Heavendesk Privacy Policy

This is an earlier version of this document, kept as it was published. It no longer applies. Read the current version (1.9).

Version
1.7
Last updated
5 October 2026
Effective
5 October 2026

1. Who is responsible for your data

The controller of your personal data is:

INTEGRA MATEUSZ RYCZKO Gen. Ludomiła Rayskiego 34, 05-140 Łacha, Poland Sole trader registered in the Polish Central Registration and Information on Business (CEIDG) NIP: 1131950903 · REGON: 142677103 Email: support@heavendesk.com

We have not appointed a Data Protection Officer, as we are not required to. Write to the address above with any question about your data.

2. What this policy covers

This policy covers personal data we process through:

  • the website at heavendesk.com,
  • your Heavendesk Account,
  • the broker and the relay that connect your devices,
  • email we send you about your Account.

It does not cover the machines you run Heavendesk on. Those are yours.

3. What we do NOT collect

We want this near the top, because for a remote desktop product it is the part that actually matters.

  • We never see the contents of your sessions. Screen, audio, keyboard and mouse input are end-to-end encrypted between your own devices. When a direct connection is not possible and traffic passes through our relay, the relay forwards ciphertext: it cannot read what it is carrying and it does not try. Nothing from a session is stored by us.
  • The Software does not report what you do. It never sends us your screen, your keystrokes, your files, the names of your machines, the programs you run, or who you connect to. There is an optional diagnostics report, described in section 4.8: it is off unless you turn it on, it carries technical facts about the software and the hardware it is running on, and it is not linked to your Account.
  • The website has no analytics, no tracking pixels and no advertising cookies. There is no Google Analytics, no third-party tracker, and no profiling.
  • We never receive your card number. Payments go directly to Stripe.
  • We do not sell, rent or share your data for anyone else's marketing.

4.1 Account data

Username, email address, password (stored only as an Argon2id hash, never in plain text), email verification status and time, account role, the language you want our emails in, and the times the Account was created and last updated.

If you turn on two-factor sign-in, we also keep the secret your authenticator app uses, encrypted, and your recovery codes, stored only as hashes.

Why: to create and run your Account and to identify you. Legal basis: Article 6(1)(b) GDPR, performance of a contract with you.

4.2 Sign-in sessions

A hash of your session token (the token itself is only in your browser cookie), the expiry time, and a truncated browser user-agent string.

Why: to keep you signed in, and to let you and us identify and revoke a session. Legal basis: Article 6(1)(b), and Article 6(1)(f) legitimate interest in account security.

4.3 Device data

For each device you enrol: a device identifier, the name you give it, its role, its public key, an encrypted device token, and the time it was last seen.

Why: to authenticate your devices, to connect them to each other, and to enforce the number of devices your plan allows. Legal basis: Article 6(1)(b).

4.4 Subscription and billing data

Your plan, subscription status, the identifiers Stripe assigns to you as a customer and to your subscription, renewal and cancellation dates, and the entitlement recorded against your Account.

Card details are handled by Stripe and never reach our systems.

Why: to sell you a plan, to charge for it, and to grant the right limits. Legal basis: Article 6(1)(b), and Article 6(1)(c) legal obligation for invoicing and accounting records.

4.5 Connection data

To connect two of your devices, the broker learns the public IP address and port each of them is reaching us from, and passes them to the other device so that a direct connection can be attempted. When a direct connection fails, the relay learns the same addresses in order to forward packets between them.

This is unavoidable: establishing a connection over the internet means each end learns where the other is. Both ends are normally your own machines. When you connect to a machine someone has shared with you, or someone connects to a machine you shared (section 4.9), the other person's device learns your address in the same way.

Why: to establish sessions. Legal basis: Article 6(1)(b).

4.6 Server logs

The website, the broker and the relay write operational logs. These contain IP addresses, timestamps, usernames, device identifiers, and records of events such as sign-ins, failed sign-ins, device enrolment and revocation, and relay allocations opening and closing. They do not contain session content.

Why: to keep the Service running, to diagnose faults, to rate-limit, and to detect and investigate abuse and attacks. Legal basis: Article 6(1)(f), our legitimate interest in the security and availability of the Service.

4.7 Support requests

If you open a support ticket from your Account, or email us for support or to make a complaint, we process what you send, including any logs you attach, together with your username and email address so that we can reply. When we answer a ticket, we also tell you by email.

Why: to answer you. Legal basis: Article 6(1)(b), or Article 6(1)(f) where you are not a customer.

