Legal Documentation

Privacy Policy

Last Updated: August 5, 2026

1. Overview of Zero-Data Retention Architecture

Onscryn Inc. ("Onscryn", "we", "our", or "us") is fundamentally built upon a zero-trust, zero-endpoint-retention architectural model. When our users stream Windows desktop applications through their web browser tabs, all calculation and processing occurs inside ephemeral, temporary virtualized containers located within our secure cloud data centers. We do not inspect, cache, or store proprietary customer business files, CAD models, ERP records, or keystrokes beyond the immediate micro-second duration necessary to transmit visual hardware frame differential tiles to your authorized browser session.

2. Information We Collect

We collect only the minimum telemetry and identity data required to operate our service, maintain enterprise IT auditing logs, and prevent unauthorized network access:

  • Account Identity Data: Names, corporate business email addresses, company name, and Single Sign-On (OIDC/SAML) identifier tokens when an organization registers for our platform.
  • Security & Audit Telemetry: To assist your enterprise IT administrators with regulatory compliance (such as SOC2 or HIPAA), we register connection timestamps, IP originating addresses, bandwidth consumed, session duration, and termination statuses.
  • Billing & Subscription Records: Payment processing is handled via PCI-DSS compliant third-party payment processors. We do not store credit card numbers on our servers.

3. Ephemeral Container Scorch Protocol

When a streaming session concludes—either by explicit tab closure, manual disconnect, or reaching an administrative idle timer—our orchestrator initiates our "Scorch Protocol." The individual single-tenant container filesystem, RAM memory state, and temporary swap disks are cryptographically wiped and completely annihilated. Zero persistent user cache or enterprise application data persists after session termination.

4. International Data Transfers & GDPR Compliance

For customers operating within the European Economic Area (EEA), United Kingdom, or Switzerland, Onscryn guarantees compliance with GDPR requirements. We offer localized container execution pools inside EU data centers (such as Frankfurt, Germany) to guarantee strict regional data sovereignty and prevent trans-Atlantic enterprise data transit.

5. Contact Our Data Protection Officer

If you have specific legal inquiries regarding this Privacy Policy, our data processing addendums (DPAs), or wish to exercise statutory data access rights, please contact our Legal & Privacy team at privacy@onscryn.com.