Local controls stay local
Pairing, button presses, keyboard text, live microphone audio and screen sharing go directly to the device you select.
Privacy policy
Cryptid Remote controls TVs and computers on the local network you choose. We do not receive your remote-control input, microphone audio, typed commands, or live screen-share frames on our servers.
The short version
Pairing, button presses, keyboard text, live microphone audio and screen sharing go directly to the device you select.
Searches and filters go to our catalogue API and relevant content suppliers so we can return results.
You may create an optional Firebase account using an email address and password. The current app does not sync your saved content or process in-app purchases.
We do not show third-party ads, use advertising IDs, sell personal information, or create a persistent catalogue visitor ID.
01 / Scope
Cryptid Remote is operated by Cryptid VPN Ltd ("we", "us" or "our"). Cryptid Apps is our developer name on Google Play. This policy covers the Cryptid Remote phone app, its connection to Cryptid Remote Desktop, the supporting movie and TV catalogue service, and this privacy page.
This policy does not cover other Cryptid-branded products, which may have their own notices.
02 / On your network
These features work between your phone and the TV or computer you select. Their contents are not sent to Cryptid VPN Ltd's servers.
Local IP addresses, ports, device names, models, platforms, versions, discovery responses, pairing tokens, a random phone identifier, and pairing certificates or keys may be accessed or stored to find and reconnect to your devices.
Stored locally until you forget the device, clear app data, or uninstall.Button presses, pointer or gamepad input, keyboard text, and assistant or search commands are sent directly to the selected TV or Cryptid Remote Desktop.
Used only for the requested operation and not intentionally retained by us.If you start a supported voice feature and grant permission, live microphone audio is streamed directly to the selected TV. Typed speech may create a temporary audio file on your phone.
Live audio is not stored by us; temporary audio is deleted after use.After Android's screen-capture confirmation, live frames go directly to the selected Cryptid Remote Desktop. The phone and desktop keep only the latest frame briefly in memory for display.
The session is not recorded or uploaded to our servers; memory is cleared when it ends.The app may read nearby Bluetooth device names and addresses and remember the preferred host and relevant Bluetooth settings for supported gamepad features.
Stored in app-private storage until cleared or the app is uninstalled.Favourite TV apps, watchlists, media title identifiers, country and provider selections, custom search providers, control targets, and gamepad settings are stored on your device.
Not synced to our servers in the current version.03 / Online catalogue
When you use the movie and TV catalogue, the app contacts api.cryptidvpn.com. We process only what is needed to return and protect the requested service:
| Information | Why it is used | Where it goes |
|---|---|---|
| Title or person searches | Return matching catalogue results | Our API and the relevant catalogue supplier |
| Country, provider, genre, year, language, rating, media type, sort, category, and page selections | Return the availability and filters you request | Our API and, where necessary, catalogue suppliers |
| IP address, user agent, requested route, and time | Transmit, secure, and troubleshoot the request | Cloudflare and Hetzner as infrastructure providers |
The catalogue application does not keep request logs or per-visitor metrics. Its production container has application logging disabled, and the app does not assign or send a persistent catalogue visitor identifier.
Search caches may contain a search term and returned results for no more than 24 hours; the term is hashed in the cache filename. Other catalogue response caches expire within three days, with top-ten caches limited to 24 hours. Cache entries are not associated with an account, visitor ID, or IP address.
Using search and filters is optional, but the catalogue cannot return the requested result without them. Local remote-control features work without an account or the hosted catalogue.
When you visit this privacy page, Cloudflare and our host receive ordinary technical request information such as your IP address, browser information, route, and time so the page can be delivered securely. We do not use that request to choose your catalogue country. This page does not set advertising or analytics cookies and contains no third-party analytics tracker.
04 / Your device
Cryptid Remote asks for a device permission only when the related platform or feature requires it. Depending on your device, these may include:
You can deny or revoke a permission in your phone's settings. The related feature may then stop working.
05 / Other organisations
We use providers only where needed to deliver, distribute, support, or protect Cryptid Remote:
Proxies and protects our catalogue API and this site and may process IP addresses and traffic, browser, device, and security information.
Privacy policyHosts the Cryptid Remote API in Germany. No Hetzner server backup is currently enabled for the catalogue API.
