This policy explains what happens to your data when you use Remote Visio: the browser extension published in the Chrome Web Store as “Remote Visio Camera”, the sending web page at relay.remotevisio.com (which remotevisio.com/send leads to), the relay service behind that page, and this website, remotevisio.com.
The short version: Remote Visio has no account and no server of ours in the audio or video path. Your voice, your picture and the meeting’s sound travel directly between your own devices, encrypted. To find each other, your devices go through our relay on Cloudflare, which passes only connection messages that are encrypted end to end between them. The extension and the sender page send us no analytics, no crash reports and no usage data. This website uses Google Analytics only if you accept it.
Who we are
Remote Visio is published by Hykops. Hykops is the controller of the personal data described in this policy that it actually receives: the relay’s connection data, the website data and the emails described below. You can reach us at omar@hykops.com for any question about this policy or your data.
Remote Visio is free software under the GNU Affero General Public License v3.0, originally written by Shu Chunhui (github.com/hueshu/relaymic). The source code that Hykops builds the extension, the sender page and the relay from is public at github.com/ohayak/relaymic, so you can check the statements in this policy against the code.
How Remote Visio works, in one paragraph
On the computer you control through remote desktop, you add the Remote Visio extension to a Chromium browser. On the device in front of you (a laptop, phone or tablet), you open the sender page, remotevisio.com/send, pair it with that computer once (the extension shows a link or QR code, the page shows a number, you type it on the computer and click Allow), and press Start. The page sends your microphone and, if you choose, your camera to the extension over WebRTC, and plays the meeting’s sound back to you. On the computer, the extension offers web meetings three devices: Remote Visio Microphone, Remote Visio Speaker and Remote Visio Camera. The audio and video go from one of your devices to the other. They never pass through Hykops.
The browser extension “Remote Visio Camera”
The extension is published in the Chrome Web Store as “Remote Visio Camera” (the name dates from when it carried only the camera). It runs in Chrome, Edge, Brave, Arc, Vivaldi, Opera and other Chromium browsers on the computer you remote into. Its single purpose is to add Remote Visio Microphone, Remote Visio Speaker and Remote Visio Camera to the device lists of web pages, connected to your own sending device, which you pair with it.
Permissions and why it needs them
- storage: to save your settings and your answers for each site, on this computer.
- offscreen: to keep the connection to our relay and the WebRTC connections that carry your device’s microphone, camera and speaker in a hidden page of the extension, because a browser service worker cannot hold them. That page has no user interface and plays nothing aloud.
- alarms: to check once a minute that the hidden page is running, so your device can reconnect after a browser restart.
- unlimitedStorage: to keep the pairing keys of your devices from being deleted when the browser needs space. The extension stores a few kilobytes.
- Scripts on
https://pages,http://localhostandhttp://127.0.0.1: meetings run on many different sites, so the extension’s scripts must be present on any secure page to add the three devices to that page’s device list and answer the page’s request for them. The scripts do not read page text, forms, passwords, cookies or your browsing history, and they do not report which sites you visit. A site gets audio or video from Remote Visio only after you allow it.
The extension does not ask for access to your tabs, cookies, browsing history or downloads, and contains no remote code. The only server it contacts is our relay, relay.remotevisio.com, described below.
What it handles
- Audio and video from your own sending device, delivered into the pages you allowed, as a microphone and a camera would be. The extension decodes them to hand them to each page.
- The sound an allowed page plays into Remote Visio Speaker, sent to your own sending device.
- The website origin in the address bar of a page that asks for the devices (for example
https://meet.google.com). The extension needs it to ask for and remember your consent. It tells your paired device which sites use the devices (as a status on the sender page), once that device sends its microphone. - One local network address of the computer (for example
192.168.1.20), which a page you allowed can see in the connection that brings it the devices. Chrome gives sites the same kind of information once you let them use a camera or microphone. A page never sees a public address through Remote Visio.
