Skip to content

Privacy Policy

Effective date: 1 May 2026

This Privacy Policy explains what information the Zeruth remote-desktop platform collects, how that information is used, who it is shared with, and what choices you have. It applies to the Zeruth Android, Windows, and web clients, and to the Zeruth backend that they connect to.

1. Who runs Zeruth

Zeruth is built and operated by an independent developer. For privacy- related questions, contact [email protected].

2. What data we collect

2.1 Account data

If you create an account, we store:

2.2 Device data

For each device enrolled to your account or used in anonymous mode, we store:

2.3 Connection metadata

When two devices establish a remote-desktop session, we record minimal session metadata so the helper and host can find each other and so we can investigate abuse:

2.4 Optional diagnostic logs

If you opt in to diagnostic sharing on the first run of a Zeruth client (the consent banner is off by default), we receive structured log entries — log level, component name, message, and timestamp — to help us debug crashes and connection issues. Diagnostic logs are retained for 14 days by default; entries flagged as Errors or higher are retained for 60 days. You can revoke this consent at any time in the client settings.

2.5 What we do not collect

3. How we use your data

4. How we share your data

We do not sell your data. We do not share your data with advertisers. We do not use your data for marketing.

Limited disclosure occurs only in these cases:

5. Data retention

6. Your rights

You can:

7. Children

Zeruth is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered an account, contact [email protected] and we will delete it promptly.

8. International transfers

Zeruth servers are currently hosted in the European Union. If you connect from outside the EU, your data is transferred to and processed in the EU under the protections of the GDPR and the EEA legal framework.

9. Security

Passwords are hashed with Argon2id. All client-server traffic uses TLS. Remote-desktop session media is end-to-end encrypted via DTLS-SRTP. Refresh tokens are scoped per device and can be revoked individually.

No system is perfectly secure; if you become aware of a vulnerability, please report it responsibly to [email protected].

10. Changes to this policy

We will update the effective date at the top of this page when material changes are made. For significant changes (e.g., introducing a new category of data collection), we will notify active accounts by email at least 14 days before the change takes effect.

11. Contact

Questions, requests, or complaints — email [email protected].