FOR IT AND SECURITY:

WHAT LEAVES THE ENDPOINT

This page exists so you can decide without a sales call. It lists what the product sends, who receives it, what we keep, and what we do not have yet.

THE SHORT VERSION

> VDI Agent runs on the employee's host PC, outside the remote session. When the user asks a question, the window they selected is captured, read, and sent with their question to the AI model they chose. We pass it through; we do not keep it. Nothing is installed inside your VDI, and nothing is captured unless the user asks for it. It can also be run with no cloud at all.

WHAT LEAVES THE ENDPOINT

DATAWHENWHERE IT GOES
A screenshot of the window you chooseOnly when you press capture or send, never continuouslyOur backend, then the AI provider you picked
The text our OCR reads from that screenshotSame moment, in the same requestOur backend, then the AI provider you picked
Your question and the recent turns of that conversationWith each request you sendOur backend, then the AI provider you picked
Account id, licence key and a device identifierOn sign-in and with each requestOur backend only — never sent to an AI provider

WHAT DOES NOT HAPPEN

  • >Nothing is installed inside the VDI session. The app runs on the host PC and types into the session like a keyboard.
  • >No continuous screen recording, no background capture, no keylogging. A capture happens when the user asks for one.
  • >We do not store screenshots, OCR text, questions or answers on our servers. The request is forwarded to the provider and the answer streams back; none of it is written to our database or to our logs.
  • >The conversation is kept on the user's own PC (chat-state.json, text only — screenshots are not saved there) and can be deleted by deleting the file.
  • >Payment data never reaches us: card details go straight to Stripe.

WHO ELSE RECEIVES DATA

> The AI providers below receive screen content only for the request the user sent, and only the one they selected. The rest never see screen content at all.

PROVIDERPURPOSELOCATION
Anthropic (Claude)AI model, only if the user selects itUnited States
OpenAI (GPT, o3)AI model, only if the user selects itUnited States
Google (Gemini)AI model, only if the user selects itUnited States
DeepSeekAI model, only if the user selects itChina
VercelHosting for the website and the backendUnited States
SupabaseDatabase: accounts, plans, credit ledgerUnited States
StripePayments and invoicingUnited States / Ireland

CONTROLS THAT EXIST TODAY

Local-only mode

The app can run entirely on local providers — Ollama or the Claude Code, Codex and Gemini CLIs. In that mode no screen content leaves the machine at all, and no cloud account is needed.

One active device per account

A licence works on one machine at a time. Signing in elsewhere pushes the previous device out, so a shared or leaked account is visible immediately.

The user chooses the model

Each request names the provider. If DeepSeek or any other provider is unacceptable to you, the user simply does not select it — and on the Free and Pro plans the most expensive models are not reachable at all.

Account-level revocation

Deleting the account stops access immediately, on every device, including any sub-accounts under it.

WHAT WE DO NOT HAVE YET

> You will find this out in the first questionnaire anyway, so here it is first. These are on the roadmap for the Team and Enterprise plans, not available today.

  • >No admin console: you cannot yet see or manage your employees' accounts from one place.
  • >No audit log you can export.
  • >No SSO / SAML. Sign-in with a Microsoft work account is built but not yet enabled.
  • >No automatic redaction of personal data before a screenshot is sent.
  • >No EU-only data residency: our hosting and the AI providers are outside the EU today.
  • >No way for IT to centrally block the cloud providers from the application itself.

ON EMPLOYEES INSTALLING THIS ON THEIR OWN

> We would rather you knew. A tool that reads a work screen and sends it to an AI provider belongs in your approved list or nowhere: if it is used quietly, your organisation is the one carrying the data-protection risk, without knowing it. That is why this page exists instead of a page about bypassing restrictions. If you want it blocked, block vdiagent-backend.vercel.app — the app reaches the AI providers only through it, so without that host the cloud side is dead on your network. If you want it approved, write to us and we will answer a questionnaire, sign a data processing agreement, and tell you what we cannot do yet.

TALK TO US:

Security questionnaires, data processing agreements, pilots.

enterprise@vdiagent.ai →

See also privacy policy and terms of service.