Privacy Policy

Effective 15 September 2026

FreeRDC processes only the data needed to authenticate a ChatGPT connection, pair your device, relay requested operations, and protect the service from replay or misuse.

Data processed

OAuth client metadata may include a client name and redirect URI. Authentication records contain pseudonymous account and client identifiers, granted scopes, and token expiry metadata. Device trust records contain a device identifier, Ed25519 public key, pairing time, and recent-connectivity time. Short-lived relay records can contain the file path, file content, process arguments, or operation result needed to carry out the specific tool call you requested.

Retention

OAuth authorization transactions expire within 10 minutes; authorization codes within 5 minutes; access tokens within 1 hour; refresh tokens and dynamically registered client records within 30 days. Agent challenges expire within 1 minute, agent sessions within 15 minutes, and replay markers within 30 seconds. Relay commands expire within 1 minute; terminal relay records expire within 10 minutes and may be removed earlier after retrieval. Device trust records remain until you revoke the device. Pairing/revocation audit records contain the event, device identifier, and timestamp and expire within 30 days.

Storage and disclosure

The hosted service runs on Deno Deploy and uses Deno KV for the records described above. Tool requests and results are transmitted between ChatGPT, the FreeRDC service, and your paired device. When you use web tools, the paired device contacts the public websites or public search providers needed for your request; if you explicitly enable a configured country proxy, that proxy carries the corresponding web traffic. Interactive browser tools use an account-and-device-bound browser context stored on the paired device so site sessions can persist between runs. Cookies and local site storage in that browser context remain on the paired device until cleared and are not stored in Deno KV or accepted as plugin inputs. Browser-planning decisions for the public plugin are generated locally on the paired device and are not sent to an automatic paid or remote planner. FreeRDC does not sell personal data and does not use this service data for advertising.

Your controls

You can revoke a paired device with FreeRDC and disconnect the plugin in ChatGPT. Expiring authentication and relay records are automatically removed according to the periods above. For support with privacy or deletion, use the support link below.