Skip to content
DeskRanger
Product
Access & controlSupport & collaborationFiles & connectionsDevices & teamsSecurity & controlVirtualization & infrastructure
Remote desktopSee and control your Mac from a Mac, iPhone, iPad or right in the browser. With keyboard shortcuts, multiple displays and one-click system actions like Mission Control.
Access your own devicesOne switch is all it takes: your Mac stays reachable, even after a restart, at the login window and when the screen is locked.
Displays & resolutionSwitch between displays, match the resolution to your window or view everything pixel-perfect at 1:1. Even Macs without a monitor deliver a sharp picture.
Browser accessConnect right in the browser, with nothing to install and the same end-to-end encryption as in the app. Browser sessions are confirmed by the person at the device.
Help with a support codeThe other person reads you a short support code and confirms the session visibly on their own device. They can end it at any time.
Share your screenShare your iPhone or iPad screen with your other devices or via a support code. For showing and explaining: iOS allows viewing only, no remote control.
Privacy modeShield the remote screen from onlookers. The live session remains visible and can be ended on the host.
File transferSend files both ways during a session. Keep track of progress and incoming transfers.
ClipboardCopy text between devices. Clipboard sharing is part of your session controls.
Existing PCs via RDPOpen existing Windows Remote Desktop PCs in the same app, directly or through one of your devices on the same network, with no port forwarding. VNC and SSH follow.
Terminal & SSHOpen a shell or work together in a terminal. For tasks that do not need a full desktop.
Access to servicesReach web interfaces, files and services behind a device, such as your own server or NAS.
Groups & favoritesAll your devices at a glance: groups, favourites, search and live status. DeskRanger finds devices on the same network by itself.
Device informationSee CPU, memory, storage and versions. Query your own devices without starting a screen session.
Teams & rolesLook after devices together and set responsibilities: shared groups, tiered roles and channels for the whole team.
End-to-end encryptionSession content stays between your devices. Coordination servers cannot read screens, keystrokes or files in plaintext.
Device lockNew devices need approval from a device you already trust, so a stolen password alone is not enough to get in.
Access policiesDecide who may reach which devices, with rules for files, clipboard and unattended access.
Virtual machinesCreate, start and open virtual machines on your own hardware. An optional module for your infrastructure.
Containers & workspacesManage workspaces on your hosts, including suitable GPU workloads. Hardware determines the possibilities.
Snapshots & backupsSave states and keep data on your own devices. Advanced cloud targets and retention are proposed for Pro.
All featuresPlatformsRoadmapDeskRanger · Early access
PersonalBusinessPricingHelp
Resources
GuidesComparisonsFrequently asked questionsRoadmapAbout us
Sign inDownload
Sign inDownload
◐

Legal

Privacy policy

How we handle your data – on this website and in DeskRanger.

Last updated: 2 October 2026

The essentials

  • This website sets no cookies. We count visits with a self-hosted Plausible instance, without a profile and without storing anything in your browser.
  • What happens in your sessions – screen, input, clipboard, files, terminal – is end-to-end encrypted and never reaches our servers in readable form.
  • For your account and devices we store only what the service needs: email address, name, device list and connection metadata.
  • You can delete your account in the app at any time; your devices are removed along with it.

The controller is exenso GmbH. Questions about privacy: support@exenso.ai

Visitor statistics

We count visits with a self-hosted Plausible instance: no cookies, nothing stored in your browser, no profile. You can object to it on this device.

Visits from this device are counted, without a profile.

Translation – the German version is binding. German version (binding)

Contents

  1. 1. What this covers
  2. 2. Controller
  3. 3. Visiting this website
  4. 4. DeskRanger account
  5. 5. Devices and connections
  6. 6. Session content, relays and device information
  7. 7. Emails
  8. 8. Purchases, App Store and TestFlight
  9. 9. Contacting us by email
  10. 10. Where the services run
  11. 11. Recipients at a glance
  12. 12. Transfers to third countries
  13. 13. Your rights
  14. 14. Required data and automated decisions
  15. 15. Security
  16. 16. Changes

1. What this covers

This policy describes which personal data we process when you visit this website (www.deskranger.app) and when you use DeskRanger: the apps, the web console and the services behind them – account, coordination and relays. DeskRanger is in development; where something is only planned, we say so.

2. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

exenso GmbH
Bundesstraße 16
77955 Ettenheim
Germany

Represented by the managing directors Thomas Schwarz, Michael Unmüßig. For any question about data protection, reach us at support@exenso.ai. More details are in the Legal notice.

3. Visiting this website

No cookies, no third-party trackers

This website sets no cookies and includes no third-party advertising or tracking services. It loads no fonts, scripts or other content from third-party servers; the visitor statistics (below) also run through www.deskranger.app. Links to other providers (for example on the comparison pages or to app stores) open their pages only when you click them.

If you choose the “Light”, “Dark” or “System” appearance, your browser stores that choice locally (localStorage, key deskranger-theme). It also remembers the platform you choose in the help (key deskranger-help-platform). Neither leaves your browser. This is strictly necessary for the function you asked for (§ 25(2) no. 2 TDDDG). The website’s sign-in page currently transmits nothing you enter.

Visitor statistics with Plausible

To understand which pages and features interest people, we count page views and a few clicks (such as “Download free”, “Request early access” or “Contact sales”, and links to other websites; in the help, the answers to “Was this helpful?” and searches without results, without the search term) with Plausible Community Edition. We run Plausible ourselves, in the EU at our cloud hosting provider (section 10); the data goes to no other provider. The script is loaded from www.deskranger.app and sends to www.deskranger.app.

It records the page visited, the referring page, campaign parameters in the address, browser, operating system, device type (from the window width) and the country derived from the IP address at the time of the request. Plausible sets no cookies and stores nothing in your browser. To group the page views of one day into a visit, Plausible computes a hash from the IP address, browser identifier, website and a random value that changes daily; the random value is deleted after 24 hours, and the IP address is not stored. Recognising you across days or building a profile is therefore not possible.

The legal basis is our legitimate interest in data-minimising visitor statistics (Art. 6(1)(f) GDPR). You can object at any time: with “Stop counting this device” on this page your browser stores the entry plausible_ignore, after which the script sends nothing.

Retention: Once the daily random value is deleted, the stored page views can no longer be linked to anyone. We keep the statistics as long as we need them to evaluate and improve the website.

Hosting and access logs

The website runs as a static site at our cloud hosting provider (section 10). Our web server writes no access logs. At its network edge, the hosting provider records technical data for every request: IP address, time, method, requested address, status code, browser identifier (user agent), amount of data transferred, response time and the region that handled it. We need this data to deliver the website securely and to find errors (Art. 6(1)(f) GDPR). It keeps this data for 30 days and deletes it afterwards.

If you open deskranger.app without “www”, a forwarding service of our domain registrar redirects you to www.deskranger.app. The registrar technically processes your IP address and the request (Art. 6(1)(f) GDPR; for the transfer to the United States see section 12).

Status page

Our status page (status.deskranger.app) shows whether our services are running. On purpose it is not hosted by our cloud hosting provider but by a provider of code hosting and static web pages based in the USA, so that it stays reachable during an outage. On a visit it technically processes your IP address and the request (Art. 6(1)(f) GDPR; for the transfer to the United States see section 12). The status page sets no cookies and counts no visits. It loads the current state in the browser from the same provider.

4. DeskRanger account

DeskRanger needs an account. Our account service stores:

  • Account data: name, email address, whether it is confirmed, time of registration and – for an account with a password – the password only as a cryptographic hash, never in plain text.
  • Sign-in sessions: for every sign-in a session key, expiry time, and the IP address and browser or app identifier (user agent) at the time of sign-in. A session ends when you sign out or after seven days without use.
  • Sign in with Apple or Google: the identifier the provider assigns to you, the email address it sends us (with Apple, an anonymous relay address if you choose), your name if you share it, with Google possibly the address of your profile picture, and the provider’s sign-in tokens. If a DeskRanger account already exists with exactly the email address Apple or Google sends us, we connect the sign-in to that account only if the provider reports the address as verified; a different address (such as Apple’s relay address) leads to an account of its own. We will offer Google sign-in once it is set up. The sign-in itself is also governed by the privacy policies of Apple or Google (Google Ireland Limited, Ireland).
  • Links by email (once we send emails, section 7): to reset your password, a single-use code that expires after one hour; the link to confirm your email address works for 24 hours and is not stored on our side.

