downloaded from the Bro page). Opening
Settings → App updates does ask dualirl.com for a small file listing the latest published version number, so it can tell you whether a newer build exists. Opening that screen is the only thing that triggers it, and nothing else in the app contacts us. The request is not cancelled if you navigate away, so it can complete a few seconds after you leave. The request sends no account, no device identifier, no advertising id, and nothing about how you use the app — just a request for that one file, with a generic client identifier (the HTTP library’s own, not a browser profile). Like any web request it necessarily reveals your IP address to the server, and we make no claim that a fixed IP couldn’t be correlated across visits; if that matters to you, skip the screen and check the download page in a browser instead. Beyond that one file, the only other thing that contacts us is Twitch sender-badge images, described in “Live chat overlay” below — nothing else in the app sends data to us. The
streaming-specific sections below (camera, microphone, stream keys) apply to Dual IRL Stream
only; Bro’s own permissions are listed separately in the permissions section.
What the app sends, and where
The app is a live-streaming tool. When you go live, it captures your camera and microphone and encodes them into a video stream, which is sent only to the streaming server (ingest) you enter yourself — for example your own RTMP/RTMPS, SRT, or SRTLA server, or a platform endpoint you choose. We (the developer) never receive, see, store, or have access to that audio or video. We operate no ingest server and no backend that your stream passes through.
What stays on your device
Your settings — including stream keys, server URLs, and passphrases — are stored on your device. We never receive them, and we operate no account or backend that holds them. Your stream credentials (keys/passphrases) are only ever sent to the streaming destination you choose. If you sign in to Twitch, the resulting login token is also stored on your device and is sent only to Twitch’s own API (to read channel status — see the next section); it is never sent to us or to your stream destination. If you enter a Rumble Live Stream API URL (which contains a secret key for your own Rumble channel), it too is stored only on your device and is sent only to Rumble’s own API to read your channel’s status — never to us or to your stream. These stored credentials are excluded from Android’s cloud backup and device-to-device transfer, so they are not copied off your device. Uninstalling the app removes them.
Optional third-party connections
Some features are optional and only contact third parties if you turn them on:
- Twitch sign-in (optional). If you sign in to Twitch, the app uses Twitch’s standard device-authorization flow and stores the resulting access token on your device. The token authorizes the channel-status requests below (Twitch’s Get Streams returns public data and needs no special permissions). Governed by Twitch’s Privacy Notice.
- Channel status badge (optional). If you enter a Twitch or Kick channel name, the app periodically requests that configured channel’s public live/viewer status (Twitch’s Helix API; Kick’s public channel API) to show the viewer-count and uptime badge. This runs whenever the preview screen is open and a channel is configured — independently of whether the chat overlay is shown. The channel can be any public channel you enter, not necessarily your own. Governed by the respective platform’s privacy policy.
- Rumble channel badge (optional). Rumble works differently from Twitch/Kick: there is no public any-channel lookup, so to show your own Rumble channel’s status you paste your Rumble Live Stream API URL (which embeds a secret key for your channel). The app stores it only on your device and periodically requests that URL from Rumble’s own Live Stream API to read your channel’s live status, viewer count, and likes/dislikes for the badge. It runs only while the preview screen is open and at least one Rumble badge item is enabled. The URL/key is never shown in your stream and never sent to us. Governed by Rumble’s Privacy Policy.
