Privacy Policy
Cairn is designed to keep your terminal contents, credentials, and activity from reaching p10q.
Effective September 21, 2026
Scope
This policy applies to Cairn Remote on iPhone and iPad and Cairn for macOS, provided by P 10 Q LLC ("p10q"). Cairn Remote connects to a Mac you control.
Data p10q does not collect
The Cairn apps have no p10q account system, advertising, in-app analytics, tracking SDK, or third-party crash-reporting service. Except for support information you choose to send, p10q does not receive or retain:
- terminal input, output, commands, files, or session contents;
- SSH private keys or AWS access credentials;
- paired Mac names, addresses, or workspace information;
- camera images or scanned QR codes; or
- in-app usage analytics, advertising identifiers, or location data.
Distribution, support, and App Store purchases
Cairn for macOS is available by direct download from p10q's public release repository. The Mac app does not require activation or validation and does not send license or purchaser information to p10q.
Apple processes purchases of Cairn Remote under Apple's terms and privacy policy. p10q does not receive payment-card details from Apple.
If you contact support, p10q receives the information you choose to send and retains it as needed to answer the request, maintain business records, prevent abuse, and comply with law. Do not send private keys, access tokens, or unrelated terminal contents.
Information stored on your devices
The current Mac app does not require or store licensing credentials. An older installation may leave a legacy Cairn license record in the macOS Keychain; current releases do not use that record to control access.
The iOS app stores paired Mac connection details, a per-device SSH private key, and credentials for your own AWS EC2 Instance Connect Endpoint in the iOS Keychain. These Keychain items are restricted to the device and do not synchronize through iCloud Keychain.
The app also stores display preferences and optional connection diagnostics locally. Connection diagnostics may contain host names, AWS resource identifiers, connection states, and error messages. They remain on the device unless you choose to share them with support.
Connections and AWS
When you connect remotely, the iOS app sends traffic through infrastructure in your own AWS account and then to your Mac. AWS EC2 Instance Connect Endpoint provides the network path. SSH encrypts the terminal session and verifies the jump host using a pinned host key.
p10q does not operate this connection service and cannot access the traffic. AWS processes network requests and operational metadata under your AWS agreement and the AWS Privacy Notice. Your internet provider and Apple may also process ordinary connection metadata as part of providing their services.
Device permissions
- Camera: used only to scan a pairing QR code. Images are processed on the device and are not saved or sent to p10q.
- Local network: used when you connect directly to a Mac on the same network.
Retention and deletion
Cairn has no p10q app account or p10q-hosted app profile. Use Settings > Forget all Macs in the iOS app to remove saved connection details and credentials from the Keychain. Deleting an app may preserve Keychain items unless you clear them in the app first.
To revoke remote access immediately, use Remote > Paired iPhones on the Mac. To remove the related AWS credential completely, delete the matching cairn-iphone-* IAM user in your AWS account. Deprovisioning Cairn's jump host removes the AWS resources created for remote access.
Children
Cairn is a developer tool and is not directed to children under 13. p10q does not knowingly collect personal information from children.
Changes
We may update this policy when Cairn's data practices change. The effective date above identifies the current version. Material changes will appear here before the related app update is released.
Contact
Email questions about Cairn privacy to tom@p10q.com.