Shoof privacy policy

Last updated

Shoof lets the person at a Windows PC show their screen to a helper's phone, and it is built so that what you share stays between the two devices. The session is end-to-end encrypted, Shoof itself records and stores nothing of your screen, and it has no ads, no accounts and no analytics or tracking of its own. This policy explains what Shoof for Windows and the Shoof phone app process, where, and for how long.

Who we are

Shoof is made by 0d.ae, which also runs the Shoof relay, Shoof's STUN and TURN server and the license server described below. For any question about this policy or about your data, write to ask@0d.ae.

During a session

  • Nothing is shared until the PC user agrees. Each request shows the name the helper typed (Shoof can't verify it) and how they connect. The PC user chooses one screen or one window and clicks Share, or denies the request; a request nobody answers is declined after 60 seconds. The PC user can pause or stop at any time.
  • The helper can only look, point, draw and type. Shoof contains no remote-control code: the helper can't use the PC's mouse or keyboard, open files, or see anything that isn't shared. Text from the helper reaches the PC's clipboard only when the PC user clicks Copy.
  • The PIN never travels over the network. The PC user tells it to the helper. With SPAKE2, the two apps prove to each other that they know the same PIN without revealing it, and derive the encryption keys from it.
  • Everything is end-to-end encrypted. After that handshake, every message that sets up the connection is encrypted (AES-256-GCM). The video, the drawings and the chat travel between the two devices over WebRTC, encrypted with DTLS (DTLS-SRTP for the video) and tied to the PIN handshake, so no server in between can read or alter them.
  • Shoof stores nothing of your screen. It does not record sessions: the video, the drawings and the chat exist only on the two devices while the session runs, and chat messages are not saved afterwards. As with any app, though, the helper's phone can take screenshots or record its own screen, and Android may keep a picture of the session for its list of recent apps if the helper leaves the app during a session. Share only with someone you trust, and prefer sharing one window.
  • What the two sides see of each other. The PC user sees the helper's name (typed by the helper, otherwise the phone's model), the type of device, the app version and how the helper connects: on the same network, the phone's IP address; over the internet, the relay or broker the request came through. The helper sees the PC's name and the name of the shared screen or window, and the phone app also receives the PC's Windows and Shoof versions. As with any direct connection, each device also learns the other's IP address.

How the two devices connect

Shoof connects in the following ways, depending on where the two devices are and what is turned on.

  • The same network (Wi-Fi or LAN). The phone connects to the PC directly, and the video and the drawings go straight between the two devices. Servers are still contacted, as described below: both apps ask STUN servers for their own address; while the PC's relay is on (the default), Shoof for Windows reports each session's events to the relay and asks it for TURN credentials; and with Shoof Pro, the phone also sends its connection request through the relay (and the MQTT broker, if turned on) and continues on whichever path answers first. So that nearby phones can find it, Shoof for Windows answers their search on the local network with the PC's name and ID. You can turn this off (Settings › Privacy › Show this PC to nearby helpers); a phone can still connect by typing the ID.
  • The Shoof relay (lab.0d.ae), run by us. Over the internet, the two apps exchange their connection messages through this small server. It only passes along messages it cannot read, and the video never goes through it. Like any server, it sees the IP addresses of the devices that use it, which PC a phone contacts, and when. If you enter your own relay address in the apps, that relay's operator handles this data instead of us. Our relay keeps:
    • for each PC that uses it: the PC's ID, its name (by default the Windows computer name), the Shoof and Windows versions, whether it is online or in a session, its last IP address, a hash of its secret relay key, and when it registered and was last seen. Shoof for Windows uses the relay by default (Settings › Connections › Relay server). This record is kept until we delete it: ask us and we will.
    • the connection messages: handshake values that are useless without the PIN, then encrypted data. Each one is deleted once the recipient picks it up; undelivered ones expire after about 2 minutes and are then removed by routine cleanup.
    • while "Report sessions to the relay administrator" is on (the default): events without content for every request and session, also on the same network, such as "session started", "session ended", "request declined" or "wrong PIN", with the connection type, how a session ended, its duration, whether a screen or a window was shared, the number of wrong PINs, the PC's ID, its IP address and the time. They are deleted after 30 days and never contain what you share, names, messages or the PIN.
    • to limit abuse: the IP addresses of recent requests, for a few minutes.
  • A public MQTT broker (off by default). If you turn it on in both apps, they also exchange their encrypted connection messages through a public MQTT broker run by a third party (by default broker.emqx.io). The broker sees the PC's ID in the message topics, the IP addresses and the timing. On a public broker anyone can subscribe and see the topics and the encrypted messages, but nobody can read them or join the session.
  • STUN servers. In every session, also on the same network, both apps ask a STUN server for their own public address, so that the devices can find a direct path to each other. By default this is Shoof's own STUN server, turn.0d.ae, which we run. A STUN server sees the device's IP address and the time, and nothing of the session. You can change the list in the settings of both apps. While the PC's relay is on, both apps also use every STUN server that the relay lists: our relay lists only turn.0d.ae. Another relay that you enter in the apps may list other servers, which then see the same.
  • TURN (turn.0d.ae). For every session the PC user allows, also on the same network, the PC gets short-lived credentials from our relay for Shoof's own TURN server, turn.0d.ae, which we run, and shares them with the phone inside the encrypted session. Both devices then contact the TURN server while they connect, so it sees their IP addresses and the timing. When no direct path works (common on mobile data), it also carries the encrypted video and drawings and sees the amount of data; it cannot decrypt them. For each session it relays, its log keeps the devices' IP addresses and ports, the amount of data and a user name made of an expiry time and a random value (no name and no PC ID). This log is limited to 30 MB (three files of 10 MB, the oldest removed first), which with light use can cover several months. Our relay makes the credentials itself, with a secret it shares only with the TURN server. If we switch the relay to Cloudflare's TURN service instead, Cloudflare's TURN server sees the same, and to get the credentials the relay sends Cloudflare only its own key and their lifetime, nothing about you. A TURN server that you set up yourself in the settings sees the same.

