← Enactive Remote

Privacy

Enactive Remote is a window onto your own computer: from a browser you start tasks there, follow them, and answer the questions it asks. Your computer does the work. This service carries the messages between your computer and your browsers, and keeps them so a browser that was away can catch up.

What you write and what your computer reports back is encrypted on your computer and on your browsers before it reaches the service. The service stores it and passes it on, but cannot read it. This page says what it can read, what it cannot, how long it keeps things, and how to take your data out or delete it.

What the service cannot read

All of this is stored only as encrypted data. The keys that open it are made on your computer and on the browsers you have added, and they never reach the service. A leak of the database, of a backup or of the server's disk shows the encrypted data and nothing more. The same holds for anyone who runs the service: they can look at the stored data, and it is unreadable to them.

One exception, which makes answering a permission request safe: next to each request the service keeps a fingerprint of the exact action, so that your browser can check that the action it shows you is the one your computer asked about. The fingerprint cannot be turned back into the action, but someone who guesses the action exactly - the same command, in the same folder, for the same run - could confirm the guess.

What the service can see

To do its job the service has to know who you are, which devices are yours, and what to deliver where. It keeps these kinds of records:

Put plainly: the service knows that you use it, how many computers and browsers you have, which browsers and operating systems those are, when you run tasks and how many, whether they finished, failed or were cancelled, how many permission requests they raised, how much encrypted data they produced, and the names you give your computers.

Your first sign-in

When you first sign in, the service records the provider, your provider id and display name, and the time, together with the operator's decision about admission. These records stay after the decision. Deleting an account removes them; records of a sign-in that never became an account are kept until the operator removes them.

What we do not keep

What this design cannot protect against

If someone takes over your GitHub or Google account

They can sign in and see what the service sees. They cannot read your tasks or send anything to your computer: that needs a key held only by your computer and the browsers it trusts. But they can remove your computers and browsers from the service, sign out every session, and delete your account with everything stored for it.

If this happens: secure the GitHub or Google account and end its sessions there, then sign in here and use "Sign out everywhere". If computers or browsers were removed, add them again: for a computer, register it again from this page and paste the new code into the desktop app; browsers are added again from that computer.

Signing in

You sign in with GitHub or Google. From GitHub the service keeps your account's number and your username; from Google, your account's id and your profile name. Each provider handles its own sign-in under its own privacy policy.

Who else carries your traffic

The service is reached through Cloudflare, which ends the encrypted HTTPS connection from your browser and passes the traffic on to the server. So Cloudflare sees everything the service sees on the way in and out: your IP address, your cookies, all the information listed under "What the service can see", and the panel's code - which it delivers, and could alter. It never sees what is encrypted end to end: the contents of your tasks, and your keys.

Sessions

A sign-in lasts at most 8 hours, after which you sign in again. You can sign out of one browser, or of every session at once.

Your security log

The service keeps a log of what happened to your account: sign-ins (which provider, not from where), browsers added and removed, computers added and removed, the operator disabling or enabling the account, and signing out everywhere. Only you can read the log in the panel; the operator can read the database, where it is kept like the rest of what is listed above. It holds no secrets, no encrypted contents and no addresses, and each entry is kept for 90 days.

How long things are kept

Everything else the service holds for you - sessions, invitations, the encrypted keys sent to your browsers, workspace ids and commands - stays while your account exists and goes with it when the account is deleted.

Backups

The database is backed up. Backups are kept for 30 days and then removed. Like the database, a backup holds your contents only in encrypted form.

Deleting your account

You can delete your account from the panel. Everything stored for it — computers, browsers, tasks, history, the security log, and the records of your first sign-in — is deleted at once. Copies of it in backups are gone when those backups are removed, within 30 days. Your computer is told the account no longer exists, and stops.

Taking your data out

"Download my data" in the panel gives you what the service stores for your account, except three things: the fingerprints of your computers' connection tokens and the ids of your sessions, which work as credentials, and the operator's own records of deciding your admission, which are the operator's and not yours to keep (the admission itself, and when it was decided, are in the file). Your browser opens what it has keys for and writes a file you keep; the readable text is put together in your browser and is never sent anywhere. Two things stay encrypted in the file: the commands your browsers sent to your computers, and the keys sent to your browsers, so the file cannot open anything else. You can download your data once an hour.

Changes to this page

Changes are announced on this page before they take effect.

Contact

Questions about this page, or about the service, go to the operator through github.com/StasEdward/Enactive/issues. It is a public place: do not put anything private in a report.

← Back to Enactive Remote · Terms