This policy describes how Vibe Remote (“Vibe Remote,” “we,” or “us”) processes information when you visit our website, create an account, connect a Mac, or use the Vibe Remote mobile web application.
Information we collect
Account information
When you sign in with GitHub, we receive the GitHub account identifier and basic profile information that GitHub makes available through the authorization screen. We use it to create and secure your Vibe Remote account.
Device and authorization records
We store registered Mac and phone identifiers, public keys, enrollment and pairing token hashes, access grants, revocations, and timestamps needed to authenticate your devices.
Operational information
Our service processes connection timestamps, relay routing identifiers, coarse network and error information, and aggregate service metrics. This information is used to operate, secure, diagnose, and improve the service.
Development content
In hosted mode, terminal traffic, source-file content, Git data, agent messages, approvals, screen video, and remote input are end-to-end encrypted between your paired phone and Mac. The hosted relay is designed not to possess the keys needed to read that content.
How we use information
- Authenticate accounts and connected devices.
- Route encrypted connections between your phone and Mac.
- Detect abuse, investigate failures, and maintain service reliability.
- Communicate material security, service, or policy updates.
- Comply with applicable legal obligations.
Retention
Account and active device records are retained while your account remains active. One-use phone pairing secrets expire after five minutes, and Mac enrollment tokens expire after ten minutes. Hosted web sessions have a 30-day idle expiration and a 90-day absolute expiration. We retain limited security and operational records only as long as reasonably necessary for the purposes described above.
Service providers
We use infrastructure, content delivery, authentication, monitoring, and backup providers to operate Vibe Remote. These providers process information on our behalf under their own contractual and security obligations. GitHub handles GitHub sign-in under GitHub’s privacy policy.
Cookies and local storage
The public marketing site does not use advertising cookies. The application uses a secure authentication cookie and browser storage for device keys, pairing state, and application preferences. A phone’s private device key is created as non-extractable browser cryptographic material.
Your choices
You can revoke a paired phone, disconnect a Mac, remove browser data, or request account deletion. You can also remove Screen Recording and Accessibility permissions in macOS System Settings.
Security
We use technical and organizational safeguards appropriate to a service that provides remote terminal and desktop access. No service can guarantee absolute security. Read our security overview for implementation details.
International processing
Depending on your location and the infrastructure used to provide the service, information may be processed outside your country. Where required, we use appropriate safeguards for international transfers.
Changes to this policy
We may update this policy as the product and legal requirements change. We will publish the revised policy here and update the effective date. Material changes may also be communicated through the service.
Contact
For privacy questions, access requests, or deletion requests, contact support@vibe-remote.net.