Help › How & why
Encryption, direct connections and relays
Why our servers cannot see your screen, and what they know anyway.
End-to-end encrypted
Everything that happens in a session, meaning picture, input, clipboard and files, is encrypted between the two devices. The keys are created on the devices and never leave them.
- Every device has its own key. Our service confirms it with a device certificate valid for one year.
- Every session needs a permission from our service that is valid for 60 seconds and can be used once. The target device checks it itself.
- The connection itself uses TLS 1.3; both sides identify themselves with their device keys.
Direct or through a relay
DeskRanger connects the devices directly when possible, in the same network or over the internet. If that fails, for example behind strict firewalls, a relay forwards the data. The relay sees only encrypted data, the addresses of both devices and their public keys. It holds no key to decrypt anything and stores no content. In the browser a session always runs through a relay.


What our servers know
Our service knows your devices, groups and favourites, and connection data: who connected when with what, with which permissions, directly or through a relay, for how long and how much data. Never the content. We delete the permissions after 30 days and the session records after 12 months, and both at once when you delete your account. All services run in data centres in the Netherlands. The details are in the Privacy Policy.
New devices in the account
When a new device signs in to your account, your other devices show New device in your account. If that wasn’t you, remove it right there with Remove Device.