Privacy Policy
Last updated: June 26, 2026
This Privacy Policy explains how Tethry ("Tethry," "we," "us," or "our") collects, uses, discloses, and protects information when you use our remote-desktop software, websites, and related services (collectively, the "Service"). By creating an account or using the Service, you acknowledge the practices described in this Policy. If you do not agree, please do not use the Service.
1. About Tethry and Our Privacy Approach
Tethry lets you install a small Windows application on your computer (the "Host") and control that computer from a phone or any web browser (the "Viewer"). Remote sessions are end-to-end encrypted. Our relay forwards only sealed packets that it cannot read, decrypt, or inspect. As a result, Tethry does not have access to the contents of your remote sessions, the screen data transmitted between your devices, keystrokes, files, or anything else carried inside the encrypted session.
The information described below is the limited operational, account, security, and billing data we necessarily process to provide, secure, and bill for the Service.
2. Information We Collect
2.1 Account Information
- Email address and (where you provide it) your name or display name.
- Authentication credentials managed through our authentication provider (Supabase), including password hashes or, where you choose Google sign-in, an associated Google account identifier. Tethry does not receive or store your Google password.
- Account settings, preferences, and the devices you register to your account.
2.2 Connection and Security Logs
To power your personal security dashboard and to detect and prevent unauthorized access, our relay records metadata about connection events (not session contents). This includes:
- The IP address of the Host computer and of the Viewer device.
- Approximate geolocation (city and country) derived from those IP addresses.
- The internet service provider (ISP) associated with those IP addresses.
- Connection and disconnection timestamps and total session duration.
Approximate geolocation and ISP information are derived from IP addresses using a third-party lookup service (ipapi.co). This connection metadata describes who connected, from where, and for how long — it does not reveal what occurred during the encrypted session.
2.3 Usage Telemetry and Device Information
- Diagnostic and performance data such as application version, operating system version, feature usage, error and crash reports, latency, and connection quality metrics.
- Technical information automatically generated when you interact with our websites or applications, such as browser type, device identifiers, and pages or screens viewed.
2.4 Payment Information
Payments and subscriptions are processed by Stripe. Tethry does not collect or store full payment card numbers. We receive limited billing metadata from Stripe, such as your subscription plan and status, billing country, the last four digits and brand of your card, and transaction identifiers. Your card details are handled directly by Stripe under Stripe's own terms and privacy policy.
2.5 Cookies and Similar Technologies
We use cookies and similar technologies on our websites. See Section 6 for details.
2.6 Communications
If you contact us (for example, at [email protected]), we collect the information you provide and our correspondence with you so we can respond and keep records.
3. How and Why We Use Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service, including establishing and relaying encrypted connections between your devices.
- Create and manage your account and authenticate you.
- Power your security dashboard and detect, investigate, and prevent unauthorized access, fraud, abuse, security incidents, and other harmful or unlawful activity.
- Process subscriptions, trials, one-time "add time" purchases, renewals, and other billing through Stripe.
- Develop new features and improve performance, reliability, and user experience through analytics and telemetry.
- Communicate with you about your account, transactions, security alerts, technical notices, updates, and support requests.
- Enforce our Terms of Service and other agreements, and protect the rights, property, and safety of Tethry, our users, and others.
- Comply with applicable legal obligations and respond to lawful requests.
4. Legal Bases for Processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, we process personal data under the following legal bases:
- Performance of a contract: to provide the Service you request, manage your account, and process payments.
- Legitimate interests: to secure the Service, detect anomalies and abuse, maintain connection logs for your security dashboard, improve and develop our products, and operate our business — provided these interests are not overridden by your rights.
- Consent: where required, for example for certain analytics cookies. You may withdraw consent at any time.
- Legal obligation: to comply with applicable laws and lawful requests.
5. Sharing and Disclosure of Information
We do not sell your personal data. We share information only as described below.
5.1 Service Providers and Sub-Processors
We share information with trusted third parties that perform services on our behalf and are bound to use it only to provide those services:
- Stripe — payment processing and subscription billing.
- Supabase — authentication and database hosting for account data.
- Cloudflare — hosting, content delivery (CDN), and TURN relay for forwarding sealed, encrypted session packets.
- ipapi.co — IP-based approximate geolocation and ISP lookup.
- Fontshare — web font delivery for our websites and applications.
Because remote sessions are end-to-end encrypted, our hosting and relay providers forward only sealed packets they cannot read.
5.2 Legal and Safety Disclosures
We may disclose information if we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our agreements; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Tethry, our users, or the public.
5.3 Business Transfers
If Tethry is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy.
5.4 With Your Direction
We may share information at your request or with your consent, including with team administrators on a Team plan who can manage members and view account-level information for their team.
6. Cookies and Tracking
We use two categories of cookies and similar technologies:
- Essential cookies — required for the Service to function, such as keeping you signed in, maintaining sessions, and protecting security. These cannot be disabled through our consent control.
- Analytics cookies — help us understand how the Service is used so we can improve it.
Where required by law, we obtain your consent before setting non-essential cookies. You can manage your preferences at any time through our cookie settings control (the "Cookie settings" link in our footer). You can also control cookies through your browser settings, though disabling certain cookies may affect functionality.
7. Data Retention
We keep personal data only for as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Raw connection IP logs (including full Host and Viewer IP addresses) are retained for approximately 90 days, after which they are truncated and/or anonymized so they are no longer reasonably linkable to you. Aggregated or anonymized connection statistics may be retained longer.
- Account data is retained while your account is active and for a reasonable period afterward to comply with legal, tax, accounting, dispute-resolution, and security obligations.
- Billing metadata is retained as needed to meet financial and legal recordkeeping requirements.
When data is no longer needed, we delete, anonymize, or aggregate it.
8. Security
We take reasonable and appropriate technical and organizational measures to protect information, including end-to-end encryption of remote sessions, encryption in transit, access controls, and a relay architecture designed so that we cannot read session contents. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and devices.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete your personal data, subject to legal exceptions.
- Portability / Export — request a copy of certain data in a portable format.
- Objection and Restriction — object to or request that we restrict certain processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
9.1 GDPR Rights
If you are in the EEA or UK, you may exercise the rights above and lodge a complaint with your local data protection authority. We will respond within the time required by applicable law.
9.2 California and U.S. State Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct it, and to be free from discrimination for exercising your rights. Tethry does not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. Because we do not sell or share personal information in this way, no "Do Not Sell or Share My Personal Information" action is required, but you may still exercise your other rights.
9.3 How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on your request, and we may decline requests where permitted by law. You may use an authorized agent where allowed.
10. International Data Transfers
Tethry operates globally and uses service providers located in various countries. Your information may be processed and stored in countries other than your own, including the United States, which may have data-protection laws different from those in your jurisdiction. Where required, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
11. Children's Privacy
The Service is not directed to, and is not intended for, children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us personal data, please contact us at [email protected] and we will take appropriate steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the updated Policy on our website. Material changes may be communicated through the Service or by other means. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at [email protected].