Privacy
Enactive Remote is a window onto your own computer: from a browser you start tasks there, follow them, and answer the questions it asks. Your computer does the work. This service carries the messages between your computer and your browsers, and keeps them so a browser that was away can catch up.
What you write and what your computer reports back is encrypted on your computer and on your browsers before it reaches the service. The service stores it and passes it on, but cannot read it. This page says what it can read, what it cannot, how long it keeps things, and how to take your data out or delete it.
What the service cannot read
- The titles and the text of your tasks.
- What a run reports while it works, and its summary when it ends.
- The permission requests your computer sends you: which tool, with what arguments, in which folder, and the full text of the question.
- The details of your notifications.
- The names of your workspaces.
All of this is stored only as encrypted data. The keys that open it are made on your computer and on the browsers you have added, and they never reach the service. A leak of the database, of a backup or of the server's disk shows the encrypted data and nothing more. The same holds for anyone who runs the service: they can look at the stored data, and it is unreadable to them.
One exception, which makes answering a permission request safe: next to each request the service keeps a fingerprint of the exact action, so that your browser can check that the action it shows you is the one your computer asked about. The fingerprint cannot be turned back into the action, but someone who guesses the action exactly - the same command, in the same folder, for the same run - could confirm the guess.
What the service can see
To do its job the service has to know who you are, which devices are yours, and what to deliver where. It keeps these kinds of records:
- Your account and how you sign in: the name shown for your account and, for each way you sign in, the provider (GitHub or Google), the provider's id for your account, and the display name the provider gives it.
- Your sign-in sessions: when each began, when it ends, and whether it was ended early.
- Your browsers: each one's public key, a label made automatically from the browser's and the operating system's names (such as "Firefox on Windows" - so the service learns which browsers and systems you use), when it was added, when it was last seen, and when it was removed.
- Your computers: the name you give each one (this name is not encrypted, and the panel says so where you type it), a fingerprint of its connection token (not the token itself), when it was last seen, and which generation of its keys it is on.
- Your workspaces: their ids, not their names.
- Your tasks, runs, commands, permission requests, progress messages and notifications: their ids, kinds, statuses and times, and how large their encrypted contents are.
- Invitations to add a browser: when each was made, when it expires, and whether it was used.
- Keys sent to your browsers: encrypted, so that only the browser they are for can open them.
- Your security log: see below.
Put plainly: the service knows that you use it, how many computers and browsers you have, which browsers and operating systems those are, when you run tasks and how many, whether they finished, failed or were cancelled, how many permission requests they raised, how much encrypted data they produced, and the names you give your computers.
Your first sign-in
When you first sign in, the service records the provider, your provider id and display name, and the time, together with the operator's decision about admission. These records stay after the decision. Deleting an account removes them; records of a sign-in that never became an account are kept until the operator removes them.
What we do not keep
- No IP addresses. None is stored with your account or in the security log. Limits on how often a request can be made use the address for a few minutes, in memory only, and it is never written down.
- No email address and no password. The service does not ask GitHub or Google for your email address, and it has no password of its own.
- No provider tokens. GitHub or Google confirms who you are once, at sign-in; the service keeps no access to your account there, and asks for no access to your repositories, mail or files.
- No tracking. No analytics, no advertising, and nothing loaded from another site. The cookies are the ones signing in needs: one for your session, one that protects the forms you send, and short-lived ones during sign-in itself.
What this design cannot protect against
- Altered code. The panel you use in a browser is code this service sends.
An operator who sent altered code — or someone who had taken over the server, or Cloudflare (see
below) — could take your keys from the browser. No web page can prevent this. What the service
does is make an alteration visible: it publishes the fingerprint (SHA-256) of every script and
stylesheet it serves at
/.well-known/enactive-panel.json, and each release publishes the fingerprints of the files it ships, so anyone can compare. - What the service can see, listed above. It is not encrypted, because the service needs it to deliver anything at all.
- A compromised computer or browser. Whatever can read your screen or your browser's storage can read what you read there. A browser holds keys, so whoever controls it can also start tasks on your computer and answer its permission requests, as you could. Remove a browser you no longer trust from the panel.
- A browser that was already compromised when it invited another. When one of your browsers admits another by invitation, it also tells the new browser which signing key your computer has. A browser that was compromised at that moment can make the browser it admitted trust a key it controls, and go on reading what that browser sends even after it has itself been removed. Two things limit this. The admitted browser sees your computer's real key change arrive under another key, reports it as tampering, and asks to be added again from the computer. And adding a browser from your computer ("Add a device" in the desktop app) never depends on another browser's word.
If someone takes over your GitHub or Google account
They can sign in and see what the service sees. They cannot read your tasks or send anything to your computer: that needs a key held only by your computer and the browsers it trusts. But they can remove your computers and browsers from the service, sign out every session, and delete your account with everything stored for it.
If this happens: secure the GitHub or Google account and end its sessions there, then sign in here and use "Sign out everywhere". If computers or browsers were removed, add them again: for a computer, register it again from this page and paste the new code into the desktop app; browsers are added again from that computer.
Signing in
You sign in with GitHub or Google. From GitHub the service keeps your account's number and your username; from Google, your account's id and your profile name. Each provider handles its own sign-in under its own privacy policy.
Who else carries your traffic
The service is reached through Cloudflare, which ends the encrypted HTTPS connection from your browser and passes the traffic on to the server. So Cloudflare sees everything the service sees on the way in and out: your IP address, your cookies, all the information listed under "What the service can see", and the panel's code - which it delivers, and could alter. It never sees what is encrypted end to end: the contents of your tasks, and your keys.
Sessions
A sign-in lasts at most 8 hours, after which you sign in again. You can sign out of one browser, or of every session at once.
Your security log
The service keeps a log of what happened to your account: sign-ins (which provider, not from where), browsers added and removed, computers added and removed, the operator disabling or enabling the account, and signing out everywhere. Only you can read the log in the panel; the operator can read the database, where it is kept like the rest of what is listed above. It holds no secrets, no encrypted contents and no addresses, and each entry is kept for 90 days.
How long things are kept
- History is kept for a number of days the operator sets; the panel shows the current number, and says when older history was removed. Progress messages and notifications older than that are removed even while their run is going; an ended run is removed whole, with its task, after the window.
- The security log is kept for 90 days.
- Your account, browsers and computers are kept while your account exists.
Everything else the service holds for you - sessions, invitations, the encrypted keys sent to your browsers, workspace ids and commands - stays while your account exists and goes with it when the account is deleted.
Backups
The database is backed up. Backups are kept for 30 days and then removed. Like the database, a backup holds your contents only in encrypted form.
Deleting your account
You can delete your account from the panel. Everything stored for it — computers, browsers, tasks, history, the security log, and the records of your first sign-in — is deleted at once. Copies of it in backups are gone when those backups are removed, within 30 days. Your computer is told the account no longer exists, and stops.
Taking your data out
"Download my data" in the panel gives you what the service stores for your account, except three things: the fingerprints of your computers' connection tokens and the ids of your sessions, which work as credentials, and the operator's own records of deciding your admission, which are the operator's and not yours to keep (the admission itself, and when it was decided, are in the file). Your browser opens what it has keys for and writes a file you keep; the readable text is put together in your browser and is never sent anywhere. Two things stay encrypted in the file: the commands your browsers sent to your computers, and the keys sent to your browsers, so the file cannot open anything else. You can download your data once an hour.
Changes to this page
Changes are announced on this page before they take effect.
Contact
Questions about this page, or about the service, go to the operator through github.com/StasEdward/Enactive/issues. It is a public place: do not put anything private in a report.