# SideWire Privacy Policy Last updated: June 15, 2026 SideWire is a message and file transfer tool for moving content between your own devices. This policy explains what data is processed when you use the app, particularly when using Remote mode via the SideWire relay server. It applies to all components published by EERIE under the SideWire name. ## Local Mode (Same Wi-Fi) When using Local mode, no data leaves your local network. All communication happens directly between your devices over your router. No data is sent to any external server, and SideWire does not collect, store, or transmit any information to us. Files received by a device are stored, encrypted, in a temporary folder on that device and are automatically deleted after about an hour. ## Remote Mode (Relay Server) When using Remote mode, your device connects to the SideWire relay server at sidewire-relay.fly.dev so that devices that are not on the same network can reach each other. Your messages, files, and file names are end-to-end encrypted on your device before they are sent (AES-256-GCM, with a key derived from your room password). The relay only ever sees encrypted data it cannot read, and your password is never sent to the relay. The following data is processed by the relay to operate the service: - **IP address** - Your public IP address is logged for abuse prevention and rate limiting only. - **Device name** - The name you choose (for example "John's Phone") is shared with other devices in your room and also appears in the server's operational logs. - **Room code** - The room identifier is stored while the room is active. - **Messages** - Text messages are stored as encrypted data the server cannot read, in memory, while the room exists. They are deleted when the host leaves or the server restarts. - **Files** - File contents and file names are encrypted on your device, so the relay only ever handles data it cannot read. The encrypted file is held in the room's memory while the room is open, so devices that join later can still receive it, and is deleted when the room closes. Only the file size (never the name) is logged, for abuse prevention. ## Data Retention - IP addresses and activity logs are kept in memory (up to 10,000 entries) and are lost on server restart. - Fly.io retains platform server logs for up to 7 days for operational purposes. - Room data (messages and files, all encrypted) is deleted when the host disconnects or the room is closed. - No data is written to a permanent database or to long-term storage. ## Why We Log IP Addresses IP logging is used solely for abuse prevention - detecting and rate-limiting clients that send excessive traffic or try to disrupt the service. We do not sell, share, or use IP data for any other purpose. ## Third-Party Services The relay server is hosted on Fly.io, and Fly.io's privacy policy applies to their infrastructure. The relay is open source and can be self-hosted if you prefer to run your own. ## Your Rights (GDPR / CCPA) Depending on your jurisdiction, you may have the right to request access to data about you, request its deletion, or object to processing. SideWire has no user accounts and does not persistently store personal data: in-memory room data is erased when the room closes or the server restarts, and the only remaining records are short-lived operational logs (up to about 7 days). If you have concerns, contact us below. ## Children's Privacy SideWire is not directed at children and does not knowingly collect any data from anyone. ## Contact For privacy-related inquiries, open an issue at https://github.com/EerieGoesD/sidewire/issues or email eeriegoesd@gmail.com. SideWire is provided by EERIE. No accounts. No tracking. Local mode stays on your network; Remote mode is end-to-end encrypted.