# DSH Remote Privacy Policy / 隐私政策 [English](#english) · [简体中文](#简体中文) Last updated / 最后更新:August 23, 2026 / 2026 年 8 月 23 日 ## English DSH Remote is an independent open-source companion for controlling a Harness instance running on a computer you own or manage. The project maintainer does not operate its own relay, analytics, advertising, account, push, or model gateway service for the iOS or Android app. The Android app includes Google ML Kit for on-device QR scanning; its separate metrics behavior is disclosed below. ### Data handled by the app The app stores the display name and network address of computers you add in local device preferences. For a same-Wi-Fi pairing, it also stores the random access credential generated by Desktop. Android encrypts the complete saved-computer record with an Android Keystore AES-256-GCM key. The app reads project and task titles, conversation and subagent messages, tool summaries, task status, file and session reference candidates, approval requests, and questions directly from your computer. It sends prompts, explicitly selected or pasted images, subagent follow-ups, stop requests, approval decisions, and question answers directly to that computer. DSH Remote does not send this Harness content to the project maintainer or to Google ML Kit. Harness on your computer may send prompts and related context to the model provider configured there. That transfer is governed by your provider configuration and the provider's privacy terms, not by a DSH Remote service. ### Android QR scanner and Google ML Kit Camera access starts only after you choose to scan a Desktop pairing QR code. The Android scanner uses the bundled `com.google.mlkit:barcode-scanning` library. QR camera images and decoded QR contents are processed on-device; they are not sent to Google servers by ML Kit and are not saved or uploaded by DSH Remote. Google's ML Kit documentation states that the Android SDK separately collects the following data for diagnostics and usage analytics: - device information, including manufacturer, model, OS version/build, and available ML hardware accelerators; - application package name and version; - a per-installation identifier that is not intended to uniquely identify a user or physical device; - performance metrics such as latency; - API configuration such as image format and resolution, input/output size, feature version, event type, and error codes. Google states that these metrics are encrypted in transit with HTTPS and are not transferred to third parties. DSH Remote does not receive them. The current scanner does not enable ML Kit's barcode auto-zoom feature. See Google's [ML Kit terms and privacy explanation](https://developers.google.com/ml-kit/terms) and [Android data-disclosure guide](https://developers.google.com/ml-kit/android-data-disclosure). ### Photos, notifications, and local network When you explicitly use the system photo picker or paste an image, the app processes that image to remove metadata and fit the limits reported by your computer, then sends it directly to that computer as part of your prompt. The mobile apps do not keep a separate photo library or upload service. Local-network access is used to reach a Harness computer on your network. Notifications are generated on the device when a connected task completes or needs attention. Android notifications are best effort