Privacy policy
Last updated: July 20, 2026
Latenz streams a desktop from your machine to your browser or device, peer-to-peer. This policy explains what personal data we process to make that work, what we deliberately never have access to, and the rights you have over your data. It is written to be read, not skimmed past.
The short version
- We never see, store or can decrypt your screen content, audio, keystrokes, clipboard or transferred files. Media is encrypted end-to-end between your host and your viewer (see the security page); our servers handle only login, host registry and connection setup.
- We collect the minimum needed to run accounts, sessions and billing.
- We don't sell data, run ads, or use third-party advertising trackers.
Data we process
| Data | What exactly | Why (legal basis) |
|---|---|---|
| Contact-form submissions | Email address and whatever you tell us — organisation, role, the software you use, what you need. Never an IP address. | Replying to your enquiry (pre-contractual measures) and your consent |
| Account | Email address, user ID, sign-in timestamps (via Firebase Authentication) | Provide the service (contract) |
| Host metadata | Host name you chose, OS and hardware/codec capabilities, agent version, tags, last-seen time | Show and manage your fleet (contract) |
| Session log | Which viewer (or guest link) connected to which host, start time — never the session content | Security auditing of access to your machines (legitimate interest) |
| Relay usage | Bytes relayed through TURN per account, per billing cycle. No relay is deployed at present, so no such bytes are being recorded. | Metering plan allowances and credits (contract) |
| Billing | Subscription and purchase state. Payment details (card, address, VAT) are collected and held by Paddle, our merchant of record — they never reach our servers | Paid plans (contract, legal obligations) |
| Connection data | IP addresses seen by our signaling and relay servers while a connection is active; standard server logs | Operating and securing the service (legitimate interest) |
Data we do not process
Your video, audio, input events, clipboard and file-transfer contents flow directly between your host and your viewer over encrypted WebRTC. If a TURN relay ever carries a session, it forwards packets it cannot decrypt and keeps only byte counts; no relay is deployed at present, so today every session is direct or it does not connect. We have no mechanism to watch a session, record one, or hand one to anyone else — the capability does not exist in the architecture, which is a stronger guarantee than a promise.
Cookies and local storage
There are no advertising cookies and no third-party trackers of any kind. What exists:
- Firebase Authenticationkeeps your session token in your browser's local storage. Sign-in does not work without it.
- NEXT_LOCALE — a cookie remembering whether you chose Italian or English, so the choice survives the next visit.
- latenz-theme — local storage, remembering the light or dark preference you picked.
- latenz_gate — set only while the public site is in its pre-launch state, and only if you have been given the link that opens it. It carries no information about you: a timestamp and a signature proving the link was valid. It disappears at launch.
- Paddle sets its own cookies during checkout, as described in its privacy policy.
Analytics
The public pages — this one, the home page, pricing, the business page — carry Umami, which we run ourselves on our own EU server. It is not a third party: nothing about your visit is sent anywhere else.
It records the page address and the page that referred you, your browser, operating system and device type, your screen size and browser language, and an approximate location — country, region, city — derived from your IP address. It sets no cookie and stores no IP address: your address is combined with your browser string into a hash that changes every day, which is enough to count a visit and not enough to follow you across days or across sites. There is no column in the database that could hold an IP even if we wanted one. It honours the browser's Do Not Track signal. Aggregated statistics are kept indefinitely; there is no per-visitor record to keep.
The dashboard and the session viewer carry no analytics at all. The script is loaded only on the public pages listed above, and it is also given the list: if you move from a public page into the app without reloading — clicking “Sign in” and going on to your dashboard — every measurement is discarded before it is sent, not filtered afterwards. Nothing observes you once you are signed in.
Who we share data with (subprocessors)
The analytics above is deliberately absent from this list: we run it ourselves, on our own server, which is the reason we chose it.
- Google Firebase — authentication (email, credentials, sign-in events).
- Paddle — payments, as merchant of record; the checkout contract for paid plans is between you and Paddle.
- IONOS — hosting of the platform and database (EU data center, Germany).
- Cloudflare — TLS termination and DDoS protection in front of the web app and API.
Relay (TURN) servers, when deployed, are operated by us and a session may use the region nearest to you (including outside the EU); relay traffic is end-to-end encrypted media we cannot read. No relay is deployed at present. We share data with no one else, except if legally compelled — and even then, the session content everyone actually cares about is not ours to give.
Retention
- Account, host and billing records: for the life of the account.
- Session log and relay counters: up to 12 months, then deleted or aggregated. The session log records host/account identifiers, timestamps and end reason only — no IP addresses and no session content.
- Contact-form submissions: 24 months from our last exchange with you, then deleted. You can ask us to delete one sooner and we will.
- Server logs: up to 30 days.
- Deleting your account removes your account record, hosts, guest links and session history; billing records are retained as long as tax law requires.
Your rights (GDPR)
If you are in the EU/EEA or UK, you can ask us to access, correct, export, restrict or delete your personal data, object to processing based on legitimate interest, and lodge a complaint with your supervisory authority. We honor the same requests from everyone else too. Write to [email protected]; we respond within 30 days. Where processing rests on legitimate interest (session audit log, server logs), we've judged it necessary to protect exactly the thing this product touches — access to your machines — and you can object at that address.
We do not use your data for automated decision-making or profiling, and we do not knowingly provide the service to children under 16.
Data transfers
The platform and database run in the EU. Where a subprocessor processes data outside the EU (Google, Paddle, Cloudflare, non-EU relay regions), transfers rely on their EU Standard Contractual Clauses / Data Privacy Framework certifications.
Changes and contact
If this policy changes materially, we'll note it here and, for significant changes affecting active accounts, notify you by email. Data controller and contact: Ilaria Zanotto, a sole proprietor established in Italy (PEC: [email protected]) — [email protected].