Last Updated: 24 July 2026
POP Remote is a multi-protocol remote desktop client for Android. This Privacy Policy explains what personal data we process when you use the app and our related services, why we process it, and what rights you have.
The data controller responsible for that processing is:
"We", "us" and "our" in this policy refer to that company. We are established in Portugal, so our lead supervisory authority for data protection is the Comissão Nacional de Proteção de Dados (CNPD).
We have not appointed a Data Protection Officer, because we are not required to do so under Article 37 of the General Data Protection Regulation (GDPR). Privacy enquiries are handled directly at the address above.
We do not use the Android Advertising ID. POP Remote contains no advertising SDKs, serves no ads, and the AD_ID permission is explicitly removed from the app. We do not build advertising profiles and we do not sell or share your personal data for advertising purposes.
Under Article 6 of the GDPR we must have a lawful basis for each purpose. They are as follows.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the app: authenticating you, maintaining your account, syncing settings, enforcing plan limits | Account information, device identifier, usage counters | Performance of a contract — Art. 6(1)(b). We cannot provide the service without this. |
| Processing subscriptions and entitlements | Account identifier, purchase token from Google Play | Performance of a contract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) for tax and accounting records. |
| AI Tasks: analysing screenshots of your remote desktop and carrying out the task you described | Screenshots, task text, session context | Consent — Art. 6(1)(a). This feature is off unless you start a task, and you can stop using it at any time. |
| Voice commands and spoken responses (Premium) | Audio you record, transcribed text | Consent — Art. 6(1)(a). |
| Crash reporting, diagnostics, keeping the service secure and preventing abuse | Device information, diagnostics, IP address | Legitimate interests — Art. 6(1)(f): keeping the app working correctly and protecting it from misuse. You can turn crash and diagnostic reporting off in the app under You → Share usage and crash data. Measures we take to keep the service secure and prevent abuse continue regardless, as they are what protect every user's account. |
| Product analytics to understand which features are used and improve them | Usage data, app instance identifier | Legitimate interests — Art. 6(1)(f). You can turn this off in the app under You → Share usage and crash data, or object at any time; see section 9. |
| Responding to your support enquiries | Your correspondence and account information | Legitimate interests — Art. 6(1)(f): answering people who contact us. |
Accounts for POP Remote are managed with Microsoft Entra External ID, a Microsoft identity service. When you sign in, you authenticate against Microsoft and the app receives a token plus your basic profile — your name and email address. We do not receive or store your password.
You may sign in either with an email address and password you set up with us, or by using a Google account as a federated identity provider. If you choose Google, Google confirms your identity to Microsoft, which then issues the token to the app. In that case Google will know that you signed in to POP Remote; Google's handling of that is governed by Google's own privacy policy, linked in section 6.
When you connect to a computer over RDP or VNC, the connection is made directly from your device to that computer. Screen content, keystrokes, mouse input, audio and redirected devices do not pass through our servers, and we have no ability to observe or record them.
AI Tasks is optional. When you start a task, the app captures screenshots of the remote desktop session and sends them, together with your task description, to Microsoft's AI services (Microsoft Foundry / Azure OpenAI) through our API gateway. The model reads the screen and returns the actions to perform.
Microsoft processes this data on our behalf as a processor. It is not used to train Microsoft's or OpenAI's models.
However, under Microsoft's standard terms, prompts and responses — which here means your screenshots and task text — are retained by Microsoft for up to 30 days in a secured store so that Microsoft can detect and review abuse of the service. Authorised Microsoft personnel can access that store to investigate content flagged by automated systems. After 30 days the data is deleted. Microsoft's documentation of this is linked in section 6.
Voice input used for Premium voice commands is sent to Microsoft's speech services for transcription and is subject to the same arrangement.
Some app builds can write AI debug screenshots to your device's Downloads folder to help with troubleshooting. These files stay on your device. You can delete them at any time using any file manager.
