All-Chat Legal
Last updated: July 30, 2026
The person responsible for data processing on this website is listed in the Impressum. For privacy-related inquiries contact all.chat.support@gmail.com.
When you connect Twitch, YouTube, TikTok, Kick, or Discord we store the minimum data required to create overlays and reconnect later:
Legal basis: Art. 6(1)(b) DSGVO – performance of a contract (providing the service you signed up for).
For active overlays we temporarily process:
Chat messages sent through All-Chat are logged for rate-limiting and abuse detection and automatically deleted after one hour. Messages displayed in the overlay are streamed through memory and are not persisted once the overlay session ends.
Legal basis: Art. 6(1)(b) DSGVO (service delivery) and Art. 6(1)(f) DSGVO (legitimate interest in abuse prevention).
To render and sync overlays we store:
Legal basis: Art. 6(1)(b) DSGVO.
If you choose to link multiple platform accounts as a viewer (e.g. Twitch + YouTube), we create a unified viewer profile that associates your platform identities. This is opt-in only and requires your explicit action.
Legal basis: Art. 6(1)(a) DSGVO – your consent. You can unlink platforms at any time from the viewer settings.
For observability and abuse prevention we log:
Legal basis: Art. 6(1)(f) DSGVO – legitimate interest in maintaining service security and availability.
Premium features are unlocked through a paid membership on Patreon. If you connect your Patreon account to All-Chat, we store:
We do not receive or store your payment details; payments are processed entirely by Patreon. Patreon notifies us via webhooks when your membership changes, and a periodic reconciliation keeps the state current. Disconnecting Patreon in the Settings page deletes the stored tokens and revokes subscription-derived premium.
Legal basis: Art. 6(1)(b) DSGVO – providing the premium features you subscribed to. For the data you provide on patreon.com itself, Patreon, Inc. (US) is an independent controller; see the Patreon Privacy Policy.
Everything we store directly supports the core overlay experience:
No storage system is perfectly secure, but we follow industry best practices to keep your tokens and overlays safe.
We connect to the following services to deliver the core product:
Every integration remains subject to the platform's own policies and scopes you approve.
Typography assets originally distributed by Google Fonts are self-hosted on our infrastructure. The fonts used by the All-Chat interface are bundled at build time via Next.js, and fonts selectable for overlay customization are served through a server-side proxy at /font-proxy/*. Your browser only connects to the All-Chat origin; no IP address, user agent, or request metadata is transmitted to Google when fonts are loaded. This aligns with the Landgericht München I ruling on Google Fonts (20 January 2022, Az. 3 O 17493/20).
Legal basis: Art. 6(1)(f) DSGVO – legitimate interest in delivering the visual appearance of the overlay. The font files themselves are licensed under the SIL Open Font License 1.1 or Apache 2.0.
Overlay and dashboard pages may load the following external resources. Each request transmits your IP address and browser user agent to the respective provider:
Legal basis: Art. 6(1)(f) DSGVO – legitimate interest in providing a functional and visually complete overlay experience. You can avoid loading these by not opening the theme marketplace. Fallback avatars (shown when a platform avatar is unavailable) are generated locally in your browser and involve no external request.
Your use of All-Chat's YouTube integration is also governed by the Google Privacy Policy. This applies only to the YouTube API integration (data flows described in Section 5.1); it does not apply to fonts, which are self-hosted as described in Section 5.2.
We never sell or rent your data. We may disclose information when required by law or to respond to legitimate security incidents.
To understand how the site is used and where to improve it, we run Umami, an open-source analytics tool that we host ourselves. It is cookieless: it sets no cookies, creates no persistent identifier, and performs no cross-site or cross-device tracking. The data is processed on our own infrastructure and is not shared with any third party (unlike Google Analytics or similar services).
For each page view it records aggregate, non-identifying information:
Your IP address is not stored: it is used only momentarily to derive the country and to generate a daily, salted hash for counting unique visits, after which it is discarded. We do not track public overlay views (the pages OBS loads as a browser source). You can block the analytics script with any browser content blocker without affecting the site.
Because the tracker stores no information on, and reads none from, your device, it does not require consent under § 25 TDDDG; the processing of the resulting data rests on Art. 6(1)(f) DSGVO – our legitimate interest in measuring and improving the service.
You can exercise the following at any time:
Contact us at all.chat.support@gmail.com or use the Settings page. You also have the right to lodge a complaint with your supervisory authority (Aufsichtsbehörde).
We do not use automated decision-making or profiling within the meaning of Art. 22 DSGVO.
For YouTube Data: You can revoke All-Chat's access to your YouTube data via the Google security settings page.
All-Chat uses browser localStorage (not cookies) for essential functionality:
We do not use advertising cookies or cross-site tracking. We do use privacy-friendly, cookieless usage analytics (self-hosted Umami) – it sets nothing on your device and stores no personal identifier; see Section 5.6 for the full description. Fonts are self-hosted (Section 5.2) and do not set cookies. The GitHub API (Section 5.3) may cause GitHub to set its own cookies when the theme marketplace is loaded.
All-Chat is not intended for children under 16 (the DSGVO minimum age for consent to data processing in Germany). If we discover data belonging to a minor we will delete it immediately.
All-Chat itself is hosted on servers located in Germany (see Section 4.1). However, when you use streaming platform integrations, data is transferred to servers operated by Twitch (Amazon, US), Google/YouTube (US), TikTok (various), and Kick (AU). If you connect a Patreon membership, data is exchanged with Patreon, Inc. (US). The GitHub API (theme marketplace) may also involve transfers to the US.
Where a provider is certified under the EU–US Data Privacy Framework, the transfer rests on the EU Commission's adequacy decision (Art. 45 DSGVO). Otherwise, the transfer is necessary to perform the service you requested (Art. 49(1)(b) DSGVO). Fonts are self-hosted on our infrastructure and therefore do not involve any third-country transfer when loaded.
We'll post updates to this page when the policy changes and include a new Last Updated date. Significant changes will be announced inside the dashboard.
We connect to Twitch EventSub to receive chat messages. We do not access channel analytics, subscriber information, or payment data.
We use the YouTube Live Chat API. We do not access video content, channel analytics, or subscriber data. API usage is subject to YouTube's quota limits. You can revoke access via Google security settings or the All-Chat Settings page. Disconnecting deletes your stored OAuth tokens.
We access live stream chat data only. We do not access your videos, followers, or other personal content. Revoke access through TikTok app settings or All-Chat settings.
We connect via WebSocket to receive live chat. We do not access channel analytics or payment data.
When you connect a Discord server, we store the guild ID and name. Chat relay uses webhook URLs you configure. We do not access server member lists or DMs.
Email: all.chat.support@gmail.com
This contact is for users of the official hosted service at allch.at. Self-hosted installations should contact their own administrator.