1. Controller
Jilence, Jonas Kelm, c/o autorenglück.de, Franz-Mehring-Str. 15, 01237 Dresden,
Germany.
Email: [email protected]. Further mandatory
information is in the Imprint.
2. What JilChat is
JilChat is a client for Twitch chat. The chat itself comes from and goes to Twitch — JilChat is the display, not the source. We additionally run our own service for push notifications, direct messages, uploads and the JilChat Pro subscription. The sections below are about those own features.
3. Account and identity
Signing in works exclusively through Twitch OAuth. There is no separate password. From Twitch we receive and store:
- Twitch user ID
- login name and display name
- the URL of your Twitch profile image
We add our own JilChat account UUID and issue a JWT as proof of session. Both exist solely to attach your settings to the right account.
Access tokens and session tokens live on your device only: on Android in encrypted preferences backed by the Android Keystore, on iOS in the Keychain with a device-bound protection class. Stored this way they are not included in backups and not transferred to another device.
4. Twitch chat
Chat messages are received from and sent to Twitch live. JilChat keeps no permanent archive of its own of Twitch chat. What is said in chat is subject to Twitch's rules and privacy notice — see section 11.
5. Push notifications (JilChat Pro only)
If you set up push notifications, we store on the server:
- your device token — FCM on Android, APNs on iOS
- the channels you subscribed for notifications
- your highlight words
- whether you want to be notified on mentions and/or on highlight words
Subscribed channels and highlight words are stored in plain text on our server. This is the most sensitive point in this policy and we name it plainly: for the service to match an incoming chat message against your words, it has to be able to read those words. Encrypted storage would make server-side matching impossible. If you pick highlight words that reveal something about you personally, be aware of that. You can change or remove your words at any time in the settings, and push can be switched off entirely.
To detect matches, our service briefly processes messages from the channels users selected, in memory. Messages that do not match are not stored.
6. Direct messages
Direct messages are end-to-end encrypted, using HPKE with DHKEM(P-256, HKDF-SHA256), HKDF-SHA256 and AES-256-GCM. Our server only ever sees ciphertext and cannot decrypt it — it does not hold the matching key.
Per device, the server holds only:
- a random device ID
- the corresponding public key. The private key is generated on the device and is never transmitted to us.
One detail belongs here for accuracy: so the notification extension can decrypt an incoming message while the screen is locked, the private key on iOS uses a protection class that includes it in an encrypted device backup. From such a backup it can be restored onto a new device. It is not synced to iCloud, and it never reaches our servers by any route.
The server mailbox is a staging area only: once your device has fetched and acknowledged a message, it is deleted from the server immediately. Messages never collected — because a device is no longer in use, for instance — are removed automatically after 30 days at the latest. You can also empty the mailbox by hand in the settings at any time.
The message history lives only on your device. We keep no copy of it.
7. Uploaded content
Images and voice messages you share in chat are stored on JilChat infrastructure (Cloudflare R2) and shared through a short link. We store the file itself, technical metadata and the link.
Anyone holding the link can see the content — the links are not protected by a sign-in, because they have to work for everyone reading along in Twitch chat. Share them accordingly.
- Images expire automatically after 7 days.
- Voice messages expire automatically after 3 days.
An hourly cleanup job removes expired files permanently. To delete something sooner, you can delete your own voice message in the app; for images, send the link to [email protected]. Deleting your account removes any uploads still present.
The app accesses the microphone only while you are recording a voice message. There is no background recording.
8. Purchases (JilChat Pro)
The purchase itself runs entirely through the respective store. We never see payment data — no card numbers, no billing addresses. Only Google or Apple hold those.
- Google Play: we process the purchase token and a pseudonymous account ID
(
obfuscatedAccountId) and verify the purchase through the Google Play Developer API. - App Store: we process the StoreKit transaction identifier and verify it through Apple's App Store Server API.
From that we derive and store: subscription status, the number of paid periods, and the milestone badges earned from them.
9. Feedback
If you send feedback from the app, we store your message, your Twitch login, the app and build version, the OS version and the device class. A diagnostic report is attached only if you explicitly enable that switch.
10. Diagnostics and tracking
- Firebase Crashlytics for crash reports.
