Privacy Policy
Last updated 22 September 2026. Deskbat is operated by Deskbat LLC.
What we never store
The contents of a remote session — what is on the screen, what is typed, what is clicked — are never stored on our servers. A session is a direct encrypted connection between the two computers. When a direct route is unavailable, media passes through our TURN relay, which forwards it without recording or retaining it.
If you start a recording from the Windows app, that recording is written to a folder on the computer doing the recording. It is not uploaded to us and we cannot read it.
The website carries no analytics, advertising or third-party tracking scripts.
What we collect
Your account. Your name, email address, a hashed password, and — because multi-factor authentication is required — your authenticator secret and recovery codes. We never store your password or authenticator codes in readable form.
Your sessions. Which browsers and apps are signed in, and when each was last active, so you can review and revoke them.
Your organization. Organization and site names, who belongs to them, each person's role, and invitations you create, including the invited email address.
Your computers. For each enrolled computer: the name you give it, its permanent Client ID, its operating system and app version, when it was last seen, and its public key. Public keys only verify identity; they cannot decrypt anything.
Connection records. For each connection: which account connected to which computer, whether it was view-only or control, when it started and ended, and why it ended. This is what makes the Activity view possible, and it is deliberately kept so that access to your computers is reviewable.
Administrative activity. Changes to members, permissions, sites and devices, recorded with who made them and when.
Technical data. Our servers and our network provider process IP addresses to route connections and to defend against abuse.
Cookies
We use one cookie, to keep you signed in. It is restricted to the site that set it, is not readable by scripts, and is not used for advertising or tracking. There are no third-party cookies.
Why we hold it
To run the service you asked for: to sign you in, to show you your computers, to enforce who may connect to what, and to give you and your administrators a reviewable record of that access. We do not sell personal data, and we do not use it to build advertising profiles.
How long we keep it
Account, organization and device records are kept while the account or device is active. Connection and administrative records are kept so that access history remains reviewable. When a device is removed or an account is closed, its records are deleted or disconnected from you, except where we must keep something to meet a legal obligation.
Your choices
You can view and change your profile, replace your recovery codes, and sign out other sessions from Settings in My Deskbat. An organization owner or administrator can remove members and devices. To request a copy of your data, correct it, or have your account deleted, email us using the address below.
Children
Deskbat is a tool for work and is not directed at children.
Changes
If we change this policy we will update the date at the top of this page. Material changes will be communicated to account holders.
Contact
Email [email protected] with any question about this policy or your data. Please keep passwords, authenticator codes and unattended-access passwords out of your message.
← Back to Deskbat