vikn.io
All policies

Vikn Remote Desk

Privacy Policy

Last updated: August 28, 2026

What Vikn Remote Desk can see during a remote session (nothing), and the account, device and connection data we do hold.

  • 1. Introduction
  • 2. What Happens During a Remote Session
  • 3. Information We Collect
  • 4. Consent and Control on the Device Being Controlled
  • 5. How We Use Your Information
  • 6. How We Share Information
  • 7. Security
  • 8. Data Retention
  • 9. Your Rights
  • 10. Deleting Your Account
  • 11. Children's Privacy
  • 12. International Data Transfers
  • 13. Changes to This Privacy Policy
  • Contact

1. Introduction

Vikn Codes LLP ("we", "us", or "our") operates Vikn Remote Desk, a remote access and remote support tool (the "Service"). It lets a person connect to a computer or Android device and see its screen and control it, with that device's consent, so that a colleague or a support engineer can work on it from somewhere else.

This is a remote-access product, so this policy leads with the part that matters most: what we can and cannot see while a session is running. That is section 2.

This policy covers Vikn Remote Desk only. Other Vikn products — including Vikn Desk — are separate services with their own privacy policies. Signing in uses the shared Vikn identity service described in section 3.

By installing or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

2. What Happens During a Remote Session

During a session, the following travels between the two devices: the shared screen as video, the mouse and keyboard input the controlling side sends, clipboard contents when clipboard sharing is used, and any files either side transfers.

All of it moves directly from one device to the other over an encrypted peer-to-peer connection. It is encrypted on the sending device and decrypted on the receiving device. It is not sent to us, it is not stored on our servers, and we cannot decrypt it.

When a direct connection is not possible

Some networks will not allow two devices to reach each other directly. In that case the encrypted stream is passed through a relay server we operate, which forwards the traffic without holding the keys to it — it moves ciphertext from one side to the other. The relay does not record the stream.

We do not record sessions

The Service has no session recording feature. We do not capture screenshots, video, keystrokes, clipboard contents or transferred files, and there is nothing on our side for us — or anyone who compelled us — to hand over. What we keep about a session is described in section 3 under "Session history": who connected to which machine, when, and for how long. Never what was on the screen.

What the person at the device can see

A session cannot start without consent from the device being controlled — see section 4. While one is running, the person sitting at that device can always tell: on Android an ongoing notification shows the session and a Stop button, and an on-screen pointer follows the remote cursor, so it is visible that someone else is driving.

3. Information We Collect

Account information

Accounts are held by the shared Vikn identity service, which is the same account you use for other Vikn products.

  • Your name and email address, and your password stored only as a salted hash.
  • The organizations you belong to and your role in them.
  • Access tokens issued to keep you signed in.

Registered devices

When you add a machine to your account so that you can reach it later, we store a record of that machine: a name (by default the machine’s own name, which you can change), its operating system, the nine-digit ID it uses to identify itself to the connection service, when it was last seen online, and a hash of the credential the machine uses to prove it is itself. We store the hash, not the credential.

Session history

When a session ends we write one line of history: which machine was connected to, which account owns it, who connected (for sessions authorized through your account — a session joined with a one-time code or an unattended password proves knowledge of a secret rather than an identity, so no person is recorded), how the session was joined, when it started and ended, and how long it lasted.

This exists so an account can answer "how many hours did we spend on this customer’s machines last month, and which engineer spent them" — the number a support business bills on — and so that the owner of a machine can audit who reached it.

Connection and diagnostic information

  • Network addresses of the two devices, exchanged so they can find each other and establish the connection.
  • Your IP address, seen by our servers as with any internet service, and recorded in server logs.
  • App version, operating system and browser or device user agent.
  • Error reports when a connection fails — the machine ID being dialled, the stage it failed at, an error description, and the address the app was trying to reach. We use these to find outages we would otherwise never see, such as an app that cannot reach the connection service at all.

Unattended access credentials

If you set a password on a machine so it can be reached without someone approving each session, that password is never sent to us and is not stored on our servers. The machine keeps only a value derived from it, which cannot practically be turned back into the password, and a viewer authenticates against the machine itself. If you lose that password we cannot recover it — you set a new one at the machine.

Billing information

Your plan, and a record of your purchases and invoices. Payments are processed by our payment providers, or by Apple or Google for a purchase made inside a mobile app; we receive a record of the transaction, not your card number.

What we do not collect

  • The contents of any session — screen, input, clipboard or files. See section 2.
  • Audio. The app has no microphone or system-sound capture of any kind, on any platform.
  • Your location.
  • Your contacts, photo library, call logs, SMS, or the files on your device outside a transfer you start yourself.
  • Advertising identifiers. We run no advertising and no cross-site tracking.

4. Consent and Control on the Device Being Controlled

Nothing about this product works without the device on the other end agreeing to it. How that consent is given depends on the platform.

