Crystal Chatbox Privacy Policy
Effective and last updated: July 23, 2026
This Privacy Policy explains how CrystalWare Studios processes information when you use Crystal Chatbox, including the Meta Quest version of the application.
Information Crystal Chatbox processes
Crystal Chatbox does not include advertising or third-party analytics, does not sell personal information, and does not request Meta account profile information through Meta Platform APIs.
The application may process the following information:
- Messages, templates, profiles, preferences, integration settings, OSC network settings, and app configuration you create.
- Optional integration credentials, authorization tokens, or session cookies for services you choose to connect, including Spotify, VRChat, Pulsoid, HypeRate, Discord, or a custom heart-rate service.
- If you choose to sign in with a CrystalWare account (via Discord), your Discord username, avatar, and a CrystalWare-issued account ID, plus a copy of your Crystal Chatbox settings so they can be loaded on another device.
- If you turn on the optional diagnostics setting, anonymous crash reports and usage pings tied to a random install ID rather than your identity.
- Optional Spotify playback information, such as track and artist names, album artwork, playback position, and duration.
- Optional heart-rate readings supplied by your selected heart-rate provider.
- Optional weather location or approximate location inferred by the weather provider from your internet address when automatic weather is enabled.
- VRChat information requested through the VRChat API, such as your profile, current world or instance, friends, users, worlds, avatars, and authentication status.
- Search terms and results used with enabled avatar-search providers.
- Quest battery level, application status, diagnostic logs, message history, and sound files you choose to add.
- Technical request information that internet services normally receive, such as internet address, user agent, timestamps, and request status.
How information is used
Information is used only to provide features you choose to use, save your preferences, display integration information, send messages through OSC, authenticate connected services, search supported providers, check for application updates, diagnose errors, maintain security, and respond to support or privacy requests.
Local storage
App settings, messages, profiles, history, logs, added sound files, and connected-service tokens or session cookies are stored locally in Crystal Chatbox's app data on your device. VRChat passwords are used to submit a sign-in request directly to VRChat and may be held temporarily in memory while sign-in or two-factor authentication is completed; they are not intentionally saved as persistent app data.
Network communication and third parties
When you enable or use an online feature, Crystal Chatbox sends the information needed for that feature to the applicable service:
- VRChat for account authentication, user, world, instance, avatar, and related VRChat features.
- Spotify and CrystalWare Studios' Spotify authorization service for OAuth authorization, token refresh, and playback information.
- Discord and CrystalWare Studios' account service, only if you choose to sign in, for authenticating you and storing your synced settings.
- CrystalWare Studios' diagnostics service, only if you enable it, for anonymous crash reports and usage pings.
- Pulsoid, HypeRate, or a custom endpoint you provide for optional heart-rate information.
- wttr.in for optional weather information.
- GitHub for release and update checks.
- Enabled avatar-search providers for avatar searches and results.
- VRChat or another destination you configure on your local network for OSC messages.
These services process information under their own terms and privacy policies. CrystalWare Studios does not control independent third-party services. Information may also be disclosed when required by law, to protect users or the service, or to investigate abuse and security incidents.
Retention
Locally stored information remains on your device until you remove it through Crystal Chatbox, clear the app's storage, or uninstall the app. Connected-service providers retain information according to their own policies. Limited server and security logs created by CrystalWare Studios' web services may be retained only as reasonably necessary for operation, fraud prevention, security, troubleshooting, and legal obligations.
Your choices
All integrations are optional. You can disable integrations, disconnect connected accounts, remove stored settings where the app provides that option, clear Crystal Chatbox's app storage in your device settings, or uninstall Crystal Chatbox. Disabling a feature stops future processing by Crystal Chatbox for that feature, except where information must be retained for security or legal reasons.
Data deletion requests
You may request deletion of personal information collected or stored by CrystalWare Studios at no charge, regardless of where you live. Join the CrystalWare Studios Discord, create a support ticket, and title the request Privacy/Data Deletion - Crystal Chatbox. Include enough information to identify the service or connection involved, but never include passwords, authorization tokens, session cookies, government identification, or other sensitive credentials in a Discord message.
CrystalWare Studios may ask for reasonable verification before fulfilling a request. If any information cannot be deleted because it must be retained for security, fraud prevention, dispute resolution, or a legal obligation, the reason will be explained. Information stored only on your device must be deleted by clearing the app's storage or uninstalling the app. For data held by a connected third party, you may also need to submit a request directly to that provider.
Children's privacy
Crystal Chatbox is not directed to children under 13. CrystalWare Studios does not knowingly collect personal information from children under 13. If you believe a child has provided personal information, submit a privacy support ticket so it can be reviewed and deleted where applicable.
Security
CrystalWare Studios uses reasonable measures intended to protect information, including encrypted HTTPS connections for supported online services. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
International processing
Online providers may process information in countries other than your own. By enabling an integration, you direct Crystal Chatbox to communicate with the selected provider as necessary to provide that feature.
Changes to this policy
This policy may be updated when Crystal Chatbox's features or data practices change. The updated version will be posted on this page with a revised effective date.
Contact
For privacy questions or requests, join the CrystalWare Studios Discord and create a support ticket.