개인정보 처리방침
최종 업데이트: 2026년 8월 19일
Reach("앱")는 두 개의 앱으로 이루어진 원격 데스크톱 도구입니다. iPhone과 iPad용 Reach Viewer(App Store 등록명 "Reach Remote"), 그리고 Mac용 Reach Host입니다. Reach는 KMWORKS, INC.("당사")가 배포하며 이 방침에 대한 책임도 당사에 있습니다. 이 문서는 두 앱과 그 뒤에 있는 선택적 백엔드가 이용자의 데이터를 어떻게 다루는지 설명합니다.
요약
- 화면, 오디오, 입력은 끝에서 끝까지 암호화됩니다. 당사는 이를 저장하지도 읽지도 않습니다. 직접 연결 세션은 본인 기기 사이에만 머물고, 중계 세션은 Cloudflare TURN을 지나가지만 TURN은 읽을 수 없는 암호화된 패킷을 전달할 뿐입니다.
- 계정이 전혀 없어도 Reach를 쓸 수 있습니다. Nearby(같은 네트워크)와 수동 Direct IP는 기기 간 직접 연결로 동작합니다.
- Reach 계정은 선택 사항이며, Internet Direct와 Relay(중계) 경로를 열어 주는 것이 바로 이 계정입니다. 로그인하면 본인 기기끼리 서로를 찾고 신뢰하는 데 필요한 최소한의 정보만 저장하며, 그 항목은 아래에 하나씩 적어 두었습니다.
- 앱에는 추적 SDK도, 광고 식별자도 없습니다. 백엔드는 서비스를 운영하고 보호하기 위한 운영 텔레메트리와 로그를 기록하며, 이를 광고나 이용자 프로파일링에는 사용하지 않습니다.
- 앱 안에서 계정과, 계정 데이터베이스에서 그 계정에 연결된 데이터를 삭제할 수 있습니다. 계정이 만들어지기 전 생성된 WebAuthn 챌린지와 서비스 보호용 카운터·운영 로그에는 아래에 적은 예외가 적용됩니다.
계정 없이 Reach 사용하기
로그인하지 않아도 두 가지 경로를 쓸 수 있습니다. 두 경로 모두 화면, 오디오, 입력은 물론 연결 후보까지 당사 인프라를 거치지 않습니다.
- Nearby(같은 네트워크) — Reach Viewer가 같은 네트워크에 있는 Mac을 Bonjour/mDNS로 찾아 암호화된 QUIC 연결을 직접 엽니다. 기본 설정에서는 첫 연결에 Mac에 표시된 페어링 코드를 확인합니다. 세션 데이터는 네트워크 밖으로 나가지 않습니다.
- 수동 Direct IP — 호스트 주소와 포트를 직접 입력하면(기본값은 UDP 8443이며, 보통 라우터에 포트포워딩 규칙이 필요합니다) 앱이 그 주소로 곧장 연결합니다. 시그널링 서비스도, 중계도 쓰지 않습니다.
다만 경로와 별개로, Mac에서 호스트 페어링이 활성화되어 있고 원격 접속이 켜져 있으면 Reach Host가 호스트 연결 메타데이터를 담은 작은 레코드를 Apple의 CloudKit에 게시해 본인 기기끼리 서로를 알아볼 수 있게 합니다. Reach Viewer도 여기에 대응하는 신뢰 레코드를 게시할 수 있습니다. 둘 다 바로 아래에서 자세히 설명합니다.
CloudKit 페어링 메타데이터
Reach Host는 Reach iCloud 컨테이너의 공개 CloudKit 데이터베이스에 CKRecord를 기록합니다. 이 레코드는 페어링 코드를 키로 삼기 때문에 코드를 모르면 사용자가 찾아낼 수 없지만, 데이터베이스 범위 자체는 개인 컨테이너가 아니라 공개 영역입니다. 저장소를 운영하는 곳이 Apple이더라도 당사는 이를 기기 밖으로 나가는 데이터로 간주합니다.
레코드에는 다음이 담깁니다.
