Privacy notice
Effective 4 October 2026.
This covers illogical control, the hosted service at control.illogical.widgets.wtf, and this website. It's run by Jake Gaylor, an individual, who decides what's collected and why. Questions, requests and complaints: privacy@illogical.widgets.wtf.
The short version
- Control relays your terminals but can't read them. Every connection between your devices and your machines is end-to-end encrypted, including the ones control relays, so what your terminals, agents and editors show passes through it only in a form it can't read. That rests on trusting the web page control serves you and the account a machine joins, which you confirm with a fingerprint; what holds against control sets out the limits.
- It keeps what it needs to sign you in and to connect your devices to your machines, and nothing for advertising. There's no analytics or tracking on control or this site, and nothing is sold or shared for marketing.
- You can delete your account, and with it what control holds about you.
What control keeps
- Your account: a random id, the name you give it, and when it was made.
- How you sign in: with GitHub, your GitHub user id and username (not your email, and no GitHub token is kept after sign-in); with a passkey, its public key and a counter. Sign-in sessions are stored as hashes of their tokens and expire after 30 days.
- Your devices and machines: each one's public key and the name it was given, who approved it and when, and removals. For a machine, also the addresses it reports so your devices can reach it directly (for example its tailnet or local network address) and when it last connected. Recovery codes are stored only as public keys derived from them, never the codes.
- Teams: a team's name, its member list and roles (signed by its owners' devices), invites (stored as hashes) and requests to join.
- Notifications: if you turn on push notifications, your browser's push subscription. Your machines encrypt their notifications for your device themselves; control passes them to your browser's push service and sees only that one was sent and its size.
- Relay use: how many bytes it relayed for your account each day.
- Hosted sandboxes (offered by invitation during the beta): a record of each one you start, until it's deleted.
- Live updates from GitHub (if you use the GitHub App for pull request and issue blocks): control checks each webhook's signature and passes only which repository and item changed to your machines; it never stores the payload. It asks GitHub whether you may see a repository and remembers the answer for ten minutes.
IP addresses. Control uses the address you connect from to limit how often sign-ins and other requests can be tried. It holds these in memory only, not in its database. Its logs record events (a sign-in, a refused approval, an account deleted) with account and device ids, not what you did in your terminals.
Why
To provide the service you asked for: signing you in, approving devices, connecting them to your machines and relaying when they can't connect directly (under the GDPR, performing our contract with you). To keep it secure and working: rate limits, logs and backups (our legitimate interest in running a safe service).
Who else handles it
- Fly.io runs control and keeps its database and logs (in the United States). Hosted sandboxes run on Fly.io's Sprites.
- Cloudflare serves this website, answers DNS for control's domain, holds control's encrypted database backups (R2), and forwards email to the address above.
- GitHub, when you sign in with GitHub or use the GitHub App. Its own privacy statement applies to your GitHub account.
- Your browser's push service (Google, Apple or Mozilla, depending on the browser), if you turn on notifications.
Some of them are in the United States, so your information may be processed there.
How long
- Your account and what belongs to it: until you delete it.
- Sign-in sessions: 30 days at most. Codes for joining a machine: 15 minutes. Desktop app sign-in links: 10 minutes.
- Backups: overwritten as they age, kept for at most 30 days.
- Logs: kept by Fly.io for a short time under its own policy.
Deleting your account
Delete account on control's page removes what control holds that is only yours: your sign-ins, sessions, passkeys, devices and machines, push subscriptions, hosted sandboxes, usage counts, and teams you founded. If you belong to a team someone else founded, the team keeps listing your name until an owner removes it, and the public keys and device names your devices used to sign its member list are kept while that team exists, so its history can still be checked. Backups age out within 30 days. You can also ask by email.
Your rights
You can ask for a copy of what control holds about you, to have it corrected or deleted, or to stop a use you object to. Write to privacy@illogical.widgets.wtf; you'll get an answer within a month. If you're in the EU or UK, you can also complain to your data protection authority. California residents have the same rights under the CCPA; your information is not sold or shared for advertising.
This website
This site sets no cookies and runs no analytics. Cloudflare, which serves it, processes your IP address and request to deliver the page. Its fonts come from Google Fonts, so your browser fetches them from Google.
The software on your machines
illogical itself, on your computers, doesn't report anything to the operator. It talks to control only if you join a machine to it, and to other services only for features you use (for example GitHub for releases and pull requests, Tailscale, or code-server's download when you open an editor).
Children
Control isn't meant for anyone under 16.
Changes
If this notice changes, the new version is posted here with a new date, and changes that matter are announced on this site and in the release notes before they apply.