ilyStream connects to a lot of accounts and devices on your behalf. This page explains how it looks after the keys that make that possible, and how to tell us if you find a problem.
Keys, sign-ins and pairings
- API keys you add, such as an ElevenLabs key, are stored in Windows Credential Manager on your PC. You can replace a key with Update key or delete it with Remove.
- Spotify: ilyStream saves your sign-in securely, and Disconnect removes it.
- Philips Hue: pairing gives your PC a credential for your bridge. Forget removes it.
- Features that need a key or a network connection say so in the app, for example Needs a key and Needs the network next to a voice engine.
Local where it can be
ilyStream offers local options so data doesn’t have to leave your PC:
- The AI Co-Host can run on your own machine with Ollama.
- Text-to-Speech can use system or on-device voices.
- Philips Hue is controlled over your local network, and Razer Chroma through Razer’s SDK on your PC.
When a feature does send data to a network service, ilyStream says so where you turn it on. Text-to-Speech, for example, shows “Messages leave this computer to be spoken by a network service.”
Only the access a feature needs
Our rule is to request only the permissions a feature uses today, never access “just in case”. Each integration page lists the data that integration uses and how to disconnect it.
This website
- ilystream.app is served only over HTTPS. The
.appdomain requires it. - No third-party scripts, cookies or trackers. Everything is served from ilystream.app.
- Strict response headers, including a Content Security Policy, protection against framing, and MIME-type sniffing protection.
Verifying downloads
Download ilyStream only from ilystream.app/download. Each installer is published with a SHA-256 checksum; the download page shows how to check it in PowerShell.
Reporting a vulnerability
If you believe you’ve found a security vulnerability in ilyStream or ilystream.app, please email security@ilystream.app. Please don’t report security issues publicly until we’ve had a chance to fix them.
What to include
- A description of the issue and its impact.
- Steps to reproduce it, and a proof of concept if you have one.
- The ilyStream version (shown at the bottom of the app’s navigation rail) or the URL affected.
What you can expect
- We’ll confirm we’ve received your report.
- We’ll investigate and keep you updated on our progress.
- Once it’s fixed, we’re happy to credit you, if you’d like.
Good-faith research
We won’t pursue legal action against research carried out in good faith under this policy. That means: only test against your own accounts and devices, don’t access or change other people’s data, don’t disrupt services for anyone else, and give us reasonable time to fix an issue before disclosing it.
Out of scope
- Vulnerabilities in the platforms and services ilyStream connects to, such as TikTok, Twitch, YouTube or Discord. Please report those to the service directly.
- Social engineering, physical attacks, and denial-of-service testing.
Our contact details are also published in security.txt.