- 호스트 이름 — macOS가 네트워크에서 사용하는 기기 이름
- 호스트의 공개 신원 키와 TLS 인증서 지문
- 설정해 둔 경우, 호스트의 외부 IP 주소와 포트
- 직접 연결 후보 — QUIC 연결을 세우는 데 쓰이는 LAN과 WAN 엔드포인트
- 게시 시각과 CloudKit 레코드 스키마 버전
- 연결 전 기능 메타데이터 — 지원 코덱, 시스템 오디오 지원 여부, 광고용 기본 해상도, 기능 페이로드 버전
- iCloud 사용자 레코드 이름 — Reach iCloud 컨테이너 안에서만 유효한 고정 식별자입니다. 항상 담기는 값은 아니고, iCloud Auto-Trust가 켜져 있고 iCloud 계정이 확인된 경우에만 기록되어 viewer가 같은 iCloud 계정에 속한 호스트를 알아보는 데 쓰입니다
iCloud에 로그인되어 있으면 Reach Viewer도 연결을 시도할 때 같은 공개 데이터베이스에 대응하는 신뢰 레코드를 게시할 수 있습니다. viewer의 공개 키 지문, 타임스탬프, 그리고 CloudKit이 찍어 주는 iCloud 사용자 레코드 이름이 담깁니다. Mac에서 iCloud Auto-Trust를 명시적으로 켠 경우에만, 이 레코드는 같은 Apple ID로 확인된 아직 신뢰되지 않은 viewer를 첫 연결에서 페어링 코드 없이 신뢰하는 데 쓰입니다. 이미 신뢰된 viewer는 저장된 지문으로 재연결하므로 이 레코드가 필요하지 않습니다. 신뢰 기기 목록에서 수동으로 제거된 지문은 이 자동 신뢰보다 우선해 차단되며, 다시 신뢰하려면 새 페어링 코드를 명시적으로 입력해야 합니다. Mac은 레코드를 검증하고 로컬 신뢰 저장이 성공한 뒤 CloudKit에 삭제를 요청합니다. 삭제 요청이 실패하면 같은 신뢰 항목의 이후 연결 완료 시 다시 시도할 수 있지만, 즉시 또는 최종적인 물리 삭제를 보장하지는 않습니다. Mac의 신뢰 기기 목록에서 viewer를 지우는 동작은 Mac에 저장된 로컬 신뢰를 취소하는 것이며, CloudKit 레코드 삭제와는 별개입니다.
이 데이터는 오직 본인 기기끼리 연결을 세우기 위해서만 존재합니다. 광고, 프로파일링, 분석에 쓰이지 않으며 Apple의 CloudKit 인프라 외에 누구와도 공유되지 않습니다. Reach Host에서 페어링이나 원격 게시를 중지하거나 페어링 코드를 초기화하면 호스트 레코드를 회수합니다. Reach Viewer의 “Forget Mac”은 그 기기에 저장된 연결 정보와 로컬 신뢰만 지우며, Mac의 CloudKit 레코드를 삭제하지는 않습니다. iOS 설정에서 Reach의 iCloud 데이터를 삭제할 수도 있습니다.
Reach 계정 (선택)
Reach 계정은 인터넷 경로 두 가지를 열어 줍니다. 저장된 연결 프로필로 NAT 통과를 수행하는 Internet Direct와 Relay(중계)입니다. 또한 같은 계정에 속한 기기끼리는 페어링 코드 없이 서로를 신뢰할 수 있습니다. 다만 계정이 있다고 해서 경로가 저절로 생기지는 않습니다. 연결하려면 여전히 다이얼 가능한 직접 연결 후보가 있거나 중계가 설정되어 있어야 합니다.
로그인은 이메일로 합니다. 일회용 매직 링크나 코드를 보내 드리며 비밀번호는 없습니다. 로그인하면 당사 백엔드가 계정에 연결된 다음 정보를 저장합니다.
- 이메일 주소 — 로그인에만 사용합니다.
- 계정 레코드 — 계정 식별자와 이메일, 서버가 보관하는 계정 서명 키 한 쌍, 그리고 생성·인증 시각, 세션 세대 값, 계정 역할처럼 로그인 상태를 관리하는 데 필요한 메타데이터입니다.
- 기기 목록 — 등록한 기기마다 기기 식별자, 이름, 종류(Mac 호스트인지 iPhone 또는 iPad viewer인지), 암호학적 식별자(공개 키, 키 지문, TLS 인증서 지문), 그리고 등록·최근 확인·해지 시각을 저장합니다. Mac 호스트는 다른 기기가 다이얼할 수 있도록 접속 가능한 주소와 포트에 더해 직접 연결 후보 목록도 함께 보관합니다.
- 로그인 상태 — 수명이 짧은 세션 토큰과 리프레시 토큰을 해시 형태로 저장하며 만료 시각과 회전 시각이 함께 남습니다. 고엔트로피 매직 링크 토큰은 해시로만 저장합니다. 다만 다른 기기에서 입력하는 6자리 폴백 코드는 코드 자체가 같은 단기 로그인 대기 행에 저장되며, 이메일, 컨텍스트 해시, 만료·사용 시각, 무차별 대입을 막기 위한 시도 횟수가 함께 남습니다.