To prevent abuse, the service limits sign-in attempts per IP address; these counters exist only in memory. For connections to our coordination service, the account service issues short-lived credentials (15 minutes) that contain only your account identifier and display name – never your email address.

In the web console (at app.deskranger.app; currently in preparation), your browser keeps the sign-in in a cookie of the account service (__Secure-better-auth.session_token, HttpOnly, Secure, SameSite=Lax; up to seven days, or until you close the browser if you do not choose “Keep me signed in”). Signing in with Apple or Google adds a cookie for the sign-in flow that lasts five minutes. These cookies are strictly necessary for the sign-in you asked for (§ 25(2) no. 2 TDDDG). The apps keep their sign-in in your device’s keychain or secure storage.

Legal basis: Art. 6(1)(b) GDPR (providing the service); for abuse prevention, Art. 6(1)(f) GDPR.

Deletion: You can delete your account at any time in the app or in the web console. We then delete your account data, sign-in sessions and linked sign-ins; before that, the coordination service deletes everything it holds for your account: devices, groups, favourites, saved connection targets, plan data, connection metadata and support codes (section 5).

5. Devices and connections

Our coordination service manages your devices and brokers connections. It knows your account only by an identifier; it never sees your email address or password. It stores:

  • Devices: device name, platform, kind of device, app version, supported functions, the device’s public key and the validity of its device certificate, whether unattended access is switched on, a salted hash that groups entries of the same computer, and when the device was added and was last online.
  • Groups and favourites that you create.
  • Connection targets you add by hand (for example an RDP server): name, protocol, address, port, the device that relays the connection and, if given, the user name – never a password; credentials stay in your device’s keychain.
  • Connection metadata: for every connection, which device of which account connected to which device, the permissions granted, whether it was attended or started with a support code, times, whether it ran directly or through a relay, duration and amount of data transferred. Never content (section 6).
  • Support codes only as a keyed hash; they are deleted 24 hours after they expire.
  • Plan and limits of your account.

While a device is online, the service keeps in memory its network addresses (the IP addresses and ports the device reports for direct connections, and its relay) and a summary of its reachability. It passes them to the devices that may connect – your own devices, or the person you help or who helps you with a support code – so that they can connect directly. From the IP address a device connects from, it derives a short network tag, hashed per account, to recognise devices in the same network; it does not store the IP address itself in the database. To prevent abuse, it limits support-code redemptions per IP address in memory.

Directly distributed versions ask the coordination service for updates and download them from storage at our cloud hosting provider in the EU; this transmits the platform, update channel and version number.

Legal basis: Art. 6(1)(b) GDPR; for connection metadata also Art. 6(1)(f) GDPR (security, traceability of access, enforcing plan limits).

Retention: device data, groups, favourites and connection targets until you remove them or delete your account; network addresses only while the device is online. Of the connection metadata, we delete the connection grants (which device was allowed to connect to which device, with which permissions and how the connection came about) after 30 days and the session records (start, end, direct or through a relay, duration, amount of data) after 12 months; the service checks this every hour. If you delete your account, we delete both at once. If you had a session with another person’s device through a support code, that person’s own record of it stays with them until their retention period ends; it then no longer points to your account.

6. Session content, relays and device information

What happens in a session – screen, sound, keyboard and mouse input, clipboard, files and terminal – is end-to-end encrypted and travels directly between the devices involved whenever possible. If there is no direct path, our relays forward the data. They see only encrypted data, the IP addresses of the connected devices and their public keys; they hold no keys to decrypt anything and store no content. A relay admits only devices enrolled with the coordination service and checks this with it.

Device information such as processor, graphics, memory and disk load or the operating system version is exchanged directly and encrypted between your devices (or within a session the device has accepted). It is not stored on our servers. Finding devices nearby happens in the local network. The apps contain no analytics or tracking services.

The operational logs of our services are kept at our cloud hosting provider. The account and coordination services write no passwords, session keys, email addresses, IP addresses or session content into these logs; they contain technical identifiers such as account, device and connection IDs. The relays do not log IP addresses either, only a shortened device identifier and a connection number, for example when a connection ends. As for the website, however, the hosting provider records at its network edge the technical data listed in section 3, including the IP address, for every request to our services – including the setup of a relay connection. It deletes all these logs after 30 days (section 3).

