Security and privacy
Last updated 4 Sept 2026
Quick answer
EasySwitch never mirrors your desktop. Input, clipboard and the files you move cross the network end-to-end encrypted with the Noise protocol on every tier; if you switch Extend on, the extra display EasySwitch created — and only that — streams too. Machines pair by confirming a fingerprint, it stays on your LAN by default, and the app has no account and no telemetry.
Privacy is the point of EasySwitch, not a setting. Here is exactly what it does and doesn’t do with your data.
Your desktop is never captured
EasySwitch is not remote desktop and never mirrors the screen you are using. These cross the network:
- Input events — the mouse moves, clicks and keystrokes you send to another machine.
- Clipboard data — text and images you copy, and files only when you paste them (the pull model).
- Files you explicitly move — drag-and-drop and web-bridge transfers.
- An extra display, only while you’re extending one — see below.
What Extend does and doesn’t send
Extend asks your operating system for a brand-new, empty display and streams that. Your existing desktop is not read, recorded or mirrored at any point: what travels is a screen that did not exist until you asked for one, containing only what you drag onto it. Leave Extend switched off and nothing of the kind leaves the machine.
The stream is encrypted like everything else and stays on your local network. On a Mac, macOS still asks for Screen Recording permission before it will start — that permission gates all screen reading and cannot distinguish a display we created from your desktop, so its name promises more access than EasySwitch ever uses.
Everything is end-to-end encrypted — free
Every machine-to-machine connection is encrypted with the Noise protocol (Noise_XX with X25519, ChaCha20-Poly1305 and BLAKE2s). Both ends authenticate each other’s keys, messages are replay-protected, and session keys rotate after an hour of idle.
Encryption is on every tier, including free, and is never a paid feature. A license unlocks capabilities; it never unlocks security.
Pairing establishes trust once
The first time two computers connect, a short fingerprint appears on both screens. You confirm it matches and click Trust — that ties the connection to that machine’s key. From then on the machines reconnect silently, and if a key ever fails to match, EasySwitch refuses the connection as a possible impersonation. There’s no password and no PIN for machine-to-machine trust.
It stays on your network
By default EasySwitch only accepts connections from your local network and ignores addresses from outside it. There’s no relay, no cloud broker, and no internet round-trip for normal use — your input and clipboard travel straight from one of your machines to another.
The web bridge is a separate, lighter trust tier
The optional web bridge lets a phone or browser exchange files and text over local HTTP, gated by a fresh 6-digit PIN (five wrong tries locks that device out briefly). It exposes only the received-files folder and the last text you sent — not your disk, and not input control. Treat it as a trusted-LAN convenience; the encrypted input and clipboard paths are unaffected by it.
Your license verifies offline
Adding a license key makes one online call — to activate that device — which returns a signed receipt. Every launch after that verifies the key and receipt offline, so a licensed app keeps working forever with the internet unplugged. There is:
- no account inside the app,
- no telemetry and no usage tracking, and
- no hardware fingerprinting — activation uses a device identifier derived from the app’s own key pair (generated on first launch), nothing is read from your hardware.
See Licensing and pricing for the details.
What the app asks our server, and when
Besides activation, the app makes up to three small requests once per launch. None carries usage data, and every one of them fails silently — block our domain at your firewall after activating and nothing changes, ever.
| Request | When | What it carries | What it can do |
|---|---|---|---|
| Seat check | Every launch, licensed installs only | License id, device identifier, OS, the computer’s display name and your OS username (the same fields activation sent, so your account’s device list can name the machine) | Return the app to the free tier only after you removed that computer from your account, or after a refund. Unreachable server → nothing. |
| Update feed | Every launch while Update automatically at startup is on (the default; off switch in the About card) | Nothing beyond the platform it asks for and the IP address any web request has | Download and install a newer build. Microsoft Store installs never make this request — the Store updates them. |
| Notices | Every launch | Nothing — the answer is identical for every copy of the app | Show a release note or service message in the app. |
Free-tier installs make the update and notice requests only. Turn auto-update off and a free install asks us for nothing at all after download.
See also
- Licensing and pricing — the one-call activation model in full.
- Clipboard and file transfer — the “no transfer without a paste” model.
- Getting started — pairing step by step.