- 패스키 — 패스키로 로그인하는 경우 WebAuthn 챌린지와 패스키의 공개 자격 증명(자격 증명 ID, 공개 키, 서명 카운터, 전송 방식)을 저장합니다.
- 남용 방지 카운터 — 로그인 표면을 보호하기 위해 IP 주소와 정규화된 이메일 주소를 키로 하는 단기 요청 카운터를 별도로 유지합니다.
- App Store 심사용 계정 — 심사 기간에만 쓰이는 계정에는 해시된 심사 로그인 코드, 실패 시도 횟수, 시도 창 시작 시각이 계정 레코드에 함께 저장됩니다.
위 목록은 계정 데이터베이스에 계정과 연결해 저장하는 레코드의 전부입니다. 운영 텔레메트리·요청 로그와 시그널링의 일시 데이터는 아래 별도 절에서 설명합니다. 이용자를 인증하고 본인 소유 기기 사이의 연결을 이어 주기 위해서만 존재합니다. 화면, 오디오, 입력은 여기에 결코 포함되지 않으며, 어떤 항목도 판매되거나 공유되지 않고 광고나 추적에 쓰이지도 않습니다.
백엔드는 Cloudflare에서 동작합니다. 이 방침은 특정 처리 지역을 보장하지 않습니다.
시그널링과 일시적 연결 후보
로그인 상태에서 Internet Direct와 Relay(중계)를 시도할 때는 시그널링 서비스가 일시적인 연결 후보, 즉 IP 주소와 포트를 주고받아 두 기기가 서로에게 닿는 경로를 찾도록 돕습니다. 시그널링은 연결 후보와 시도 인증 정보, viewer의 공개 IP 주소가 있는 경우 그 주소, 그리고 요청 속도 제한 상태를 시도 하나당 최대 60초 동안 보관하고, 시도가 취소되거나 만료되면 삭제합니다. 연결이 성공한 순간 즉시 지워진다고 보장하지는 않습니다. 세션 내용은 여기에 닿지 않습니다. 화면, 오디오, 입력은 Reach 인프라를 결코 지나가지 않습니다.
Cloudflare TURN을 통한 Relay(중계)
CGNAT, 엄격한 방화벽, 일부 모바일 네트워크처럼 직접 경로를 열 수 없을 때 Reach는 세션을 Cloudflare TURN으로 우회할 수 있습니다. 중계는 Reach Host에 직접 입력한 본인의 TURN 자격 증명을 사용하며, 입력하기 전까지는 아무 동작도 하지 않습니다.
영상, 오디오, 입력은 중계를 지나는 동안에도 QUIC 위 TLS 1.3으로 끝에서 끝까지 암호화된 상태를 유지합니다. Cloudflare는 패킷을 전달할 뿐 내용은 읽지 못합니다. 다만 트래픽이 더 먼 길을 돌아가므로 중계 세션은 직접 연결보다 느립니다.
계정 삭제와 기기 제거
Reach 계정은 앱 안에서 언제든 삭제할 수 있습니다. 삭제는 완전 삭제입니다. 계정 레코드, 등록된 모든 기기, 모든 세션, 대기 중인 로그인 코드, 그 계정에 연결된 WebAuthn 챌린지와 패스키 자격 증명이 계정 데이터베이스에서 한 번에 제거됩니다. 다만 계정이 만들어지기 전 단계에서 생성돼 계정 식별자가 비어 있는 WebAuthn 챌린지는 이 삭제 대상에 포함되지 않으며, 자체 만료 시각이 지나면 더 이상 인증에 쓰이지 않습니다. 서비스 보호용 요청 카운터와 운영 로그는 이 삭제 요청의 대상이 아닙니다. 카운터는 설정된 요청 제한 창에 따라 만료되며, 운영 로그는 Cloudflare에 별도로 보관됩니다.
만료되었거나 이미 사용된 로그인 링크·코드·세션은 그 시점부터 인증에 사용되지 않습니다. 다만 현재 구현은 만료 시점에 해당 레코드가 물리적으로 삭제되는 것까지 보장하지는 않습니다.
계정을 지우지 않고 기기만 개별적으로 제거할 수도 있습니다. 로그아웃은 계정 삭제가 아닙니다. 해당 기기에서 계정 토큰만 지울 뿐입니다. 연결 환경설정, 신뢰 기기 기록, 입력해 둔 중계 자격 증명은 직접 지우기 전까지 기기에 그대로 남습니다.