4.8 Diagnostics (optional, off by default)

If — and only if — you switch it on, the Software sends periodic technical reports about itself. This is off when you install it and stays off until you choose otherwise. You can turn it off again at any time in Settings, and it stops immediately.

What a report contains:

  • The version of the Software, your operating system and its version, the kernel release, and the CPU architecture.
  • Hardware class: CPU model, the graphics driver in use, amount of memory, how many monitors are attached and at what resolutions.
  • Which capture method and which video encoder the Software selected, and where it had to fall back to a slower one, and why.
  • Performance figures: target and actual frame rate, bitrate, dropped frames, reconnections, how long a session lasted, and whether it ran directly or through the relay.
  • An error signature if it stopped badly — an identifier for where a failure happened, not a message.

What a report never contains:

  • Anything from a session — no image, no video, no audio, no keyboard or mouse input.
  • The names of your devices, your username, your computer's hostname, or file paths.
  • Window titles, or the names of programs you are running.
  • Your IP address. Reports arrive over the network, so the connection itself necessarily carries an address; our receiving code never reads it and there is no field for it in the diagnostics records.
  • Your MAC address, disk serial numbers, or any other permanent hardware identifier.
  • Which of your devices connected to which, or when you were using the machine.
  • Any link to your Account, your email address, or your subscription.

You can see exactly what would be sent. The Settings page shows the real report, generated by the same code that would send it, before you decide.

How reports are identified. Each installation generates a random identifier when you first turn diagnostics on. It exists only so that a hundred reports from one machine are not mistaken for a hundred machines. It is not derived from your hardware, your Account or anything else about you, and it is destroyed and replaced if you turn diagnostics off and on again. You can see the current identifier in Settings — quote it to us if you ever want the reports from your installation deleted.

Why: to find out which hardware and which distributions the Software actually runs badly on, so we can fix it. A remote desktop touches an unusually wide range of graphics drivers, and most failures we have found so far were on hardware we do not own.

Legal basis: Article 6(1)(a) GDPR — your consent. Storing the identifier on your device is done with the same consent, as required by Article 5(3) of the ePrivacy Directive. You may withdraw it at any time; withdrawal does not affect reports already sent, which you can ask us to delete using the identifier above.

4.9 Shared machines

You can let another Heavendesk user connect to one of your machines, and accept machines others share with you. For each share we keep who shared which machine with whom, whether it has been accepted, and whether the other person may only watch. A shared session uses the lower of the two accounts' plans, so we look at both plans when it starts.

To make sharing work, the other person sees your username and the name of the shared machine. When they connect, the person at your machine sees their username and the name of the machine they are connecting from. When you invite someone, we email them to say so.

For the owner of a shared machine, we keep a log of connections to it through shares: who connected, from which of their machines, when, and how long for.

Why: to let you give other people access to your machines, to let you see who used that access, and to enforce the limits you set. Legal basis: Article 6(1)(b).

4.10 Records of what you agreed to

When you create an Account, and again when you buy a plan, we record which versions of the Terms of Service and the End-User Licence Agreement you accepted, when, and where (at sign-up, or the checkout it belonged to), together with a fingerprint (a SHA-256 hash) of the exact text you were shown. When you buy a plan, we also record that you asked for the service to start before the withdrawal period ends (section 10 of the Terms).

Why: so that we can show what was agreed, and when. Legal basis: Article 6(1)(b), and Article 6(1)(f), our legitimate interest in being able to establish and defend legal claims.

5. Cookies and local storage

We use two cookies:

Name Purpose Type Lifetime
rd_session Keeps you signed in. Contains a random token only. Strictly necessary 14 days
hd-lang Remembers the language you chose with the language switch. Contains a language code only. Remembers your choice; set only when you use the switch 1 year

Both are httpOnly and SameSite=Lax, so scripts in your browser cannot read them, and other websites cannot have them sent with requests they make in the background.

The website's language. Until you choose one with the switch, we go by the language your browser says you prefer, which it sends with every request. We use it only to pick the language, and do not store it.

There are no analytics, advertising or tracking cookies, which is why there is no cookie banner: cookies that are strictly necessary, or that only remember a choice you made yourself, do not require consent.

If you turn on diagnostics (section 4.8), the Software stores the random identifier described there on your computer, outside your browser: the installation identifier in its own system directory, and the record of whether it has asked you in its configuration file. Both are removed when you turn diagnostics off. This storage is done with your consent, as Article 5(3) of the ePrivacy Directive requires.

