Privacy Policy
Last updated: September 29, 2026
Your screen, keystrokes, clipboard and files never reach us. They go straight between your own devices over your Tailscale network.
What we store
- Account: your email address, the name you give (optional), and your password as a salted scrypt hash, never the password itself.
- Sessions: for each signed-in device, the IP address and app/browser identifier it signed in from, and when the session expires.
- One-time codes: the 6-digit codes we email, stored hashed, for 15 minutes.
- Subscription: which store you subscribed through, the store’s purchase reference, the product, its status, when it renews or expires, and whether it auto-renews.
Who processes it
- Cloudflare hosts this service and its database.
- Resend delivers our emails.
- Apple and Google take payments and tell us the subscription’s status.
We don’t sell your data, show ads, or use tracking or analytics tools.
How long we keep it
Until you delete your account. Sessions end after 90 days without use; accounts whose email was never verified are deleted after 7 days.
Deleting your data
Delete your account in the app (Profile → Delete account) or at api.awaydesk.app/delete-account. This removes your account, sessions and subscription records right away. It doesn’t cancel an App Store or Google Play subscription; cancel that in the store.
Contact
hello@awaydesk.app. If this policy changes, the new version appears here with a new date.