Privacy policy
TideDesk collects as little as it can. The app has no analytics, advertising or automatic upload service. This page says what does leave your computer, and what we keep when you buy a licence.
The controller for the personal data described here is Gîrlea Cristian-Valeriu PFA, Str. Dimitrie Hârlescu, Sector 2, București, Romania. Contact: [email protected].
The app
Between your computers
TideDesk sends screen, system audio, input and optional text clipboard data only between the two computers you connect. Settings and saved computers are stored on your computer. Clipboard sharing is off by default; clipboard contents are not saved to settings or logs.
Finding an internet address (STUN)
While running, the host asks public STUN servers (by default stun.l.google.com and stun.cloudflare.com) for its internet address about every 25 seconds. Each request is 20 bytes with no content; those servers learn the computer's public IP address and port. The viewer asks once when it connects over the internet. This can be turned off or pointed at other servers in Settings.
Introductions by device ID
By default, the host registers its device ID, public certificate and public IP address and port with TideDesk's connection service, rendezvous.tidedesk.app, refreshed about every 25 seconds, so that the service can introduce viewers who ask for that ID. A viewer connecting by device ID tells the service its own public address and which ID it asked for; a viewer that never connects by ID never contacts it. The service keeps this in memory only, logs counts rather than IDs or addresses, and never carries sessions, access codes or any screen, audio, input or clipboard content. Registration can be turned off, or another service named, in Settings.
Opening a direct path
Small "punch" packets (42 bytes, no content) go only to the address you typed or the one the service returned. The session then runs directly between your computers; TideDesk never relays it through a server.
Your local network
A viewer connecting by device ID also broadcasts a 24-byte query for that ID on its local network (UDP port 47800), so other computers there can see which ID it looks for. A host answers only queries for its own ID, from its own local network. Nothing of this leaves the local network. Answering can be turned off in Settings.
Problem reports
The app can send a problem report to TideDesk's report service, report.tidedesk.app, only when you press "Send to TideDesk" after seeing the whole report. The service keeps the report's text, the app version and the time. It never stores the sender's IP address: it holds it in memory only, to allow at most 5 reports an hour from one address. An organisation can send its computers' reports to its own service instead, or turn sending off, with administrator settings.
This website
This website adds no analytics scripts or cookies. It requests public release information from GitHub, which receives technical request data such as your IP address; see GitHub's privacy statement. Our hosting provider may also process technical request data to deliver and protect the site; see Cloudflare's privacy policy.
When you buy a licence
Paddle.com processes your payment and billing details as merchant of record; see Paddle's privacy notice. Paddle sends us your name, email address, country, the edition bought and the order number, so that we can issue your licence, answer support requests and keep the records the law requires. Romanian accounting law requires 10 years for invoices and supporting records; we keep the rest for as long as the licence is active plus 2 years.
Your licence file holds your name, email and edition and stays on your computers; TideDesk never sends it anywhere.
When you write to us
When you email [email protected], we use what you send only to answer you and to fix what you report. Bug reports you post on GitHub are public; never post licence or payment details there.
Emails about your licence
After you buy, we email the address you paid with a confirmation of what you bought. When you ask on the licences page, we email it a link that signs you in there. Neither email contains your licence key: you read it on this website only. These emails go out through Resend, which receives your email address and the email's text to deliver them; see Resend's privacy policy. Asking with an address that bought nothing sends nothing and keeps nothing.
Paddle sends its own emails about a purchase: the receipt and the subscription confirmation, and, if you open the checkout and leave without paying, one email offering to continue. Those come from Paddle under its privacy notice, linked above, not from us.
So that the emailed link opens only for the person who asked, the licences page keeps a random value in your browser's storage and sends it, with a 6-digit code it shows you, when you ask. The licence service keeps a fingerprint of that value and the code with the link for 30 minutes. The value identifies nothing else and is not used to follow you. To keep robots out, the form can also ask Cloudflare Turnstile to check that a person is asking; Turnstile then receives technical data such as your IP address (see Cloudflare's privacy policy).
Your rights
You may ask to see, correct or delete the personal data we hold about you, to restrict or object to its use, or to receive a copy, by writing to [email protected]. Records the law requires us to keep are kept for that time. You can also complain to the Romanian data protection authority (ANSPDCP, dataprotection.ro) or the one where you live.
Changes
We say on this page when it changes. A change that affects what we keep about customers is also sent by email.