6. Who else processes your data

We use a small number of providers, each under a data processing agreement, each only for the purpose listed:

Provider Purpose Location
Stripe Payment processing, billing, invoices Ireland and the United States
Resend Sending transactional email (verification, account and billing notices) United States
Zoho The support@heavendesk.com mailbox: receiving and answering email you send us European Union
Oracle Cloud Infrastructure Hosting the website, the broker and a relay Germany (Frankfurt)
OVHcloud Hosting a second relay Poland (Warsaw)

The website and the broker run on servers in Germany, and the relays in Germany and Poland. All of them are inside the European Economic Area, so hosting them involves no transfer outside the EEA.

Backups. Copies of the website and broker databases are kept on our own equipment in Poland, so that the Service can be restored after a failure. They are encrypted in transit and at rest, and are used for nothing else.

Payments. When you buy a plan, the sale is made by Link (Sold through Link, LLC), Stripe's merchant of record service (section 1 of the Terms). Link receives your order and your payment and billing details and handles them as a separate controller, under its own privacy notice.

Stripe and Resend are established in or transfer data to the United States. Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on Standard Contractual Clauses. You can ask us for details of the safeguards in place.

We may also disclose data where we are legally required to, for example in response to a lawful order from a competent authority.

7. How long we keep it

Data Retention
Account data Until you delete your Account, then removed
Sign-in sessions Until they expire (maximum 14 days), then deleted automatically
Device records Until you revoke the device or delete your Account
Email verification tokens Until used or expired
Billing and invoice records 5 years from the end of the tax year, as required by Polish accounting and tax law
Server logs Up to 30 days, longer only where a specific security incident is being investigated
Shares Until the owner or the other person ends the share, or the shared machine or either Account is removed. Invitations nobody accepts lapse after 14 days
Log of connections to your shared machines 90 days
Support tickets and support email Up to 2 years from the last message in the conversation, or until you delete your Account if that comes first
Records of what you accepted (section 4.10) Until you delete your Account
Backups Up to 12 months, then deleted on a rolling schedule
Diagnostics reports (section 4.8) Up to 12 months, then deleted. Aggregate counts derived from them (for example "how many installations use this graphics driver") are kept without any identifier and cannot be traced back to an installation.

Deleting your Account revokes your enrolled devices, ends every share you gave or were given, and removes your Account record from both the website database and the broker. Billing records that we are legally required to keep are retained for the period above, and nothing else. Copies in our backups are not edited one by one: they disappear as those backups expire, within 12 months. If we ever have to restore a backup, we delete again anything that had been deleted after that backup was taken.

8. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict processing;
  • object to processing based on our legitimate interest, including the processing of logs described in section 4.6;
  • receive your data in a portable, machine-readable form;
  • withdraw consent, where we rely on consent, without affecting processing already carried out.

To exercise any of these, write to support@heavendesk.com. We will respond within one month, and will tell you if we need longer because a request is complex. You can delete your Account at any time by writing to that address from the email address registered to it; we delete it without undue delay, and at the latest within one month.

If you believe we are handling your data unlawfully you may complain to the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl

If you live in another EU country you may complain to your own supervisory authority instead.

9. Security

  • Passwords are stored only as Argon2id hashes, on both the website and the broker.
  • Session tokens are stored only as SHA-256 hashes; the token itself exists only in your browser.
  • Stored device tokens are encrypted at rest with a key held outside the database.
  • Two-factor sign-in secrets are encrypted, and recovery codes are stored only as hashes.
  • Backups are encrypted.
  • Sessions between your devices are end-to-end encrypted, and the relay only ever handles ciphertext.
  • Website traffic is served over HTTPS.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.

10. Automated decision-making

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. The entitlement attached to your Account is worked out mechanically from the plan you bought; it is not a decision about you.

11. Children

Heavendesk is not directed at children under 16. Do not create an Account if you are under 16. If we learn that we hold data about a child under 16 without proper authorisation, we will delete it.

12. Changes to this policy

We may update this policy. The version and date at the top always show the current one. If a change materially affects how we handle your data, we will notify Account holders by email at least 14 days before it takes effect.

Where a change introduces something that needs your consent, we do not switch it on and tell you afterwards. Diagnostics (section 4.8) were introduced in version 1.1 of this policy: they are off for every existing installation, and they stay off unless you turn them on yourself.

13. Contact

Questions about this policy, or about your data:

Integra Mateusz Ryczko Gen. Ludomiła Rayskiego 34, 05-140 Łacha, Poland support@heavendesk.com

14. Language

This policy is also published in Polish. If you live in Poland and are a Polish citizen, the Polish version governs.