How private is ToyControl really
A plain-English read on what ToyControl stores, what it does not, and what your partner can and cannot see in a room.
Sex tech has a privacy reputation problem. Some apps log everything, some have had real breaches, some bury concerning terms in their privacy policies. We get the question often: "how private is ToyControl?"
This article answers it without marketing language. What we store, what we do not store, and what each piece of software in the system sees.
What lives on your computer
Most of ToyControl runs in your browser. That means most of what you do is on your computer, not ours.
- Scripts you import are stored in your browser's local storage. They never go to our servers.
- Folders you index are read directly from your disk. The files never leave your computer.
- Pairing data is held by your browser. We do not see which toys you have paired or how often.
- Session state (what is playing, the current intensity) is computed in the browser and sent to your toy over Bluetooth. We do not see it.
If we shut down our servers tomorrow, your library and your sessions would still be on your computer. They are yours.
What lives on our servers
A small set of things that need to be on a server.
- Your account (an anonymous user ID, plus your email if you signed up with one).
- Your settings (per-device hardware: multiplier, speed range, etc.). These sync so you can sign in on another computer.
- Your subscription status (Pro or Free, trial time remaining).
- Usage events for the trial counter. Anonymous, just "this user_id played for one more minute".
That is it.
What we deliberately do not store
- The scripts you play. Library content is on your computer.
- Video files. Same.
- What scene or video you watched. We have no idea.
- The toy's actual movement during a session. No telemetry.
- Camera or audio from Remote Control rooms. Peer-to-peer.
- Chat messages from rooms. They live in the room only, gone when the session ends.
- Your card details. Stripe handles all of that.
What other parts of the system see
Stripe (payments)
Stripe sees your card details, name on card, and billing address. We see the customer ID and subscription status; that is all Stripe sends us.
Statement descriptor on your card statement is TCTRL.
Cloudflare (hosting)
Cloudflare hosts our app and serves it to your browser. They see IP addresses for incoming connections, like any web service. They do not see anything about your sessions.
Supabase (database)
Supabase is the database that stores our user_settings table. The data is encrypted at rest. Their staff cannot read individual rows without admin access, which is gated.
Your browser
Your browser sees everything you do, because you are using it. Chrome, Edge, etc. have their own privacy practices. None of this is unique to ToyControl.
What Remote Control rooms expose
Rooms are where the most data could leak, so let us be specific.
To other participants
In a room, the other participants see:
- Your display name (whatever you typed, or "Anonymous").
- Your camera, if you turned it on.
- Your microphone, if you turned it on.
- The current speed your toy is at (the slider position).
- Chat messages you send.
To our servers
For a room, our server handles the matchmaking (the 5-letter code system) and acts as a meeting point. Once peers are connected, the video and audio go peer-to-peer. They do not transit our servers.
The slider values are also peer-to-peer.
We do see, briefly, that two users are in a room together. We do not see what they are doing.
What happens with public rooms
A public room is visible in the lobby. Anyone using ToyControl can find it and join. Things to know:
- Your display name is visible to anyone in the lobby.
- Your camera and mic state (on or off) is visible to anyone in the lobby.
- Strangers can join without your explicit permission (that is the point of "public").
If privacy is a concern, set the room to Private. The 5-letter code is only known to people you share it with.
Anonymous accounts
If you skip the email at sign-in, your account is anonymous:
- No email is stored.
- We have only a random user_id.
- If you lose your browser cookie, you lose the account. We cannot recover it because we have no email to verify you with.
This is the most private way to use ToyControl. The trade-off is that your settings do not follow you to another computer.
See Anonymous account vs email account.
Encryption
- TLS for everything between your browser and our servers.
- Encryption at rest on the database (AES-256, Supabase default).
- WebRTC for peer-to-peer connections (built-in encryption).
- No end-to-end encryption on chat messages within a room (they hop through the same WebRTC connection but are not separately E2E encrypted). The messages do not transit our servers, but a participant in the room sees them.
What we would do if subpoenaed
We would comply with valid legal requests for the data we have, which is: user IDs, settings, subscription status. We would not have logs of what you played, because we do not have those logs in the first place.
How to be most private
If you want the most private setup:
- Sign in anonymously. Skip the email.
- Use a private browser window. Settings will not save, but no trace will be left.
- Skip the trial usage tracker by paying directly with a virtual card (not connected to your real identity).
- Use Private rooms instead of Public.
- Keep camera and mic off unless you specifically want them on.
Bottom line
We have built ToyControl to know as little about you as possible. The reason is simple: we cannot lose what we never had. If our servers were breached, the attacker would find anonymous user IDs and hardware settings. That is the data minimum we believe a control app should require.
For the deeper details, see our Privacy policy and Terms of service.