Privacy Policy
Last updated: July 2026
This Privacy Policy explains how OnOffMyPC (“we”, “us”, “Operator”) collects, uses, and shares personal data when you use our websites, web app, mobile apps, and APIs (the “Service”). For consumer accounts we act as the data controller for account and device data we store to provide the Service. Business customers who process personal data through a paid B2B arrangement may also need our Data Processing Addendum.
What we collect
Account. Email address; hashed password when you register with email/password (we never store passwords in plain text); account timestamps; and, if you use social sign-in, the provider subject identifier and email shared by that provider (Google, Apple, or Microsoft when enabled).
Devices and usage. When your ESP32 device is connected, we receive and store:
- Commands you send (power on, power off, reset) and their delivery status
- Telemetry: PC power state, room temperature, room humidity, Wi-Fi signal strength
- Device registration details you provide (name, firmware version, last-seen time)
- Scheduled commands you create
Push notifications. If you enable notifications in a supported mobile app, we store a push-notification token so we can send alerts (for example device offline/online or command delivered/failed). Android uses Google Firebase Cloud Messaging (FCM). Apple Push Notification service may be used if/when an iOS client is enabled for push.
Billing (when paid unlocks are offered). Checkout is provided by Polar, our merchant of record. Polar collects contact, billing, tax, and payment details. We do not receive or store your full card number. We store Polar checkout, customer, order, receipt, amount, currency, refund status, and device identifiers so we can grant access and show purchase history.
Security and operations. Client IP addresses are used transiently for rate limiting and may be recorded in a security audit log for security-relevant events. We may receive messages you send via the contact form.
We do not use advertising or analytics SDKs in the OnOffMyPC apps, and we do not sell personal data.
Why we use it (purposes and lawful bases)
In plain language, we process data to:
- Provide the Service — authenticate you, route commands, show status and history, send transactional email (verification, password reset), and deliver push alerts you enable (contract / steps needed to provide the Service you request)
- Secure the Service — rate limiting, abuse prevention, audit logging (legitimate interests in operating a secure service; legal obligations where applicable)
- Billing — grant device unlocks and reconcile Polar notifications when paid features are enabled (contract)
- Support — respond to privacy@ / support@ requests (legitimate interests and, where required, legal obligations)
Where we rely on consent (for example optional push notifications on some platforms), you can withdraw it in the OS or app settings.
Subprocessors
We use these processors to run the Service:
- Hosting Providers — application hosting, databases, email routing, and related edge hosting
- Resend — transactional email (verification, password reset)
- Polar — hosted checkout/customer portal, merchant-of-record payments, tax, invoices, receipts, and refunds (when paid unlocks are offered)
- Google Firebase Cloud Messaging — Android (and related) push delivery
- Apple / Google / Microsoft — identity providers when you choose social sign-in; Apple may also provide push delivery for iOS when that client uses APNs
We do not place your Wi-Fi passwords or device pairing secrets in marketing analytics tools; those stay on-device or in our operational systems as needed for the Service.
International transfers
Data is processed on our hosting providers' globally distributed infrastructure and by the subprocessors above. By using the Service you acknowledge that processing may occur in countries other than your own. Where GDPR or similar laws apply, we rely on appropriate transfer mechanisms used by our providers (for example, standard contractual clauses and published data transfer terms where applicable).
Retention
We apply the following retention windows in production (enforced by scheduled cleanup unless noted):
- Raw telemetry — 30 days, and at most about 2,000 rows per device
- Hourly telemetry aggregates — 90 days
- Commands — 30 days
- Finished scheduled commands — 30 days after sent/cancelled
- Security audit log — 180 days
- Auth tokens (email verify / password reset) — deleted when used or expired
- Accounts and devices — until you delete them; account deletion has a 15-day grace period before permanent purge
- Billing / Polar records we store — kept with the account until purge; Polar may retain transaction and tax records under its own legal obligations
- Operational backups — roll off on approximately a 90-day schedule
You can permanently delete your account and associated Service data from the app (Account → Delete account), or by emailing [email protected] or [email protected]. Email deletion and access requests are processed within 30 days.
Your rights
Depending on where you live (including under the GDPR/UK GDPR), you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. To exercise these rights, email [email protected].
You can download a machine-readable copy of your account data anytime from the web app under Account → Download my data (JSON export of profile, devices you own, billing summary, and recent account activity). You may also email [email protected] for assistance.
You may also lodge a complaint with your local data protection authority. If you are in the EEA/UK and we later appoint an EU/UK representative, we will update this page.
Cookies and tracking
The marketing site (this site) sets no cookies and uses no third-party tracking scripts. The OnOffMyPC apps (web dashboard and mobile) use a session token stored on your device for authentication. Automated bot protection tools may run on login/register pages. If you purchase an unlock or open a receipt, you leave the app for Polar’s hosted checkout or customer portal, where Polar’s own cookie and privacy practices apply.
Children
The Service is not directed at children under 16. If you believe we have collected data from a child incorrectly, contact [email protected] and we will delete it.
Changes
We may update this Privacy Policy from time to time. We will post the updated policy with a revised “Last updated” date.
Contact
Privacy questions, access, deletion, or export requests: [email protected]. General support: [email protected]. Security inquiries may also use support@.