Privacy Policy

Last updated 3 September 2026. Plain language, no surprises.

Office Remote Desk does two different things, and they have genuinely different privacy properties. A remote session or a call travels directly between the two computers and is never stored by the server. Your workspace — chat, files, projects, tracked hours — is stored on the server so that history and search work on every device. We would rather say that clearly than blur the two together.

What never touches the server

Screen pixels, keyboard and mouse input, clipboard contents and transferred files in a remote session are encrypted end to end (DTLS-SRTP) between the two devices. Meeting video and audio go peer to peer between participants the same way. The server only introduces the two ends; it cannot read any of it, and none of it is stored. Call recordings, if you make them, are written to the recorder’s own computer and are never uploaded.

What is stored on the server

So that your team can search yesterday’s conversation from a different machine, workspace data is stored: accounts (name, email, hashed password), chat messages, uploaded files, projects and tasks, meeting records, tracked time and, where enabled, work-diary screenshots. This is not end-to-end encrypted. On a self-hosted deployment it sits on your server, under your control. Passwords are hashed with scrypt and are never recoverable, by us or by anyone.

Connection metadata

The signalling server sees the 9-digit device IDs that need to be introduced and the timestamps of those requests, plus a hardware fingerprint used to run the free trial. That is what makes a connection possible and stops a reinstall minting an endless supply of trials. It is kept while the session is active, plus a short log window for abuse prevention.

Time tracking (WorkTrack)

Only while a member has started their own timer, and only if their workspace has turned it on, the app records: how long the timer ran, how much of each minute had any input, a count of keyboard and mouse events, and periodic screenshots of the primary display.

It never records which keys were pressed, or anything that was typed. There is no setting that turns this into a keylogger: the app has no code that captures typed content, and the database has no column that could store it. Nothing at all is recorded while the timer is stopped or paused.

Members can see their own diary and delete any screenshot of themselves — the tracked minutes stay, the image goes. Administrators of a workspace can see its members’ diaries; nobody else can. Screenshots can be blurred, switched off for particular projects or people, and are deleted automatically after the retention period the workspace sets. Employee monitoring is regulated in many countries: if you enable it, check your local law first.

The website

We count installer downloads on our own server — platform, time and the referring page. Your IP address is not stored: only a salted hash, which lets us tell one person’s five downloads from five people’s and is useless for identifying anyone. There are no third-party analytics scripts, no advertising trackers and no cookies for tracking.

Accounts and payment

A workspace account holds your name and email address. There is no in-app payment and no payment processor: paid plans are activated with a licence key we issue directly, so we hold only what you send us when you ask for one. We do not sell personal data to anyone, ever.

Self-hosted deployments

If you run your own server and TURN relay, none of the above reaches us at all — it is your machine, your database and your backups. That is the deployment we recommend for anyone with a confidentiality obligation to their own clients.

Your choices

You can request a copy of your data or its deletion at any time via our support page. On a self-hosted deployment, ask the administrator of your workspace — the data is on their server, not ours.