HydraDesk
Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how GSMFABRICA CO LIMITED ("HydraDesk", "we", "us") handles information when you use the HydraDesk Support software, the hydradesk.org website, and our remote-support service (the rendezvous and relay servers).
The short version
- HydraDesk is a self-hosted remote-support tool — we run our own servers, not a third-party cloud service.
- A support session starts only when the person being helped runs the app and shares their ID and one-time password.
- Remote sessions are end-to-end encrypted; we do not store what happens during a session.
- We do not sell your data or use advertising trackers.
Who we are
HydraDesk is a service operated by GSMFABRICA CO LIMITED, a company registered in Hong Kong, which is the data controller for the personal data described here. It operates the hydradesk.org website and the HydraDesk Support service. For any privacy question or request, contact privacy@hydradesk.org.
Information we process
Website visitors. When you visit hydradesk.org, our servers keep basic technical logs — your IP address, browser type, the pages requested and the time — to operate the site and protect it against abuse. We do not use advertising or cross-site tracking cookies.
Support sessions. To connect two devices, our servers process the device/peer ID, the IP addresses of the participants, and connection metadata (timestamps, session duration, and whether the session used a direct or relayed connection). The contents of a session — screen images, keyboard and mouse input, files and clipboard — travel over an end-to-end encrypted connection directly between the two devices. When a direct connection is not possible, that encrypted traffic is relayed through our server, but it is not decrypted or stored by us.
Why we process it
- To provide the service — establishing and maintaining the connection you request.
- Security and integrity — preventing abuse, diagnosing faults, and keeping the service reliable (our legitimate interest).
- Consent — where a specific processing activity requires it.
Retention
Connection metadata and server logs are kept only as long as necessary to operate and secure the service, and are then deleted. We do not retain the content of remote sessions.
Sharing and processors
We do not sell your personal data or share it for advertising. Our servers are operated on infrastructure provided by our hosting provider, which acts as a processor on our behalf. We may disclose information where required by law or to protect the service and its users.
Security
Sessions use end-to-end encryption, and clients verify the server using a public key. Access to the servers is restricted. No system is perfectly secure, but we take reasonable measures to protect the service.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or object to the processing of your personal data, or to data portability (for example under the GDPR). To exercise a right, contact privacy@hydradesk.org. You may also have the right to complain to your local data-protection authority.
Children
HydraDesk is not directed to children and is intended for use by adults arranging or providing technical support.
Changes to this policy
We may update this policy from time to time. The "last updated" date above always reflects the current version.
Contact
Questions about this policy: privacy@hydradesk.org.