Privacy Policy

Last updated: July 30, 2026

This Privacy Policy explains how lcxl-remote-desk (the "Service") collects, uses, and protects your information. Please read it before using the Service.

1. Information We Collect

Account information (username and optional email); when you choose Google, GitHub, WeChat, or Weibo sign-in, the stable external account identifier returned by that provider and any email suggestion or display name saved for form prefill; optional telemetry data (anonymous information such as service, operating system, and host details and a unique client identifier); and device evidence collected temporarily for diagnostics and redacted before use. Provider email and display name never become local credentials automatically.

2. Remote Session Content

Remote screen, audio, and input are transmitted directly between the control and controlled endpoints over WebRTC; the signaling server does not retain your remote screen content.

3. AI Diagnostics & Data Processing

Diagnostic evidence is always redacted before it reaches a model (fail-closed); audits record only content-free summaries (counts, sizes, token usage, provider, etc.) and never retain raw model output, screenshots, or prompts. AI model keys are kept as server-side secrets, never returned to the browser and never written to logs.

4. Storage & Security

Account and configuration data are stored in the deployment’s database and transmitted over secure channels. In private-cloud deployments the data is fully under the customer’s control.

5. Third Parties & Data Sharing

When you use features such as TURN relay or third-party AI model providers, the relevant data is transmitted to the corresponding service as required by the feature. When you actively choose external sign-in, your browser is redirected to the selected OAuth provider and the authorization-code exchange and identity-profile request necessarily transfer data to and from that provider. The Service does not persist OAuth access or refresh tokens, and it does not automatically treat provider email or display name as a local credential. We do not sell your personal information.

6. Cookies & Sessions

Session-based cookies are used for authentication between the browser and the server to keep you signed in.

7. Your Rights

You may access, correct, or delete your account information and may delete your account. In organization / private-cloud deployments, the relevant administrator can assist with these actions.

8. Contact & Changes

Updates to this policy will be published on this page. To exercise the rights above or for any privacy-related questions, contact us through the operator’s published contact details.

Service operator: lcxbox.app; Contact email: [email protected].