Light RemoteLegal Center
DownloadsSupportProduct home
Legal documents
Terms of ServicePrivacy PolicyCookie Policy
Product
Support Downloads Light Remote

Privacy Policy

Last updated: October 6, 2026

This Privacy Policy explains how Light Remote handles information when you use the hosted service, account portal, device software, official plugin/MCP surface, downloads, and related services. Light Remote is part of the thaiduy.digital product ecosystem.

This policy describes Light Remote's own processing. Third-party AI clients, identity providers, infrastructure services, code hosts, and other integrations have their own privacy practices.

1. Scope

Light Remote is designed to connect an authenticated AI client to an explicitly authorized user-owned device. The hosted service does not expand the access granted by that device, its operating system, or its Local Wall policy.

2. Data used to provide the service

Depending on how you use Light Remote, we may process the following categories:

  • Account data: email address, authentication provider, verification state, account status, plan, entitlements, and security events.
  • Device data: device identity, display name, platform, architecture, software version, capabilities, connection state, last-seen time, Main/Fleet role, and policy or compatibility metadata.
  • Authorization and session data: client-to-device approvals, session identifiers, target-device references, grants, leases, operation identifiers, and recovery state.
  • Remote task data: data required for an operation, which may include file paths or content, search terms, command input, terminal input/output, transfer chunks, process state, and bounded Real Remote semantic or visual state.
  • Usage and diagnostics: tool-call counts, connected device-hours, timestamps, error categories, compatibility information, service health, security events, and diagnostic logs.
  • Support and communication data: information you send when requesting support, account help, upgrades, or other assistance.

3. Purpose and sharing

We use information to authenticate users, link and route work to the intended device, enforce policy and entitlements, recover durable operations, provide account and activity views, prevent abuse, troubleshoot failures, distribute updates, communicate about the Service, and comply with legal obligations.

We do not sell personal data or use remote task content for behavioral advertising. Light Remote does not train a general-purpose AI model on your remote task content.

4. Remote task data

Remote task data is processed because the requested operation cannot be performed without moving the necessary instruction or result between the selected client and device. We aim to minimize what is transmitted and to keep credential material out of remote responses.

Some task data may exist transiently in memory, request buffers, transport layers, or security/diagnostic logs. Durable jobs, transfers, terminals, sessions, or Real Remote state may retain the minimum operational metadata needed for continuation, recovery, or policy enforcement.

Light Remote is not intended as a general cloud-storage service. Keep authoritative copies of files and important state on systems you control.

5. Restricted secrets

Remote tools are not intended to collect passwords, MFA or OTP codes, private keys, bearer tokens, API keys, full payment-card data, government identifiers, or protected health information. Response sanitization and policy controls are used to reduce accidental exposure, but users remain responsible for avoiding unnecessary secret handling.

6. Authentication and account cookies

Light Remote uses strictly necessary account cookies for sign-in, verified registration flows, and short-lived pending actions. Theme preference is stored locally in the browser. See the Cookie Policy for details.

7. Third-party services

When you choose to use a third-party service, information may be exchanged with that provider as necessary for the feature. Examples include:

  • an AI client or model provider that sends remote-tool requests and receives results;
  • an identity provider used for sign-in;
  • email and infrastructure providers used to deliver transactional messages and host the Service;
  • code hosting or release distribution providers used to publish software; and
  • other integrations you explicitly enable.

Those providers process data under their own terms and privacy policies. Light Remote does not control how a third-party AI service uses information after it leaves Light Remote and is received by that provider.

8. Retention and controls

We retain information only for as long as reasonably needed for the purpose for which it is processed, security, recovery, account operation, dispute handling, or legal compliance. Different records have different lifecycles:

  • account records generally remain while the account is active and for a limited period after closure where needed for recovery, security, or legal obligations;
  • device records remain until removed, revoked, or otherwise cleaned up under account lifecycle rules;
  • short-lived approval and registration artifacts expire automatically;
  • durable session or operation state remains only while needed to continue, recover, audit, or safely close the operation; and
  • usage, security, and diagnostic records may be retained longer than transient task data because they are used for quotas, abuse prevention, service integrity, and troubleshooting.

You can remove or revoke devices, close sessions, stop managed processes or terminals, and use available account controls to reduce retained operational state.

9. Account inactivity and deletion

Free accounts may enter an inactive or dormant state after an extended period without use, as shown in the Service. Dormancy is not the same as immediate deletion. Where account deletion is available or requested, we will remove or de-identify information that is no longer required, subject to security, backup, fraud-prevention, and legal retention needs.

10. Security

Light Remote uses layered controls including authenticated accounts, explicit device targeting, Local Wall A/B approval, device-local final policy, scoped sessions, restricted secrets, service hardening, and signed or health-gated update mechanisms where supported.

No security measure can guarantee absolute protection. You are responsible for securing your own devices, operating systems, local accounts, networks, and third-party AI accounts.

11. Your choices and privacy rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of certain personal data. You can also revoke devices and sessions through available product controls.

To make a privacy request, contact support@thaiduy.digital. We may need to verify your identity before acting on a request.

12. International processing

Internet services may process information in more than one country because infrastructure and third-party providers can operate globally. Where applicable law requires safeguards for international transfers, we will use measures appropriate to the relevant processing.

13. Children

Light Remote is a technical remote-computing product and is not directed to children. Do not create an account if you are not legally permitted to enter into the applicable agreement in your jurisdiction.

14. Changes to this policy

We may update this policy when the Service, legal requirements, or data practices change. The updated date above indicates the current version. Material changes will receive additional notice where appropriate or required.

15. Contact

Privacy questions and requests can be sent to support@thaiduy.digital.

Light Remote ยท thaiduy.digitalsupport@thaiduy.digital