Privacy Policy
01Who we are
RoamDeck ("the app") consists of an Android application and a Windows server program ("RoamDeck Server") that you install on your own PC. The data controller is the developer: Gabriele Contarini — contact: support@roamdeck.app.
02No accounts, no profiles
RoamDeck does not require — and does not offer — user accounts. We do not collect names, e-mail addresses, advertising identifiers or usage analytics. Pairing between phone and PC happens locally with a QR code or PIN, and the resulting pairing token is stored only on your devices.
03What stays between your devices
All session content is exchanged directly between your phone and your PC, protected by end-to-end encryption (TLS with certificate pinning on LAN; an end-to-end encrypted channel over WebRTC/DTLS when remote). This includes:
- screen images and audio of your PC;
- keyboard, mouse and terminal input/output;
- files you transfer;
- voice audio for dictation (see section 5).
None of this content is sent to, stored on, or readable by our servers.
04What our servers see
To make remote access work we operate two infrastructure services (currently hosted on Hetzner servers in Germany, EU):
- Rendezvous server (
rv1.roamdeck.app): forwards short, end-to-end encrypted signaling messages so your phone can locate your PC. It cannot decrypt them. - TURN relay: when a direct peer-to-peer connection is not possible (about 10–20% of networks), traffic is relayed through our server. The relayed traffic remains end-to-end encrypted; the relay cannot read it.
These services process technical connection data (IP addresses, timestamps, pseudonymous device identifiers, bytes relayed) in memory and in short-lived operational logs, used exclusively to operate the service, enforce free/Pro bandwidth limits, and prevent abuse. Logs are retained for a maximum of 30 days, are never sold, and are not shared with anyone.
We process this technical connection data to provide the service you request (Art. 6(1)(b) GDPR) and, for abuse prevention and free/Pro bandwidth limits, on the basis of our legitimate interest in running a secure, sustainable service (Art. 6(1)(f)).
To set up a direct connection, your device contacts a STUN server we run on our own EU infrastructure (alongside the relay) to discover its own network address. No third party is involved and no session content is exchanged.
Service providers & transfers. Our own servers are in the EU (Germany, Hetzner). The only other company that processes any data for us is Google (Play Billing and purchase verification), which may involve a transfer to the United States under Google's standard contractual clauses and Data Privacy Framework participation. We use no advertising or analytics providers.
05Voice dictation
- Free tier: where available, speech recognition runs on your Android device using the system's on-device recognizer. On older Android versions without an on-device model, the system recognizer may process the audio through its own provider (e.g. Google); in all cases the audio never passes through our servers.
- Pro tier: audio is sent over the end-to-end encrypted channel to your own PC, where it is transcribed locally by Whisper. It never reaches our servers or any third-party cloud.
06Purchases
RoamDeck Pro is sold through Google Play Billing. Payments are processed entirely by Google; we never receive your payment details. To validate a purchase, the app sends the Google-issued purchase token to our verification endpoint, which checks it with Google in real time and returns a signed, anonymous Pro pass (tier and expiry only). This check is stateless: we keep no purchase database and do not store the purchase token, product ID or your identity; only a short-lived in-memory hash of the token is kept briefly, to rate-limit abuse. We process this data to provide the purchase you requested (Art. 6(1)(b) GDPR). See Google's own privacy policy for how Google processes payment data.
07Android permissions
- Camera — only to scan the pairing QR code.
- Microphone — only for voice dictation, while you use it.
- Local network discovery — to find your PC on the LAN (mDNS/NSD).
- Storage (Android 9 and older only) — to save files you receive into your Downloads folder; newer Android needs no storage permission.
No permission is used for advertising or tracking.
08Data stored on your devices
Pairing tokens, the PC's TLS certificate fingerprint, terminal/session preferences and similar settings are stored locally on your phone and PC. Uninstalling the app and the PC server removes them. You can also revoke individual paired devices at any time from the PC tray menu.
09Your rights (GDPR)
RoamDeck is designed to process as little personal data as possible. For anything covered by the EU General Data Protection Regulation (essentially the technical connection data of section 4) you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority. Contact us at support@roamdeck.app.
10Children
RoamDeck is a technical tool intended for general audiences and is not directed at children under 13. Because RoamDeck has no user accounts and we do not read session content, we do not collect personal data that would identify a user or their age.
11Changes
If this policy changes, the new version will be published at
https://roamdeck.app/privacy with an updated date.
Informativa sulla privacy
01Chi siamo
RoamDeck ("l'app") è composta da un'applicazione Android e da un programma server per Windows ("RoamDeck Server") che installi sul tuo PC. Il titolare del trattamento è lo sviluppatore: Gabriele Contarini — contatto: support@roamdeck.app.
02Niente account, niente profili
RoamDeck non richiede — e non offre — account utente. Non raccogliamo nomi, e-mail, identificatori pubblicitari né analytics di utilizzo. L'abbinamento tra telefono e PC avviene in locale con QR code o PIN, e il token di abbinamento è salvato solo sui tuoi dispositivi.
