1. Introduction
Your privacy is important to us. It is Carlos Sura's policy to respect your privacy regarding any information we may collect from you across our website, vesselrdp.com, and the Vessel RDP software ("the Software").
2. Information We Collect
2.1 Support Form Data
When you contact us via our Support page, we collect your name, email address, and the contents of your message. This data is transmitted via Formspree and delivered to our support inbox. It is used strictly to respond to your inquiry and provide customer support.
2.2 Website Usage Data & Cookies
Our website collects standard server logs, including your IP address, browser type, and pages visited, for operations and security. Additionally, we use Google Analytics to analyze website traffic and user engagement. This service utilizes tracking cookies to gather anonymous statistics. You can choose to accept or decline these cookies via the consent banner. We do not sell your data to third parties.
2.3 Data Stored Locally by the Software
The Vessel RDP software runs on your own machine. Your connection profiles — including server addresses, ports, usernames, display and quality preferences, and feature toggles (clipboard, audio, microphone) — are stored locally in an application database on your device (on Linux, under ~/.local/share/vesselrdp/). If you choose to save a connection password, it is encrypted at rest on your device using AES-256-GCM; where supported, authentication tokens are stored in your operating system's secure keyring. We never transmit your stored credentials to us. Separately, the Software maintains a local certificate-trust record (hostname, port, and certificate fingerprint for each server you've connected to) to detect impersonation on future connections — the same trust-on-first-use model used by SSH. This record also never leaves your device.
2.4 Crash and Error Reporting
To diagnose stability problems, the Software uses Sentry to report unexpected crashes and errors. A crash report includes technical diagnostic data such as the error and stack trace, application version, and operating system details. We configure Sentry to not send personal identifiers, and we additionally strip user, hostname, and request context before any report leaves your device. We never collect your keystrokes, screen contents, clipboard data, or the contents of your remote sessions. Crash reporting is enabled by default, but you can turn it off at any time by disabling it in the application or by setting the VESSEL_DISABLE_CRASH_REPORTS environment variable. A local crash.log file is also written to your device, which you may optionally attach when contacting support.
2.5 Your Remote Sessions
When you connect to a remote host, the Software communicates directly between your machine, that remote host, and — for Microsoft Entra ID (Azure AD) sign-in — Microsoft's authentication services. This traffic does not pass through us. The data exchanged during a session (including any clipboard, audio, or microphone content you enable) flows between you and the remote host you have chosen, governed by your organization's IT policy.
3. Third-Party Services
We rely on the following third-party services:
- Formspree: Processes our website contact form submissions. Subject to Formspree's privacy policy.
- Cloudflare Turnstile: Protects our support form from spam and bots, as a privacy-preserving alternative to traditional CAPTCHAs.
- Google Analytics: Analyzes website performance and usage. We initialize Google Analytics in restricted mode; tracking cookies are only enabled if you provide explicit consent. Subject to Google's Privacy Policy.
- Sentry (Functional Software, Inc.): Processes optional crash and error reports from the Software, as described in section 2.4. Subject to Sentry's privacy policy.
- Microsoft: When you sign in to a remote host using Microsoft Entra ID (Azure AD), the Software contacts Microsoft's authentication endpoints. This interaction is governed by Microsoft's privacy policy.
4. Data Retention and Security
We retain collected information only for as long as necessary to provide the requested service. Support correspondence is kept while needed to assist you; crash reports are retained for a limited period for debugging and then discarded. We protect the data we hold within commercially acceptable means to prevent loss, theft, and unauthorized access, disclosure, or modification. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
5. Your Rights
You have the right to request a copy of the personal data we hold about you, or to ask that we delete or correct it. To exercise these rights, please contact us using the details below.
6. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the date above.
7. Contact Us
If you have any questions or concerns about our privacy practices or your data, please contact us at: [email protected].