7. Emails

For “Reset password”, confirming your email address and, later, invitations to a team, we send emails (sender noreply@deskranger.app) through an email delivery provider. It receives your email address and the content of the message (for example a reset link) and stores delivery and log data in the United States (section 12). Nothing from your sessions or devices goes to it.

Legal basis: Art. 6(1)(b) GDPR. The delivery provider is our processor.

8. Purchases, App Store and TestFlight

Purchases

DeskRanger cannot be bought yet. Before purchases become possible, we will add here who handles them and which data that involves.

App Store and TestFlight

You get the iPhone and iPad apps from Apple’s App Store (in the EU: Apple Distribution International Ltd., Ireland) and preview versions through TestFlight. Apple processes data about your Apple ID, downloads and purchases as an independent controller. If you take part in TestFlight, Apple gives us your name and the email address you were invited with, plus installation and usage information, and crash reports and feedback if you send them. We use this to distribute test versions and fix errors (Art. 6(1)(b) and (f) GDPR). In-app purchases from the App Store, once possible, are handled by Apple; we then receive only the status of your subscription. The same applies to further app stores once DeskRanger is available there.

9. Contacting us by email

If you write to us (see Contact), we process your message and contact details to answer your request (Art. 6(1)(b) GDPR for questions about your account or a contract, otherwise Art. 6(1)(f) GDPR). We delete the messages once they are resolved unless statutory retention duties apply (for example six years for business letters under § 257 HGB). Our mailbox is hosted by a provider of office and email services that processes the messages as our processor; where data reaches the United States in the process, section 12 applies.

10. Where the services run

A cloud hosting provider operates the website, visitor statistics, account service, coordination service, relays, database and update storage for us as a processor. All of these services run in data centres in the EU (the Netherlands). The provider is based in the United States, so access from the United States, for example for support and operations, cannot be ruled out (section 12).

11. Recipients at a glance

  • Cloud hosting provider (based in the USA, data centres in the EU) – operates the website, the visitor statistics and all services; processor.
  • Email delivery provider (based in the USA) – sends emails; processor.
  • Provider of office and email services – our mailbox for enquiries; processor.
  • Domain registrar (based in the USA) – redirect from deskranger.app to www.deskranger.app.
  • Provider of code hosting and static web pages (based in the USA) – our status page.
  • Apple – Sign in with Apple, App Store and TestFlight; independent controller.
  • Google (Google Ireland Limited) – Google sign-in, once offered; independent controller.

We do not sell personal data. Authorities receive data only where we are legally obliged to provide it.

12. Transfers to third countries

Some of our service providers are based in the United States or can access data from there (section 11). They are certified under the EU-U.S. Data Privacy Framework; we base transfers to the United States on the European Commission’s adequacy decision for it (Art. 45 GDPR) and, where needed, additionally on the EU standard contractual clauses (Art. 46(2)(c) GDPR).

13. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3)). Write to us at support@exenso.ai.

Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation (Art. 21 GDPR).

Complaints: You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.

14. Required data and automated decisions

Without an email address (or Sign in with Apple or Google) and a name we cannot set up an account; without the device data in section 5 we cannot broker connections. You can use the website without providing any data. We make no automated decisions within the meaning of Art. 22 GDPR and create no profiles.

15. Security

All connections to our services are encrypted with TLS, and sessions between devices are additionally end-to-end encrypted. Every device has its own key that never leaves it; a session needs a short-lived authorization issued by the coordination service, which the target device checks itself. Every live session is visible on the device.

16. Changes

We update this policy when DeskRanger or the law changes, in particular before email delivery or purchases start. The version published here applies.

DeskRanger

Remote access and remote support for your devices. End-to-end encrypted, made in Germany.

Product

All featuresPlatformsPricingSecurity

Resources

HelpGuidesFrequently asked questionsRoadmapComparisonsStatus

Company

About usContactPersonalBusiness

Comparisons

DeskRanger / TeamViewerDeskRanger / AnyDeskDeskRanger / RustDeskDeskRanger / SplashtopDeskRanger / Screens
© 2026 exenso GmbH
Legal noticePrivacyTerms of use