- Live chat overlay (optional). If you enable the chat overlay, the app
fetches public chat messages and emote images from Twitch and/or Kick to display them to you,
the operator. Twitch chat connects to Twitch’s IRC service; Kick chat connects
through Pusher (
pusher.com— the third-party real-time messaging service Kick uses for live chat) in addition to Kick’s own API. If you also enable Rumble chat, your own channel’s chat is read from Rumble’s own Live Stream API (the same URL as the Rumble badge above — no extra connection) and merged into the same overlay. Whenever Twitch chat is enabled, the app also fetches real Twitch sender-badge images (e.g. subscriber-tier badges) from our ownapi.dualirl.comtoken-broker backend (which relays the request to Twitch’s official Helix API without exposing a credential to your device) — once for that channel’s numeric Twitch id and once globally. This happens whenever Twitch chat connects, independently of the “show badges” display setting, which only controls whether badges are drawn once fetched; like any web request it necessarily reveals your IP address to that backend. Governed by the respective providers’ privacy policies (Twitch, Kick, Pusher, Rumble). - Weather & time overlay tool (website, optional). The free
weather overlay on this site is a browser source you can add
to your own streaming software. When loaded it makes keyless requests to
open-meteo.com(weather + time zone),openstreetmap.orgNominatim (turning coordinates into a coarse place name), and — only if you supply an RTIRL pull key —rtirl.com. By default the displayed place is coarsened to state + country so it doesn’t reveal your city; you can opt into a finer level (county or city) in the builder, which then shows more precise location. Your coordinates and any RTIRL key live in the overlay URL’s#fragment, which browsers don’t send to a server. No 3rd-party analytics or trackers are involved — this page carries the same self-hosted page-load counter as the rest of the site (see “This website” below), which never sees the fragment and reports a fixed page path rather than your actual URL. Weather & time data is by Open-Meteo (CC BY 4.0) and place names are © OpenStreetMap contributors; governed by Open-Meteo and the OpenStreetMap Foundation. The condition/wind icons load as images fromcdn.jsdelivr.net(Twemoji, CC BY 4.0) instead of relying on your device’s own emoji font. - Platform-stats widget (website, optional). The
platform-stats widget shows a config-free sample preview with no
network requests until you configure at least one channel. Once configured it polls, directly from your
browser:
kick.com(keyless) for a Kick channel; and Dual IRL’s own token-broker backend atapi.dualirl.comfor a Twitch channel (which mints and holds a Twitch app credential server-side, so your browser never needs one) and, if you supply one, a Rumble channel (which relays just the key from your own Rumble Live-Stream-API URL to Rumble’s own API and back, since Rumble’s API doesn’t allow a browser page to call it directly; the key is never logged). Your channel names and any URL live in the overlay URL’s#fragment, which browsers don’t send to a server. No 3rd-party analytics or trackers are involved — this page carries the same self-hosted page-load counter as the rest of the site (see “This website” below), which never sees the fragment and reports a fixed page path rather than your actual URL. Governed by the respective providers’ privacy policies (Kick, Rumble); the Twitch and Rumble requests go only to Dual IRL’s own backend, which relays them to Twitch’s official Helix API and Rumble’s own API respectively. A small set of status icons (uptime, unreachable warning, Rumble sentiment) load as images fromcdn.jsdelivr.net(Twemoji, CC BY 4.0) instead of relying on your device’s own emoji font. - Viewer-count widget (website, optional). The
viewer-count widget makes the SAME kind of requests as the
platform-stats widget above (Kick keyless direct from your browser; Twitch and, if supplied, Rumble via
Dual IRL’s own
api.dualirl.combackend) — showing a current count, trend arrow, and session peak/average per platform instead of a compact status row. It makes no requests at all until you configure a channel. Your channel names and any URL live in the overlay URL’s#fragment, which browsers don’t send to a server. No 3rd-party analytics or trackers are involved — this page carries the same self-hosted page-load counter as the rest of the site (see “This website” below), which never sees the fragment and reports a fixed page path rather than your actual URL. Governed by the same providers’ privacy policies linked above. An unreachable-status icon loads as an image fromcdn.jsdelivr.net(Twemoji, CC BY 4.0) instead of relying on your device’s own emoji font. - Fan Finder tool (website, optional). The
Fan Finder lookup tool makes a request directly from your browser to
kick.com(keyless, no account or login required) whenever you submit a channel and username — the same lookup Kick’s own chat UI performs when you click a username. It makes no request until you submit the form. The channel/username you enter are never written to this site’s own URL or access logs (they are form inputs, not URL parameters), but they are sent to Kick as part of the request — Kick’s own privacy policy governs what it does with that request. Only Kick is supported; no equivalent keyless per-user lookup exists for Twitch/Rumble/YouTube. - Merged chat overlay tool (website, optional). The
