PRIVACY POLICY · BETA
Process only what is needed and keep screen content outside the boundary.
This policy applies from September 21, 2026 to member authentication, app distribution, and usage statistics in the ViewSphere beta service.
Core principle
ViewSphereManager processes only the minimum information required for host-mode authentication and service operation. A provider-verified email is used for member identification and account management; names, phone numbers, and profile photos are not stored.
Stored and collected data
Member authentication stores the identity provider, a pseudonymized account identifier, the latest provider-verified email and verification time, registration and recent sign-in times, account state and role, and the display language and observation time from the latest app authentication. For Apple members, a refresh token is stored encrypted solely to revoke authorization during account deletion. Sharing statistics are limited to a random session ID, host OS, app version and build, timestamps, duration, participant counts, and normal completion.
Data we do not collect
- Google or Apple names and profile photos
- ID tokens, access tokens, and authorization codes
- Shared screen video or audio content
- Participant names, member information, or IP addresses
- Device serial numbers or MAC addresses
- ViewSphere quality, audio, and detailed app settings
How information is used
The pseudonymized account identifier links the same member, while email helps web administrators distinguish members and manage account status. The latest observed app language supports language availability reviews and member support and is not used for authentication or access decisions. Email is not included in ViewSphere app authentication responses. Sharing statistics are linked to the authenticated host account and let web administrators review aggregate and member-level usage and app stability. They are not used to track individual participants or for advertising.
Retention
Member and external identity information is retained until account withdrawal or the processing purpose ends. Sharing statistics are retained for up to 13 months from collection to review service quality and version stability, and are deleted when either that period expires or the account is withdrawn, whichever comes first. Records required by law or for dispute handling may be isolated and retained only for the applicable purpose and period.
Account withdrawal and deletion
Members can delete their account directly from the account screen after recent reauthentication and explicit confirmation. The external identity link, email, active sessions, and member usage statistics are deleted. For Apple members, the stored encrypted refresh token is used to revoke Apple authorization. Accounts linked to web administration or release audit records must first transfer operational responsibility.
External services
Identity verification uses Google OpenID Connect or Sign in with Apple. Google tokens are not stored. An Apple refresh token is stored encrypted only to revoke authorization during account deletion. ViewSphereManager operates on AWS-hosted servers and databases, and each provider's privacy terms also apply.
Contact and privacy requests
Send requests to access, correct, delete, or restrict personal information, as well as account-withdrawal requests, to contact@view-sphere.com. Requests that require account ownership verification are processed after a secure verification step.