All of this goes between the extension and the pages on the same computer, and from there only to your own sending device. None of it reaches Hykops or any third party, apart from the meeting service you chose to use, which receives your audio and video as it would from any microphone and camera.
What it stores
In the browser’s extension storage on this computer, not synced to your other devices:
- your two settings, Offer Remote Visio’s devices to websites and Use Remote Visio by default;
- the sites you allowed or blocked;
- the version of the consent question you answered, and the last consent window you closed without answering (site, window and time), so it doesn’t ask again at once.
In the extension’s own database (IndexedDB, which web pages cannot read): the pairing keys of your devices (non-extractable), the hashes of their relay tickets, their names and the platform they reported, when each was paired and last used, the name you gave this browser, and the identifier of this browser’s relay mailbox. Nothing of it is synced.
While the browser runs, it also keeps the consent windows that are open and how often a site’s question was dismissed, in session storage that the browser clears when it quits.
Your control
Each site must ask you once before it can use Remote Visio’s devices, and one answer covers all three. You can remove a site in the extension’s popup at any time: its connections close and it asks again next time. You can switch all of Remote Visio’s devices off with Offer Remote Visio’s devices to websites. The popup lists your paired devices with Remove next to each; a removed device can no longer connect, and a device not used for 60 days is removed by itself. Removing the extension from your browser deletes everything it stored.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In plain words: the extension uses the data it handles only to provide its single purpose described above. It does not sell that data, does not use or transfer it for any other purpose, does not use or transfer it for advertising or to determine creditworthiness or for lending, and no person at Hykops can read it, because it never reaches us.
The sending web page
The page you open on your sending device is served by us at relay.remotevisio.com. remotevisio.com/send redirects there.
- It asks your browser for permission to use your microphone and, if you turn the camera on, your camera. It sends them only to the computer you selected under Computers, one at a time.
- It saves your choices in that browser’s local storage, on your sending device only: which of the microphone, camera and speaker are on, the microphone gain and speaker volume, the sound profile (Denoise, Clean or Raw), the devices you picked, and whether the debug log is on.
- It keeps your pairings in that browser’s database (IndexedDB), on your sending device only: for each paired computer, its name and identifier, the pairing keys (non-extractable), the relay ticket that lets the page reach that computer, and when it was paired and last used; and the name you gave this device. They stay until you forget the computer on the page or clear the site’s data. Safari may delete a page’s data by itself after seven days without a visit.
- It sets no cookies, loads no third-party scripts, and contains no analytics. Its only outside link points to the source code on GitHub.
- Its debug log stays in the page. It leaves the page only if you press Copy and paste it somewhere yourself.
- Its code comes from our servers, so whoever controls our deployment could change it. We publish the hashes of the files we serve (
relay/send-manifest.jsonin the source repository), so anyone can check that what relay.remotevisio.com serves is what the repository holds.
The relay
The relay is a small service of ours on Cloudflare, at relay.remotevisio.com, through which your sending device and the extension find each other and set up their connection. Everything that passes through it between a paired device and its computer is encrypted end to end with keys the two made during the pairing.
- What it sees: the IP address of each side, the times and sizes of the encrypted messages, whether a computer’s browser is online, and, when a paired device connects again, the ticket that device presents. With Cloudflare’s request data, it can derive an approximate location from the IP address.
- What it never sees: the connection details (SDP), your network candidates, device names, the pairing number, keys, audio or video.
- What it keeps: for each computer, the hashes of its paired devices’ tickets and two timestamps (when its room was created, when it was last online); a pairing room counts the devices that joined it. A computer’s relay room is deleted 24 hours after it has no paired device left, or 90 days after the computer was last online. A pairing room is deleted after 10 minutes.
- Request logs (Cloudflare Workers Logs): time, route, status and request details such as IP address, approximate location and browser type, with query strings (and so room identifiers) removed. They are deleted automatically after at most 7 days.
- Legal basis: our legitimate interest in providing the connection you asked for (GDPR Article 6(1)(f)).
