What LocalCommander processes
Depending on the action you request, LocalCommander may transiently process account identifiers, paired-device identifiers, tool names, request IDs, file paths or selected file content, screenshots, window metadata, clipboard content and browser page content.
Why the data is processed
Data is processed to authenticate and authorize the user, route a request to the correct paired computer, execute the requested workflow, return the result, meter plan usage, prevent abuse and maintain service reliability.
What is stored by the service
LocalCommander stores account identifiers, plan and usage counters, paired-device records, hashed pairing and OAuth credentials, OAuth client metadata and support tickets. Device credentials are stored on the Windows PC using the operating system's protected user credential mechanism.
Execution payloads
The gateway is designed to route tool requests and results rather than archive their contents. Usage metering records tool names and call counts, not tool arguments, file bodies, screenshots, clipboard values or browser page contents. Operational logs may contain request metadata and non-secret error information needed to diagnose failures.
Remote execution
The Windows companion initiates outbound encrypted connections. It does not require a public inbound port. LocalCommander account and OAuth bearer tokens are not forwarded to the Windows companion; the companion receives only its device-scoped credential and routed tasks.
Authentication and billing
Account authentication is handled through Google Cloud Identity Platform. Paid-plan checkout and subscription management may be handled by Stripe when billing is enabled. Those providers process their own service data under their respective privacy terms.
Retention and deletion
Account, device and entitlement records are kept while needed to provide the service. Revoked device records and usage history may be retained for security, billing and abuse-prevention purposes. Support requests are retained while needed to resolve and document the request. A user may request account-data deletion through the support channel, subject to records that must be kept for legal, fraud-prevention or billing purposes.
User controls
Users can disconnect an AI client, revoke paired computers, sign out, rotate pairing credentials by revoking and re-pairing a device, and request account-data deletion.
Privacy or security request
Use the public LocalCommander support form and choose Privacy or Security. Do not include passwords, access tokens or recovery codes.