Privacy Policy
Effective date: 1 May 2026
This Privacy Policy explains what information the Zeruth remote-desktop platform collects, how that information is used, who it is shared with, and what choices you have. It applies to the Zeruth Android, Windows, and web clients, and to the Zeruth backend that they connect to.
1. Who runs Zeruth
Zeruth is built and operated by an independent developer. For privacy- related questions, contact [email protected].
2. What data we collect
2.1 Account data
If you create an account, we store:
- Your email address
- Your chosen display name
- An Argon2id hash of your password (the plain password is never stored or transmitted in clear text)
- Multi-factor authentication settings, if you enable MFA (TOTP secret only; we do not store recovery codes in plain text)
2.2 Device data
For each device enrolled to your account or used in anonymous mode, we store:
- A device fingerprint derived from a randomly-generated install identifier and the device model name (SHA-256 hash; the inputs are not retained)
- Operating system family and form factor (e.g., "Android", "Phone")
- A short connection password (rotates on demand) and, for anonymous-mode devices, a 9-digit public Zeruth ID
- Online / offline state and the timestamp of the most recent signaling check-in
2.3 Connection metadata
When two devices establish a remote-desktop session, we record minimal session metadata so the helper and host can find each other and so we can investigate abuse:
- Pairs of device IDs that initiated a session
- Session start and end timestamps
- The IP address used at signaling time
- Recent-connections shortlist scoped to your account, so that frequent helpers reappear in the UI
2.4 Optional diagnostic logs
If you opt in to diagnostic sharing on the first run of a Zeruth client (the consent banner is off by default), we receive structured log entries — log level, component name, message, and timestamp — to help us debug crashes and connection issues. Diagnostic logs are retained for 14 days by default; entries flagged as Errors or higher are retained for 60 days. You can revoke this consent at any time in the client settings.
2.5 What we do not collect
- Remote-desktop video, audio, file transfers, and clipboard contents are end-to-end encrypted via WebRTC (DTLS-SRTP) and travel peer-to-peer between the participating devices. Even when our optional TURN relay is used to traverse restrictive networks, our servers see only encrypted ciphertext. We have no technical ability to view, store, or decrypt the contents of a remote-desktop session.
- Contacts, photos, microphone, location, or any data not directly required for the features you use.
- No third-party advertising SDKs or trackers are embedded in the app.
3. How we use your data
- To authenticate you and authorize device pairings
- To route signaling messages between paired devices so they can establish an encrypted peer-to-peer connection
- To detect and prevent abuse (rate limiting, suspicious sign-in detection)
- To diagnose and fix software defects (only with explicit opt-in consent)
- To send essential service notifications (e.g., security alerts, account deletion confirmation)
4. How we share your data
We do not sell your data. We do not share your data with advertisers. We do not use your data for marketing.
Limited disclosure occurs only in these cases:
- Infrastructure providers that host the Zeruth backend and TURN relay (currently Hetzner Cloud, EU). These providers process data solely as instructed and have no independent rights to it.
- Legal compliance — if compelled by valid legal process. We will narrow the disclosure to the minimum required and, where lawful, notify you in advance.
5. Data retention
- Account data — retained while your account is active.
- Diagnostic logs — 14 days for routine entries, 60 days for errors and above.
- Audit log entries — up to 24 months. Personal identifiers are pseudonymised when an account is deleted.
- Backups — up to 30 days. Backups are not used to restore deleted accounts.
6. Your rights
You can:
- Access a copy of the personal data we hold about you — email [email protected] from your registered address
- Correct inaccurate data — display name and email can be edited in the app
- Delete your account — see the Account Deletion page
- Withdraw diagnostic-sharing consent at any time, in the client settings
- Lodge a complaint with your local data-protection authority if you believe we have mishandled your data
7. Children
Zeruth is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered an account, contact [email protected] and we will delete it promptly.
8. International transfers
Zeruth servers are currently hosted in the European Union. If you connect from outside the EU, your data is transferred to and processed in the EU under the protections of the GDPR and the EEA legal framework.
9. Security
Passwords are hashed with Argon2id. All client-server traffic uses TLS. Remote-desktop session media is end-to-end encrypted via DTLS-SRTP. Refresh tokens are scoped per device and can be revoked individually.
No system is perfectly secure; if you become aware of a vulnerability, please report it responsibly to [email protected].
10. Changes to this policy
We will update the effective date at the top of this page when material changes are made. For significant changes (e.g., introducing a new category of data collection), we will notify active accounts by email at least 14 days before the change takes effect.
11. Contact
Questions, requests, or complaints — email [email protected].