Draft. This is a draft and not yet in effect. It will be reviewed before Pocketlid launches and may change.

Privacy Policy

Last updated: October 5, 2026

Who we are

Pocketlid is operated by a sole proprietorship based in Türkiye (“Pocketlid”, “we”, “us”). We are the data controller for the personal data described in this policy. You can reach us at support@pocketlid.com.

The short version

Your screen, audio, keyboard and pointer input, files and clipboard travel directly between your phone and your Mac, encrypted end to end. They never pass through our servers in readable form. When a relay is needed, it only forwards encrypted packets. We store what we need to run your account and connect your devices — and nothing more.

What we collect

  • Account data: your email address and, if you sign in with a third-party provider, the account identifier it gives us.
  • Device data: for each Mac and phone on your account, its name, device type and public key, plus when it was added and last seen.
  • Connection metadata: when your devices connect, whether a Mac is online, pending wake requests and technical setup messages, including IP addresses and network candidates needed to establish a peer-to-peer connection.
  • Wake-on-LAN data: your Mac’s network hardware address, local IP address and broadcast address, so a phone on the same network can wake it.
  • Beta waitlist: if you sign up for the beta, your email address, chosen platform and language — see “Beta waitlist” below.
  • Support messages: what you send us by email.
  • Contact form: your name, email address, topic and message, plus your organization and team size if you give them. We use them only to reply to you, keep them as long as needed for the conversation, and deliver them to our support inbox via Resend.
  • Subscription data (after launch): your plan, its status and expiry date, as reported by the app store or payment provider. We don’t receive your full card details.

What we don’t collect

  • The content of your screen, audio, keystrokes, files, clipboard or terminal sessions.
  • Your Mac’s PIN. Only the Mac stores a value derived from it.
  • Your Mac login password. If you save it in the app, it’s stored encrypted on your phone and protected by your fingerprint.
  • Advertising identifiers. This website uses no cookies and no analytics.

Stored only on your devices

Connection history and connection notifications are kept on your Mac. The keys of trusted devices are stored on each device. Pocketlid’s settings are stored locally on the device they belong to.

Why we use your data

We use your data to provide the service (creating your account, listing your devices, connecting them and handling wake requests), to keep it secure (rate limiting, preventing abuse, revoking devices), to answer support requests and, after launch, to manage subscriptions.

Under the GDPR, our legal bases are the performance of our contract with you (Art. 6(1)(b)), our legitimate interest in keeping the service secure (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c)). Under Türkiye’s Personal Data Protection Law No. 6698 (KVKK), we rely on Article 5(2)(c) (necessary for a contract), 5(2)(ç) (legal obligation) and 5(2)(f) (legitimate interest).

Beta waitlist

If you sign up for the beta on our website, we store your email address, the platform you chose (Android, iPhone or both), your language, and when you signed up and confirmed. We use this only to invite you to the beta and to send you emails about it.

Our legal basis is your consent (GDPR Art. 6(1)(a); KVKK Article 5(1), explicit consent). We use double opt-in: you’re only added to the list after you click the confirmation link we email you. Unconfirmed signups are deleted after 7 days. You can withdraw your consent and leave at any time with the link in every beta email, or by writing to support@pocketlid.com.

Beta emails are sent via Resend, and the list is stored on Cloudflare.

Service providers

We use a small number of providers who process data on our behalf:

  • Cloudflare — hosting of this website, our API, database and encrypted relay.
  • Resend — sending sign-in code and beta emails, and delivering contact form messages to our support inbox.
  • Google Workspace — our support email.
  • App stores and payment providers — processing purchases, after launch.

International transfers

Some providers process data outside Türkiye and the European Economic Area, including in the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses, and on the transfer mechanisms of KVKK Article 9.

How long we keep data

Account and device data are kept while your account exists. Sign-in codes expire within minutes; session tokens expire or are revoked when you sign out. Connection metadata is kept only as long as needed to operate and secure the service. When you delete your account, your account and device records are deleted, except where the law requires us to keep something longer.

Your rights

You can access, correct, export or delete your data, object to or restrict certain processing, and withdraw consent where processing is based on consent. Under KVKK Article 11 you have equivalent rights, including to learn whether your data is processed and to request its deletion. You can delete your account at any time in the app under Settings › Delete account, or email us. You also have the right to complain to a supervisory authority, such as the Personal Data Protection Authority (KVKK) in Türkiye or your local authority in the EU.

Security

We design Pocketlid so that we don’t need to see your content: connections are encrypted end to end, devices authenticate each other with keys that stay on the device, and our server is treated as untrusted. Read more on our security page.

Children

Pocketlid isn’t directed at children under 16, and we don’t knowingly collect their data.

Changes

We’ll update this policy when our practices change and show the date of the latest version at the top. For significant changes, we’ll let you know in the app or by email.