Privacy Policy
Last updated: September 30, 2026
This Privacy Policy describes how MainVac (“MainVac”, “we”, “us”) handles information in connection with MainVac for Mac, MainVac for iPhone, iPad and Android (together, the “Apps”), and the website mainvac.com (the “Website”). By using the Apps or the Website, you acknowledge the practices described in this Policy.
1. Summary
The mobile Apps do not collect personal information. Screen content transmitted through MainVac is not received, stored or accessible by us. We do not sell or rent personal information, and we do not use or disclose it for advertising.
2. Screen Content and Remote Input
Video of the shared window and remote input, including taps, scrolling, text and keyboard shortcuts, are transmitted directly between your computer and your mobile device using end-to-end encryption. Where a direct connection cannot be established, encrypted traffic may be forwarded through third-party relay servers, which cannot decrypt it. We have no access to screen content, window titles, keystrokes or clipboard data.
3. Information We Do Not Collect
MainVac does not require an account. The Apps contain no advertising, analytics or tracking software development kits, and do not track users across apps or websites owned by other companies. The mobile Apps do not transmit any information to us. The Mac App communicates with us only for the service verification described in Section 7 and the update check described in Section 8.
4. Information Stored on Your Devices
Paired device records, saved connections and their notes, connection keys, shortcut settings and other preferences are stored locally on your devices and are not transmitted to us. Keys and credentials are stored in the operating system’s secure storage (Keychain on Apple platforms and Android Keystore on Android). Deleting a saved connection in the App deletes its credentials, and revoking a device on your computer terminates that device’s access.
5. Device Permissions
The Apps request the following permissions solely for the purposes stated:
- Camera (mobile Apps): to scan the pairing QR code displayed by the Mac App. Camera images are processed on the device and are neither stored nor transmitted.
- Local Network: to discover and connect to your computer on the same network.
- Picture in Picture and background execution (mobile Apps): to continue displaying the shared window after you leave the App. The Apps do not play or record audio.
- Screen Recording (Mac App): to capture the single window you select, which is transmitted only to devices you have paired.
- Accessibility (Mac App): to deliver remote input to the selected window, only while remote control is enabled on your computer.
6. Third-Party Connection Services
- Quick Connect: uses the Tailcat network and its public relay servers to establish connections across networks. The operators of these servers may process IP addresses and connection metadata. They cannot access transmitted content, which is end-to-end encrypted.
- Tailscale: where you choose to use it, this connection method operates under your own Tailscale account, either through the Tailscale app on your mobile device or through sign-in within the Mac App, including a self-hosted control server that you configure. Such use is governed by the privacy policy of Tailscale or of the relevant server operator.
- Local network: connections remain within your network and do not involve any third party.
7. Mac App Service Verification
To verify that the Mac App may provide its connection service on your computer, the Mac App periodically transmits the following information to our verification service:
- A pseudonymous device identifier, being a one-way hash derived from a hardware identifier. It cannot be used to derive the underlying hardware identifier and does not include the name of your computer.
- Any key you enter in the Mac App.
The verification service is hosted by Cloudflare, Inc., which processes IP addresses in order to operate its network. We do not record IP addresses in our database or logs.
8. Software Updates
Subject to the preference you select at first launch, the Mac App periodically retrieves a static update feed from our download server to determine whether a new version is available. These requests contain no identifier other than information inherent in any HTTP request. The mobile Apps are updated through the App Store or Google Play.
9. Support Communications
When you choose to send feedback, the App creates a draft message in your own email application containing the following diagnostic information: App version, operating system version, device model (not the device name), and a random identifier generated solely for support purposes. No information is sent unless you send the message. We use the contents of support communications only to respond to you and to resolve reported issues.
10. The Website
The Website does not use cookies, analytics or third-party tracking technologies. It stores a limited number of preferences, such as your language selection, in your browser’s local storage; this information is not transmitted to us. The Website is hosted by Cloudflare, Inc., which processes IP addresses in order to deliver it.
11. Disclosure of Information
We do not sell, rent or otherwise disclose personal information to third parties for their own purposes. We may disclose the limited information described in this Policy where required by applicable law or legal process.
12. Data Retention and Deletion
Verification records, consisting of the pseudonymous device identifier and its verification status, are retained for as long as necessary to provide the Mac App. Support communications are retained for as long as necessary to provide support. You may request deletion of your records at any time by contacting us. Information stored on your devices may be deleted within the App or by uninstalling the App.
13. Security
All connections are end-to-end encrypted. A new device may connect only after approval on your computer, using a pairing code that is not transmitted over the network or a time-limited QR code invitation. Keys are stored in operating system secure storage, and remote control remains disabled until you enable it.
14. Children’s Privacy
The Apps and the Website are not directed to children under the age of 13, and we do not knowingly collect personal information from children.
15. International Data Processing
Our verification service and the Website operate on the global network of Cloudflare, Inc. Requests may therefore be processed in countries or regions other than the one in which you reside.
16. Your Rights
Depending on your place of residence, including under the EU General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act and the Personal Information Protection Law of the People’s Republic of China, you may have the right to access, correct, delete or obtain a copy of your personal information, and to object to or restrict its processing. To exercise these rights, contact us at the address below. We will respond within 30 days. We may request information reasonably necessary to locate the relevant records.
17. Changes to This Policy
We may update this Policy from time to time. The revised Policy will be posted on this page with an updated date. Material changes will be indicated on this page before they take effect.
18. Contact
For questions regarding this Policy or your personal information, please contact [email protected].