Privacy Policy
Last updated 17 September 2026 · ComeOnPC is operated by Helium22 ("we", "us").
1. Who we are
ComeOnPC (comeonpc.com) is a screen-sharing service provided by Helium22, United Kingdom. Contact: hello@helium22.com. We are the data controller for the personal data described here.
2. What we collect and why
| Data | Why | Kept for |
|---|---|---|
| Your IP address as seen by our server, and the public address of your network | To pair the two people in a session and to enforce the one-session-per-address rule that stops abuse | While your browser is connected; then only in security logs (below) |
| The 6-digit session code, your role (Presenter or Watcher) and session start/end times | To create and end the session | While the session runs |
| Connection diagnostics (types of network paths your browser found, technical error codes, browser name) | To diagnose failed connections, only when a session fails or you press "Test my connection" | 90 days in the security log |
| For account holders: username, email address, password (stored as a one-way hash), authenticator secret, sign-in times and addresses | To run your account and protect it with two-factor authentication | For the life of the account, then deleted within 30 days |
| For account holders: month-by-month usage totals (number of sessions, session time and the amount of relayed data, never the content) | To apply plan limits, keep free use within its allowance, and report on the service | 24 months |
| If you ask to be told when registration opens: your name, email address, and the consent wording you agreed to | Only to tell you that registration has opened | Until we have told you, or until you ask us to delete it, whichever is sooner |
| Security and administration log (sign-ins, settings changes, sessions ended by an administrator) | Security, abuse prevention, support | 90 days |
| Billing details for paid plans | To take payment and issue invoices | Held by our payment processor (see section 5); we keep invoice records for 6 years as required by UK tax law |
3. What we never collect
- The contents of your screen, your voice, or the pointer movements: these go browser to browser, encrypted with DTLS-SRTP, and are never sent to, stored on, or recorded by our servers.
- Keyboard or mouse control never happens unless the person being helped installs the ComeOnPC Helper and approves it. Even then, the control commands travel directly between the two browsers (or through our relay, which cannot read them) and are never recorded or stored by us. There is no unattended access.
- Advertising identifiers, tracking cookies or analytics profiles. The only cookies we set are sign-in cookies (for account holders and administrators), which are essential for signing in.
4. Relay servers
When two networks cannot connect directly, the encrypted stream is passed through a relay server operated for us by Cloudflare, Inc. The relay forwards packets but does not hold the keys to decrypt them. Cloudflare sees the IP addresses involved and the volume of data, which it needs to provide the service. Cloudflare's own privacy notice applies to that processing.
5. Who we share data with
- Hostinger hosts the ComeOnPC service and database.
- Cloudflare provides the relay servers described above.
- Stripe, through our billing platform ProcessMy, handles card payments for paid plans. We never see full card numbers.
- Nobody else, except where the law requires it.
Some of these providers process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Agreement or an adequacy decision.
6. Legal basis (UK GDPR)
We process session and security data because it is necessary to provide the service you asked for and in our legitimate interest of keeping it secure. Account and billing data are processed to perform our contract with you and to meet legal obligations. The "tell me when registration opens" list is kept on the basis of your consent, which you can withdraw at any time by emailing us.
7. Your rights
You can ask us for a copy of your personal data, ask us to correct or delete it, object to or restrict processing, and complain to the Information Commissioner's Office (ico.org.uk). Email hello@helium22.com; we respond within one month.
8. Security
All traffic to comeonpc.com uses HTTPS. Media is encrypted end to end. Passwords are hashed with scrypt, administrator accounts require an authenticator app, and sign-ins are rate-limited and logged.
9. Children
ComeOnPC is not directed at children under 13 and we do not knowingly collect their data.
10. Changes
We will post any changes on this page and update the date at the top. Material changes to how we use account data will be emailed to account holders.