화면 기록과 시스템 오디오 (Reach Host)
Reach Host는 선택한 디스플레이를 캡처하기 위해 macOS 화면 기록 권한을, viewer에서 보낸 입력을 전달하기 위해 손쉬운 사용 권한을 요청합니다.
시스템 오디오는 ScreenCaptureKit을 통해 캡처됩니다. Reach Host는 마이크 권한을 요청하지 않고 마이크 샘플도 처리하지 않습니다. 필요한 것은 화면 기록/시스템 오디오 권한입니다. 캡처는 Mac에서 이뤄지며 해당 세션에 대해 인증된 viewer에게만 전송됩니다.
커서 위치 공유
Direct Touch 모드에서는 픽셀 단위로 정확하게 포인터를 움직일 수 있도록 viewer에 커서 핸들이 나타납니다. 이를 움직이기 위해 Reach Host는 Mac 커서의 위치, 즉 정규화된 좌표와 그 커서가 속한 디스플레이, 타임스탬프를 연결되어 인증된 viewer로 보냅니다. 영상·입력과 같은 암호화된 QUIC 세션을 쓰며, 이 정보는 기록되거나 저장되지 않고 제3자에게 전송되지도 않습니다.
Reach Host → Devices & Trust → Advanced → Cursor Telemetry에서 끌 수 있습니다. 끄면 호스트는 커서 위치 전송을 멈추고, 지원되는 viewer에는 화면에 남은 핸들을 지우라고 알립니다.
로컬 네트워크 접근
Reach Viewer는 Reach Host가 실행 중인 Mac을 Bonjour/mDNS로 찾기 위해 로컬 네트워크 접근을 사용합니다. Nearby(같은 네트워크) 경로에는 반드시 필요합니다. 이 권한이 없어도 Direct IP 주소를 직접 입력하면 연결할 수 있습니다.
앱 업데이트 (Reach Host)
Reach Host는 Sparkle 업데이트 프레임워크를 사용해 실행할 때와 실행 중 주기적으로 새 버전을 확인합니다. 업데이트 확인은 GitHub Pages에서 호스팅되는 당사 업데이트 피드로 보내는 평범한 HTTPS 요청이며, 다른 HTTPS 요청과 마찬가지로 IP 주소와 User-Agent 헤더가 해당 엔드포인트에 보입니다. 다만 계정 식별자, 텔레메트리를 비롯해 이용자를 식별할 수 있는 데이터는 함께 보내지 않습니다. Reach Viewer는 App Store를 통해 업데이트되며 Apple의 표준 App Store 정책을 따릅니다.
분석, 추적, 광고
앱에는 분석, 추적, 광고 식별자(IDFA), 핑거프린팅, 쿠키, 제3자 프로파일링 SDK가 전혀 없습니다. Crashlytics, Sentry, Google Analytics 같은 도구도 사용하지 않습니다.
백엔드는 다릅니다. 서비스를 운영하고 보호하기 위해 Cloudflare에 운영 텔레메트리와 요청 로그를 기록합니다. 연결 수명주기 이벤트에는 이벤트 이름과 시각이 담기고, 해당되는 경우 연결 시도 식별자, 리전 레이블, 역할(호스트인지 viewer인지), 결과, 지연 시간이 함께 기록됩니다. 호스트 소켓 등록 및 등록 거절 이벤트에는 앱 버전과 빌드 번호, 소켓 종류, 재연결 경로, 호스트 기기를 가리키는 안정적인 SHA-256 기반 가명 식별자가 추가됩니다. 대응하는 kill-switch 이벤트에는 그 항목들에 더해 Worker 요청 엔드포인트가 기록됩니다. 호스트 초대와 소켓 종료 이벤트에는 이 항목들이 붙지 않습니다. 이와 별개로 운영 로그에는 그룹·정리 건수 같은 수치, 소켓 리스 해제 사유와 상태·오류 클래스·짧은 상관 접두사가 남고, 기기 복원 로그에는 Reach 계정 식별자와 기기 식별자의 앞 8자가 남습니다. 요청 속도 제한 상태도 유지됩니다. 가명 식별자는 해시이며 기기 이름이나 계정 이메일을 담지 않습니다. 현재 파이프라인은 이용자가 고른 연결 경로 종류는 기록하지 않습니다. 이 데이터는 연결 성공률과 장애를 진단하기 위한 것이고, 광고나 이용자 프로파일링에 사용하지 않으며 판매하거나 제3자와 공유하지 않습니다. 화면, 오디오, 입력 내용은 여기에 포함되지 않습니다.
