POCKETPILOT WEBSITE PRIVACY NOTICE Updated 10 September 2026 CONTROLLER Christian Tchobansky, trading as Appler's Shop Privacy requests: https://pocket-pilot.net/support MAC APP PERMISSIONS On macOS, Screen Recording allows picture sharing, Accessibility allows approved input controls, and Automation may be requested for system power controls. Audio is not captured. Permission status is checked locally, not sent as a website analytics event. Permission requests do not send a test power command. You can revoke permissions in System Settings. Mac pairing and activation secrets use the app's protected local storage. The optional Anywhere processing described below applies to both Windows and Mac. WEBSITE AND SUPPORT The website host processes ordinary request information such as IP address, time, requested page, device/browser information, and security signals to deliver and protect the site. PocketPilot does not use advertising trackers or create marketing profiles. PocketPilot keeps daily aggregate totals of qualifying website entries and installer download starts. A website entry is counted only when a public page is opened directly or from outside PocketPilot. Reloads, navigation within the site, background loading, administrative traffic, and excluded networks are omitted. Each aggregate record contains only the UTC day, metric name, and total count. This ordinary site counter does not use an analytics cookie or store a visitor identifier, referrer, page-by-page history, or exact event time. These totals are estimates, not unique-person counts, and may still include automated traffic. To exclude the owner's network from these totals, Cloudflare's edge-provided network address is normalized and converted to a server-keyed one-way value before comparison or storage. IPv6 addresses are reduced to their network prefix for this purpose. PocketPilot does not store or display the raw address. The resulting pseudonymous exclusion value is used only to prevent owner and test traffic from entering the aggregate counters. Administrative areas are restricted and protected. Their access process and security configuration are intentionally not published. Short-lived abuse- prevention data is used only to protect those areas and is not used for advertising or visitor profiling. When a visitor uses the support form, the submitted name, reply email, optional purchase reference, request category, and message are encrypted with a server-only key and stored in the website database so the owner can review and answer the case through PocketPilot's protected support system. Administrative replies are encrypted there as well. The private notification email contains only the case reference, category, and a private case-management link, not the customer's contact details or message. For a referral-link deletion request, the server uses the secure referral receipt cookie to attach the correct referral reference and approval state; the form does not send a referral ID. The raw source IP address is not stored. One-way values derived from the request token, payload, source address, and email address support duplicate protection and abuse limits. When a visitor requests a referral link, PocketPilot stores the public name, requested link, sharing plan, request status, reference, review times, completed-download total, and the time of a statistics reset or link-name change. The raw source IP address is not stored; a server-keyed one-way value is used only for short-term abuse limits. A secure HttpOnly request-receipt cookie lets the same browser check the decision, view private statistics, change an approved link name, and submit a verified deletion request. The cookie lasts for up to 180 days and its lifetime is refreshed after a successful statistics check. An approved referral link first shows a choice. If the visitor agrees, PocketPilot sets a secure HttpOnly SameSite referral cookie for 30 days with a signed referral reference, expiry, and random nonce. After one complete Windows installer delivery, PocketPilot stores a server-keyed one-way attribution value, referral reference, release version, and completion time. This prevents the same signed attribution receipt from being counted twice. No raw IP address, email, user-agent, browsing history, or raw referral cookie is stored. Declining never blocks the site or download. PAYMENTS AND LICENSING PayPal and, when selected, the PayPal-backed Apple Pay or Google Pay integration process payment credentials and billing contact data. PocketPilot receives and keeps payment references and status, a one-way browser purchase-claim identifier, the recorded checkout acknowledgement version and time, license issuance and email-delivery details, and activation records. An activation record includes its activation identifier, the installation's public key and derived public identifier, activation and verification times, and the related purchase reference. Raw Windows hardware serials and the installation's private key are not uploaded. PocketPilot never receives complete card details. The owner may issue a complimentary Premium license without PayPal. PocketPilot then keeps the license environment, an opaque license identifier, a private owner label, issuance and rotation times, generation, active or revoked status, and activation details. The formatted signed license key is shown to the owner when created or rotated but is not stored as a full key in the complimentary- license ledger. Complimentary grants are kept separate from purchases and revenue. A secure HttpOnly payment-claim cookie lets the same browser recover its verified purchase. It lasts for up to one year and is not used for advertising. The payer email returned by PayPal or Google Pay, or a license-delivery email the buyer explicitly enters after verified payment, may be sent to the transactional email provider for delivery but is not stored in PocketPilot's payment database. SERVICE PROVIDERS Cloudflare hosts the website and encrypted support-case database. PayPal processes checkout, PayPal payments, and the PayPal-backed Apple Pay and Google Pay options. Google provides the Google Pay wallet interface and the private inbox used to receive case notifications. Resend delivers purchase emails, support acknowledgements, case notifications, and owner-written support replies when configured. Providers receive only the data needed for their role and may process information outside the EEA under their applicable safeguards and terms. RETENTION AND RIGHTS Purchase, payment, licensing, and purchase-related support data is processed to perform the Premium contract or take requested steps connected with it. Accounting and consumer-law records are processed to meet legal obligations. Site security, abuse prevention, reliable message delivery, general support, referral-request review, and the establishment or defence of legal claims are processed for the seller's legitimate interests in safely operating and supporting PocketPilot. Optional referral