Privacy Policy
Effective Date & Last Updated:
Cmend is an interactive desktop signaling and remote-relay platform enabling authenticated users to negotiate private sessions, exchange media overlays, stream displays, and grant scoped remote-control directives under explicit, bilateral consent. This Privacy Policy details our data architecture, storage lifecycles, and cryptographic standards across our web interface, native desktop clients, and mobile applications.
Information We Collect & Retain
We adhere to data-minimization principles, collecting only metadata and telemetry necessary to execute signaling protocols, enforce permissions, and verify legal eligibility:
- Discord Authentication Data: User identity is provisioned via Discord OAuth using the restricted
identifyscope. We store your unique Discord Snowflake ID, username, discriminator, display name, and avatar hash. We do not access, process, or store your email address, phone number, or guild list. - Age Verification Documentation: For accounts seeking access to age-gated functionality, we collect voluntarily uploaded government identification photos, real-time verification selfies, handwritten passphrases, date verifications, and associated Discord usernames.
- Cryptographic Secrets & Control Codes: Device targeting utilizes an alphanumeric Control Code. Local client-to-server authorization utilizes programmatic Client Secrets (
cm_*). To protect your credentials while supporting on-demand retrieval in your dashboard, secrets are stored using AES-256-GCM encryption alongside a one-way SHA-256 lookup hash. - Device Telemetry & Push Tokens: We collect active network status (online/offline), connected environment (Windows, Linux, or Mobile/Capacitor), and Firebase Cloud Messaging (FCM) device registration tokens for mobile event dispatching.
- Granular Permission States: We persist the toggle configuration of your explicit permission matrix, including grants for text banners, media playback (audio, image, video), desktop wallpaper updates, input blocking, screenshot capture, webcam triggering, and screen mirroring.
- Ephemeral In-Memory Captures: Discrete screenshot and webcam captures triggered during consensual sessions are processed strictly through bounded, volatile in-memory ring buffers (capped at 20 captures per account). Captures are never written to long-term relational databases.
- Ephemeral Chat Logs: Text messages dispatched through the session chat interface are buffered in volatile memory caches (up to 200 messages) to support live active-window continuity.
- Audit, Session & Abuse Records: To protect platform integrity, we log private session state transitions (creation, acceptance, termination), rate-limit counters, user blocking pairs, and abuse report records.
- Authentication Cookies: We set an
httpOnly,SameSite=LaxJWT session cookie (cmend_session) valid for up to 7 days, and an ephemeral state cookie (cmend_oauth_state) used strictly to protect against CSRF attacks during Discord OAuth handshakes.
Purpose & Legal Basis of Processing
Cmend processes personal data and device metadata strictly for the following purposes:
- Service Delivery & Relay Routing: Authenticating users, resolving Control Codes, delivering WebSocket and Server-Sent Event (SSE) packets, and routing WebRTC streaming sessions.
- Enforcing User Consent Boundaries: Intercepting remote command dispatches against the target user’s stored permission toggles to prevent unauthorized hardware, input, or sensor interaction.
- Legal Compliance & Age Gating: Validating that operators engaging in sensitive, adult, or remote device interactions satisfy mandatory minimum age thresholds.
- Abuse Prevention & Platform Security: Enforcing rate limits, executing account-level bans across active network sockets, and mitigating automated scanning or SSRF exploitation.
Third-Party Processors & Infrastructure
We never sell, rent, monetize, or trade your personal data or interaction telemetry. Data routing through third parties is restricted exclusively to essential infrastructure providers:
Third-party identity provider facilitating OAuth2 token exchange and basic account provisioning.
Encrypted, access-controlled object storage infrastructure utilized to store age verification assets. All files are bound to an automated 7-day lifecycle purge rule.
Real-time media relay infrastructure providing selective forwarder unit (SFU) rooms for screen mirroring sessions.
Push notification delivery service for waking mobile client endpoints when WebSocket connections are dormant.
Data Retention & Automated Purge Schedules
We maintain strict, automated data lifecycles to minimize permanent retention of sensitive records:
- Age Verification Uploads (7-Day Hard Purge): Identification documents and verification selfies uploaded to Cloudflare R2 object storage are governed by an automated object lifecycle rule. All verification images are automatically and permanently deleted from Cloudflare R2 exactly seven (7) days following submission, regardless of approval status.
- Volatile Captures & Screen Frames: Webcam captures, desktop screenshots, and screen-mirroring video streams reside strictly in volatile RAM ring buffers or peer-to-peer WebRTC channels; they are never committed to our relational database and are destroyed on buffer overwrite or server restart.
- Client Relays & Event Logs: Session transition logs are maintained for security auditing and dispute resolution, purged systematically in accordance with network maintenance lifecycles.
- Account Data: Core profile attributes, blocks, and permission matrices remain active until an account deletion is requested or an account is banned for malicious activity.
Security Architecture & Cryptography
We implement defense-in-depth technical safeguards to protect your telemetry and host machine:
- Cryptographic Storage: Client secrets are encrypted at rest using AES-256-GCM with unique initialization vectors (IVs) and authentication tags, backed by SHA-256 integrity digests.
- Network Security: All API communication and media relays require Transport Layer Security (TLS 1.3). Real-time mirror streaming is encrypted end-to-end via WebRTC protocols (DTLS/SRTP).
- SSRF & Loopback Defense: Remote media relay endpoints enforce rigorous IP validation, rejecting loopback (
127.0.0.1,::1), link-local, and reserved private subnets to prevent Server-Side Request Forgery or local file intrusion on client machines. - Cookie Isolation: Authentication cookies are delivered with strict
httpOnly,SameSite=Lax, andSecureflags to neutralize browser-level token theft.
Your Privacy Rights & User Controls
You maintain continuous administrative control over your data footprint and hardware exposure:
- Real-Time Permission Revocation: You can toggle off any remote permission (webcam, screenshot, input blocking, mirroring, media) instantly via your settings dashboard. Changes take immediate effect across all connections.
- Session Disconnect & Blocking: Terminate active sessions at any time using platform kill-switches, or establish two-way blocking relationships to permanently prohibit interactions from specific accounts.
- Secret Invalidation: Regenerate your Client Secret instantly via your profile to revoke authorization tokens across all running desktop instances.
- Right to Erasure (GDPR / CCPA): You may request the expedited manual deletion of your profile, verification records prior to their 7-day expiration, and associated database mappings by contacting administrative support.
Contact & Data Protection Inquiries
For compliance questions, formal GDPR/CCPA data erasure requests, or security vulnerability disclosures, please open a secure inquiry ticket through our official communication portal: