Privacy Policy — Sharpin Remote Commander
Last updated: 13 September 2026
This Privacy Policy explains how the hosted Sharpin Remote Commander service processes personal data. It applies to the public relay, account/dashboard, device enrollment, OAuth/MCP connection, support processes, and related hosted services operated by the controller below. A fully self-hosted installation may have a different controller and privacy notice.
1. Controller
Firma Michael Gruber
Edelstauden 55
8081 Pirching am Traubenberg
Austria
VAT ID: ATU75251905
Email: info@digital-pinball.com
2. What the service does
Sharpin Remote Commander lets an authenticated user connect computers that the user owns or is authorized to administer to supported MCP/AI clients. The public OpenAI profile is restricted to a user-configured local workspace. A separate private profile can expose broader administrative capabilities and is not intended for public OpenAI directory submission.
3. Personal data we process
Depending on how you use the service, we process:
- Account data: email address, account identifier, password hash and salt, email-verification status, account role, account creation time.
- Authentication and OAuth data: hashed web-session tokens, hashed verification/reset tokens, OAuth client metadata, scopes, redirect URIs, hashed access/refresh tokens, expiry/revocation metadata, PKCE/authorization metadata required to complete OAuth flows.
- Device data: device identifier, device name, operating-system/platform string, agent version, local capability flags, service policy, last-seen time, revoked/active state and a hashed device credential.
- Remote-operation data: the selected tool/action and arguments required to route a user-requested operation to the selected device, plus the result/error returned by the agent.
- Audit/security data: tool name, success/failure, affected device reference where necessary, limited summary metadata, authentication/security events, rate-limit state and ordinary infrastructure logs such as timestamp, request status and IP address where generated by the hosting/security layer.
- Support data: the content and contact data you send when requesting support, privacy assistance or reporting a security issue.
The service does not intentionally use remote file contents, command output or support content for advertising, behavioral profiling, or training our own AI models.
4. Sources of data
We receive data directly from you, from enrolled device agents acting at your request, from an MCP/AI client you connect (for example ChatGPT), and from our hosting/security infrastructure.
5. Purposes and legal bases under the GDPR
We process data for the following purposes:
- Account creation, authentication, device enrollment, OAuth authorization and execution of user-requested operations: Art. 6(1)(b) GDPR (performance of a contract / steps requested before entering into a contract).
- Service security, abuse prevention, rate limiting, incident detection, minimal audit logging and reliable operation: Art. 6(1)(f) GDPR (legitimate interests in securing and operating the service), balanced against user rights and supported by data minimization.
- Support and service communications: Art. 6(1)(b) GDPR where related to the service; otherwise Art. 6(1)(f) GDPR.
- Compliance with legal obligations: Art. 6(1)(c) GDPR where applicable.
- Optional marketing communications: only where separately offered and where a valid legal basis exists, including consent where required. The Remote Commander application itself does not require marketing consent to function.
6. Remote-operation payloads and data minimization
Remote operations are designed to be transient:
- queued operation arguments are stored only until claimed by the selected device agent and are then scrubbed from the durable job record;
- completed operation results are deleted after delivery to the waiting request;
- if a caller disconnects, completed/orphaned results are automatically cleaned up after a short safety window (currently up to approximately five minutes);
- stale, unclaimed jobs are automatically removed;
- application audit entries do not store file contents, command strings, terminal input, or full path values.
The public profile is designed for a dedicated workspace folder. Users should not place payment-card data, protected health information, passwords, API keys, MFA/OTP codes, private keys, government identifiers or other secrets/specially protected data in that workspace.
7. Retention
Unless a longer period is required by law or needed to investigate a concrete security incident:
- account/device records: until account deletion or until they are no longer required to provide the service;
- web sessions: up to 14 days;
- email-verification tokens: up to 24 hours;
- password-reset tokens: up to 1 hour;
- OAuth authorization codes: up to 5 minutes;
- OAuth access tokens: normally up to 1 hour;
- OAuth refresh tokens: normally up to 30 days and rotated/revoked when used or withdrawn;
- queued job arguments: until claimed, then scrubbed; stale unclaimed jobs: up to 1 hour;
- completed operation results: normally seconds, with orphan cleanup up to approximately 5 minutes;
- application action-audit records: up to 30 days by default;
- production application/security logs: target retention 30 days;
- transactional-email event/log data at the selected email provider: target retention 30 days where configurable;
- production database backups: target retention 7 days.
When an account is deleted in the dashboard, application database records associated with that account are deleted through database relationships. Residual copies can remain temporarily in encrypted infrastructure backups until the backup retention period expires.
8. Cookies and local browser storage
The account dashboard uses a strictly necessary session cookie (src_session) for login state and CSRF protection. It is configured as HttpOnly, Secure in HTTPS production deployments, SameSite=Lax, and expires with the web session. No advertising cookie or cross-site behavioral tracking is required for the service.
9. Processors and recipients
For the planned production deployment at mcp.digital-pinball.com, the following categories of service providers are intended to be used:
- Google Cloud Platform (Google Cloud): hosting the relay/API, PostgreSQL database, Redis coordination service, encrypted secrets, release storage, networking, logging and monitoring. The intended primary region is Frankfurt, Germany (
europe-west3) where supported. - Brevo: transactional email delivery for account verification and password reset. Brevo states that its database processing/storage is in the European Union. Before public launch, transactional-log/email-preview retention will be configured to a defined minimal period (target: 30 days) rather than relying on the provider default.
- OpenAI: when you connect Sharpin Remote Commander to ChatGPT/another OpenAI surface, requests and tool results necessarily pass through OpenAI under the terms and privacy notices applicable to your OpenAI account. OpenAI and the Sharpin Remote Commander operator act independently for their respective processing as provided by applicable platform terms.
- Other MCP/AI clients chosen by you: if you connect another provider or client, that provider receives data necessary to perform the requested tool call under its own terms/privacy policy.
The final published subprocessor list must always reflect the actual production deployment. We do not sell personal data.
10. International transfers
We aim to keep the primary hosted service in the EEA. Some providers may be headquartered outside the EEA or may provide support/access from other countries. Where a restricted international transfer occurs, we rely on an applicable lawful transfer mechanism supplied by the relevant processor or otherwise available under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses, as applicable.
11. Security
We use technical and organizational measures designed for the risk profile of remote-computer access, including encrypted transport, OAuth 2.1/PKCE, hashed bearer/device credentials, per-user tenancy separation, device revocation, per-device capability controls, local workspace/allowlist enforcement, rate limiting, short-lived remote-operation payloads, audit logging that excludes payload content, restricted production secrets and signed agent updates.
No internet service can guarantee absolute security. Users must protect their account, connected devices and recovery channels and should revoke access immediately if compromise is suspected.
12. Automated decision-making
We do not use personal data processed by Sharpin Remote Commander for solely automated decisions that produce legal or similarly significant effects on users.
13. Your rights
Subject to the conditions and exceptions in applicable law, you may have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent. You may delete your account through the dashboard or contact us at info@digital-pinball.com.
You also have the right to lodge a complaint with a supervisory authority. The Austrian supervisory authority is:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien
Austria
Email: dsb@dsb.gv.at
14. Children
The hosted service is intended for persons who can legally enter into a contract for the service. It is not directed to children.
15. Changes to this policy
We may update this policy when the service, processors, legal requirements or processing practices change. Material changes will be communicated through the service or by another reasonable channel where required.
16. Contact
Privacy and account-deletion requests: info@digital-pinball.com