In the phone app, connecting over the internet (through the relay or MQTT) is part of Shoof Pro. Without it, the phone connects only on the same network.

What is stored on your devices

On the PC, Shoof for Windows keeps in your Windows profile (%APPDATA%\Shoof):

  • its settings, including the PC's ID and the name shown to helpers. The relay key, a custom PIN, the relay registration token and a TURN password are encrypted with Windows DPAPI for your Windows account.
  • the history of requests and sessions (the last 200): the name the helper typed and their type of device, when, for how long, what was shared (a screen, or a window by its program only, never its title), how the helper connected (on the local network, with the phone's IP address), how it ended, and blocked wrong-PIN attempts. It never contains window titles, chat messages or anything shown on the screen, and it is never uploaded. You can delete it with History › Clear history.

When you uninstall Shoof, you are asked whether to delete the settings and the history too.

On the phone, the Shoof app keeps:

  • the name shown to the PC user, if you set one (otherwise the app uses the phone's model);
  • its settings: the relay and MQTT addresses, the STUN and TURN servers (with a TURN password if you enter one), the drawing defaults and the language;
  • your recent PCs: their ID, name and the time of the last connection, at most 20. You can rename or forget each one;
  • with Shoof Pro, the license data described below.

If backup is turned on for your phone, Android may include the app's settings and recent PCs in your device backup; the license data is excluded. Uninstalling the app removes all of it from the phone.

Shoof Pro and the license check (phone app only)

Shoof for Windows has no license and never contacts the license server. In the phone app, Shoof Pro is activated with a license key bought on 0d.ae.

  • Activation sends the license key; this installation's public device key and its fingerprint (a one-way hash of the phone's Android ID, specific to Shoof); the phone model; the platform and the Android version; and the Shoof version.
  • The daily check sends only the license token (a signed proof of the license, issued by 0d.ae) and a signature made with the device key. The token names the device by its key ID and fingerprint. Showing your devices, deactivating the license on this phone and listing what your license includes send the same.
  • Every license request also carries the product code (shoof), the time and a one-time random number, which stop replays, and is signed with the device key.
  • Plans and prices. Opening the upgrade screen loads Shoof Pro's plans and prices from 0d.ae, in the language of the app.
  • Never sent. No license request sends anything about your sessions, PCs, screens, drawings, chat, IDs or PINs to the 0d.ae license server. The Shoof relay, described above, is a separate service.
  • On the phone, the license token and the license details (such as the plan, the expiry date, the number of devices and the last characters of the key) are stored encrypted with a key kept in the Android Keystore. The device key is created in the Android Keystore and cannot be exported. The license key itself is never stored.
  • At 0d.ae we keep the license; from your purchase, the e-mail address, the name given at checkout and the amount paid; for each device the license is activated on, the details sent at activation, the device's public key, when it was activated or deactivated, and the time and IP address of its latest check; and a log of activations, moves, deactivations and failed license requests, with the time and the IP address (failed requests are deleted after 90 days). You can see your devices and deactivate one at 0d.ae/account.
  • Buying happens on 0d.ae, and payments are handled by Stripe: your card details go to Stripe, never to us. See the 0d.ae privacy policy.

The QR code scanner

The phone app scans the PC's QR code with Google's ML Kit, which is built into the app and reads the code on the phone itself. The camera is on only while the scanner is open, and no picture is saved. ML Kit sends Google technical data for diagnostics and usage analytics: the phone's make, model and Android version, the app's package name and version, a per-installation identifier that Google says is not meant to identify you or your device, the scanner's settings, performance figures and error codes. See Google's ML Kit data disclosure.

What Shoof doesn't do

  • No ads, and no analytics or tracking of its own.
  • No account: neither app asks you to sign up or sign in.
  • No recording, and no copy of your screen on any server.
  • We don't sell your data, and we share it with no one beyond what this policy describes.

Permissions

  • Shoof for Windows shares only the screen or window that the PC user chose, only after they clicked Share, and only until the session ends; the previews in the picker stay on the PC. It listens on the local network (TCP port 47800, or the next free port up to 47809, and UDP port 47801) so that phones on the same Wi-Fi can connect; Windows Firewall may ask you to allow this.
  • The phone app uses the network, and the camera only to scan the PC's QR code. The video library inside the app also declares two permissions meant for calls (Bluetooth, on Android 11 and older, and changing audio settings). Shoof has no sound, does not use them, and has no microphone permission.

Your choices

  • To use Shoof on the same network only, turn off the relay (and leave MQTT off) on the PC in Settings › Connections. The PC then reports no events to the relay and asks it for nothing.
  • To connect on the same network without contacting any server, also clear the STUN servers in both apps and, with Shoof Pro, the relay server address in the phone app.
  • To send no session events, turn off "Report sessions to the relay administrator" in Settings › Connections.
  • To stay hidden from nearby phones, turn off "Show this PC to nearby helpers" in Settings › Privacy.
  • Clear the history on the PC, and forget recent PCs on the phone, at any time.
  • To have a PC's record deleted from the relay, or the data of a license, write to ask@0d.ae.

Children

Shoof is a general-audience tool and is not directed at children. It does not ask for anyone's age, and it does not collect personal information beyond what this policy describes. If you believe a child has given us personal information, write to us and we will delete it.

Changes to this policy

When Shoof changes how it handles data, we update this policy and publish the new version on this page.

Contact

For questions about this policy, or to see or delete data we hold about you, write to ask@0d.ae.