Last updated: September 15, 2026
This policy describes FireTop's current connectivity, content protection, and operational-data boundaries.
FireTop requires no sign-up, login, or account. Device pairing uses a QR code or pairing code displayed by the host.
FireTop uses LAN/direct connectivity first and a FireTop-operated relay as a fallback. There is currently no active, supported Tailscale media path.
FireTop does not currently package a self-hosted relay setup flow or relay configuration UI. Screen, audio, and input content are end-to-end protected with Noise from the relay: the relay forwards opaque protected content and cannot decrypt it. Routing, session, and operational metadata remain visible to the relay, and the relay keeps a record of each relayed session — the two device identifiers, when it started and ended, whether it was view-only, and a short reason it ended — for up to 90 days. That record contains no screen, audio, input, address, credential, or free-text data.
A machine that FireTop hosts also tells the relay about itself: its operating system and version, its hardware, which version of FireTop it runs and the build it was made from, whether it hosts as a service, where it is installed, and what it is doing about updates. The relay keeps that description, and a record of which versions each machine was offered and which it came back on. That is a description of the machine, never of anything on it: no screen, audio, input, credential or free-text data.
Protected pairing and registration identifiers or keys may also transit relay infrastructure.
FireTop includes diagnostics and update checks. Diagnostics can be collected for troubleshooting, and the desktop updater uses FireTop infrastructure.
If you send a problem report from the app, FireTop receives the text you typed, the list of machines this app is paired with (names, platforms, when they were paired and last used, and a short fingerprint of each pairing key, never the key itself), and connection statistics for that session: frame rates, bitrates, delays, queue lengths and error counts from your device, from the other device in the session if its owner allows it in Settings, and from our relay. The other device is told when its statistics were included. From FireTop Desktop, the report also includes the app's own diagnostic log for the last 15 minutes. Pairing codes, clipboard contents, file paths and machine names you chose to exclude are removed on your device before anything is sent. Statistics never contain anything from your screen, your typing, or your files. Reports are removed from our systems within 90 days.
The FireTop virtual display driver receives the pixels of the virtual monitor only to discard them. It stores nothing and connects to nothing.
FireTop has no third-party integrations, advertising networks, or data brokers.
Questions? Open an issue at github.com/roguecomet-dev/FireTop/issues.