How private is ToyControl really

A plain-English read on what ToyControl stores, what it does not, and what your partner can and cannot see in a room.

Sex tech has a privacy reputation problem. Some apps log everything, some have had real breaches, some bury concerning terms in their privacy policies. We get the question often: "how private is ToyControl?"

This article answers it without marketing language. What we store, what we do not store, and what each piece of software in the system sees.

What lives on your computer

Most of ToyControl runs in your browser. That means most of what you do is on your computer, not ours.

If we shut down our servers tomorrow, your library and your sessions would still be on your computer. They are yours.

What lives on our servers

A small set of things that need to be on a server.

That is it.

What we deliberately do not store

What other parts of the system see

Stripe (payments)

Stripe sees your card details, name on card, and billing address. We see the customer ID and subscription status; that is all Stripe sends us.

Statement descriptor on your card statement is TCTRL.

Cloudflare (hosting)

Cloudflare hosts our app and serves it to your browser. They see IP addresses for incoming connections, like any web service. They do not see anything about your sessions.

Supabase (database)

Supabase is the database that stores our user_settings table. The data is encrypted at rest. Their staff cannot read individual rows without admin access, which is gated.

Your browser

Your browser sees everything you do, because you are using it. Chrome, Edge, etc. have their own privacy practices. None of this is unique to ToyControl.

What Remote Control rooms expose

Rooms are where the most data could leak, so let us be specific.

To other participants

In a room, the other participants see:

To our servers

For a room, our server handles the matchmaking (the 5-letter code system) and acts as a meeting point. Once peers are connected, the video and audio go peer-to-peer. They do not transit our servers.

The slider values are also peer-to-peer.

We do see, briefly, that two users are in a room together. We do not see what they are doing.

What happens with public rooms

A public room is visible in the lobby. Anyone using ToyControl can find it and join. Things to know:

If privacy is a concern, set the room to Private. The 5-letter code is only known to people you share it with.

Anonymous accounts

If you skip the email at sign-in, your account is anonymous:

This is the most private way to use ToyControl. The trade-off is that your settings do not follow you to another computer.

See Anonymous account vs email account.

Encryption

What we would do if subpoenaed

We would comply with valid legal requests for the data we have, which is: user IDs, settings, subscription status. We would not have logs of what you played, because we do not have those logs in the first place.

How to be most private

If you want the most private setup:

  1. Sign in anonymously. Skip the email.
  2. Use a private browser window. Settings will not save, but no trace will be left.
  3. Skip the trial usage tracker by paying directly with a virtual card (not connected to your real identity).
  4. Use Private rooms instead of Public.
  5. Keep camera and mic off unless you specifically want them on.

Bottom line

We have built ToyControl to know as little about you as possible. The reason is simple: we cannot lose what we never had. If our servers were breached, the attacker would find anonymous user IDs and hardware settings. That is the data minimum we believe a control app should require.

For the deeper details, see our Privacy policy and Terms of service.

Related