- Firebase Cloud Messaging for delivering push notifications.
- Apple MetricKit performance reports — only with your explicit consent, see below.
Performance reports (optional, off by default). If you consent, the iOS app sends a technical report at most once per day that the operating system itself compiles on your device (Apple MetricKit). It contains rendering and execution measurements: frame rate while scrolling, CPU time, launch duration, memory use, plus device model, iOS version and the app and build version.
The report contains no chat content, no messages, no name, no Twitch account and no identifier that identifies you. Its sole purpose is finding stutters and performance problems on devices we cannot test ourselves. You can turn the transmission off at any time in the app settings under “Feedback”; we ask for consent once on first launch, and without active consent the report stays on the device.
Beyond that: no analytics SDK, no ad tracking, no advertising IDs, no sharing of data for advertising purposes, and no cross-app tracking. The performance reports come from the operating system, not from an embedded analytics service.
11. Third parties contacted while chatting
For emotes, badges and cosmetics the app talks to these providers directly, depending on which features are enabled. Technically this transmits your IP address to them; their own privacy policies apply:
- Twitch — Privacy Notice
- 7TV — Privacy Policy
- BetterTTV — Privacy Policy
- FrankerFaceZ — Privacy Policy
- Chatterino badges — badge lists from the Chatterino community
- ffz:ap — additional badges for FrankerFaceZ
Acting as processors on our behalf: Google (Firebase Cloud Messaging, Crashlytics, Google Play Developer API), Apple (APNs, App Store Server API), Cloudflare (R2 storage) and the host of our API and website.
12. Legal bases
- Art. 6(1)(b) GDPR (contract): account, sign-in, providing app features, handling JilChat Pro, direct messages, uploads.
- Art. 6(1)(a) GDPR (consent): push notifications including channels and highlight words, microphone access, attaching diagnostic reports to feedback, sending performance reports (Apple MetricKit). Consent can be withdrawn at any time with future effect — usually by turning the feature off in the settings.
- Art. 6(1)(f) GDPR (legitimate interests): secure and stable operation, abuse prevention, crash diagnostics, handling deletion requests filed through the website.
13. Retention
- Account and settings data: until the account is deleted.
- Push tokens, channels, highlight words: until you turn the feature off or delete the account.
- Direct messages in the server mailbox: until acknowledged by your device, at most 30 days.
- Images: 7 days. Voice messages: 3 days.
- Subscription data: until the account is deleted.
- Feedback: until resolved, at the latest until the account is deleted.
- Performance reports: 90 days, then deleted automatically. They are stored separately from feedback and without any link to your account.
- Deletion requests filed on the website: up to 6 months after completion, then deleted automatically.
- Technical server logs: only as long as secure operation requires.
14. Transfers to third countries
Google (Firebase Cloud Messaging, Crashlytics, Google Play), Apple (APNs, App Store), Cloudflare and Twitch are US providers or process data outside the EU. Such transfers rely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, on the adequacy decision for the EU-US Data Privacy Framework under Art. 45 GDPR. Despite those safeguards, access by authorities in those countries cannot be ruled out in every case.
15. Your rights
Where the statutory conditions are met, you have the right to:
- access to the data held about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with future effect (Art. 7(3) GDPR)
Write to [email protected]. Independently of that, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — for example the Saxon Data Protection Commissioner or the authority where you live.
16. Deleting your account and data
In the app: Settings → Delete Account. Without the app installed, go to jil.chat/en-US/delete-account. That page also lists in detail what gets deleted, what remains and how long it takes.
What is deleted is the JilChat account — your Twitch account and any active store subscription are unaffected.
17. The jil.chat website
Visiting the website produces technically necessary server logs, in particular IP address, timestamp and the resource requested. The public website sets no analytics or advertising cookies and has no cookie wall. The non-public admin area uses a strictly necessary session cookie.
In the form on the deletion page we process the Twitch username you enter, your contact address and an optional message. To fend off bulk submissions we additionally store a hash of your IP address — not the address itself — which is dropped once the request has been handled.
18. Changes to this policy
We update this policy when features, providers or legal requirements change. The version published here is the one that applies; the date above identifies it.
This English version is provided for convenience. The German version is authoritative for users in Germany.