The relay never carries audio or video. Remote Visio does not provide a TURN relay: if your two devices cannot reach each other directly, they do not connect, and no media of yours passes through any server of ours.
This website
Hosting
remotevisio.com is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). To deliver the pages and protect the site from abuse, Cloudflare processes technical data about each request: your IP address, browser type, the page requested and the time. The request logs kept in our Cloudflare account (Workers Logs: time, page requested, status, and request details such as your IP address and browser) are deleted automatically after at most 7 days. Cloudflare’s own processing for security and network operations follows the Cloudflare privacy policy. Our legal basis is our legitimate interest in running a working and secure website (GDPR Article 6(1)(f)).
Analytics, only with your consent
If you click Accept in the cookie banner, the site loads Google Analytics 4 (property G-RMG8MNGGZQ), provided by Google LLC or, in the European Economic Area and the UK, Google Ireland Limited. It tells us which pages are visited, how visitors arrived, and general information such as country, device type and browser. It uses the _ga and _ga_RMG8MNGGZQ cookies, described in our Cookie Policy. Google receives your IP address with each request and uses it to estimate your approximate location; according to Google, Google Analytics 4 does not log or store IP addresses. We use this information only to understand how the site is used and to improve it. We do not use it to identify you, for advertising, or to build profiles.
If you click Decline, or do nothing, Google Analytics is not loaded and no analytics cookies are set. If your browser sends a Global Privacy Control signal, we treat it as Decline and do not show the banner. You can change your choice at any time with Cookie settings at the bottom of every page. Our legal basis is your consent (GDPR Article 6(1)(a)), which you can withdraw at any time without affecting what happened before. You can read how Google uses information from sites that use its services.
If you write to omar@hykops.com, we receive your email address and what you write. We use them only to answer you and to follow up on your request. If you send us the sender page’s debug log, it contains your devices’ network addresses and names, the name of the computer you send to, and the website origins of the meeting pages that used Remote Visio; we use it only to solve your problem and delete it with the conversation. Our legal basis is our legitimate interest in answering the people who contact us, or the steps you ask us to take (GDPR Article 6(1)(b) and (f)).
What the website does not do
No account, no forms, no newsletter, no advertising, no social media trackers and no fonts or scripts loaded from third parties before you consent. Links to other sites (GitHub, the Chrome Web Store) take you to services that have their own privacy policies.
Who receives data
We do not sell personal data, and we do not share it for advertising. Service providers that process personal data for us (Cloudflare for hosting and the relay, Google for analytics) do so under data processing terms that require them to protect it at least as well as this policy does. The parties involved are:
- Cloudflare: hosting of the website and of the relay (request data, the relay’s connection data), and one of the default STUN servers (IP address and port).
- Google: Google Analytics on the website, only after your consent; one of the default STUN servers (IP address and port); the Chrome Web Store, which distributes and updates the extension under Google’s policies.
- Xiaomi: one of the default STUN servers (IP address and port).
- GitHub, which hosts the source code, under GitHub’s policies.
- The meeting services you use (for example Google Meet, Microsoft Teams or Zoom on the web), which receive the audio and video you send into a meeting, as with any microphone and camera, under their own policies.
- Authorities, if the law requires us to disclose data we hold. Given the above, that can only be the relay’s connection data, website data and emails.
About the STUN servers. To find a direct network path between your devices, both the extension and the sender page ask public STUN servers for their public address: stun.l.google.com (Google), stun.cloudflare.com (Cloudflare) and stun.miwifi.com (Xiaomi). A STUN server sees the IP address and port of the device that asks it, at the moment it asks. It never receives your audio or video. Each operator handles that data under its own privacy policy (Google, Cloudflare, Xiaomi).
How long data is kept
- On your devices: the extension’s storage and the sending page’s choices and pairings stay until you delete them (see the next section); a paired device is removed from the computer after 60 days without use.