merged chat overlay reads public Kick and/or Twitch chat directly
from your browser, the same read-only/anonymous connections described above for the app’s own chat
overlay: Kick via a keyless channel-resolve request plus its Pusher WebSocket, Twitch via its anonymous
IRC-over-WebSocket service. If you enable 7TV emotes (on by default) it also makes keyless requests to
7tv.io. Resolving a Twitch channel’s numeric id via an anonymous GraphQL request togql.twitch.tvhappens whenever EITHER 7TV emotes OR Twitch badge images (see below, on by default) are enabled, since both features need that same id — turning off both avoids this request entirely. If you also enable 7TV namepaints (off by default, requires 7TV emotes), it opens a WebSocket toevents.7tv.iofor live namepaint grants/revocations, and, for each Twitch chatter without one already learned live, sends that chatter’s numeric Twitch account id to7tv.io(plus a further keyless GraphQL request if they have an active namepaint) to look up their currently-equipped one; this per-chatter lookup does not happen for Kick chatters. Twitch sender badge images (on by default) are fetched, once per connected channel, from Dual IRL’s own token-broker backend atapi.dualirl.com(which relays the request to Twitch’s official Helix API without exposing a credential to your browser) — this is the request that needs the channel’s numeric id described above; Kick badge images come directly from Kick as part of its own channel-resolve response. Emote/badge images themselves load directly from their platform’s own CDN —files.kick.com(Kick),static-cdn.jtvnw.net(Twitch),cdn.7tv.app(7TV) — each an untrusted per-payload URL the sender’s own client controls, same as the app’s own chat overlay; the page’s content-security-policy allows any HTTPS host for images for this reason, rather than a fixed list. Literal Unicode emoji in chat messages and event text (unless you hide emojis) likewise load as images, fromcdn.jsdelivr.net(Twemoji, CC BY 4.0), instead of relying on your device’s own emoji font. No login required for Kick/Twitch, no channel credentials for either. Your channel names live in the overlay URL’s#fragment, which browsers don’t send to a server. If you also enable Rumble chat, this tool is read-only and requires no interactive login, but the URL you supply DOES carry a credential: your own Rumble Live Stream API URL (which embeds a secret key for your channel), stored only in that same#fragment. Every few seconds, just the key is sent to Dual IRL’s ownapi.dualirl.combackend, which relays it to Rumble’s own API and back to read your channel’s chat — never logged, since Rumble’s API doesn’t allow this page to call it directly from a browser. No 3rd-party analytics or trackers are involved — this page carries the same self-hosted page-load counter as the rest of the site (see “This website” below), which reports a fixed page path rather than your actual URL. Governed by the respective providers’ privacy policies (Kick, Pusher, Twitch, 7TV, Rumble). - Location tracker overlay tool (website, optional). The
location tracker overlay is a browser source that shows a label-free
minimap following your device’s live GPS. When loaded it makes keyless map-tile
requests to
basemaps.cartocdn.com(CARTO), which necessarily reveals your device’s IP address and the map area you are in — i.e. your live route — to that tile host, the same way the weather overlay’s requests do — and, only if you supply an RTIRL pull key for an off-device rig that can’t read its own GPS, pollsrtirl.comdirectly from your browser. Because it broadcasts live location, it is the most location-sensitive tool here and is built to fail hidden: it renders nothing until you set a private home point, blacks the whole map out near home, and hides when GPS is unavailable or denied, when a location fix goes stale, or if the map fails to load. Your home point lives in the overlay URL’s#fragment, which browsers don’t send to a server, is compared only in your browser, and is never transmitted or drawn. Any RTIRL key lives in that same fragment (so this page never sees or logs it), but IS sent to RTIRL’s own API as a query parameter on every poll to fetch your position — sent only to RTIRL, never to us. No 3rd-party analytics or trackers are involved — this page carries the same self-hosted page-load counter as the rest of the site (see “This website” below), which never sees the fragment and reports a fixed page path rather than your actual URL. Map tiles are © OpenStreetMap contributors and © CARTO; governed by CARTO and the OpenStreetMap Foundation.
The in-app operator overlays (chat, stats, viewer count drawn inside the Dual IRL Stream app) are shown only to you and are never part of your broadcast video. The website browser-source tools above (the weather overlay, the platform-stats widget, the viewer-count widget, the merged chat overlay, and the location tracker) are different: you deliberately add them to your own scene, so they appear in your broadcast if you choose to include them.