기기에 저장되는 데이터
- 연결 환경설정 — 선택한 디스플레이, 해상도, 코덱, 프레임레이트, 비트레이트, 스크롤 방향 토글, 커서 텔레메트리 켬/끔, 그리고 Mac마다 마지막으로 고른 경로
- 저장된 연결 정보 — Direct IP 호스트에 입력한 주소와 포트, 그리고 페어링한 Mac의 페어링 코드
- 신뢰 기록 — 페어링한 호스트, 그리고 호스트가 신뢰한 viewer의 암호학적 지문
- 계정 세션 토큰(로그인한 경우) — 기기의 보안 키체인에 저장됩니다
- 중계 자격 증명(입력한 경우) — Mac의 macOS 키체인에 저장됩니다. 당사로는 결코 전송되지 않으며, Mac이 중계 세션에 필요한 단기 자격 증명을 발급받기 위해 Cloudflare API로만 보냅니다
- 진단 로그 — 문제 해결을 위해 일시적으로 보관하며, 이용자가 직접 리포트를 공유하지 않는 한 업로드되지 않습니다
iPhone이나 iPad에서 앱을 삭제하면 앱 컨테이너 데이터도 함께 지워집니다. Mac에서는 Reach Host 앱 번들을 지워도 설정, Application Support 파일, 키체인 항목이 자동으로 삭제되지는 않습니다. 깨끗이 지우고 싶다면 직접 제거해 주세요.
이 웹사이트
reachremote.app은 Cloudflare Pages에서 정적으로 호스팅되며 쿠키를 심거나 방문자 분석 스크립트를 실행하지 않습니다. 다만 페이지가 브라우저에서 직접 불러오는 리소스가 있어, 그 요청의 IP 주소와 User-Agent 같은 표준 HTTPS 메타데이터가 해당 제공자에게 보입니다. 웹 글꼴은 Google Fonts에서, 페이지를 그리는 데 쓰는 자바스크립트 라이브러리는 unpkg에서 불러오며, Reach Host 다운로드의 최신 버전을 확인하기 위해 GitHub Releases API를 호출합니다.
제3자 서비스
- Cloudflare — 선택적인 계정 백엔드와 시그널링 서비스를 호스팅하고, 본인 자격 증명으로 설정하는 TURN 중계를 제공합니다. Cloudflare는 당사의 인프라 제공자로서 이 데이터를 처리하며 세션 내용은 읽을 수 없습니다.
- Apple (CloudKit) — 본인 기기끼리 서로를 발견할 수 있도록 위에서 설명한 페어링 메타데이터를 저장합니다.
- Apple (App Store) — Reach Viewer를 배포하며 Apple의 표준 App Store 정책을 따릅니다.
- GitHub — Reach Host 업데이트 피드(appcast)를 GitHub Pages에서 호스팅하고 Host 설치 파일을 GitHub Releases로 배포합니다. 업데이트를 확인하거나 내려받을 때 GitHub가 IP 주소와 User-Agent 같은 표준 HTTPS 요청 메타데이터를 처리합니다.
- Google Fonts, unpkg — 이 웹사이트가 브라우저에서 직접 불러오는 글꼴과 자바스크립트 라이브러리를 제공합니다. 앱은 이들에 접속하지 않습니다.
위에 적은 인프라 제공자 외에 어떤 곳과도 데이터를 공유하지 않습니다. 광고 네트워크나 데이터 브로커와 맺은 관계는 없습니다.
보안
Nearby(같은 네트워크), 수동 Direct IP, Internet Direct, Relay(중계) — 모든 경로는 QUIC 위 TLS 1.3으로 암호화되고 인증서 핀닝으로 보호됩니다. viewer는 이미 신뢰하는 인증서 지문을 가진 호스트에만 연결합니다. 그 지문은 페어링할 때 기록되었거나, Reach 계정의 기기 목록에 보관된 것이거나, 이용자가 명시적으로 허용한 첫 직접 연결에서 고정(TOFU)된 것입니다. 이후 지문이 달라지면 연결은 거부됩니다. 어떤 경로에서도 당사는 이 트래픽을 복호화할 수 없습니다.
아동 개인정보
Reach는 만 13세 미만 아동을 대상으로 하지 않으며, 아동의 정보를 알면서 수집하지 않습니다. 페어링과 계정 메타데이터는 연결을 세우는 데에만 쓰이고 광고, 프로파일링, 추적에는 결코 쓰이지 않습니다.
방침 변경
이 방침은 필요에 따라 갱신될 수 있습니다. 변경 사항은 이 페이지에 게시하고 맨 위의 날짜를 함께 갱신합니다. 신뢰 모델이나 데이터 흐름이 바뀔 때마다 방침을 수정합니다.
