Last updated: 2 August 2026
CoWatch P2P has no servers. We do not collect, store, receive or sell any of your data. There is no account, no analytics, no tracking, and no telemetry.
When you create or join a room, three things travel between the people in that room, and nowhere else:
All of it is sent directly from your browser to the browsers of the other people in your room, over a WebRTC connection. None of it reaches us, because there is no “us” to reach. The extension has no backend of its own.
Two browsers cannot find each other without help. The extension therefore uses:
relay.damus.io and nos.lol) to exchange
the connection handshake. They see only the handshake, addressed to a topic
derived from your room code. They do not carry your playback data.stun.cloudflare.com) to discover how your browser
can be reached through your router. STUN reveals your network address to the
peers you are connecting to, which is inherent to any direct connection.These are operated by third parties under their own policies. We have no agreement with them and send them nothing beyond what a connection handshake requires.
The extension stores nothing persistently: no cookies, no local storage, no saved history. Close the tab and nothing of the session remains.
The extension requests access to https://www.youtube.com/* only. It needs it
to read the player’s state, apply the actions your room sends, and draw its own
small overlay. It runs nowhere else and can see no other site.
Room codes are short and human-readable, which makes them easy to share out loud. It also means the space of possible codes is small: someone who guessed a code in use could join that room and see the display names in it. Do not treat a room as private, and do not type anything into your display name that you would not say to a stranger.
Questions or concerns: open an issue on the project’s repository.