RDesk is a self-hosted remote-desktop service: a lightweight agent runs on the machines you choose, and a web console lets you view and control them from your browser. This policy explains what information the service handles, why, and the choices you have.
01Information we collect
To provide remote-access functionality, RDesk processes:
- Account information — the username, display name, and password (stored only as a salted hash) you create to sign in to the web console.
- Agent & device data — for each machine running the agent: a generated Display ID and agent identifier, machine name, operating-system version, the logged-in username reported by the device, and online/last-seen status.
- Connection & session metadata — timestamps of connections, which agent a session targeted, session duration, and approximate transfer volume, used to show activity and keep sessions healthy.
- Network information — IP addresses of agents and viewers, used for routing, security, and abuse prevention.
- Cookies — a single authentication cookie that keeps you signed in to the console. No advertising or cross-site tracking cookies are used.
02Screen content and files
During an active, approved remote session the agent transmits screen images, keyboard/mouse input, clipboard text, and any files you explicitly transfer. This content is relayed in real time between the agent and your browser to make remote control work. RDesk does not record sessions or retain screen content or transferred files on the server beyond what is needed to deliver them for the active session.
03How the information is used
- Authenticate you and maintain your signed-in session.
- List your agents, show their status, and establish remote-control connections.
- Enforce the connection-approval and unattended-access settings you configure.
- Protect the service — detecting abuse, unauthorized access, and operational faults.
RDesk does not use your data for advertising or profiling, and does not sell it.
04Access control & consent
A remote machine is only accessible to accounts authorized on this instance. Unless unattended access is deliberately enabled on that machine, an operator physically present must approve each incoming connection. When a session is active, the agent shows an on-screen indicator so anyone at the machine can see it is being accessed and can end the session.
05Data retention
Account and agent records are kept for as long as your account and agents remain registered on this instance. Connection metadata is retained to display activity and for security, and may be cleared periodically by the operator. Screen content and in-transit file data are not persisted after a session ends.
06Security
Console traffic is served over encrypted HTTPS, and passwords are stored only as salted hashes. Access to a machine requires a valid account, and unattended access can be protected with a separate password. No system can be guaranteed perfectly secure; you are responsible for keeping your credentials and unattended passwords confidential and for who you authorize.
07Your choices
- Remove an agent at any time from the dashboard to stop that machine from being reachable.
- Leave unattended access disabled so every connection needs on-device approval.
- Uninstall the agent to remove it and its local identifiers from a machine.
- Request deletion of your account and associated records from the instance operator.
08Children
RDesk is a tool for IT administration and is not directed to children under 13. It should be used only by those authorized to administer the machines involved.
09Changes to this policy
This policy may be updated as the service evolves. Material changes will be reflected here with a revised “last updated” date.
10Contact
Questions about this policy or your data should be directed to the operator of this RDesk instance at privacy@rdesk.bd.