attribution is processed only after the visitor's consent. The digital-delivery confirmation is recorded as part of the purchase contract. Encrypted support-case content, encrypted owner replies, and related delivery metadata in the website database are assigned an expiry 730 days after submission and are deleted during later support-system maintenance activity. The encryption key remains server-only. One-way rate-limit values are removed after their applicable short abuse-prevention windows. Case notifications and correspondence held by email providers are kept only while needed to handle the request or establish or defend claims, subject to the mailbox retention process. Data may be kept longer when required for a dispute or by law. Purchase and accounting records are retained for the periods required by applicable law. Pending and rejected referral requests are assigned an expiry 180 days after submission and are removed during later referral-system maintenance. Approved and later-deactivated link details and the non-identifying completed-download total remain so the owner can operate active links and preserve the admin history. Pseudonymous referral conversion records provide the last-30-days and latest-completion statistics; they are assigned a 730-day expiry and later deleted without reducing the stored total. The owner can reset a link's visible completed-download total to zero. A reset does not delete existing pseudonymous conversion records, because they remain necessary until expiry to prevent the same signed attribution receipt from being counted again; conversions completed before the reset are excluded from the recent and latest-completion statistics. Changing a link name keeps its referral reference and statistics, while the former name is retired so it cannot be reassigned. If the owner approves a verified deletion request, the referral link and its pseudonymous conversion records are deleted and the public name remains retired to prevent later takeover. The 30-day attribution cookie can be removed at any time in browser settings. Complimentary-license records, including revoked tombstones and their activation history, remain so PocketPilot can enforce revocation, prevent reuse on another installation, and preserve the owner's license audit history. Revocation stops new activation and online renewal, but an already signed offline activation lease may remain valid until its expiry. Updated releases use 7-day leases. Older releases continue receiving legacy 30-day leases during the compatibility period and must update before legacy issuance is retired; the seven-day maximum therefore applies only after an installation has converted to the current lease version. You may ask for access, correction, deletion, restriction, portability, or object to processing where applicable. You may also complain to the competent data-protection authority. Submit a request at https://pocket-pilot.net/support. LOCAL WINDOWS REMOTE In local Wi-Fi mode, the companion serves the remote on your trusted private network without using the relay. Anywhere instead forwards encrypted screen pictures through a separate relay. Neither mode uploads pictures to the marketing website, PayPal or support, unless you share a screenshot yourself. POCKETPILOT: ANYWHERE — OPTIONAL PREMIUM CONNECTION Anywhere is an opt-in connection for every Premium user with version 1.4.0 or later. The PC and paired browser connect through relay.pocket-pilot.net; the mobile controller is served at remote.pocket-pilot.net. It does not ask for a Windows password or PIN, and the Premium key is not a relay password. To enable and renew access, the PC sends a signed Premium activation proof and proves possession of its protected activation identity. The relay verifies these proofs and stores a one-way binding derived from the license and installation identifiers alongside the connection registry. It does not receive card details or the installation's private activation key. Verification uses short-lived challenges; the PC renews access automatically while enabled. Control messages, entered text, app information and icons, and transient screen pictures are encrypted between devices. The relay forwards encrypted content and is not designed to decrypt or record it. PC audio is not carried. Connection infrastructure can process IP addresses, request times, browser information and security signals. The relay sees random connection/device identifiers, timing, traffic size and disconnect reasons; encryption does not hide this metadata. The registry stores random PC-room and mobile-peer identifiers, one-way hashes of transport credentials, expiry times and aggregate traffic accounting. Names, permissions and trusted identities are held on the PC. The browser keeps its non-extractable private key and connection credentials in IndexedDB as necessary connection storage, not an advertising cookie. Clearing it requires pairing again. Invitation secrets use the URL fragment, are removed by the controller, and are not included in the page request. Cloudflare provides the HTTPS edge and tunnel for these connections. The separate relay is operated on PocketPilot's server, with its server operator and network providers supporting delivery. This is not the payment or support database. Provider processing and international safeguards described above also apply to connection infrastructure. Active sockets and unused invitations are in memory and disappear on expiry or restart. Removal revokes the phone's active registry entry. Expired mobile entries are pruned when another controller enrolls. PC registrations and remaining registry entries have no scheduled automatic deletion job; expiry blocks access but is not deletion. They remain until operator removal. Local backups retain the latest 14 scheduled snapshots; removed records can remain until backup rotation. Application event logs contain fixed service events, not control content, and retain seven rotations. Infrastructure providers have their own retention; these periods do not describe Cloudflare's records. Connection processing provides the optional service you request. Abuse controls and limited operational records serve the legitimate interest in secure, reliable operation. Switching Anywhere off stops new connections without deleting pairings. Remove access in Windows Devices, or use Forget on a connected phone. Request registry deletion or exercise data rights through https://pocket-pilot.net/support. Never send registration files, pairing links or private keys. Clear local browser storage separately after removing access. Fresh session keys provide forward secrecy for the updated protocol: later theft of saved identity keys alone should not reveal earlier recorded session content. This does not change the protection of older traffic. Independent security review is pending. A compromised paired device or controller page can expose access and content while in use. Read https://pocket-pilot.net/security#anywhere before sensitive use.