01. OVERVIEW & CORE PHILOSOPHY
FreeStream is a free and open-source, retro 32-bit styled macro pad suite designed to turn mobile devices into remote controllers for personal computers. FreeStream is built upon a strict foundation of privacy by design and data minimization.
- No User Accounts: You do not need to register, provide an email address, or create a profile.
- No Telemetry or Tracking: We do not track user actions, device identifiers, usage metrics, or crash statistics.
- No Cookies or Ad Trackers: Our web application and relay service do not set cookies, tracking pixels, or third-party surveillance scripts.
- 100% Free & Open Source: The complete source code is published under the CC0 1.0 Universal public domain dedication for community review.
02. ARCHITECTURE & DATA HANDLING
FreeStream operates under two networking models depending on your network topology:
2.1 Local Area Network (LAN) Mode
When both your phone and PC are connected to the same local Wi-Fi or wired network, FreeStream uses multicast DNS (mDNS) discovery under_freestream._tcp and connects directly over raw TCP on port 39500.
In LAN mode, zero data leaves your home or office network. All packets (discovery, challenge–response authentication, command triggers, acknowledgments) are routed entirely within your local subnet.
2.2 WAN Fallback (WebSocket Relay) Mode
If local network discovery is blocked (e.g. guest Wi-Fi client isolation or separate network segments), the Android app and PC server connect to our hosted WebSocket relay (/api/ws).
The relay functions strictly as an ephemeral, in-memory bridge:
- Both devices join a temporary room matching your chosen Room ID.
- The relay forwards incoming command envelopes directly to the paired peer in volatile memory.
- No Message Logs: The relay does not record or write keystrokes, macro payloads, or room activity to disk or a database.
- Automatic Purging: Once both peers disconnect, the room and its memory state are immediately purged.
03. AUTHENTICATION & SECURITY
FreeStream prevents unauthorized access to your PC through a cryptographic challenge–response handshake:
- Zero Plaintext Password Exposure: Your chosen password is never sent over the network, whether on LAN or over the relay.
- Challenge–Response: The PC server issues a random 32-byte cryptographic salt (nonce). The client returns an HMAC-SHA256 digest of the password combined with the nonce. The PC validates the digest locally.
- Relay Blindness: Even when routing through the public WebSocket relay, the server cannot inspect, deduce, or derive your password.
04. DEVICE PERMISSIONS & HARDWARE ACCESS
In compliance with Google Play Store Developer Policies and operating system privacy frameworks, we disclose all requested permissions:
| PLATFORM | PERMISSION | PURPOSE & JUSTIFICATION |
|---|---|---|
| Android | INTERNET | Required to establish TCP socket connections to the PC server or fallback WebSocket relay. |
| Android | ACCESS_NETWORK_STATE | Required to check Wi-Fi connection availability before initiating local network discovery. |
| Android | CHANGE_WIFI_MULTICAST_STATE | Required for mDNS packet reception via Android Network Service Discovery (NSD) to find PC servers automatically. |
| Windows PC | Simulated Input (SendInput) | Required to synthesize configured macro keystrokes and media keys when triggered by the remote. |
FreeStream does NOT request or access Location, Microphone, Camera, Contacts, Photos, Storage, or unique hardware telephony identifiers (IMEI, Android ID).
05. LOCAL DATA STORAGE & RETENTION
- Windows Server: Configuration settings (last Room ID, visual theme) are stored locally in
%LOCALAPPDATA%\FreeStreamServer\appsettings.json. Your password is never saved to disk. - Android App: Button names, macro configurations, and UI theme choices are saved on your local device via Android Jetpack DataStore. No data is synchronized to cloud servers.
06. INTERNATIONAL REGULATORY COMPLIANCE
European Union & UK (GDPR)
Under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and UK GDPR, FreeStream acts with complete adherence to data minimization principles. We do not process personal data other than ephemeral IP routing metadata in volatile memory necessary to route WebSocket packets under Article 6(1)(b) (contract / service fulfillment) and 6(1)(f) (legitimate interest in network operations).
Because FreeStream maintains no accounts, logs, or personal records, there is no personal data available to access, rectify, or delete.
California Consumer Privacy Act (CCPA / CPRA)
FreeStream does not sell, share, or rent personal information for cross-context behavioral advertising or commercial gain.
Children’s Privacy (COPPA)
FreeStream does not knowingly collect or solicit any personal information from children under the age of 13.
07. THIRD-PARTY SERVICES
Web typography uses Google Fonts (Inter), which are cached by modern browsers. External links to GitHub for issue tracking or code inspection are governed by GitHub's Privacy Statement.
08. CONTACT & GOVERNANCE
If you have questions regarding this Privacy Policy or FreeStream's data protection principles, please open a public discussion or issue on our repository: