Privacy Policy
Last updated: 5 September 2026. The data controller is Avendavi, a Swedish business operating EasyKVM. Contact: info@avendavi.com.
EasyKVM is a software KVM switch. Everything it does — keyboard, mouse, clipboard, audio, monitor switching — happens on your own local network. The only reasons the app or this website ever talk to us are selling you a license, checking that license, and delivering updates. This page lists exactly what that involves.
What we collect, and why
- Email address. Used to deliver your license key, sign you in to your account with a magic link, and answer support requests. Legal basis: performance of our contract with you.
- Payment records. Card details are entered on Stripe's checkout page and are held by Stripe, never by us. We store Stripe's reference IDs (customer, checkout session, payment) so we can match your license to your payment and process refunds. Stripe shows us the last four digits of the card and the billing country. Legal basis: contract, and our legal obligation to keep accounting records.
- License records. Your license key, its status (active, refunded, revoked), when it was activated, and when the host machine was last changed. Legal basis: contract.
- Host machine record. When you activate, the app sends a device identifier, the platform (macOS or Windows), and a label you can edit (for example "Sam's Mac mini"). The device identifier is a salted SHA-256 hash of your computer's hardware UUID (macOS) or MachineGuid (Windows) — we never receive the raw value. We also record the activation time and the time the app last renewed its license token, which it does about once a week when online. Legal basis: contract (the one-host-per-license rule) and our legitimate interest in preventing license fraud.
- Sign-in and host-change tokens. One-time links emailed to you when you sign in or move your license to a new host. We store only a hash of the token; sign-in links expire after 15 minutes, host-change links after 24 hours. Legal basis: contract.
- Server logs. Standard web-server and API logs: IP address, user agent, request path, timestamp, and the email address on sign-in and activation requests. Used for security, abuse prevention (rate limiting), and debugging. Legal basis: legitimate interest in keeping the service secure.
- Support messages. When you use the contact form, we collect your email, the optional name and setup details you type, and your message. This is emailed straight to our support inbox (Google Workspace) and is not stored in our server database. We keep it as long as needed to handle your request and for our records, then delete it. Legal basis: to answer your request, and our legitimate interest in providing support.
What we don't collect
- No usage analytics — we don't track what you do with the app or how often you use it.
- No crash telemetry — the app has no crash reporter.
- No keystrokes, mouse movements, clipboard content, audio, or screen content. These travel directly between your two computers over your LAN, encrypted with TLS, and never pass through any server of ours.
- No advertising, no tracking cookies, no data sales, no profiling.
Network connections the app makes
Apart from talking to your peer machine on your LAN, the app connects to two places: our license server (to activate and, about once a week, to renew your license token — see above) and GitHub (to check for and download updates: the Mac app fetches a Sparkle appcast, the Windows app queries the GitHub Releases API). GitHub receives your IP address and standard request headers when the app checks for updates; we don't receive anything from that check. Joiner machines never contact our license server.
Where your data is stored and who processes it
Our license server and database run on Hetzner Cloud servers in the EU. We use these service providers (sub-processors), each of which handles only what its job requires:
- Stripe — payment processing, tax calculation, receipts. Stripe is an independent controller for the payment data it collects; see Stripe's privacy policy.
- Resend — sends our transactional emails (magic links, license keys, host-change confirmations).
- Hetzner — hosting for the license server and database.
- GitHub — hosts the downloads and update feeds.
Where a provider processes data outside the EU/EEA, transfers rely on the EU Standard Contractual Clauses or an adequacy decision.
How long we keep it
- Account and license records — for as long as your license exists, or until you ask us to delete your account.
- Host machine record — until you change host or the license is deleted.
- Sign-in and host-change tokens — minutes to hours; expired tokens are purged within a day.
- Server logs — 30 days.
- Database backups — 30 days, so deleted data can persist in a backup for up to 30 days after deletion.
- Accounting records (invoice and payment data) — 7 years, as required by the Swedish Bookkeeping Act (bokföringslagen). This survives an account deletion request.
Your rights
Under the GDPR you can ask us to access, correct, delete, or export your personal data, restrict how we use it, or object to processing based on our legitimate interests. Email info@avendavi.com from the address on your account and we'll respond within 30 days. Deleting your account also revokes any license tied to it — we'll tell you that before we proceed. If you're unhappy with how we handle your data, you can complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), at imy.se, or to the authority in your own EU country.
Cookies
We set a single session cookie (ekvm_session) when you sign in on the account page so you stay signed in. It is HttpOnly, lasts 30 days, and contains no tracking data. It is strictly necessary for that page to work, so no consent banner is needed. The rest of the site sets no cookies. No third-party analytics, no advertising cookies.
Children
EasyKVM is not directed at children under 13, and we don't knowingly collect personal data from them. If you believe a child has bought a license, email us and we'll delete the data and refund the purchase.
Changes to this policy
If we change this policy we'll update the date at the top and, for material changes, email account holders before the change takes effect. We won't start using your data for new purposes without a legal basis for doing so.
Contact
Privacy / data questions: info@avendavi.com
General support: support@avendavi.com