Last updated 11 September 2026
TODO: lawyer pass required
We hold the minimum needed to run accounts, plans and sessions. We do not sell your data, we do not run advertising trackers, and your projects and footage never sit on our servers: they go directly between you and the people you invite.
TODO: insert the legal entity acting as data controller, its registered address, and a contact for data protection questions. If we appoint an EU or UK representative, name them here.
| What | Why | How long |
|---|---|---|
| Email address and display name | Signing you in, and showing your name to people in your session | Until you delete your account |
| Password (hashed, never readable) | Signing you in | Until you delete your account |
| Session records: device type, label, IP, last used | Showing you where you are signed in, and letting you revoke a device | Until revoked or expired |
| Subscription status and billing identifiers | Knowing what plan you are on. Card details are held by our payment processor, never by us | As long as tax law requires |
| Room metadata: code, name, host, peer count, project name | Running the session and showing public rooms | Deleted on a rolling schedule after the room closes |
| Diagnostic logs from the panel | Finding bugs. Levels and volume are configurable, and can be switched off | Rolling window, then deleted |
Edits and file transfers move between the host and the guests. Where a direct peer-to-peer connection is not possible, frames are forwarded by our relay, which treats them as opaque bytes: it does not decode, inspect, log or store them. Room records exist so the host can see who is in the room and so public rooms can be listed; they are deleted on a rolling schedule after a room closes.
Only the service providers we need to operate: hosting, the database, our payment processor, and our transactional email provider. Each processes data on our instructions.
TODO: list the sub-processors by name and location, and state the transfer mechanism for data leaving the UK/EEA.
You can see and change your name and password, and revoke any signed-in device, from your account pages. You can ask us for a copy of your data, ask us to correct or delete it, or object to processing, by emailing support@parallaxplugin.com. Deleting your account removes your profile, sessions and room history.
TODO: add the lawful bases per purpose, the retention periods in concrete numbers, and the supervisory authority people can complain to.
One cookie, aemp_session, keeps you signed in. It is strictly necessary, set only after you sign in, and is not used for analytics or advertising. There is no cookie banner because there is nothing to consent to.
Passwords are hashed with Argon2. Session tokens are stored hashed and can be revoked individually. Traffic is encrypted in transit. No system is perfect: if we ever suffer a breach affecting you, we will tell you.
The service is not aimed at children and we do not knowingly collect their data.
We will update the date at the top when this changes, and email you first if the change is material. Terms of service are separate.