What this server keeps
This page describes the qoop server at this address: the service you sign in to and that passes data between your phone or browser and your machines.
We ask Google only for your basic profile: the scopes openid, email
and profile. We keep:
- Google's identifier for your account, your email address and your name.
- Your sign-in sessions: a hash of the session cookie, when it started and when it was last used, and for the phone app a hash of its sign-in token and when it was made.
- The machines you linked: each machine's public key, the name it gave itself, and when you linked it.
We do not call any Google service on your behalf, do not keep Google's tokens, and do not read your Google data beyond the fields above.
While you link a machine or ask a machine to let in a new phone or browser, the request holds the network address and rough location it came from, the device's name and kind, and its public key. They are shown to you on your machine so you can tell your own request from someone else's, and are dropped when the request ends or after ten minutes.
Terminal contents travel end to end encrypted between your machine and your phone or browser. This server passes the bytes along and holds no key to read them. A browser, unlike the phone app, runs the page this server sends, so whoever runs this server could change that page; approve only browsers you trust, and their access ends after 30 days. Push notifications carry fixed sentences such as "An agent is waiting for you", never text from your screen; they go through Apple or Google to reach your phone.
Two cookies, both needed for sign-in: one holds the state of a sign-in for ten minutes, the other your session. No analytics, no advertising, no third-party scripts.
We do not sell or share your data. It is kept on this server, with one backup copy on the
same server that is replaced every day. Deleting your account from the app removes your
account, sessions and machine links; running qoop logout on a machine unlinks it.