abacad
Privacy Policy
Last updated: 23 July 2026
abacad ("abacad", "we", "us") is a device-relay console: it lets you pair your own devices and securely relay commands to them from an AI agent you control. This policy explains what we collect, why, and what we never do with it. We keep the surface small on purpose.
Information we collect
- Account details. The email address you register with, and a password that is stored only as a one-way bcrypt hash — never in plaintext.
- Google sign-in (optional). If you choose "Continue with
Google", we receive from Google your email address, basic profile
(name), and a stable Google account identifier, using only the
openid,email, andprofilescopes. We use these solely to create and identify your account. - Session data. An opaque session cookie that keeps you signed in.
- Device metadata. Device names, platform, hashed device tokens, and last-seen timestamps for the devices you pair.
- Activity trail. A record of account and device events — sign-ins, credential changes, device lifecycle, and the relayed commands that pass through the service (method, timing, and outcome) — so you can audit what happened.
- On-demand screenshots. When you or your agent request a screen capture from a paired device, the most recent frame is cached to display it in the dashboard.
- Screen, on-screen text, and files in transit. To carry out your agent's actions, screen captures, the device's on-screen text (accessibility tree), screen recordings, and any files you transfer pass through our relay. Binary payloads (screenshots, recordings, files) are streamed through a temporary blob store; on-screen text is relayed to the requester and is not written to durable storage, and command parameters (such as typed text or tap coordinates) are not recorded in the activity trail.
How we use your information
- To create and secure your account and keep you signed in.
- To operate the core service: routing your commands to your own devices.
- To show you an audit trail of activity on your account.
Service providers
Signing in with Google involves Google as the identity provider; your use of Google sign-in is also governed by Google's Privacy Policy. We may run on infrastructure providers that host the service on our behalf.
Data retention
We retain account and device data for as long as your account is active. Activity-trail entries are pruned automatically after a retention window. Cached screenshots are overwritten by newer captures, expire automatically after a short window (by default 24 hours), and are deleted when the device is removed. Transferred files and screen recordings held in the blob store are deleted automatically after a retention window (by default 7 days).
Your choices
- You can remove paired devices and rotate their tokens at any time.
- You can revoke abacad's access to your Google account from your Google account permissions page.
- You can request deletion of your account and associated data by contacting us.
Security
Passwords are bcrypt-hashed; device, MCP, and session tokens are stored only as hashes; and traffic is served over HTTPS. No system is perfectly secure, but we aim to store as little as possible.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy: privacy@abacad.ai.