DeskLink

Privacy Policy

Effective date: [EFFECTIVE DATE] · Contact: [SUPPORT EMAIL]

This policy describes what [LEGAL ENTITY] ("DeskLink", "we") processes when you use the services we operate (hosted accounts, device linking, billing, release downloads). If you run DeskLink fully self-hosted, we operate no service for you and process no personal data about your sessions — the data stays in infrastructure you control.

1. The short version

2. What we process, and why

DataWhereWhy
Email, name, password (stored as a one-way scrypt hash)accounts databasesign-in
Device ID, device name, platformaccounts + session recordsyour device list, session attribution
Session records: device pair, mode, start/end time, durationaudit logbilling usage (plan minutes), security audit
Billing: plan, Stripe customer/subscription IDs, payment statusaccounts databaseplan limits, renewals
IP address, timestampserver logs / rate limitingabuse prevention
Crash reports (only if you opt in; off by default)Sentrybug fixing

We do not process: session content (screens, audio, video, chat, files, whiteboard, clipboard), your assist PINs in usable form on our servers (stored only as one-way hashes), or your AI-provider API keys (those never leave your device — the AI feature talks directly to the provider you configure).

3. End-to-end encryption — what it means and its limits

Every session performs an ephemeral ECDH (P-256) key exchange between the two devices; all data-channel payloads are AES-256-GCM encrypted. A faithfully-operated signaling server only sees metadata: who connected to whom, when, in which mode, and relayed handshake material it cannot decrypt.

Honest limits:

4. Cookies and local storage

The website and the app use browser/local storage only (no cross-site cookies): the app stores your settings, device identity key, and trust list on your device so the app works; the website may remember status-page probe URLs in your browser. There are no advertising or analytics trackers.

5. How long we keep data

6. Who else sees your data

7. Your rights

Depending on your jurisdiction (e.g. GDPR/CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. To exercise any right, or to ask any privacy question, contact [SUPPORT EMAIL]. We aim to respond within 30 days. To delete your account: in-app (Settings → Account) or by request.

8. Children

DeskLink is not directed to children under 16; we do not knowingly process their data. If you believe a child has created an account, contact us and we will delete it.

9. Changes

We may update this policy; material changes will be announced on the website or in-app before they take effect. The effective date above reflects the latest revision.