farcrew
SupportPrivacyTermsDocs

Privacy Policy

Last updated 31 August 2026

farcrew keeps a terminal session alive on a machine you own and lets you watch it from somewhere else. The service in the middle is a relay. It is built so that the thing you most care about — what is on your terminal — is encrypted before it reaches us and cannot be read by us. This policy says what we do hold, why, and for how long.

Who we are

farcrew is operated by Poor Devs OÜ (Estonian registry code 16909250), a company registered in Estonia and the controller of the personal data described below. Reach us at support@farcrew.app.

What we hold

  • Your account. An email address, and a password stored only as a salted PBKDF2 hash. If you enrol a passkey we store its public key and its label; recovery codes are stored hashed. We never hold a password or a recovery code we could read back.
  • Your sign-ins. For each active session: when it was created, when it expires, the browser or app that started it, the IP address it came from and the country that address resolves to. You can see this list, and end any session in it, in Settings.
  • Your machines. The name you gave each machine, when it was paired, when it was last connected, and a hash of the token its daemon authenticates with.
  • Session metadata. The command a session runs, the label you give it, and whether it is running, waiting on you, or finished. This is not encrypted end-to-end: the relay reads it to route frames and to decide when to notify you.
  • Notification channels, if you turn them on. A push token for each device, and your Telegram chat id if you link Telegram. A notification names the machine and the session it is about.
  • Billing. Stripe processes the payment and holds the card. We store only the customer and subscription identifiers Stripe gives us, the plan, its status, and when the period ends.
  • Operational records. Short-lived counters used to rate limit sign-in attempts, and the ordinary request logs of the network the service runs on.

What we cannot read

Terminal input and output, and any file you attach to a session, are encrypted on your device with a key negotiated directly between your client and your own machine. The relay forwards ciphertext it has no key for. Your saved workspace layout is encrypted the same way, under a key derived from your password. We do not have a way to decrypt any of it, which also means we cannot recover it for you.

Two things are deliberately outside that: the session metadata listed above, and port previews. A preview serves a port from your machine over a secret URL, in the clear, to anyone who has the URL — the console says so wherever a preview is created. Delete the preview to close it.

Why we hold it

To run the service you asked for: to sign you in, to connect you to your machines, to tell you when a run needs an answer, and to take payment. Where the GDPR applies, our basis is the performance of our contract with you, and our legitimate interest in keeping the service secure — that is what the sign-in records and the rate limiting are for. We do not advertise, we do not profile you, and we do not sell or share your data with anyone for their own purposes.

Who else touches it

  • Cloudflare — hosting, the relay, and the database.
  • Stripe — payments and the billing portal.
  • Hitglance — website, web console, and documentation analytics: page URLs, referrers, time on page, outbound links, and downloads.
  • Apple — delivering push notifications to iOS devices.
  • Telegram — only if you link a Telegram chat.

These providers process data on our instructions to deliver the parts of the service they carry. We may also disclose data where the law requires it.

How long we keep it

Account data lives for as long as the account does. Sign-in sessions expire on their own and are swept once expired; so are pairing codes, one-time challenges and rate-limit counters. Deleting your account removes the account, its machines, its passkeys, its sessions, its saved workspaces, its notification tokens, its previews and the session labels the relay kept for it. Records we must keep for tax or accounting reasons stay with the payment processor for as long as the law requires. The apps and the console clear what they held on the device itself — the sign-in token, the device key, the machine fingerprints they had pinned.

Your rights

You can access, correct, export or delete your data. Most of it you can act on yourself: Settings shows your sessions, your passkeys and your machines, and carries the button that deletes the account outright and without recovery. For anything else, or to object to or restrict our processing, write to support@farcrew.app. If you are in the EEA or the UK you may also complain to your local data protection authority.

Cookies and local storage

The web console sets one cookie, fc_session, to keep you signed in; it is HttpOnly and same-site. Everything else the console keeps — your session token, your device key, your theme and layout — lives in your browser's local storage on your own device. There are no analytics or advertising cookies.

Children

farcrew is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 16.

International transfers

The service runs on a global network, so data may be processed outside your country. Where that involves a transfer out of the EEA or the UK, it relies on our providers' standard contractual clauses.

Changes

If this policy changes materially we will say so in the console before the change takes effect. The date at the top always reflects the current version.

farcrewSupportPrivacyTerms© 2026 farcrew