Legal
Privacy Policy
Last updated June 28, 2026
This Privacy Policy explains what data RealFrame (“we”, “us”) collects, how we use it, and the choices you have. It applies to the RealFrame website, apps, and services. A foundational point: RealFrame remote sessions are end-to-end encrypted. Our servers route only ciphertext and we cannot see the contents of your screens, input, or files.
1.Data we collect
Account data: name, email, organization, and authentication data (a hashed password, or a Google account identifier if you sign in with Google). Device metadata: for devices you enroll, a device name, public key, network reachability/NAT type, and last-seen time (used for presence and connection brokering, not session contents). Billing data: handled by Stripe; we store a customer/ subscription identifier and plan status, not your full card number. Usage & diagnostics: log and aggregate telemetry (e.g. connection latency/quality) used to operate and improve the Service. Cookies: strictly-necessary cookies for sign-in/session state.
2.What we do NOT collect
We do not have access to the contents of your remote-desktop sessions. Because sessions are end-to-end encrypted between your devices, the coordinator and relay see only encrypted bytes. We do not sell your personal data.
3.How we use data
To provide and secure the Service (authentication, device enrollment, connection brokering), to process payments, to communicate with you (verification, receipts, service notices), to prevent abuse and fraud, and to improve reliability and performance. Where required, we rely on legal bases including performance of a contract, legitimate interests, consent, and legal obligation.
4.Service providers (subprocessors)
We share limited data with vetted processors solely to run the Service: Stripe (payments), Resend (transactional email), Google (optional sign-in), and Fly.io (hosting & database). Each processes data under its own terms and only as needed to provide its function.
5.Data retention
We keep account and billing records for as long as your account is active and as required for legal, tax, and audit purposes, then delete or anonymize them. Diagnostic logs are retained for a limited period. You can request deletion as described below.
6.Your rights
Depending on your location (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email privacy@realframe.io. We will respond within the timeframes required by applicable law. You may also delete your account from settings, which removes your account data subject to the retention above.
7.Security
We protect data with encryption in transit and at rest, end-to-end-encrypted sessions, identity-pinned connections, scoped access controls, and least- privilege practices. No system is perfectly secure; we work continuously to protect your data and will notify affected users and regulators of qualifying incidents as required by law.
8.International transfers
We may process data in the United States and other countries. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross- border transfers.
9.Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
10.Changes & contact
We may update this Policy; material changes will be notified via the Service or email. For privacy questions or requests, contact privacy@realframe.io. The data controller is Gopher Tech, LLC, 30 N Gould St Suite R, Sheridan, WY 82801, USA.