The short version
- Roam does not send usage analytics or crash reports to the developer.
- Camera and microphone media goes to the stream destination you configure.
- Chat, web overlays, optional location features, updates, and Tailscale contact their own services when used.
- Stream destinations and the OBS password are encrypted on the phone with Android Keystore.
- Exported recordings, password-protected backups, and diagnostics are files you control and must protect yourself.
Streaming
Roam captures camera and microphone media, combines enabled overlays, and sends the result to the RTMPS or encrypted SRT destination you enter. That destination receives the broadcast and normal connection data such as your IP address and timing information.
- RTMPS encrypts the network connection and verifies the server name by default.
- SRT uses a required passphrase to encrypt the connection.
Roam accepts RTMPS or encrypted SRT only.
The platform or server controls its own retention, moderation, and viewer access. Read its privacy terms before streaming.
Chat
Roam can read public Twitch, Kick, and YouTube chat without signing you in. When enabled, it sends the public channel name or handle you configure to those services and connects to their web or chat endpoints.
Those services receive normal network details, including your IP address and device connection metadata. YouTube chat uses an unofficial public interface and may change without notice. Roam does not send chat messages or provide chat moderation.
OBS and Tailscale
OBS WebSocket traffic is not encrypted by Roam itself. Use it only through a private network such as Tailscale. Keep OBS authentication enabled and never expose TCP 4455 to the public internet.
An encrypted SRT feed can also travel through Tailscale. Tailscale encrypts traffic between tailnet devices and handles account, device, and network metadata under its own privacy policy. Tailscale is a separate optional service.
Overlays
Imported images, HTML, and ZIP overlays are copied into Roam's private app storage. A local HTML overlay can still contact the internet if its code loads remote resources.
Remote web overlays must use HTTPS. They run with JavaScript and local web storage inside the app. The overlay provider receives normal web request details and can process anything its page asks you to enter or displays. Roam disables third-party cookies, but that does not make an untrusted overlay safe.
Location
Location access is optional and is requested only when an enabled overlay uses a location-backed token. Coordinates are used to produce the selected overlay value. While the main camera preview is visible, the value updates so you can check it before going live. Roam does not store a location history.
If you leave the camera preview while offline, Roam stops location. During an active stream, location can continue in Settings or while Roam is not on screen so the enabled overlay stays current. Roam pauses location during BRB and stops it when the stream ends or no visible overlay needs it. Android shows the active-stream notification while Roam streams in the background.
If you show a location, city, speed, or similar value on an overlay, that value becomes part of the video sent to the destination and seen by viewers. Resolving a city name may use the Android device's configured geocoding provider, which may receive coordinates.
Storage on the phone
Ordinary settings and chat channel names are kept in the app's private storage. Stream destinations and the OBS password are encrypted using a key held by Android Keystore. Android cloud backup is disabled for Roam.
Optional local recordings are saved under Movies/Roam. A backup is a password-protected file you choose to create. It includes settings, overlays and their local files, saved destinations, the active or draft Stream URL, OBS details, and other private connection details. Anyone with both the backup file and its password can read those details. Keep the file private, delete it when you no longer need it, and remember that Roam cannot recover a forgotten password.
Uninstalling Roam or clearing its app data removes its private data. Recordings, backups, and diagnostics exported to shared storage remain until you delete them.
Diagnostics
Roam keeps a small rolling operational log in private app storage. It stays on the phone unless you export it. An exported log can include the phone manufacturer and model, Android version, configured chat channel names, connection state, and engine events.
Diagnostics are designed to redact stream URLs and passwords. Review every file before sharing it. Do not send a stream key, SRT passphrase, or OBS password in a support request.
Update checks
APK installs can optionally fetch https://roamlive.app/version.json, Roam's APK release manifest, automatically at most once a day. A manual check fetches the same file immediately. Google Play installs skip this site check and update through Google Play. The site host receives normal web request data such as your IP address, time, and user agent. Roam sends no account or advertising identifier in the request.
Android permissions
- Camera and microphone: required to produce a stream.
- Location: optional, for location-backed overlay tokens in the visible camera preview and during active streaming, including when Roam is not on screen.
- Notifications and foreground service: used to keep an active stream visible to Android.
- Files and media: accessed through Android's file picker and media storage for imports, exports, diagnostics, and recordings. Roam does not request broad file access.
This website
This site has no analytics script, advertising script, payment form, or site-set cookies. Its pages and assets are served from the same site. The hosting provider and network delivery services may keep standard server and security logs.
Following an external link moves the request to that provider and its privacy terms.
Changes and contact
This page will change when Roam's data flows change. The effective date above shows the latest review.
For privacy questions, email feedback@roamlive.app before sharing sensitive diagnostics. Do not include credentials or private logs.