Privacy Policy
Cairn is designed to keep your terminal contents, credentials, and activity from reaching p10q.
Effective August 15, 2026
Scope
This policy applies to Cairn Remote on iPhone and iPad and Cairn for macOS, provided by P 10 Q LLC ("p10q"). Cairn Remote connects to a Mac you control.
Data p10q does not collect
Cairn has no p10q account system, advertising, analytics, tracking SDK, or third-party crash-reporting service. Except for purchase and support information described below, p10q does not receive or retain:
- terminal input, output, commands, files, or session contents;
- SSH private keys or AWS access credentials;
- paired Mac names, addresses, or workspace information;
- camera images or scanned QR codes; or
- usage analytics, advertising identifiers, or location data.
Purchases and license validation
Gumroad processes Cairn for macOS purchases and provides receipts, purchased downloads, and license keys. Gumroad receives purchase and payment information under the Gumroad Privacy Policy.
Cairn sends the Gumroad product identifier and license key to Gumroad when you activate or validate a license. Cairn stores the key and validation state in the macOS Keychain. p10q does not operate a separate license server or receive your terminal contents through this process.
If you contact support, p10q receives the information you choose to send and retains it as needed to answer the request, maintain business records, prevent abuse, and comply with law. Do not send private keys, access tokens, full license keys, or unrelated terminal contents.
Information stored on your devices
The iOS app stores paired Mac connection details, a per-device SSH private key, and credentials for your own AWS EC2 Instance Connect Endpoint in the iOS Keychain. These Keychain items are restricted to the device and do not synchronize through iCloud Keychain.
The app also stores display preferences and optional connection diagnostics locally. Connection diagnostics may contain host names, AWS resource identifiers, connection states, and error messages. They remain on the device unless you choose to share them with support.
Connections and AWS
When you connect remotely, the iOS app sends traffic through infrastructure in your own AWS account and then to your Mac. AWS EC2 Instance Connect Endpoint provides the network path. SSH encrypts the terminal session and verifies the jump host using a pinned host key.
p10q does not operate this connection service and cannot access the traffic. AWS processes network requests and operational metadata under your AWS agreement and the AWS Privacy Notice. Your internet provider and Apple may also process ordinary connection metadata as part of providing their services.
Device permissions
- Camera: used only to scan a pairing QR code. Images are processed on the device and are not saved or sent to p10q.
- Local network: used when you connect directly to a Mac on the same network.
Retention and deletion
Because p10q does not collect app data, p10q has no app account or server-side profile to delete. Use Settings > Forget all Macs in the iOS app to remove saved connection details and credentials from the Keychain. Deleting the app removes its local container, but iOS may preserve Keychain items unless you clear them in the app first.
To revoke remote access immediately, use Remote > Paired iPhones on the Mac. To remove the related AWS credential completely, delete the matching cairn-iphone-* IAM user in your AWS account. Deprovisioning Cairn's jump host removes the AWS resources created for remote access.
Children
Cairn is a developer tool and is not directed to children under 13. p10q does not knowingly collect personal information from children.
Changes
We may update this policy when Cairn's data practices change. The effective date above identifies the current version. Material changes will appear here before the related app update is released.
Contact
Email questions about Cairn privacy to tom@p10q.com.