Data protection informationProvides Streaming Availability catalogue data through the direct API route. Relevant searches and selections may be sent from our server.
Service documentationSupplies movie and TV metadata and artwork. Relevant title or catalogue requests may be sent to it.
Privacy policyFirebase Authentication processes an optional account's email address, Firebase user ID, authentication state, IP address, user-agent and security information. Google Cloud Firestore may store user-chosen synced content and premium entitlement if cloud sync launches.
Privacy and security informationDistribute the free app. If optional premium purchases launch, the store will handle payment-card details and we may receive transaction, product, subscription-status, and entitlement information needed to validate or restore a purchase.
Provides our privacy and support email service when you choose to contact us.
Privacy policyArtwork and provider images may load from TMDB, Movie of the Night, Google favicon services, or another relevant image host. That host receives technical connection information such as your IP address and user agent when your device loads an image directly.
If you deliberately open a title or search on IMDb, Reddit, Letterboxd, Rotten Tomatoes, YouTube, Wikipedia, Google, TMDB, a streaming service, or a custom provider, your request is handled under that service's privacy policy. We do not control independent services.
We may also disclose limited information to professional advisers, courts, regulators, or authorities where legally required or needed to establish or defend legal rights, or to a successor organisation if the business is reorganised or sold, subject to appropriate notice and safeguards.
We do not sell personal information or share it with data brokers or advertising networks. We require service providers acting for us to protect information and use it only for the agreed service.
06 / Lawful bases
Where UK data-protection law applies, our lawful bases are:
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
07 / Deletion
| Information | Retention |
|---|---|
| Local pairing, saved devices, and preferences | Until you remove or forget them, clear app data, or uninstall. |
| Live remote input, microphone audio, and screen frames | Only for the live requested operation; not intentionally retained by us. |
| Temporary synthesised speech | Deleted after the requested operation. |
| Search-result cache, including search terms and results | No more than 24 hours. |
| Other catalogue response caches | No more than 3 days; top-ten caches no more than 24 hours. |
| Catalogue app request logs and visitor metrics | Not retained; application logging is disabled. |
| Infrastructure traffic, security, and system records | Only as long as reasonably needed to deliver and secure the service, investigate an incident, or meet law. We aim for 30 days or less where provider and host controls allow. Provider-controlled periods can vary by active service and legal requirements. |
| Optional account email address, Firebase user ID, authentication and security records | While the account remains open; deleted with the account except for limited security records retained by Firebase for its documented period or a legal record we are permitted to retain. |
| Optional synced content | Not collected in the current app. If cloud sync launches, it will be kept while the account remains open and deleted with the account, subject to stated legal exceptions. |
| Premium purchase and entitlement information | While needed to provide or restore the entitlement and support the purchase. Any accounting, tax, fraud-prevention, or legal record is retained only for its applicable required period. |
| Support and privacy correspondence | Normally 12 months after the request is closed, or longer only where needed for a dispute or legal obligation. |
| Records required by law | Only for the applicable statutory period. |
No Hetzner server backups are currently enabled for the catalogue API. If backups are introduced, we will update this policy, restrict access, exclude disposable caches and logs where possible, and use a maximum 30-day encrypted rolling lifecycle unless a different period is specifically justified.
08 / Protection
Our hosted API and this site use HTTPS/TLS. We minimise application logging, restrict production access to authorised people and providers who need it, and use app-private encrypted storage or platform keystores for sensitive local credentials where the platform implementation supports them.
Local connections use the protocols supported by each TV or computer. Some local HTTP or WebSocket connections are not encrypted. Keep your phone, TVs, and computer software updated, and do not use local control or screen sharing on an untrusted network.
No transmission or storage method can be guaranteed completely secure.
09 / Control
End microphone or screen sharing in the app and revoke microphone, screen, Bluetooth, local-network, or notification permissions in device settings.
Forget or unpair devices, remove saved content and preferences, clear the app's storage, or uninstall the app.
Stop using the catalogue. Its short-lived caches expire automatically and are not tied to a visitor or account identifier.
Ask about access, correction, deletion, restriction, portability, consent withdrawal, or another privacy concern.