What the app does not do
- No analytics, usage tracking, or telemetry sent to us or to any third-party SDK.
- No crash/error reporting services.
- No advertising and no advertising identifiers.
- No selling or sharing of personal data — we collect none to begin with.
- No account, sign-up, or profile with us.
- No access to your contacts, photos, or files.
- No background location, and no location tracking or storage by the app itself. The app requests only approximate (coarse) location, foreground-only, and solely to hand to an operator-added web-source overlay that asks for it (e.g. the weather or location-tracker overlay) — see the permissions table below.
This website
The sections above cover the apps. The dualirl.com website itself uses a
small amount of privacy-friendly, cookieless analytics — self-hosted
GoatCounter running on our own
server, not Google. It records page views, referrers, browser, operating system, language, screen size, and
— derived from your IP address, which is not stored — a rough
country and, for some larger countries such as the US, an approximate region
(e.g. state/province, never a precise location). There are no cookies, no cross-site
tracking, and no personal identifiers — we cannot tie a visit back to you. It is present on
every page of this website, including the browser-source overlay and builder tools — each
simply counts a page load, no 3rd-party analytics or trackers. The weather and location-tracker overlays
additionally report a fixed page path rather than the page’s actual URL, so a
hand-typed ?query link — which the location-tracker overlay still accepts for its non-sensitive
display options (its home point and RTIRL key are fragment-only regardless), and which the weather overlay
no longer reads at all, fragment-only now — can never turn a page-load count into a stored record of your
coordinates — see those sections above. The four APK download links (Stream and Bro, each with a separate Stable and Beta build) are each
counted once per actual download request, the same privacy-friendly way as everywhere else on this page —
so we can see aggregate Stable-vs-Beta download counts per app, never who downloaded which. This is the one
count here that can also come from inside the app: Stream’s own in-app updater
(present on both its Stable and Beta builds) fetches its APK from the URL matching the running
build’s own channel when it actually downloads an available update — a separate, later step
from its routine background check for one, which only reads a small manifest file and never touches this
URL — so that download is counted too, not only a click on this website’s button. No other
information about your device or the app itself is sent.
Permissions and why they’re needed
These are Dual IRL Stream’s permissions:
| Permission | Why |
|---|---|
| Camera | Capture the video you stream. |
| Microphone | Capture the audio you stream, and — while the preview is open before you go live — measure the input level for the on-screen mic meter. Audio is never written to a file or sent anywhere except your stream. |
| Internet & network access | Send your stream to the server you choose, and — for forced-network or SRTLA bonding — request, hold, and bind the stream to specific Wi-Fi and cellular networks. Bonding can keep mobile data active alongside Wi-Fi so both carry the stream (this may use cellular data even while Wi-Fi is connected). |
| Foreground service | Keep streaming reliably while the app is backgrounded or the screen is off. |
| Wake lock | Prevent the device from sleeping mid-stream. |
| Notifications | Show the ongoing “streaming” status notification. |
| Approximate location (coarse, optional) | Requested only so that a web-source overlay you deliberately add can use your location (e.g. the weather or location-tracker overlay). The app holds no location itself — the browser Geolocation grant is passed to the overlay you chose. It is approximate (coarse), foreground-only (never background), and can be denied — with it denied, those overlays simply don’t get a location. |
Dual IRL Bro is a monitor, so it asks for far less — no camera, microphone, or location:
| Permission | Why |
|---|---|
| Internet & network access | Fetch the public live video and chat of the channels you choose to monitor, and, when you open Settings → App updates, ask dualirl.com for the latest published version number (that request can finish shortly after you leave the screen). Bro never broadcasts. |
| Foreground service (media playback) | Keep an audio-only web source playing while Bro is in the background, if you add one. |
| Notifications | Show the ongoing notification required by that audio-playback service while it runs. |
Children
The app is not directed to children, and we do not knowingly collect information from anyone — including children — because we do not collect personal information at all.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new “Last updated” date.
Contact
Questions about privacy? Email privacy@dualirl.com.