Who operates PocketDesk

PocketDesk is operated by 王威卫. For privacy questions or requests, email support.pocketdesk@gmail.com.

Remote screen, input, and clipboard

PocketDesk captures your Mac’s display, or a window you choose, and transmits it to your connected iPhone or iPad. Pointer actions, keyboard input, and composed text travel from the iPhone or iPad to the Mac. Plain text you copy on the Mac during a session is sent to the connected iPhone or iPad.

Session traffic may pass through a PocketDesk relay when the devices cannot connect directly. Remote-session contents are encrypted between your devices; the relay forwards encrypted traffic and does not decrypt or record screen video, keystrokes, composed text, or clipboard contents in server files or connection logs. Temporary buffering is used to transmit and display the session.

Text copied on the Mac is written to the system clipboard of the iPhone or iPad and can remain there under that device’s normal clipboard behavior. The iPhone or iPad’s clipboard is not sent automatically; you can paste it into PocketDesk’s compose sheet and send it as text. Longer composed text, or text with line breaks, is inserted on the Mac by briefly placing it on the Mac’s clipboard, after which the previous plain-text clipboard is put back. Applications you control on the Mac handle the information you enter according to their own practices.

Information used for accounts and connections

Local-network connections do not require a PocketDesk account or subscription. Nearby Mac discovery uses the local network. If you enable access from outside that network, PocketDesk uses account and device information to identify your Mac and authorize a connection.

  • Account information: an internal account ID, your sign-in provider’s user identifier, an email address when supplied by that provider, the account creation time, and a purchase-association token. Sign in with Apple may supply an Apple private relay email address. An Apple authorization refresh token is stored encrypted on the account service so the service can revoke that authorization when you delete the account. Sign in with Google uses the relevant account categories if that option is offered and you choose it.
  • Device and pairing information: a registered Mac’s device ID, device name, platform, connection authentication credential, and pairing time. Whether a Mac is online is held only in the running service’s memory. A separate, short-lived six-digit registration code associates the Mac with your account. The 26-character local pairing key and its QR code authorize the screen/control connection; that key is saved in your devices’ Keychains and is not stored in the account service.
  • Subscription information: product ID, transaction and original transaction IDs, purchase and expiry times, purchase environment, signature/event times, refund or revocation status, and a hashed purchase-ownership token. Apple handles payment details; PocketDesk does not receive your full card number.
  • Operational connection records: IP addresses, ports, device names and identifiers, timestamps, and registration, disconnection, relay, error, and API route/duration events. These are used to operate the service, diagnose connection failures, and investigate misuse. Remote-session payloads and pairing keys are not included in these logs.
  • Support messages: your email address, the message and attachments you choose to send, and any technical information you provide. Please remove private screen content, passwords, tokens, pairing keys, and QR codes from support attachments.
  • Website requests: the server and network providers that deliver getpocketdesk.com process basic request information, such as IP address and requested page, to serve and protect the website. The website sets no cookies, loads no third-party scripts or analytics, and its web server keeps no access log of page visits.

Why we use this information

We use information to provide requested connections, sign you in, associate your devices with your account, validate subscription access, maintain service reliability and security, answer support requests, and meet applicable legal obligations.

We do not sell or rent personal information, use it for cross-app or cross-site advertising tracking, or use remote screen, input, or clipboard contents for advertising or AI training. PocketDesk does not include third-party advertising or behavioral analytics SDKs.

Where a legal basis is required, we process information necessary to provide the service you request, protect the service and its users, comply with law, or act on your consent where consent is required. You can withdraw optional permissions through your device settings; functions that depend on them will stop working.

Who else processes information

Apple processes sign-in information, App Store purchases, subscription management, and refunds under its own policies. Google processes sign-in information if Google sign-in is offered and you choose it. PocketDesk receives only the information needed to authenticate you and validate access; it does not receive your Apple or Google password.

The connection service for the first release is being prepared on Vultr infrastructure in Los Angeles, United States. Account, signaling, and relay information described in this policy is processed there when you use that service. The website is served from the same Vultr infrastructure, its domain name is resolved by Cloudflare, and support email uses Gmail. These providers process information needed to deliver and protect those services and may process it outside your country of residence. We share information only as needed for the purposes described here.

We may disclose information when required by applicable law or a valid legal request, or when reasonably necessary to protect users, service security, or legal rights. We cannot disclose remote-session content that we have not retained.

