Privacy Policy — Desktop
Effective May 26, 2026 · Last updated May 26, 2026
Introduction
This Privacy Policy applies specifically to the GIGI Squad desktop application (macOS and Windows). It covers all data collected, used, and stored by the desktop app in addition to the data practices common to all GIGI platforms.
GIGI Squad includes features not available in the mobile app — specifically, a remote desktop capability (GIGIdesk) that allows a caregiver to view and control an elder's computer. This policy explains how that feature works and what data it involves.
GIGI is developed and operated by Softaims, based in the United States. "We", "us", or "our" refers to Softaims. "You" or "user" refers to any person who uses the application.
1.Information We Collect
Account and Profile
- Email address
- Password — stored exclusively as a one-way bcrypt hash; your plain-text password is never stored
- Display name
- Profile picture (optional — stored in AWS S3; deletable from settings at any time)
- Account role: Caregiver or Elder
- Email verification status
- Account creation date and last updated timestamp
Pairing and Relationship
- Pairing relationships between accounts
- Pairing PIN, stored as a one-way hash — never in plain text
- Pairing creation date and last updated timestamp
Call History and Metadata
We log metadata for video calls. We do not record, store, or access call audio or video content.
- Identities of participants
- Call status at each stage (ringing, active, missed, or ended)
- Call start time, end time, and total duration
Remote Control Session Data
The desktop app includes GIGIdesk, a remote desktop tool. When a remote session is initiated, we collect and store the following on our servers:
- GIGIdesk machine ID — a unique identifier assigned by GIGIdesk to each device, used to route remote connections
- Remote session start time, end time, and duration
- Identities of participants (caregiver and elder) in the session
- Session status (initiated, active, ended)
The following data is used locally only and is never sent to our servers:
- GIGIdesk permanent password — set locally in GIGIdesk config files on the elder's machine; used to authenticate the connection; never transmitted to Softaims
- Screen content — the visual content of the elder's screen during a remote session is transmitted directly between the two devices via the GIGIdesk relay infrastructure. Softaims does not receive, view, store, or process screen content.
Presence and Activity
- Real-time connection status (online or offline)
- Last active timestamp, updated each time a user disconnects
Device and Technical
- Operating system name and version (macOS or Windows)
- App version
- IP address (used for connection routing and security)
- Language and locale settings
- Country or region derived from IP address
We do not collect advertising identifiers, contacts, browser history, or files on your system.
Usage Information
- Features accessed and frequency of use
- Call and remote session initiation patterns
- Session heartbeat signals sent every 10 seconds during active calls
- Error events and performance metrics
- App settings and preferences
Support Communications
If you contact us for support, we may collect your email address, message content, and any attachments. Used only to respond to your inquiry.
2.Remote Desktop (GIGIdesk) — How It Works
GIGIdesk is a custom build of the open-source RustDesk remote desktop tool, bundled inside GIGI Squad. Here is exactly how it works and what data flows where:
Setup (Elder's Machine)
- When the elder first logs in to GIGI Squad, GIGIdesk is installed silently to the local machine (/Applications/GIGIdesk.app on macOS, bundled resources on Windows)
- GIGIdesk generates a unique machine ID for the elder's device. This ID is stored on our backend, associated with the elder's account, so caregivers can connect to it.
- GIGIdesk is configured with a permanent password derived from the elder's GIGI account. This password is stored only in GIGIdesk's local config file on the elder's device — never on our servers.
- GIGIdesk runs in the background (server mode) so it is ready to accept connections when a remote session is started from the caregiver's app.
During a Remote Session
- The caregiver's GIGI app retrieves the elder's GIGIdesk machine ID from our server
- GIGI Squad launches a GIGIdesk client process that connects to the elder's machine using the machine ID and password
- The screen content of the elder's desktop is streamed directly between the two devices via the GIGIdesk relay server
- The caregiver can see and control the elder's mouse and keyboard in real time
- Session metadata (start, end, duration) is recorded on our servers
- The elder can end the session at any time by ending the call or closing GIGIdesk
What Softaims Does Not See
- The content of the elder's screen
- Files, documents, or applications on the elder's machine
- Keystrokes or mouse movements during the session
- The permanent GIGIdesk password
GIGIdesk Relay Infrastructure
GIGIdesk uses relay servers to connect devices behind NAT/firewalls. These relay servers process encrypted packets to route the connection — they do not have access to the decrypted screen content. The relay is operated as part of the GIGIdesk (RustDesk) infrastructure.