문의
개인정보 처리방침에 관한 문의는 [email protected]으로 보내 주세요. 버그 신고와 공개 질문은 github.com/SGT-Cho/Reach에서 받습니다.
Privacy Policy
Last updated: August 19, 2026
Reach (the "App") is a remote desktop tool made of two parts: Reach Viewer for iPhone and iPad, listed on the App Store as "Reach Remote", and Reach Host for Mac. Reach is published by KMWORKS, INC. ("we", "us"), which is responsible for this policy. It explains what the apps, and the optional backend behind them, do with your data.
The short version
- Your screen, audio, and input are encrypted end to end. We never store or read them. Direct sessions stay between your own devices; relayed sessions traverse Cloudflare TURN, which forwards encrypted packets it cannot read.
- You can use Reach with no account at all. Nearby / LAN and manual Direct IP run peer to peer.
- A Reach Account is optional and is what enables the Internet Direct and Relay routes. If you sign in, we store the minimum needed for your own devices to find and trust each other — itemized below.
- No tracking SDKs and no advertising identifiers in the apps. The backend records operational telemetry and logs to run and protect the service; we never use them for advertising or profiling.
- You can hard-delete your account, and everything in the account database tied to it, from inside the App.
Using Reach without an account
Two routes are available signed out. Neither sends your screen, audio, input, or connection candidates through our infrastructure.
- Nearby / LAN — Reach Viewer finds your Mac over Bonjour/mDNS on the same network and opens a direct, encrypted QUIC connection. By default the first connection confirms a pairing code shown on the Mac. No session data leaves your network.
- Manual Direct IP — you enter the host address and port yourself (UDP 8443 by default, which usually needs a port-forwarding rule on your router), and the App connects straight to it. No signaling service, no relay.
Separately from those routes: when host pairing is active and remote access is enabled on the Mac, Reach Host publishes a small record of host connection metadata into Apple's CloudKit so your own devices can recognize each other, and Reach Viewer can publish a matching trust record. Both are described in full just below.
CloudKit pairing metadata
Reach Host writes a CKRecord into the public CloudKit database of the Reach iCloud container. The record is keyed by your pairing code, so it is not user-discoverable without that code, but the database scope itself is public rather than your private container. We treat this as data that leaves your device, even though Apple operates the storage.
The record contains:
- Your host name — the device name macOS uses on the network
- The host's public identity key and its TLS certificate fingerprint
- The host's external IP address and port, when configured
- Direct connection candidates — the LAN and WAN endpoints used to set up QUIC
- The publication timestamp and the CloudKit record's schema version
- Pre-connect capability metadata — supported codecs, whether system audio is supported, the advertised default resolution, and the capability-payload version
- Your iCloud user record name — a stable identifier scoped to the Reach iCloud container. It is not always present: it is written only when iCloud Auto-Trust is enabled and the iCloud account has been confirmed, so the viewer can recognize hosts that belong to the same iCloud account
When you are signed in to iCloud, Reach Viewer can publish a matching trust record into the same public database on a connection attempt: your viewer's public-key fingerprint, a timestamp, and the iCloud user record name CloudKit stamps on it. Only when iCloud Auto-Trust is explicitly enabled on the Mac does this record let an otherwise-untrusted viewer verified as using the same Apple ID establish trust on its first connection without a pairing code. An already-trusted viewer reconnects through its stored fingerprint and does not need it. A manual removal takes precedence over automatic trust: that fingerprint needs a new explicit pairing code before it can be trusted again. After validation and successful local trust persistence, the Mac requests deletion of the record. A failed CloudKit deletion can be retried on a later committed connection for that trust entry; immediate or eventual physical deletion is not guaranteed. Removing that viewer from the Mac's trusted devices revokes local trust on the Mac; that is a separate action from deleting the CloudKit record.
This data exists only to set up a connection between your own devices. It is never used for advertising, profiling, or analytics, and it is never shared with anyone other than Apple's CloudKit infrastructure. Reach Host withdraws its record when you stop pairing or remote publication, or reset the pairing code. “Forget Mac” in Reach Viewer removes the saved connection details and local trust on that device; it does not delete the Mac's CloudKit record. You can also remove Reach's iCloud data in iOS Settings.
Reach Account (optional)
A Reach Account unlocks the two internet routes — Internet Direct, which performs NAT traversal through a saved connection profile, and Relay — and lets devices on the same account trust each other without a pairing code. An account does not by itself create a path: connectivity still requires a dialable direct candidate or a configured relay.
