The short version

Connecting a Quad Cortex over USB, controlling it, and exporting diagnostics are all local — nothing about that reaches Freevia. The remote relay is off until you pair a device with it, and it sends only what is described below, to Google and to the relay Freevia operates.

What happens without any network connection

Connecting a Quad Cortex over USB, controlling it, editing presets, and exporting diagnostics you request are all local operations. Device state, commands, local preferences, and diagnostic exports stay on your computer or phone in app-private storage. Nothing about local use is sent to Freevia or to anyone else. This is the default and requires no setup.

The optional remote relay, if you turn it on

The remote relay is off until you choose to pair a device with it. If you do, here is exactly what leaves your device and where it goes.

Who receives it. Two parties: Google, as the identity provider you sign in with, and the relay operator — Freevia, running Cloudflare Workers, Durable Objects and KV storage at qcrc.freevia.org. Freevia operates the relay Cloudflare hosts; Cloudflare does not see the content of your commands in a form Freevia's code doesn't already control.

What is sent, and why:

DataPurpose
A one-time pairing codeProves the computer and the account belong together, once, at pairing time
A generic label naming the app host (e.g. "Windows")Lets you tell paired devices apart in the device list
A relay credentialAuthenticates the paired computer to the relay on every reconnect. Stored at the relay only as a SHA-256 hash — the relay cannot recover the credential itself from what it stores
Your Google account subject ID and verified emailIdentifies which account owns which paired devices, so remote access is scoped to you
An OAuth bearer token, if you connect an AI appLets that app reach your paired device through the relay, scoped to the permissions you approved
Device commands and device-state responsesThis is the remote control itself — what you asked the device to do, and what it reported back. Persistent hardware identifiers are stripped before this leaves the relay; full device-backup payloads are never forwarded through this path
A daily count of remote commandsShown back to you in the app, and used to watch for abuse of the relay

What is never sent through the relay: anything from local-only use — your local preferences, or a diagnostic export you generate on your own machine. Full device backups are withheld from remote command responses.

How long it is kept. Your Google account subject ID, verified email, and the hashed device credential are retained for as long as the device stays paired, with no automatic deletion. They are removed when you unpair the device. This is separate from a device credential's 90-day authentication-validity window: expiry stops that credential being accepted but does not delete the pairing record. OAuth grants and the pairing directory persist until revoked. Unpairing withdraws the device credential immediately and deletes its stored pairing record; the last device leaving an account also retires that account's connected-app authorizations.

Your controls. You choose whether to pair at all, and which Google account to pair with. Before you sign in, the app shows you which account a device would be paired to. Every destructive remote action (deleting a preset, overwriting a setlist) still requires your approval on the paired host — pairing does not hand an AI app unattended authority to erase your work. You can unpair a device at any time, which revokes it at the relay and locally. A device already paired to one Google account refuses to be re-paired to a different one without first being unpaired, so the relay cannot be used to quietly move a rig between accounts.

Third-party AI apps you connect

If you connect an AI app (for example, an MCP-capable assistant) to the relay, you are granting that app the scopes you approve at that time — reading your Quad Cortex's status and library, or also changing it. That grant is separate from pairing a computer: pairing attaches a computer to an account, connecting an app attaches that app to the same account. Removing the connector in that app's own settings revokes its access; Freevia does not control what that third-party app itself does with data it receives through the connection, and its own privacy policy governs that.

What we do not do

We do not sell personal data. We do not run advertising or behavioral analytics inside QC Remote. We do not read the content of your presets or device backups for any purpose other than relaying the command you issued.

Children

QC Remote is not directed at children, and remote pairing requires a Google account, which itself has its own age requirements.

Changes to this policy

If this policy changes, the updated version will be published at this same address with a revised date. Material changes affecting the remote relay will be reflected here before they take effect. The policy's source and revision history are also available in the public GitHub repository.

Who is responsible

Freevia EOOD is the publisher and relay operator: EIK 208913638, 6 Tsanko Tserkovski St, Sofia 1164, Bulgaria. See the legal notices for publisher, licensing, compatibility, and trademark information.

Contact

Do not post personal data, credentials, or security vulnerabilities in a public GitHub issue.