Android

  • Screen sharing starts only after you tap through Android’s own screen-capture warning. That approval is good for one session: end it and Android asks again.
  • Remote control of the device is off unless you turn on Vikn Remote Desk’s accessibility service yourself in Android Settings, after reading Android’s warning about what that service can do. Until you do, a viewer can see the screen but nothing it sends will act on your device.
  • While sharing, an ongoing notification shows the session ID and a Stop button, and cannot be dismissed.
  • The permissions the app requests are: internet and network state (to connect), foreground service and screen-capture foreground service (to keep sharing alive while the app is in the background), notifications (for the ongoing session notification), and a wake lock (so an unattended machine does not stop streaming when its screen dims). The app requests no other permission.

iOS and iPadOS

On iPhone and iPad the app can only connect out to other devices. It cannot share its own screen and cannot be controlled — iOS provides no way to do either — so nothing on your iPhone is ever exposed by installing it.

Windows, macOS and Linux

  • A one-time code shown on the machine lets someone connect once, for that session only.
  • An unattended password, which you set at the machine, lets a machine be reached when nobody is sitting at it — for your own computers and the fleet you are responsible for.
  • A machine registered to your account can be reached by that account without a code. Removing it from your account stops that immediately.
  • macOS and Linux ask for the operating system’s own screen-recording and accessibility permissions before the app can capture or control anything.

You can end a session from either side at any moment, and you can remove a registered machine from your account at any time, which stops it being reachable.

5. How We Use Your Information

We use what we collect to:

  • Introduce two devices to each other so a session can be established, and relay the encrypted stream when a direct path is not available.
  • Authenticate you, and check that a machine may be reached by the account asking for it.
  • Show you your registered machines and their online status.
  • Show you your session history, and calculate usage against your plan.
  • Bill you, and provide invoices and receipts.
  • Diagnose failed connections and keep the Service reliable.
  • Detect and prevent abuse — including use of the Service for unauthorized access to devices — and enforce our terms.
  • Comply with legal obligations.

6. How We Share Information

We do not sell your personal information, and we share no session content because we hold none. We share other information only in these circumstances:

  • Within your organization: an organization’s administrators can see its registered machines and its session history, including which member connected to what.
  • Service providers: cloud hosting, the relay infrastructure, and payment processing, under agreements that require them to protect your data.
  • Legal requirements: when required to comply with applicable law, regulation, legal process, or an enforceable governmental request.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
  • With your consent: when you direct us to share information with a third party.

7. Security

No method of transmission or storage is completely secure. Keeping your account credentials and any unattended password confidential is your responsibility — an unattended password is, by design, enough to reach that machine.

  • Session traffic is encrypted end to end between the two devices, including when it is relayed.
  • Everything the apps send to our servers travels over HTTPS/TLS.
  • Passwords are stored only as salted hashes; device credentials only as hashes; unattended passwords are never sent to us at all.
  • Relay credentials are minted per connection and expire, so a captured one is useless shortly afterwards.

8. Data Retention

We keep your account and registered machines for as long as your account is active. Session history is kept as a billing and audit record for the life of the account, and survives a machine being removed from the registry — otherwise removing a machine would erase the record of what it cost and who reached it. Diagnostic logs are short-lived and are kept only long enough to investigate faults.

After your account is closed we may retain limited information where necessary to comply with legal obligations, resolve disputes, enforce our agreements, or for security and fraud prevention. Deletion timelines are set out on our Account and Data Deletion page.

9. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your personal information.
  • Object to or restrict certain processing of your information.
  • Request a copy of your information in a portable format.
  • Withdraw consent where processing is based on consent.

Write to us using the details at the end of this policy, or follow the steps on our Account and Data Deletion page. We respond within 30 days. Where a machine or a session belongs to an organization rather than to you personally, we act on that organization’s instructions and will direct your request to its administrator.

10. Deleting Your Account

You can ask us to delete your Vikn account, your registered machines and the personal data attached to them at any time, whether or not you still have the app installed. The request routes, what is erased, what is retained and for how long are documented on our Account and Data Deletion page, linked in the footer of this page.

11. Children's Privacy

The Service is a professional tool and is not directed to children. We do not knowingly collect personal information from children under 16 (or the minimum age required in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.

12. International Data Transfers

Your account and session records may be stored and processed in countries other than the one you live in, where data protection laws may differ. Where we transfer information internationally we take steps to keep it protected in line with this Privacy Policy and applicable law. Session content is not affected: it goes between the two devices and is not stored anywhere.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you in the app. Continuing to use the Service after changes take effect means you accept the revised policy.

Contact

If you have a question about this document, or about how we handle your information, write to us — we answer every message about privacy within 30 days.

Company: Vikn Codes LLP Email: support@vikn.io Website: https://vikn.io
Vikn Desk — Privacy Policy Vikn Desk — Terms of Service Vikn Remote Desk — Terms of Service Vikn — Account and Data Deletion

Vikn · vikn.io · support@vikn.io