Remotext — Privacy Policy
Version: 1.1
Effective date: 2026-09-29
Publisher: Custavia
Contact: support@custavia.com
The short version
Remotext does not collect, transmit, or store any data about you or your work on our servers. Everything stays on your device. We have no account system, no analytics, and no advertising, and Custavia runs no server that receives your data.
Data leaves your device only when a feature you are using needs it, and it goes straight to the service that feature talks to:
- to the servers you add yourself (SFTP, SSH, FTP, FTPS, WebDAV);
- to GitHub, Dropbox, or another git host, if you connect an account or clone a repository;
- to a TV or other Google Cast device on your Wi-Fi, if you cast your screen to it — plus limited, non-identifying diagnostics that Google's Cast software sends to Google;
- to Apple or Google when you buy or restore Remotext Pro, and to our purchase-management provider RevenueCat in versions that use it;
- to a web address you type, if you import a theme from a URL.
Remotext does not currently send crash reports anywhere (see "Crash reporting" below).
What is stored on your device
Remotext stores the following data locally on your device only. None of it is transmitted to Custavia.
Files you edit
Files you open, create, or edit are stored wherever you placed them — in the app's local document storage, in Files (iOS) or Storage Access Framework locations (Android), in a git repository on your device, or on your remote servers. When you open a file from a server, Remotext keeps a working copy in its private storage so you can edit it; that copy is excluded from iCloud and Google backups and is only ever sent back to the server it came from.
Autosave and recovery data
The app keeps autosave data for open documents to protect against crashes and lost edits. It lives in the app's sandboxed storage on your device and is never sent anywhere.
Connection configuration
If you configure remote connections (SFTP, FTP/FTPS, WebDAV, Dropbox, GitHub), the app stores the host address, port, username, a nickname, your chosen authentication method, and the SSH host-key fingerprints you have accepted. This data is stored in the app's local storage on your device and is never transmitted to Custavia. Like other app data, it can be included in your device's normal iCloud or Google backup; your passwords and keys are not (see below).
Credentials, tokens, and SSH keys
Passwords, SSH private keys, passphrases, and the access tokens for GitHub and Dropbox are stored in the platform's secure credential store:
- iOS: Keychain with
kSecAttrAccessibleWhenUnlockedThisDeviceOnly. Credentials are not synced to iCloud Keychain and do not leave the device. Saved SSH passphrases always require Face ID, Touch ID, or your device passcode to use. - Android: an encrypted file protected by a hardware-backed Android Keystore key (StrongBox where available). Credentials are excluded from Google backups and device-to-device transfer. The current Android version does not yet ask for a fingerprint or face check before using a saved credential.
A credential is only ever sent to the server or service it belongs to, to sign you in there.
GitHub and git
If you connect GitHub, Remotext signs you in with GitHub's device flow: you approve Remotext on github.com in your browser, and GitHub gives the app an access token. We never see your GitHub password, and the token never reaches Custavia. You can also paste a personal access token instead. If you make commits, the name and email you enter for git are written into those commits, and become visible to anyone who can see the repository once you push it.
Dropbox credentials
If you connect a Dropbox account (currently available on iOS), Remotext uses OAuth 2 with PKCE. We never see or store your Dropbox password. The OAuth refresh token is stored in the same secure credential store described above and never leaves your device except to Dropbox.
App preferences and settings
Theme choices, editor preferences, key-binding customizations, your git name and email, and similar settings are stored in the app's local storage on your device.
Purchase state
Whether you have Remotext Pro is cached on your device so the app works offline. We do not run a purchase validation server.
Services Remotext talks to on your behalf
Each of these connections is made directly from your device to the service named. Custavia is not in the middle of any of them.
Your own servers. When you connect to a server you added, Remotext sends it your credentials (to sign in) and the file operations and terminal input you initiate. SFTP, SSH, FTPS, and HTTPS WebDAV connections are encrypted. Plain FTP is not encrypted — your password and files travel in the clear — so the app warns you and asks you to confirm before saving a plain FTP connection.
GitHub and other git hosts. When you sign in to GitHub, browse or edit a repository, commit, clone, pull, or push, Remotext talks to github.com and api.github.com (or to the git host whose address you entered) using your access token. What is sent is what those actions require: the repository paths you open, the file contents and commit messages you save or push, and your git name and email inside your commits. GitHub's privacy practices are described in the GitHub Privacy Statement at https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement.
Dropbox. If you connect Dropbox, the app talks to Dropbox's servers (api.dropboxapi.com, content.dropboxapi.com) to list, open, and save the files you choose. Dropbox's privacy policy is at https://www.dropbox.com/privacy.
Importing a theme from a URL. If you import a theme by typing a web address, the app downloads that one file over HTTPS. Like any web request, this tells the website your IP address.
Google Cast. Remotext can show your code or terminal on a TV or other Google Cast device.
- When you open the cast picker, the app looks for Cast devices on your local Wi-Fi network. On iOS this is why the app asks for Local Network access.
- While you are casting, the app sends the Cast device the name and language of the open file, the lines currently on screen and their colors, or the contents of your terminal screen. This goes directly to the Cast device over your local network, not to Custavia.
- The Cast device loads Remotext's receiver page from remotext.custavia.com, which in turn loads Google's Cast receiver library from gstatic.com. The page displays what your phone sends it and sends nothing back to us.
