Beamdesk Privacy Policy
Effective September 4, 2026
Summary
Beamdesk streams displays from your Mac to your Meta Quest over your local network. There is no Beamdesk account, cloud relay, advertising, analytics, or tracking. Kevin Tang does not receive or store your screen, audio, microphone, clipboard, room, hand-tracking, or location data.
Data Between Your Devices
The following data travels directly between your own paired Mac and Quest:
- Screen video. Your Mac captures and encodes its displays. The Quest decodes and renders the video; Beamdesk does not record or upload it.
- Mac audio. Audio from each connected Mac can be streamed to the Quest.
- Quest microphone. If you turn it on and select a Mac, microphone audio is sent to that active paired Mac for uses such as calls or dictation. It is not stored.
- Clipboard. Text and images can be relayed between your paired Macs through the Quest. File transfer requires a deliberate action. Up to six recent cards are held for the in-session shelf; previews and transfer payloads can use temporary local cache files.
- Input and workspace commands. Pointer, keyboard, display-layout, and media commands are sent to the active paired Mac.
Normal connections use TLS 1.2 or 1.3 and a certificate fingerprint pinned during one-time-code pairing. Open a two-minute pairing window in the Mac app, select the Mac on Quest, then approve only when the same six-digit Quest code is visible on both devices. New clients are blocked outside that window, and every connection must prove an approved Quest identity before receiving any stream or control traffic. Plaintext is restricted to loopback for an explicit developer ADB-reverse tunnel; remote local-network plaintext is rejected and cannot replace a paired TLS connection.
Data Processed on Your Quest
- Room and Scene data. If you enable Room Awareness and grant permission, Beamdesk reads the room model created in Quest Space Setup. It renders sparse nearby-furniture safety cues. It does not send the room model elsewhere or use it to anchor screens to furniture.
- Hand tracking. Beamdesk uses hand-ray input for panel interaction and microgesture commands. It is not recorded or transmitted. Room Awareness derives floor alignment from Quest's stable local-floor reference space, not body-joint data.
Optional Location and Weather
The Mac companion does not request Location at launch. It requests macOS Location permission only after you explicitly choose Local weather in its settings. If granted, Beamdesk takes a one-time fix and rounds both coordinates to a fixed 0.02-degree city-scale grid before storing them locally or sharing them with your paired Quest. The fix expires after 24 hours and is deleted immediately if Location is denied, restricted, or disabled. Invalid or very imprecise fixes are rejected. If Location is unavailable, Seattle coordinates are used as a fallback. Location is optional and does not affect screen streaming.
If you place a weather or air-quality desk widget, the Quest sends the active latitude and longitude to Open-Meteo to request current conditions, no more than about once every 15 minutes. Open-Meteo also receives ordinary web-request metadata such as IP address. Beamdesk attaches no account, name, or advertising identifier.
If you configure your own Google Pollen API key on the Mac and place the air-quality widget, the Mac can query Google's Pollen API using fixed Seattle coordinates. The key stays on the Mac; only the bounded pollen result is returned to the Quest. These third-party services process their requests under their own privacy terms. Kevin Tang does not receive the requests or results.
Local Storage
- Quest: paired Mac identities, pinned certificate fingerprints, a separate Keystore-wrapped credential for each Mac, preferences, and workspace layout. JPEG clipboard previews and in-progress relay payloads can exist temporarily in the app cache.
- Mac: the local TLS identity, approved Quest list, workspace drafts, preferences, and an optional rounded location fix under
~/Library/Application Support/Beamdesk/. The fix expires after 24 hours and is removed immediately when authorization is lost. Clipboard images and cross-Mac payloads can exist temporarily under~/Library/Caches/Beamdesk/Clipboard/while they remain in the six-card shelf, are in transit, or are still referenced by the pasteboard. An optional pollen API configuration can exist under~/.config/beamdesk/.
Beamdesk disables Android cloud backup for its Quest data.
Permissions
- Quest microphone: optional microphone routing to the active paired Mac.
- Hand tracking: local hand-ray interaction and microgesture commands.
- Scene and spatial anchors: optional Room Awareness safety cues.
- Internet and Wi-Fi multicast: local Mac connections, Bonjour/mDNS discovery, and optional weather requests.
- Mac Screen Recording: required to capture displays.
- Mac Accessibility: required for remote pointer and shortcut control.
- Mac Location: optional, explicitly requested one-time coordinates rounded to a fixed 0.02-degree city-scale grid for local weather.
If you deny an optional permission, the corresponding feature remains unavailable; screen streaming does not require Quest microphone, Room Awareness, or Mac Location access.
What Beamdesk Does Not Do
- No Beamdesk account, profile, or cloud storage.
- No analytics, telemetry, crash-reporting, advertising, or tracking SDK.
- No Meta social-profile, friend, leaderboard, or in-app-purchase data.
- No sale or sharing of personal information for advertising.
Retention and Deletion
We operate no server that holds Beamdesk user data. Beamdesk removes evicted shelf previews and completed Quest relays, clears clipboard caches when components stop, and clears crash leftovers on the next launch. A received Mac file remains cached only while the pasteboard refers to it; it is removed after the pasteboard changes or the companion stops. To remove local Quest data immediately, uninstall Beamdesk. To remove local Mac data, quit and delete the companion, then remove ~/Library/Application Support/Beamdesk/ (including the approved Quest list and optional location fix), ~/Library/Caches/Beamdesk/Clipboard/, and any optional Beamdesk configuration under ~/.config/beamdesk/.
Children
Beamdesk is a productivity tool and is not directed to children. We do not knowingly collect personal information from children or anyone else.
Changes and Contact
If Beamdesk's data handling changes, this page and its effective date will be updated. Questions or concerns? Email martini-doubler7g@icloud.com.