while the app process is alive; the project does not operate a background push service. ### Optional network services You may use Tailscale or another HTTPS setup you control to make your computer reachable. On trusted private Wi-Fi, you may instead enable Desktop's authenticated LAN endpoint. That LAN endpoint is not encrypted and must not be used on untrusted or shared networks. DSH Remote does not receive Tailscale credentials. Tailscale, Google ML Kit, and any model provider are separate services with their own terms and privacy policies. ### Retention and deletion Task history remains on your computer. Saved computer names, addresses, and any LAN access credentials remain on the iPhone or Android device until you remove them. You can delete individual computers from the main list or delete all saved computers from **About and privacy**. Removing mobile pairing data does not delete Desktop projects, sessions, model credentials, or repositories. ### Tracking and advertising DSH Remote contains no advertising SDK and does not track users across apps or websites. The project maintainer does not receive the ML Kit diagnostic and usage metrics described above. ### Contact For privacy questions or support, open a [GitHub issue](https://github.com/chokwinlee/deepseek-harness-desktop/issues). Never include a QR code, pairing credential, API key, private prompt, source code, private IP address, or Tailnet name. ## 简体中文 DSH Remote 是独立开源配套 App,用于控制用户自己拥有或管理的电脑上运行的 Harness。项目维护者不为 iOS 或 Android App 运营自己的 relay、分析、广告、账号、推送或模型网关服务。Android App 使用 Google ML Kit 在设备端扫描二维码,其独立的指标传输行为在下文说明。 ### App 处理的数据 App 会在设备本地保存用户添加的电脑名称和网络地址。同一 Wi-Fi 配对还会保存 Desktop 生成的随机访问凭据。Android 使用 Android Keystore AES-256-GCM 密钥加密整份已保存电脑记录。 App 直接从用户电脑读取项目与任务标题、会话与子代理消息、工具摘要、任务状态、文件和会话引用候选项、审批请求与问题;并把提示词、用户明确选择或粘贴的图片、子代理后续指令、停止请求、审批决定与问题答案直接发送到该电脑。 DSH Remote 不会把这些 Harness 内容发送给项目维护者或 Google ML Kit。电脑上的 Harness 可能把提示词和相关上下文发送给用户配置的模型服务商,该传输由用户的服务商配置与服务商隐私条款约束,不经过 DSH Remote 服务。 ### Android 二维码扫描与 Google ML Kit 只有用户选择扫描 Desktop 配对二维码后,App 才会启用相机。Android 扫描器使用内置的 `com.google.mlkit:barcode-scanning`。二维码相机图像和解码内容都在设备端处理;ML Kit 不会把这些输入发送到 Google 服务器,DSH Remote 也不会保存或上传它们。 Google 的 ML Kit 文档说明,Android SDK 会另外收集以下数据,用于诊断与使用情况分析: - 设备信息,包括厂商、型号、操作系统版本与 build,以及可用的机器学习硬件加速器; - 应用包名和版本; - 不用于唯一识别用户或实体设备的每次安装标识符; - 延迟等性能指标; - API 配置,例如图像格式与分辨率,以及输入输出大小、功能版本、事件类型和错误代码。 Google 说明这些指标通过 HTTPS 加密传输,不会转移给第三方。DSH Remote 不会收到这些指标。当前扫描器没有启用 ML Kit 条码自动缩放功能。详见 Google 的 [ML Kit 条款与隐私说明](https://developers.google.com/ml-kit/terms?hl=zh-CN)和 [Android 数据披露指南](https://developers.google.com/ml-kit/android-data-disclosure?hl=zh-CN)。 ### 照片、通知与本地网络 用户明确使用系统照片选择器或粘贴图片时,App 会处理图片、移除元数据并适配电脑返回的限制,然后作为提示词的一部分直接发送到该电脑。手机 App 不运营独立照片库或上传服务。 本地网络权限用于连接同一网络中的 Harness 电脑。连接任务完成或需要用户处理时,App 会在设备本地生成通知。Android 通知只在 App 进程仍观察任务时尽力提醒,项目不运营后台推送服务。 ### 可选网络服务 用户可以使用自己控制的 Tailscale 或其他 HTTPS 方案让电脑可连接。在受信任的私有 Wi-Fi 中,也可以开启 Desktop 带认证的局域网入口。该局域网入口没有加密,绝对不能用于不受信任或共享网络。DSH Remote 不会获得 Tailscale 凭据。Tailscale、Google ML Kit 和模型服务商都是独立服务,分别受各自条款与隐私政策约束。 ### 保留与删除 任务历史留在用户电脑。已保存的电脑名称、地址和局域网访问凭据会留在 iPhone 或 Android 设备,直到用户删除。用户可以在主列表删除单台电脑,也可以在“关于与隐私”中删除全部已保存电脑。删除手机配对数据不会删除 Desktop 项目、会话、模型凭据或仓库。 ### 跟踪与广告 DSH Remote 不含广告 SDK,也不会跨 App 或网站跟踪用户。项目维护者不会收到上文所述的 ML Kit 诊断与使用指标。 ### 联系方式 隐私或支持问题请创建 [GitHub Issue](https://github.com/chokwinlee/deepseek-harness-desktop/issues)。不要附带二维码、配对凭据、API Key、机密提示词、源码、私有 IP 或 Tailnet 名称。