This page describes the data stored by this software. The operator of your cloud instance is responsible for its privacy policy, hosting, access logs, backups and deletion requests.
We request only OpenID authentication. The database stores your Google account's stable identifier (the sub claim), linked to an internal cloud user ID. This identifier is personal data even though it is not your email address.
We do not store your Google password, email address, name, avatar or Google access, refresh or ID tokens. No Gmail, Drive, contacts or calendar access is requested. Google authenticates you on its own site. Login tokens are validated in server memory and then discarded.
We store your internal account ID, device IDs and names, device ownership, last device connection time, and hashes of device and cloud session tokens. Cloud sessions expire after 24 hours. Single-use pairing codes expire after 10 minutes; their hashes are stored temporarily.
Temporary login security records contain a hash of a random login state, a nonce and a PKCE verifier. They expire after 10 minutes, are consumed on callback, and expired records are cleaned every minute. Local accounts, if enabled by the operator, store a username and a bcrypt password hash.
The cloud handles device control requests, device login requests and credentials, session cookies and WebRTC connection signaling in memory. This application does not save those request bodies, passwords or cookies to its database. Video travels between your browser and device, directly or through the TURN service you configure; this cloud does not provide TURN or record video.
The service can observe your network connection and signaling metadata during use. Reverse proxies, hosting providers, Google and optional TURN providers have their own data practices. The application does not include analytics or persist visitor IP addresses.
Account identifiers and device ownership remain until removed. Removing a device revokes its cloud token and deletes its current device and pairing records. Signing out deletes the current session. Automatic cleanup deletes expired sessions and expired login/pairing records, but backup copies are controlled by the operator.
This release has no self-service account deletion. Contact the operator to remove an account and its associated records and to learn their backup retention policy. Existing local accounts are not automatically merged with Google accounts.