- Remotext includes Google's Cast software. According to Google's own disclosure for that software, it collects a device identifier, diagnostic data, and data about how the Cast feature is used, for analytics and to make casting work. Google states this data is not linked to your identity and not used for tracking. On iOS the Cast software starts when the app launches; on Android it starts the first time you open the cast picker. Google's privacy policy is at https://policies.google.com/privacy.
Purchases. Remotext Pro is sold through Apple's App Store and Google Play. Your payment is handled entirely by Apple or Google under their own privacy policies; we never see your payment details. Remotext also uses RevenueCat, a purchase-management service, to confirm what you have bought and to restore it on another device. Versions of Remotext that use RevenueCat contact it when the app starts and when you buy or restore, and send a random identifier generated for your installation (not your name, email, or Apple/Google account), your purchase and subscription records from Apple or Google, and basic technical details such as app version, operating-system version, and store country — plus, as with any internet request, your IP address. RevenueCat keeps this data to operate purchases for us; it is not linked to your identity or used for tracking. RevenueCat's privacy policy is at https://www.revenuecat.com/privacy.
What we never collect
- Your file contents, filenames, directory paths, or project structure
- Your server hostnames, IP addresses, or usernames
- Your credentials, SSH keys, or access tokens
- Behavioral analytics, usage events, or session data
- Your device's contacts, location, camera, or microphone
- Any advertising identifier, or any identifier linked to your identity
"We" here means Custavia. The services you choose to connect — your servers, GitHub, Dropbox, Apple, Google, and RevenueCat as described above — receive what they need to do what you asked, under their own policies.
Crash reporting
Remotext does not currently send crash reports to us or to any crash-reporting service.
The current version has no crash-reporting switch: there is nothing for one to turn on, so Settings › Privacy says that no crash reports are sent. (Earlier test builds showed a Send Crash Reports switch; it only recorded a choice on your device and never sent anything.) If we add a crash-reporting service in a future version, it will be off by default and opt-in only, and we will update this policy first — naming the service and exactly what a report contains — before any version that sends reports is released.
Apple and Google collect crash information independently of Remotext, under their own privacy policies: Apple from devices whose owners chose to share analytics with app developers, and from TestFlight beta testers; Google through Android's usage and diagnostics setting.
Network traffic summary
The only outbound network traffic Remotext ever initiates:
| Destination | Condition | Data sent |
|---|---|---|
| Your configured remote servers (SFTP/SSH/FTP/FTPS/WebDAV) | Only when you connect | Credentials to sign in; file data and commands you initiate |
GitHub (github.com, api.github.com) or a git host you enter | Only if you sign in, browse a repository, commit, clone, pull, or push | Access token; repository files, commits, and your git name and email in them |
Dropbox API (api.dropboxapi.com, content.dropboxapi.com) | Only if you connect a Dropbox account (iOS) | OAuth token; file data and commands you initiate |
| A theme URL you type | Only when you import a theme from a URL | One HTTPS download request |
| Google Cast devices on your Wi-Fi | Only when you open the cast picker or cast | Discovery; while casting, the visible lines of the open file or terminal and theme colors |
| Google (Cast software) | iOS: when the app starts. Android: after you first open the cast picker | Device identifier, diagnostics, Cast feature usage — not linked to you |
| Apple App Store / Google Play | Purchase and restore | Handled by the platform |
| RevenueCat | In versions that use it: at app start, purchase, and restore | Random installation ID, purchase records, app and OS version, store country |
| Crash-reporting service | Never (no crash reporter is active) | — |
| Custavia servers | Never | — |
Children's privacy
Remotext is a professional developer tool not directed at children under 13. We do not knowingly collect any data from children.
Changes to this policy
If we make a material change to this policy, we will update the effective date and version number above and post the revised policy at the same URL. Material changes include adding a new data-collection practice, a new service the app talks to, or turning on crash reporting.
Version 1.1 (2026-09-29) corrected version 1.0: it adds GitHub, git hosts, Google Cast, RevenueCat, and theme import from a URL, which the app uses but 1.0 did not list, and it removes the statement that opted-in crash reports go to Sentry — no crash reporter has shipped.
Contact
For privacy questions or requests, contact: support@custavia.com
Cross-check: alignment with store privacy labels
This section maps each claim above to the App Store privacy label and the Google Play Data safety answers, so no statement contradicts a store label.
| Privacy claim in this document | App Store privacy label | Play Data safety |
|---|---|---|
| Custavia collects no data | Nothing collected by Custavia's own code | Nothing collected by Custavia's own code |
| Google Cast software: device identifier, diagnostics, Cast usage; not linked | Identifiers › Device ID; Diagnostics › Other Diagnostic Data; Usage Data › Product Interaction — not linked, not tracking | Device or other IDs; App info and performance › Diagnostics; App activity › App interactions |
| RevenueCat: purchase records, random installation ID; not linked (in versions that use it) | Purchases › Purchase History — App Functionality, not linked, not tracking | Financial info › Purchase history — App functionality |
| No crash reports are sent | Crash Data: not collected | Crash logs: not collected |
| Files, credentials, and connection details stay on-device or go only to the service you chose | Not collected | Not collected |
| No analytics, no advertising identifiers | Usage Data (beyond the Cast row) and Advertising Data: not collected; no tracking | No advertising ID; analytics not collected by our code |