We do not sell, rent or trade your personal data. We share it only with the providers below, who process it on our behalf under contract, and only for the purposes listed.
| Provider | What they process for us | Their privacy documentation |
|---|---|---|
| Microsoft Foundry / Azure OpenAI Service (Microsoft Corporation) | AI Tasks: screenshots and task text. Speech-to-text and text-to-speech for voice features. |
Data, privacy and security for Microsoft Foundry Models Microsoft Privacy Statement |
| Microsoft Entra External ID (Microsoft Corporation) | Account creation, sign-in and identity tokens. | Microsoft Privacy Statement |
| Microsoft Azure API Management (Microsoft Corporation) | Routing and securing app requests to the AI services; short-lived request logs. | Microsoft Privacy Statement |
| Google Firebase (Google LLC / Google Ireland Ltd) — Analytics, Crashlytics, Firestore | Product analytics, crash reporting and diagnostics, and storage of account-related records. |
Firebase Privacy and Security Google Privacy Policy |
| Google Play Billing (Google LLC / Google Ireland Ltd) | Processing subscription purchases and confirming your entitlement. We never receive your payment card details. | Google Privacy Policy |
| Google Sign-In (Google LLC / Google Ireland Ltd) | Optional federated sign-in, if you choose it. See section 4. | Google Privacy Policy |
We may also disclose personal data where we are legally required to do so — for example in response to a valid court order, subpoena or regulatory demand — or where it is necessary to establish, exercise or defend legal claims, or to protect the safety of individuals. Where we are permitted to notify you of such a request, we will.
Our AI processing runs in Microsoft data centres in the European Union (Sweden) and in the United States. Firebase services may process data in Google data centres in the United States and elsewhere.
Where personal data is transferred outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses incorporated into our agreements with Microsoft and Google, together with the supplementary technical measures those providers apply (including encryption in transit and at rest). You may request a copy of the relevant transfer mechanism by contacting us.
| Category | Retention period |
|---|---|
| Account data | For as long as your account exists, then deleted within 30 days of your deletion request. |
| Connection details and credentials | Held only on your device. Removed when you delete the connection, clear app data or uninstall the app. |
| AI Task screenshots and task text | Not stored by us. Retained by Microsoft for up to 30 days for abuse monitoring, then deleted (see section 5.3). |
| Voice recordings | Not stored by us. Subject to the same 30-day Microsoft abuse-monitoring retention. |
| Usage analytics | Up to 14 months. |
| Crash reports and diagnostics | Up to 90 days. |
| Subscription and billing records | As required by Portuguese tax law, currently 10 years. |
| Support correspondence | Up to 24 months after the enquiry is closed. |
If the GDPR applies to you, you have the right to:
For analytics and crash reporting you do not need to write to us at all: open the app, go to the Settings tab and turn off Share usage and crash data. The setting takes effect immediately and is remembered on that device.
To exercise any of these rights, email privacy@oikostech.io. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
To delete your account and the data associated with it, see Delete Your Account, which sets out the steps, what is deleted, and what we are required to keep.
You also have the right to lodge a complaint with a supervisory authority. In Portugal this is the Comissão Nacional de Proteção de Dados (cnpd.pt). You may also complain to the authority in your own country of residence.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to access and delete it, to correct inaccuracies, and to limit the use of sensitive personal information. You have the right not to be discriminated against for exercising these rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. Use the same contact address above to make a request.
No system is perfectly secure. If we become aware of a personal data breach affecting your rights, we will notify the CNPD within 72 hours and inform you where the law requires it.
POP Remote is intended for adults and is not directed at children. It is rated for users aged 18 and over, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
The app itself uses no cookies and no advertising identifiers. It stores data locally using Android SharedPreferences and SQLite, and Firebase Analytics uses a randomly generated app instance identifier that is not linked to any advertising network. Our website uses only strictly necessary cookies.
We may update this policy as the app changes. The "Last Updated" date at the top always reflects the current version. If we make a material change — for example adding a new category of processing or a new sub-processor — we will notify you in the app or by email before it takes effect, and where the change relies on your consent we will ask for it again.
This Privacy Policy is effective as of 24 July 2026 and supersedes all previous versions.