Skip to main content

Security & extension permissions

Last updated: July 28, 2026

Overview

AniDachi separates your streaming logins from our account system. You keep your own Crunchyroll or YouTube session in Chrome. We do not ask for those platform passwords.

Accounts and billing

  • AniDachi accounts use our auth system (email / OAuth as offered on the site).
  • Paid plans are processed by Stripe. We do not store full card numbers.
  • Details: Privacy Policy.

Chrome extension

The extension overlays watchroom controls on supported pages and detects playback so friends can stay in sync. Store builds use narrow host permissions for YouTube, Crunchyroll, AniDachi web, and our Worker hosts — not blanket access to every site.

Title/episode detection for watchrooms runs in your browser and is only sent when you create or join a room. The extension must never receive service-role keys, OAuth client secrets, Stripe secrets, or TURN secrets.

Realtime rooms

Live room state and signaling use our API / Durable Object Worker. Media between friends uses WebRTC where available; we may provide ICE/TURN access for connectivity. Room tokens are short-lived and scoped to the room you join.

Report a vulnerability

Email anidachi.app@gmail.com with “Security” in the subject. Include steps to reproduce, affected URL or extension version, and impact. Please give us a reasonable window to respond before public disclosure.

Do not use this channel for general product support — use Contact.

Related

Privacy · Terms · About · Contact