How long information is kept

  • Account and device records are kept while your account exists. Removing a Mac deletes its association with the account. Successful account deletion revokes the associated Apple authorization and removes your account identity, email, registered devices, connection credentials, and stored Apple refresh token from the PocketDesk account store.
  • A limited subscription ledger can remain after account deletion to restore an existing subscription to the same verified sign-in identity, process refunds or reversals, and prevent transaction replay or transfer to another account. It contains a hashed ownership token and transaction identifiers, product, environment, dates, and refund/revocation status, without your email, sign-in identifier, account ID, devices, or refresh token. These records are pseudonymous, not anonymous: they can be associated with a later account when the same identity restores a purchase. Each subscription-period record is deleted no later than 30 days after that period’s expiry; new verified renewal periods have their own expiry and retention deadline.
  • The retention limit for PocketDesk connection-service logs is no more than 30 days. These logs are separate from account records and the subscription ledger.
  • Screen frames, input, composed text, and synchronized clipboard payloads are processed for the live session and are not retained as server recordings. Information you put into another app or your device clipboard remains subject to that app or device’s own storage behavior.
  • Support correspondence is kept for as long as reasonably needed to handle your request and any related follow-up. You may ask us to delete it.
  • If applicable law requires a limited record to be retained, we keep only the required information for the required period. Apple and other independent providers may retain their own records under their policies; deleting a PocketDesk account does not delete those providers’ records.

Your controls and requests

On iPhone or iPad, open PocketDesk → Account → Delete account and confirm. The app may ask you to authenticate with Apple again. If Apple revocation or account deletion cannot complete, the app shows an error so you can retry; do not treat an error as a successful deletion. If you cannot access your account, contact support.pocketdesk@gmail.com from the email address associated with it. We may need proportionate information to verify the request.

Account deletion does not cancel an Apple subscription or remove local pairing information from your devices. Manage or cancel your subscription in iPhone Settings → your name → Subscriptions. Stop sharing on the Mac to end access, and keep local device credentials secure.

You can request access, correction, deletion, or an explanation of how your data is used by emailing us. Depending on your location, you may also have rights to portability, restriction, objection, withdrawal of consent, or a complaint to your privacy regulator. We handle requests under applicable law and do not penalize you for exercising privacy rights.

Production use and test/review installations, such as TestFlight, use separate account and purchase-record services with the same data categories and retention rules described above. Deleting an account removes its records only in the environment currently used by that installation, subject to the limited ledger retention; it does not automatically delete another environment’s account or test records. To request deletion in another environment, email support.pocketdesk@gmail.com. Sign in with Apple authorization belongs to the same app, so revoking that authorization during deletion can affect the same Apple identity’s authorization in the other environment without deleting that environment’s data.

Permissions and security

The Mac host needs Screen Recording permission to capture the display or the window you choose, and Accessibility permission to send pointer and keyboard actions. The iPhone/iPad app uses Local Network permission to discover nearby Macs; macOS may ask the Mac host for the same permission so nearby devices can find it. You can revoke these permissions in system settings. While it is sharing, the Mac host keeps the Mac from going to sleep when idle, and keeps the display on while a device is connected.

Camera access is optional and used only to scan the Mac’s pairing QR code. Camera frames are processed on the iPhone/iPad and are not uploaded or saved as photos or videos by PocketDesk. The decoded pairing key is saved in the device Keychain. You can enter the 26-character key manually instead; camera permission is not required for remote control.

Remote screen and input transport uses TLS or DTLS with a randomly generated pairing credential. The local pairing key contains 128 bits of randomness; the shorter account-registration code does not replace it. Account requests use HTTPS and signaling uses TLS. Saved local pairing keys and account session tokens are kept in the system Keychain; the server stores Apple refresh tokens encrypted. Security also depends on your devices, software versions, network, and keeping pairing keys, QR codes, and account access private. No method of transmission or storage can guarantee absolute security.

Children and changes

PocketDesk is a general-purpose remote desktop tool and is not directed to children. If you believe a child has provided personal information without the authorization required by applicable law, contact us so we can investigate and remove it when appropriate.

We update this policy when the service or data practices change. The date at the top of this page identifies the current version. For a material change that requires notice or consent, we provide it as required by applicable law.

Contact

Operator: 王威卫. Privacy and support email: support.pocketdesk@gmail.com.