Privacy policy
Last updated: July 2026 · This is a translation of the Spanish original; if the two differ, the Spanish version prevails.
PController ("the service") is developed and operated by Alejandro Neira, a natural person domiciled in Colombia, acting as the data controller for users' personal data. This policy explains what data the service collects, how it uses it and what rights the data subject has over it. This is a translation of the Spanish original; if the two differ, the Spanish version prevails.
1. What data is collected
- Account: email address and password for authentication, or sign-in with Google OAuth. The password is handled by the authentication provider (Supabase Auth) in hashed form; PController never sees it and never stores it in plain text.
- Devices: a unique device identifier (a locally generated token), the OS hostname, the platform (win/mac/linux/android) and the IP address the machine connects from.
- Sessions and connections: session start and end timestamps, duration, and connection records including IP address and user agent, for security and abuse prevention.
- Payments: Lemon Squeezy acts as Merchant of Record. PController neither accesses nor stores card data. It receives webhooks with the subscription status and transaction data (purchase email, amount, tax, country) which it keeps as an accounting record.
- Analytics: usage events through PostHog (servers in the EU), tied to an anonymous identifier, without cookies. They can be turned off with Do Not Track or with the control in the cookie policy.
- Errors: stack traces through Sentry (DE region) when something fails. Personal data is avoided; in limited cases a diagnostic may reference an internal identifier.
- Desktop client logs: the client running on the user's PC records activity in an in-memory buffer that is cleared when the app closes. It is not sent to any external server.
1.b Minimum age
The service is aimed at adults. It is not intended for anyone under 18 and PController does not knowingly collect data from minors. Anyone who believes a minor has provided data can write to hello@pcontroller.app; that data will be deleted.
2. How the data is used
- To authenticate the user's session and keep the plan active.
- To send transactional emails (welcome, trial reminder, expiry). Every email includes an unsubscribe option.
- To improve the service through aggregated, anonymised analytics.
- To detect and prevent abuse.
3. Who the data is shared with
PController does not sell or rent personal data. It shares data only with the infrastructure providers needed to operate the service:
- Supabase (database, authentication) — hosted in us-east-1.
- Brevo (transactional emails).
- Lemon Squeezy (payment processing, as MoR).
- Cloudflare (CDN, tunnels for remote connection).
- PostHog EU (analytics, data in Europe).
- Sentry (error monitoring, DE region).
PController shows no advertising on any plan or platform.
3.b International data transfers
Some of these providers host data outside Colombia: Supabase and Lemon Squeezy in the United States; PostHog and Sentry in the European Union. By using the service, the user authorises this international transfer, carried out under each provider's contractual safeguards. This data is processed in accordance with Colombia's Law 1581 of 2012.
4. Retention
PController keeps the account and its data while the service is active. The user can delete their account at any time from app.pcontroller.app/account, under "Danger zone" (step-by-step guide). Deleting it removes the account, the devices, the subscription and the associated records, anonymises the connection data (IP, user agent) and requests removal of the contact from the email provider (Brevo).
Legal exception: PController keeps the payment transaction records (amount, tax, date, country), detached from the account, for the period required by Colombian accounting and tax rules. They are used for nothing else.
5. Cookies and local storage
The service uses the browser's localStorage for preferences and for the PC viewer's session token, and first-party cookies (host-only, no third parties) for the account session on app.pcontroller.app. Analytics (PostHog) runs without cookies. The details and controls are in the cookie policy.
6. Rights of the data subject
Under Colombia's Law 1581 of 2012 and Decree 1377 of 2013 (habeas data), the data subject has the right to access, update, rectify and delete their personal data, to withdraw consent to processing and to request proof of that consent. These rights can be exercised by writing to hello@pcontroller.app; PController responds within the legal time limits.
Residents of the European Union and the United Kingdom additionally have GDPR rights of access, portability, restriction and objection, and the right to complain to their supervisory authority. Residents of California have CCPA/CPRA rights to know, to delete and not to have their data sold; PController does not sell personal data.
7. Security
Communications between the phone and the PC use a tunnel encrypted with TLS 1.3. Authentication tokens have a TTL: the account session lives in first-party host-only cookies (not reachable from other origins or subdomains), and the PC viewer's token lives in localStorage. Neither is read by any third party.
8. Changes to this policy
For material changes, PController gives notice by email. Continued use of the service after that notice implies acceptance.
9. Contact
Privacy questions: hello@pcontroller.app