Where the right applies, you may request access to or a copy of your personal information, ask us to correct or delete it, restrict its use, receive portable information, or withdraw consent. Withdrawal does not affect processing that was lawful beforehand.
You may object at any time to processing based on our legitimate interests. Email [email protected] and explain what you are objecting to.
We may ask for proportionate information to verify a request. We will respond within the period required by applicable law and explain if an exemption applies.
UK users may complain to the Information Commissioner's Office (ICO). You may also complain to the data-protection authority where you live or work.
10 / Locations
Our API is hosted in Germany, while providers such as Cloudflare, Google, and catalogue suppliers may process information in the UK, European Economic Area, United States, or other countries where they operate.
Where personal information is transferred to a country without applicable UK adequacy regulations, we use an approved mechanism where required, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate safeguards. You may request details from [email protected].
11 / Age
Cryptid Remote is not directed to children under 13, and children under 13 should not use it. Users aged 13 to 17 should use the app with a parent or guardian's involvement where local law requires it. We minimise personal-information use for everyone.
If you are a parent or guardian and believe a child has provided personal information to us, email [email protected].
12 / Optional services
The current version supports an optional email-and-password account through Firebase Authentication. An account is not required to use the free app. The current app does not sync favourites or other saved content to an account and does not process an in-app purchase or subscription.
If you create or use an email-and-password account, Firebase Authentication processes your email address, Firebase user ID, authentication state, IP address, device or user-agent information, and security records needed to create, authenticate, protect, and administer the account. Your password is handled by Firebase Authentication and is not visible to us in readable form.
If Google sign-in is added to a future mobile release and you choose it, Google may provide the profile fields shown during sign-in, such as your email address and name. We will not receive your Google password.
When optional cloud sync is enabled, we may use Google Cloud Firestore to store favourites, watchlists, preferences, subscription entitlement, and other information you choose to sync, associated with your Firebase user ID. Local device-control credentials, live remote input, microphone audio, and screen-share frames will not become cloud account content.
Cryptid Remote will remain free to download and use, with optional premium features or access tiers available as in-app purchases. Google Play or the Apple App Store will process payment. We do not receive your full payment-card details.
To validate, provide, and restore premium access, we may process a store purchase token or transaction identifier, product or plan selected, purchase and subscription status, renewal or expiry information, store platform, and the entitlement linked to your account or device. The app store also processes purchase information under its own privacy policy.
Data deletion request
You can request deletion at any time by emailing our privacy team. This works even if you have uninstalled the app and does not require you to reinstall or sign in.
Email a deletion requestFor a current optional account, deletion will remove the Firebase Authentication account, its email address and Firebase user ID, and associated authentication information, subject only to the limited security or legal retention explained here. We will also delete support or privacy correspondence and other information we can identify from the email and details you provide, unless a limited record must be retained for a stated legal reason. We will delete the account rather than merely disabling sign-in.
Catalogue searches are not linked to an email, account, or persistent visitor ID and their caches expire automatically within the periods stated above. If synced favourites, watchlists, preferences or premium entitlement records are introduced later, those associated records will also be included in account deletion when they are no longer legally required. We will request deletion from service providers acting for us where applicable.
We may retain only limited purchase, accounting, tax, fraud-prevention, security, dispute, or legal records where necessary and permitted. We will restrict retained records to that purpose and keep them only for the applicable period. Fully anonymised information that can no longer be connected to you is not account data.
Local pairing details, preferences, and saved content remain on your device because we do not hold them; remove them by forgetting devices, clearing the app's storage, or uninstalling. Deleting a Cryptid Remote account will not automatically cancel billing managed by an app store, so store subscriptions may need to be cancelled separately through Google Play or the Apple App Store to prevent future charges.
The current app supports Firebase email-and-password accounts but does not currently collect cloud-synced favourites, purchase transactions or subscription information. We will verify each released implementation and update this policy and the app-store declarations before Google sign-in, cloud sync, or paid features go live.
13 / Updates
We will update this page when our practices or features change and revise the effective date above. If a change materially affects how we use personal information, we will provide additional notice in the app or another appropriate way before it takes effect where required.
Questions or requests
The quickest way to reach the privacy owner is by email.
[email protected] Cryptid VPN Ltd