Privacy Policy
Effective Date: August 20, 2026 • Last Updated: August 20, 2026 • App: CommandCenter (iOS) • Developer: Plenum (gr.plenum.commandcenter)
1 No Accounts, No Identity
CommandCenter has no user accounts. There is no email address, no name, no password, and no payment identity anywhere in the system. You never register, and there is nothing to sign in to.
Each device identifies itself with an Ed25519 keypair generated on the device itself and a random UUID. The private key is held in the device Keychain and never leaves the device. The server only ever sees the corresponding public key.
Because we hold no identity data, we cannot tell you who any given device belongs to, and neither can anyone who obtains a copy of the database.
2 What Is Stored On Our Servers
The backend is a Cloudflare Worker with a D1 database, currently served from an EU region. The following is stored there:
A. Device Record
The device name you choose, an optional nickname, the device model identifier, the iOS version, and the device role (commander or node).
B. Cryptographic & Routing Identifiers
The device’s Ed25519 public key, a random fleet identifier, and the Apple Push Notification token used to reach the device.
C. Telemetry
Battery level and charging state, Low Power Mode, thermal state, free and total storage, system output volume, uptime, and whether a lockdown is currently active.
D. Approximate Location — On Request Only
A latitude, longitude and timestamp are recorded only when a commander explicitly sends a “Locate” order, and only if you have granted location permission on the node device.
Location is not tracked continuously, and there is no location history — only the most recent fix is kept.
E. Command History & Receipts
Which order was sent, by which device, when it was sent, and the result text returned by the receiving device.
3 Commands That Move Your Content
Some orders carry your own content through the backend. We want to be direct about this rather than bury it.
⚠ Clipboard content can be stored in our database
Push Clipboard sends text from the commander to a node. Pull Clipboard returns the node’s clipboard text to the commander — and that text is stored in the receipt record in the database.
If your clipboard happens to contain a password, a message, or anything else sensitive at the moment a Pull Clipboard order runs, that content will be written to the receipt row. Consider this before using the clipboard commands.
Likewise, the text of Speak and Alert messages is stored as the command payload.
4 Screen Time & The Lockdown Feature
CommandCenter uses Apple’s Screen Time / Family Controls framework to shield apps on a node device when a lockdown is issued.
It does not read Screen Time usage data, app usage statistics, or browsing history. The framework is used in one direction only: to set and clear restrictions. No usage information is collected, transmitted or stored.
5 Local Network Traffic Never Reaches Us
When devices are on the same local network they communicate directly with each other using MultipeerConnectivity. That traffic is encrypted and never reaches our servers — there is no record of it in our database because it never passes through it.
6 Order Authenticity
Orders are signed on the sending device and verified on the receiving device using the Ed25519 keys described above. Our server relays orders but cannot forge one, because it never holds a private key.
7 Third Parties
There are no third-party analytics, no advertising, no tracking SDKs, and no data brokers in CommandCenter. Nothing is sold. Nothing is shared for marketing.
The only third parties involved in operating the service are:
- Cloudflare — hosting and the D1 database (currently an EU region).
- Apple — the Apple Push Notification service, used to deliver orders to devices.
8 Retention & Deletion
We would rather state the current behaviour plainly than promise a schedule we do not yet implement:
- Queued commands expire after 24 hours and stop being delivered.
- There is currently no automatic purge of historical command and receipt rows. They persist until the device is removed from the fleet, which deletes that device’s records.
- You can remove any device from the fleet at any time from the commander app.
- You can delete all local data by deleting the app from the device.
To request deletion of records held on our side, email support@plenum.gr. Include the fleet identifier or device name shown in the app so we can identify the rows to remove.
9 Intended Use
CommandCenter is built for managing your own devices — a household, or one person’s set of devices. It is not intended for monitoring other people, and using it that way is prohibited under our Terms of Service.
10 Contact
Questions about this policy, or about data held for your fleet:
Plenum Studio • CommandCenter
Email: support@plenum.gr
Website: https://plenum.gr
Jurisdiction: Athens, Greece (European Union)