03Cosa resta tra i tuoi dispositivi
Tutto il contenuto della sessione viaggia direttamente tra il tuo telefono e il tuo PC, protetto da cifratura end-to-end (TLS con certificate pinning in LAN; canale cifrato end-to-end su WebRTC/DTLS da remoto). Questo include:
- immagini dello schermo e audio del PC;
- input/output di tastiera, mouse e terminali;
- i file che trasferisci;
- l'audio della voce per la dettatura (v. sezione 5).
Nulla di tutto ciò viene inviato, salvato o letto dai nostri server.
04Cosa vedono i nostri server
Per far funzionare l'accesso remoto gestiamo due servizi di infrastruttura (attualmente su server Hetzner in Germania, UE):
- Server rendezvous (
rv1.roamdeck.app): inoltra brevi messaggi di segnalazione cifrati end-to-end perché il telefono possa trovare il PC. Non può decifrarli. - Relay TURN: quando la connessione diretta peer-to-peer non è possibile (circa il 10–20% delle reti), il traffico passa dal nostro server. Resta cifrato end-to-end: il relay non può leggerlo.
Questi servizi trattano dati tecnici di connessione (indirizzi IP, orari, identificatori pseudonimi del dispositivo, byte inoltrati) in memoria e in log operativi a vita breve, usati esclusivamente per far funzionare il servizio, applicare i limiti di banda free/Pro e prevenire abusi. I log sono conservati al massimo 30 giorni e non vengono mai venduti né condivisi con nessuno.
Trattiamo questi dati tecnici di connessione per fornirti il servizio che richiedi (art. 6(1)(b) GDPR) e, per la prevenzione degli abusi e i limiti di banda free/Pro, sulla base del nostro legittimo interesse a operare un servizio sicuro e sostenibile (art. 6(1)(f)).
Per stabilire una connessione diretta, il tuo dispositivo contatta un server STUN che gestiamo sulla nostra infrastruttura nell'UE (insieme al relay) per scoprire il proprio indirizzo di rete. Nessuna terza parte è coinvolta e non viene scambiato alcun contenuto delle sessioni.
Fornitori e trasferimenti. I nostri server sono nell'UE (Germania, Hetzner). L'unica altra società che tratta dati per noi è Google (Play Billing e verifica degli acquisti), il che può comportare un trasferimento negli Stati Uniti sulla base delle clausole contrattuali standard di Google e dell'adesione al Data Privacy Framework. Non usiamo fornitori di pubblicità o analytics.
05Dettatura vocale
- Versione Free: dove disponibile, il riconoscimento vocale avviene sul tuo dispositivo Android con il riconoscitore on-device di sistema. Su versioni Android più datate senza modello on-device, il riconoscitore di sistema può elaborare l'audio tramite il proprio provider (es. Google); in ogni caso l'audio non passa mai dai nostri server.
- Versione Pro: l'audio viene inviato sul canale cifrato end-to-end al tuo PC, dove viene trascritto in locale da Whisper. Non raggiunge mai i nostri server né cloud di terzi.
06Acquisti
RoamDeck Pro è venduto tramite Google Play Billing. I pagamenti sono gestiti interamente da Google; non riceviamo mai i tuoi dati di pagamento. Per convalidare un acquisto, l'app invia il token d'acquisto emesso da Google al nostro endpoint di verifica, che lo controlla con Google in tempo reale e restituisce un pass Pro anonimo e firmato (solo livello e scadenza). La verifica è stateless: non teniamo alcun database degli acquisti e non conserviamo il token, l'ID prodotto né la tua identità; solo un hash del token a vita breve resta in memoria, per limitare gli abusi. Trattiamo questi dati per fornirti l'acquisto richiesto (art. 6(1)(b) GDPR). Per il trattamento dei dati di pagamento da parte di Google vedi la privacy policy di Google.
07Permessi Android
- Fotocamera — solo per scansionare il QR di abbinamento.
- Microfono — solo per la dettatura vocale, mentre la usi.
- Rete locale — per trovare il PC in LAN (mDNS/NSD).
- Memoria (solo Android 9 e precedenti) — per salvare nella cartella Download i file che ricevi; su Android più recenti non serve alcun permesso di memoria.
Nessun permesso è usato per pubblicità o tracciamento.
08Dati salvati sui tuoi dispositivi
Token di abbinamento, impronta del certificato TLS del PC, preferenze di terminali/sessione e impostazioni simili sono salvati in locale su telefono e PC. Disinstallando app e server vengono rimossi. Puoi anche revocare i singoli dispositivi abbinati in qualsiasi momento dal menu tray del PC.
09I tuoi diritti (GDPR)
RoamDeck è progettato per trattare meno dati personali possibile. Per quanto rientra nel GDPR (essenzialmente i dati tecnici di connessione della sezione 4) hai i diritti di accesso, rettifica, cancellazione, limitazione, portabilità e opposizione, oltre al diritto di reclamo a un'autorità di controllo (in Italia, il Garante per la protezione dei dati personali). Scrivici a support@roamdeck.app.
10Minori
RoamDeck è uno strumento tecnico destinato a un pubblico generico e non è rivolto a minori di 13 anni. Non prevediamo account e non leggiamo i contenuti della sessione: non raccogliamo quindi dati personali che identifichino un utente o la sua età.
11Modifiche
Se questa informativa cambia, la nuova versione sarà pubblicata su
https://roamdeck.app/privacy con la data aggiornata.