Sign-in is by email. We send a one-time magic link or code; there are no passwords. If you sign in, our backend stores the following, tied to your account:
- Your email address — used only to sign you in.
- An account record — the account identifier and email, a server-held account signing key pair, and the metadata needed to manage sign-in state: creation and verification times, a session generation counter, and the account role.
- A device registry — for each device you register: its device identifier, name, type (Mac host, or iPhone or iPad viewer), cryptographic identifiers (public key, key fingerprint, TLS certificate fingerprint), and its registration, last-seen, and revocation times. For a Mac host it also holds the reachable address and port plus a list of direct connection candidates, so your other devices can dial it.
- Sign-in state — short-lived session and refresh tokens, stored hashed, with their expiry and rotation times. The high-entropy magic-link token is stored only as a hash. The six-digit cross-device fallback code, however, is stored as the code itself in the same short-lived pending-login row, alongside the email, a context hash, its expiry and consumption times, and an attempt counter that bounds brute force.
- Passkeys — if you sign in with a passkey, the WebAuthn challenge and the passkey's public credential (credential ID, public key, signature counter, transports).
- Abuse-prevention counters — short-lived request counters keyed by IP address and normalized email address, kept separately to protect the sign-in surface.
- App Store review accounts — for an account used only during App Store review, the account record also stores a hashed review sign-in code, the failed-attempt count, and the attempt-window start time.
That list is the complete set of account-linked records stored in the account database. Operational telemetry, request logs, and ephemeral signaling data are described separately below. It exists to authenticate you and to route connections between devices you own. Your screen, audio, and input are never part of it, and none of it is sold, shared, or used for advertising or tracking.
The backend runs on Cloudflare. This policy does not promise a specific processing region.
Signaling and ephemeral connection candidates
For signed-in Internet Direct and Relay attempts, a signaling service exchanges ephemeral connection candidates — IP addresses and ports — so the two devices can find a path to each other. Signaling stores candidate payloads, attempt-auth bindings, a viewer public IP address when present, and rate-limiting state for at most 60 seconds per attempt, and removes them on explicit cancellation or expiry. It is not guaranteed to be deleted the moment a connection succeeds. Session content never reaches it: screen, audio, and input never pass through Reach infrastructure.
Relay through Cloudflare TURN
When no direct path can be opened — CGNAT, restrictive firewalls, some mobile networks — Reach can route the session through Cloudflare TURN. The relay uses your own TURN credentials, entered in Reach Host, and does nothing until you enter them.
Video, audio, and input remain end-to-end encrypted with TLS 1.3 over QUIC while traversing the relay. Cloudflare carries the packets and cannot read them. A relayed session is slower than a direct one because the traffic takes a longer path.
Deleting your account and removing devices
You can delete your Reach Account at any time from inside the App. Deletion is a hard delete: the account record, every registered device, all sessions, any pending login codes, and the WebAuthn challenges and passkey credentials tied to that account are removed together from the account database. WebAuthn challenges created before an account existed carry no account identifier and are not covered by that deletion; they stop being accepted once they expire. Abuse-prevention counters and operational logs are not targeted by that request. Counters expire on their configured rate-limit windows; operational logs are retained separately in Cloudflare.
A login link, code, or session stops being accepted for authentication the moment it expires or is consumed. The current implementation does not, however, guarantee that the record is physically deleted at expiry.
You can also remove individual devices from your account without deleting the account. Signing out is not account deletion — it only clears account tokens from that device. Connection preferences, trusted-device records, and any relay credentials stay on the device until you remove them.
Screen recording and system audio (Reach Host)
Reach Host requests macOS Screen Recording permission to capture the display you select, and Accessibility permission to deliver the input you send from the viewer.
System audio is captured through ScreenCaptureKit. Reach Host does not request Microphone permission and ignores microphone samples; what it needs is Screen Recording / system-audio access. Capture happens on the Mac and is streamed only to viewers authenticated for that session.
Cursor position sharing
In Direct Touch mode the viewer shows a cursor handle for pixel-precise pointer movement. To drive it, Reach Host sends the position of the Mac's cursor — a normalized coordinate, the display it belongs to, and a timestamp — to the connected, authenticated viewer, over the same encrypted QUIC session as video and input. It is never logged, stored, or sent to a third party.
You can turn it off in Reach Host → Devices & Trust → Advanced → Cursor Telemetry. The host then stops sending cursor position and tells supported viewers to clear any handle left on screen.
Local network access
Reach Viewer uses local network access to discover Macs running Reach Host over Bonjour/mDNS. It is required for the Nearby / LAN route. Without it, you can still connect by entering a Direct IP address manually.