- The relay: a computer’s room is deleted 24 hours after it has no paired device left, or 90 days after the computer was last online; pairing rooms after 10 minutes; the relay’s request logs after at most 7 days.
- Website hosting logs: the request logs in our Cloudflare account are deleted after at most 7 days; Cloudflare’s own security logs follow its policy.
- Google Analytics data: event-level data is kept for the retention period set in our Google Analytics property, at most 14 months, then deleted automatically by Google. Reports that only contain totals, with no identifier, may be kept longer. The cookies themselves expire after up to 2 years, or when you withdraw consent.
- Emails: kept as long as needed to deal with your request and any follow-up, and deleted within two years of the last exchange.
Deleting Remote Visio’s data from your devices
- Browser extension: remove a device or a site in its popup, or remove the extension from your browser’s extensions page, which deletes everything it stored, pairings included.
- Sending page: choose Forget next to a computer under Computers, or clear the site data for relay.remotevisio.com in your sending device’s browser settings.
- The relay keeps nothing that identifies you once your devices are unpaired, beyond the request logs above, which expire on their own.
Security
- The website and the sending page are served over HTTPS; the relay accepts only encrypted connections.
- Audio and video between your devices are encrypted by WebRTC (DTLS-SRTP), and the connection setup is encrypted end to end with keys made during the pairing. The relay sees ciphertext, IP addresses and timings.
- Pairing: a device connects to a computer only after you paired it there. The pairing starts from the extension’s popup with a link or QR code that works for 10 minutes; the device shows a 6-digit number, which you type into the approval window on the computer (three tries) and confirm with Allow, and the device confirms in turn. You can remove a device at any time in the popup, and a device not used for 60 days is removed. One device sends at a time. A paired device hears what meeting pages play into Remote Visio Speaker: pair only devices you trust.
- The limit of this design: the sender page’s code is served by us. Whoever controlled our servers could serve a changed page. We publish the hashes of the served files in the source repository so anyone can check them, and the extension’s code comes only from the Chrome Web Store or from the repository.
- No system is perfectly secure. If you find a security problem, please write to omar@hykops.com.
Children
Remote Visio and this website are not directed to children under 13, or under 16 in the European Economic Area and the UK. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
International transfers
Our service providers, including Cloudflare and Google, may process data in the United States and other countries outside your own. Where the GDPR or UK GDPR applies, these transfers rely on the EU-US Data Privacy Framework and its UK extension, for which Cloudflare and Google are certified, or on the European Commission’s standard contractual clauses.
Your rights (GDPR and UK GDPR)
If you are in the European Economic Area, the UK or Switzerland, you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw your consent at any time (for analytics, with Cookie settings). You also have the right to lodge a complaint with your data protection supervisory authority.
Most data Remote Visio handles never reaches us, so we cannot access, correct or delete it for you: you control it on your own devices, as described above. To exercise your rights over the relay’s connection data, the website data and the emails we do hold, write to omar@hykops.com. We answer within one month.
Notice for California residents (CCPA/CPRA)
In the past 12 months, the website has collected, only from visitors who accepted analytics: identifiers (cookie identifiers, and IP addresses processed by our host and by Google) and internet activity (pages viewed and how visitors arrived), for the purposes described above. The relay processes the IP addresses of the devices that connect through it, to provide the connection, and keeps request logs for at most 7 days. If you email us, we also receive your email address and message. The extension and the sender page collect no personal information for us.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information. You have the right to know what personal information we collect and how we use it, to have it deleted or corrected, and not to be discriminated against for exercising these rights. To make a request, write to omar@hykops.com. We may need to confirm your request comes from you before acting on it.
Changes to this policy
If we change this policy, we update the date at the top of this page. If a change is significant, for example a new kind of data or a new party receiving it, we say so clearly on this page before it takes effect. If the extension, the sender page or the relay ever started to collect more data, this policy would say so first.
Contact
Hykops, omar@hykops.com.
For questions about using Remote Visio, see Support. For the rules on using the website and the software, see our Terms of Use and Cookie Policy.