3.System Permissions We Request
| Permission | Platform | Why We Need It |
|---|---|---|
| Screen Recording | macOS | Required by macOS for GIGIdesk to capture the elder's screen and transmit it during a remote session. Requested on first remote session setup. |
| Accessibility / Input Monitoring | macOS | Required for GIGIdesk to relay the caregiver's keyboard and mouse input to the elder's machine. |
| Camera | macOS, Windows | Capture and transmit video during video calls. |
| Microphone | macOS, Windows | Capture and transmit audio during video calls. |
| Notifications | macOS, Windows | Deliver incoming call alerts. |
| Network / Firewall rules | Windows | GIGI Squad adds Windows Firewall rules to allow GIGIdesk to connect outbound for remote sessions. No inbound internet exposure is created. |
Each permission is requested with an explanation at the time it is needed. You can revoke permissions from System Preferences (macOS) or Windows Settings at any time. Revoking Screen Recording or Accessibility will disable the remote desktop feature. Revoking Camera or Microphone will disable video calls.
4.How We Use Your Information
- Create and manage your account and profile
- Authenticate your identity and maintain your session securely
- Connect caregivers and elders through the pairing system
- Initiate, route, and complete video calls
- Route remote desktop connections between caregiver and elder
- Display your name and profile picture to your paired partner
- Show your online or offline presence status to your paired caregiver
- Deliver real-time call alerts and notifications
- Send transactional emails (OTP codes, password reset)
- Store and display call and session history to both participants
- Detect, investigate, and prevent unauthorized access and security incidents
- Enforce our Terms of Service
- Diagnose technical problems and fix bugs
- Improve app performance and develop new features
- Respond to support requests
- Comply with applicable laws and legal obligations
We do not use your information for advertising, behavioral profiling, or targeted marketing. We do not sell your personal information to any third party.
5.Legal Bases for Processing (GDPR)
If you are in the EEA or United Kingdom, we process your data under these legal bases:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Contract — necessary to provide the service |
| Video calls and pairing | Contract — necessary to provide the service |
| Remote desktop session routing | Contract — necessary to provide the service |
| Sending OTP and transactional emails | Contract — necessary to provide the service |
| Security logging and abuse prevention | Legitimate interests |
| Error logs and diagnostics | Legitimate interests |
| Responding to legal requests | Legal obligation |
| Optional profile picture | Consent |
| Push notifications | Consent |
| Screen Recording and Accessibility permissions | Consent — granted via macOS permission dialog |
6.Information We Share
We do not sell, rent, or trade your personal information. We share it only in these limited cases:
With Your Paired Partner
- Your display name
- Your profile picture
- Your online or offline status
- Your shared call and remote session history
With Service Providers
| Provider | Data Received | Purpose |
|---|---|---|
| Jitsi Meet (self-hosted) | Short-lived JWT token, call room ID | Video call infrastructure |
| GIGIdesk relay (RustDesk-based) | Machine ID, encrypted session packets | Remote desktop routing |
| Amazon Web Services (S3) | Profile picture files | Image storage |
| Resend | Email address, email content | Transactional email delivery |
| Amazon RDS (PostgreSQL) | All application data | Managed database hosting |
For Legal Compliance
We may disclose information if required by law, court order, or to protect the safety of users or the public.
Business Transfers
If Softaims is involved in a merger or acquisition, your data may transfer. We will notify you before it becomes subject to a different policy.
We do not share your information with advertising networks, data brokers, or analytics companies.
7.Video Calls
When a video call is active:
- Video and audio are transmitted in real time through our self-hosted Jitsi Meet server
- A short-lived JWT authenticates both participants and expires when the call ends
- We do not record, monitor, or store audio or video content
- Call metadata (participants, duration, status) is logged as described in Section 1
- Either participant can end the call at any time
8.Elder Safety and Control
- A caregiver cannot reach an elder without an active pairing the elder participated in establishing
- A remote session can only be started by the caregiver after the elder's machine has the GIGI app running and GIGIdesk set up
- Elders can end any remote session at any time from within GIGI Squad or by force-quitting GIGIdesk
- Elders can unpair at any time, immediately revoking all caregiver access including remote sessions
- Elders can delete their account from app settings at any time
To report unauthorized access or misuse of the remote desktop feature, contact us immediately at privacy@softaims.com. We may suspend or terminate accounts found to be misusing remote access.