App updates (Reach Host)
Reach Host checks for new versions on launch and periodically while running, using the Sparkle update framework. An update check is a standard HTTPS request to our update feed, which is hosted on GitHub Pages; as with any HTTPS request, your IP address and a User-Agent header are visible to that endpoint, but no account identifier, telemetry, or other identifying payload is sent. Reach Viewer updates through the App Store, governed by Apple's standard App Store policies.
Analytics, tracking, and advertising
The apps contain no analytics, tracking, advertising identifiers (IDFA), fingerprinting, cookies, or third-party profiling SDKs. We do not use Crashlytics, Sentry, Google Analytics, or anything comparable.
The backend is different. To operate and protect the service, it records operational telemetry and request logs in Cloudflare, Rendezvous lifecycle events carry the event name and a timestamp and, where applicable, a connection-attempt identifier, region label, role (host or viewer), outcome, and latency. Host socket registration and blocked-registration events additionally carry the app version and build number, socket kind, reconnect path, and a stable SHA-256-derived pseudonym for the host device. The corresponding kill-switch event carries those fields plus the Worker request endpoint. Host invite and socket-close events do not carry those. Separate operational logs hold numeric group and sweep metrics, socket-lease release reason, status and error class with short correlation prefixes, and a device-restoration log containing the first eight characters of the Reach account and device identifiers. Rate-limiting state is kept as well. The pseudonym is a hash; it carries no device name and no account email. The current pipeline does not record which connection route you chose. We use it to diagnose connection success rates and failures. We do not use it for advertising or user profiling, and we do not sell it or share it with third parties. Screen, audio, and input content are never part of it.
Data stored on your devices
- Connection preferences — selected display, resolution, codec, frame rate, bitrate, scroll-direction toggles, cursor telemetry on or off, and the route last chosen for each Mac
- Saved connection details — the address and port you entered for a Direct IP host, and the pairing code for a Mac you have paired with
- Trust records — cryptographic fingerprints of hosts you have paired with, and of viewers your host has trusted
- Account session tokens, if you are signed in — in the device's secure keychain
- Relay credentials, if you enter them — in the macOS Keychain on the Mac. They are never sent to us; the Mac sends them only to Cloudflare's API to mint the short-lived credentials a relayed session needs
- Diagnostic logs — kept temporarily for troubleshooting, never uploaded unless you choose to share a report
Deleting the iPhone or iPad app removes its app-container data. On the Mac, deleting the Reach Host app bundle does not automatically remove its settings, Application Support files, or Keychain items; remove those by hand if you want a clean slate.
This website
reachremote.app is a static site on Cloudflare Pages. It sets no cookies and runs no visitor-analytics script. It does load a few resources directly in your browser, so standard HTTPS metadata such as your IP address and User-Agent is visible to those providers: web fonts from Google Fonts, the JavaScript libraries the page renders with from unpkg, and a call to the GitHub Releases API to resolve the current Reach Host download.
Third-party services
- Cloudflare — hosts the optional account backend and the signaling service, and provides the TURN relay you configure with your own credentials. Cloudflare processes this data as our infrastructure provider and cannot read session content.
- Apple (CloudKit) — stores the pairing metadata described above so your own devices can discover each other.
- Apple (App Store) — distributes Reach Viewer, governed by Apple's standard App Store policies.
- GitHub — hosts the Reach Host update feed (appcast) on GitHub Pages and distributes the Host installer through GitHub Releases. GitHub processes standard HTTPS request metadata such as your IP address and User-Agent when you check for or download an update.
- Google Fonts, unpkg — serve the web fonts and JavaScript libraries this website loads directly in your browser. The apps do not contact them.
We share data with no one beyond the infrastructure providers listed above. There are no advertising-network or data-broker relationships.
Security
Every route — Nearby / LAN, Manual Direct IP, Internet Direct, and Relay — is encrypted with TLS 1.3 over QUIC and protected by certificate pinning. A viewer connects only to a host whose certificate fingerprint it already trusts — recorded when you paired, held for that device in your Reach Account's device registry, or pinned on an explicitly authorized first direct connection (trust on first use). A later mismatch is rejected. We cannot decrypt this traffic on any route.
Children's privacy
Reach is not directed at children under 13, and we do not knowingly collect information from children. Pairing and account metadata is used only for connection setup, never for advertising, profiling, or tracking.
Changes to this policy
We may update this policy from time to time. Changes are posted on this page and the date at the top is updated. We revise it whenever the trust model or the data flow changes.
Contact
Questions about this privacy policy: [email protected]. Bug reports and public questions: github.com/SGT-Cho/Reach.