Privacy policy
What FreeKiosk Cloud stores, why, and for how long.
Last updated: 2026-09-03
This policy covers FreeKiosk Cloud, the service running at cloud.freekiosk.app. It does not cover the FreeKiosk Android app used on its own, which sends nothing anywhere, nor the freekiosk.app website, which sets no cookie and loads no analytics. Those are described in the policy published on freekiosk.app.
1. Who is responsible for what
There are two different roles here, and the distinction decides who you ask for what.
- Your account and your organisation: we are the controller. We decide to hold an email address so you can sign in and so we can reach you about the service.
- Your fleet data: you are the controller, we are your processor. You decide to deploy the tablets, what they display, whether they report a location and whether screenshots are taken. We process that on your instruction and for no purpose of our own.
The company behind both is RUSHB, 2 Place du General de Gaulle, 06800 Cagnes-sur-Mer, France. Full identification is in the legal notice. For anything about data, write to support@freekiosk.app.
2. What we store
Your account
- Email address, and first and last name if you fill them in
- A password, stored only as a salted hash, never in clear text
- Whether your email has been verified
- Your organisation's name, its plan, and your role in it
- A time-based one-time-password secret, if you enable two-factor authentication
- Whether you have completed or dismissed the guided tour
Billing is not in service. The database has columns for a payment provider's customer and subscription identifiers, and nothing writes to them yet. When billing starts, this page will say so before it does.
Each enrolled device, refreshed at every heartbeat (about every 30 seconds)
- Name you gave it, model, manufacturer, Android version, app version, serial number
- Battery level, charging state and temperature
- Wi-Fi network name and signal strength, and the device's IP address
- The URL currently displayed and the app in the foreground
- Screen on or off, brightness, free storage, free memory, uptime
- Whether kiosk mode and Device Owner mode are active, and which features the device supports
- Location: latitude, longitude and accuracy, only when the device reports them. This is a device setting: a device that does not send a location has none stored.
Only the latest state is kept. Each heartbeat overwrites the previous one, so there is no history of where a device was or what it displayed over time.
Screenshots
Taken when someone in your organisation asks for one, or when a scheduled task you created asks for one. They are images of whatever the tablet was displaying, so treat them as seriously as the screen itself. They are served only to signed-in members of the organisation that owns the device: there is no public link to a screenshot.
They are deleted automatically after 90 days, and the file goes with the record rather than lingering on disk. You can delete one earlier from the dashboard, and removing a device removes its screenshots.
Reports you send us
When you use the feedback button to report a bug or ask for a feature, we store what you wrote, your email address, your organisation's name, the page you were on, and your browser's user-agent string. The email and organisation name are kept as plain text alongside the report, so it survives you closing your account: this is our support record, not your fleet data.
Any screenshots you attach are images of your own systems, so we treat them like device screenshots: no public link, and only our staff can open them. Not even you can retrieve them afterwards through the dashboard, and they are never attached to the notification email we send ourselves.
Reports and their attachments are deleted automatically after 365 days, files included. Ask us and we will delete one sooner.
Commands, alerts and activity
- Every command sent: type, parameters, status, result or error, and who sent it
- Alerts raised: type, severity, message, the device concerned, who acknowledged it and when
- Deliveries of the notifications you configured: the channel used (email, webhook, ntfy), whether it succeeded, and the response code if it failed. The destinations themselves, including a webhook URL and its secret, are settings you enter.
- Enrolment tokens: the token, who created it, when it expires and whether it was used
Technical log of the device API
Every call the devices make to /api/v1/ is recorded: method, path, HTTP
status, response time, IP address, and which organisation and device it belonged to.
This exists so that abuse can be seen after the fact, credential stuffing or one address
enrolling many organisations for example. Request and response bodies are never
recorded, precisely because they can carry an API key.
Platform counters
Once a night we store aggregate counts for the whole platform: how many organisations, devices, heartbeats, commands and alerts. These are numbers only. They contain nothing about any individual person, device or organisation.
3. Cookies
Two, both strictly necessary, both exempt from consent under the CNIL guidelines. There is no analytics cookie, no advertising cookie and no third-party cookie.
sessionid: keeps you signed in. Lasts for the session.csrftoken: protects forms against cross-site request forgery.
4. Why, on what basis, and for how long
| Purpose | Legal basis | Kept for |
|---|---|---|
| Running the service: showing device status, sending commands, raising alerts | Performance of the contract | As long as the account exists |
| Signing in and securing the account | Performance of the contract | As long as the account exists |
| Device state, including location when reported | Your instruction as controller | Overwritten at every heartbeat; removed with the device |
| Screenshots | Your instruction as controller | 90 days, then deleted automatically. Sooner if you delete them or remove the device. |
| Bug reports and feature requests you send us, with any images attached | Legitimate interest in supporting and improving the service | 365 days, then deleted automatically, files included. Sooner on request. |
| Technical log of the device API, for abuse and forensics | Legitimate interest in keeping the service secure | 30 days, then deleted by a scheduled job |
| Command and alert history | Performance of the contract | As long as the account exists |
| Aggregate platform counters | Legitimate interest in operating the platform | Indefinitely, no personal data involved |
| Answering your emails to support | Legitimate interest | 3 years after the last exchange |
5. Who else sees it
Nothing is sold, rented or shared for advertising, ever. Access is limited to the people at RUSHB who need it to run and support the service.
Each organisation is isolated: every query in the dashboard is scoped to the organisation of the person making it, so one customer cannot see another's devices, screenshots or commands. Staff accounts get a platform-wide metrics page, which shows counts and organisation names, not the contents of anyone's fleet.
We use one technical subprocessor: OVH SAS, Roubaix, France, for both hosting and email.
6. Where it is stored
On servers located in France, at OVH. No data is transferred outside the European Union, and nothing is processed by a provider subject to a non-EU jurisdiction.
7. How it is protected
- HTTPS everywhere, with certificates renewed automatically
- Passwords stored as salted hashes; optional two-factor authentication by TOTP
- Each device authenticates with its own API key, stored as a SHA-256 hash. Only a short prefix is kept in readable form, so the database cannot give a key back even to us.
- Sensitive configuration values are stored encrypted
- Screenshots are served only through an authenticated, organisation-scoped route
- Rate limits on the device endpoints, to blunt enumeration and abuse
- Nightly database backups, kept 30 days
- Strict organisation scoping on every database query behind the dashboard
8. Your rights
Under the GDPR you can ask for access to your data, correction, erasure, portability, restriction of processing, and you can object to processing. Write to support@freekiosk.app; we answer within 30 days.
Most of these you can exercise yourself: your account details are editable in settings, the activity log exports to CSV, and Settings has a Delete account page that erases your account and your organisation immediately, with no grace period. It refuses while devices are still enrolled or another member belongs to the organisation, so that one click cannot take a colleague's fleet with it; clear those first, or write to support and we will do it with you.
If the data concerns a fleet belonging to a company you work for, that company is the controller: ask them first. They may ask us, as their processor, to act.
If you think we have handled your data wrongly you can complain to the CNIL, the French supervisory authority, at www.cnil.fr.
9. Changes
The date at the top of this page says when it last changed. If we start handling something we did not handle before, this page will say what and why. It is meant to describe the service as it actually is, not as we would like it to sound.