9.Third-Party Services
Jitsi Meet (Self-Hosted)
Video infrastructure at call.gigisquad.com. Streams are not recorded. No data shared with 8x8, Inc.
GIGIdesk (RustDesk-Based)
Remote desktop technology based on the open-source RustDesk project, customized by Softaims. The relay server processes encrypted packets to route connections — it cannot decrypt or view screen content. For details on RustDesk's infrastructure, see the RustDesk documentation.
Amazon Web Services (S3)
Profile pictures stored in S3. Deleting from app settings removes the file immediately.
Resend
Transactional emails only. No marketing use of email data.
Amazon RDS (PostgreSQL)
Managed database hosted on Amazon RDS. Data encrypted in transit and at rest.
10.Data Storage and Security
- All data in transit is encrypted using HTTPS/TLS
- Passwords are hashed with bcrypt and never stored or transmitted in plain text
- JWT tokens are short-lived (15 minutes), stored in OS-level secure storage, and cleared on logout
- The GIGIdesk password is stored only in the local GIGIdesk config file on the elder's machine — it is never transmitted to our servers
- Database access uses authenticated, pooled connections with restricted permissions
- Employee access to user data is limited to what is necessary to operate the service
- Windows Firewall rules added by GIGI Squad allow only outbound connections from GIGIdesk — no new inbound rules are created that expose the machine to the internet
If you believe your account or remote session has been compromised, contact us immediately at privacy@softaims.com.
11.Data Retention
| Data | Retention Period |
|---|---|
| Account and profile data | Retained while active. Permanently deleted within 90 days of account deletion. |
| Call history and metadata | Retained for the lifetime of your account. Purged within 90 days of deletion. |
| Remote session metadata | Retained for the lifetime of your account. Purged within 90 days of deletion. |
| GIGIdesk machine ID (server copy) | Cleared immediately on account deletion or unpairing. |
| GIGIdesk password (local only) | Stored only on the elder's local machine. Not subject to our data retention — cleared when GIGIdesk is uninstalled or account is deleted. |
| OTP verification codes | Expire 10 minutes after generation. |
| JWT tokens on device | Expire 15 minutes after issuance. Cleared immediately on logout. |
| Error and crash logs | Retained for up to 90 days. |
| Support communications | Retained for up to 2 years. |
12.Your Rights and Choices
- Access — Request a copy of your personal information
- Correction — Update your name and profile picture in app settings
- Deletion — Delete your account from app settings; data purged within 90 days
- Portability — Request a machine-readable export by emailing privacy@softaims.com
- Withdraw Consent — Revoke permissions from System Preferences (macOS) or Windows Settings at any time
- Object to Processing — Contact us to object to certain uses of your data
- Lodge a Complaint — File a complaint with your local data protection authority
Contact privacy@softaims.com. We respond within 30 days.
13.California Privacy Rights (CCPA / CPRA)
If you are a California resident:
- Right to Know — What personal information is collected, used, shared, or sold
- Right to Delete — Request deletion of your personal information
- Right to Correct — Request correction of inaccurate information
- Right to Opt Out of Sale or Sharing — We do not sell or share personal information for advertising
- Right to Limit Sensitive Data Use — Request that we limit use to what is necessary to provide the service
- Right to Non-Discrimination — We will not discriminate for exercising these rights
14.Children's Privacy
GIGI Squad is not intended for children under 13. We do not knowingly collect data from children. If you believe a minor has registered, contact us at privacy@softaims.com.
15.International Data Transfers
Softaims is based in the United States. If you access GIGI from outside the US, your data may be processed in the US where data protection laws may differ. For transfers from the EEA or UK, we rely on Standard Contractual Clauses where required.
16.Changes to This Policy
When we make material changes, we will:
- Notify you via in-app alert or email at least 14 days before changes take effect
- Update the "Last updated" date at the top of this policy
- For significant changes, ask you to review and acknowledge the updated policy
Continued use of GIGI Squad after changes take effect means you accept the updated policy.
17.Contact
For privacy questions, data requests, account deletion, or security concerns:
Email: privacy@softaims.com
Company: Softaims