Privacy Policy
This policy explains what Remote Assist processes when you create an account, enroll a device, or use a consent-based assistance session.
Effective August 25, 2026Information we process
- Account information, including your email address, display name, password verifier, plan, and account status.
- When you use Google sign-in, the Google account identifier, verified email address, name, and profile image Google provides for authentication.
- When you use Sign in with Apple, the stable Apple account identifier, verified account or relay email, and name Apple provides for authentication. The server encrypts the Apple authorization needed to honor account deletion.
- Device and installation information, including device name, platform, app version, public-key fingerprint, enrollment state, permissions, and connection status.
- Session and security information, including requests, approvals, timestamps, settings, audit events, network state, aggregate transport byte counters, and diagnostic errors.
- When you subscribe with PayPal, an opaque account reference, subscription and plan identifiers, subscription status, selected billing timestamps and amounts, failed-payment count, and webhook processing records.
Screen and control data
Live screen media and remote-control messages travel through encrypted WebRTC channels between the approved Controller and Endpoint. A relay may forward encrypted traffic when a direct connection is unavailable. The Endpoint reports aggregate WebRTC bytes for plan enforcement, but not screen frames or control contents. Remote Assist does not provide cloud session recording and does not store screen video as part of the service.
The Endpoint keeps assistance visible and uses operating-system permission flows. Account sign-in does not bypass device consent or screen-capture approval.
How we use information
We use information to authenticate accounts, separate each customer's devices, enroll and identify installations, coordinate sessions, enforce plan limits, restore requested sessions, diagnose failures, prevent abuse, and protect the service.
Google sign-in
Google sign-in is used only to establish your Remote Assist identity. Remote Assist never receives your Google password. We validate a short-lived Google identity token and retain the stable account identifier needed to recognize future sign-ins. We do not request access to Gmail, contacts, Drive, Calendar, or other Google services.
Sign in with Apple
Sign in with Apple is used only to establish your Remote Assist identity. Remote Assist never receives your Apple password. We validate Apple's short-lived identity response and encrypt the provider authorization needed to recognize and revoke the connection. If you request account deletion, the service revokes that Apple authorization before deletion proceeds.
PayPal billing
PayPal processes your payer identity and funding information when you approve a subscription. Remote Assist does not receive or store your PayPal password, card number, or bank details. We exchange server credentials with PayPal and retain the limited subscription metadata needed to apply your plan, reconcile renewals and failures, prevent webhook replay, support cancellation, and maintain financial and security records. PayPal processes its copy of transaction data under its own terms and privacy notices.
Sharing and disclosure
We do not sell personal information. Information may be processed by infrastructure providers needed to operate the service, by Google or Apple for sign-in, and by PayPal for subscription billing. It may be disclosed when required by law or used to investigate fraud, abuse, a payment dispute, or a security incident. A person you authorize for assistance can see the screen and control capabilities you explicitly share during that session.
Retention and deletion
Account, enrollment, audit, monthly transfer, and session metadata is retained while needed to provide and secure the service. Expired challenges and other temporary authentication data are removed automatically. An account owner can request deletion from Settings in the Controller app or through the authenticated account portal. Access closes immediately, active sessions end, Sign in with Apple authorization is revoked when present, billing cancellation is requested, and active account data is scheduled for permanent deletion within seven days. Limited financial, security, legal-hold, and rotating backup records may be retained only for their required retention period and are not restored for ordinary service use.
Security and choices
Remote Assist uses encrypted transport, account-scoped authorization, signed installation identities, and device fingerprint pinning. No service can guarantee absolute security. Protect your devices and account, remove devices you no longer trust, and end assistance when it is no longer needed.
Children and family use
Remote Assist is designed for visible support of people you are authorized to help. A parent or guardian is responsible for deciding whether and how the service is used for a minor. It must not be installed or used for hidden monitoring.
Contact
Questions and privacy requests can be sent to avititievsky@gmail.com. Account owners should normally use the in-app deletion control or the account deletion page.