// legal

Privacy Policy

Effective July 24, 2026 · v1.0

This Privacy Policy explains how Foto Master Ltd (“ScreenSteer”, “we”, “us”) handles personal data across our website, the agent console, our developer SDKs, and the live remote-support sessions the service enables. We designed ScreenSteer to be consent-first and data-minimal, and this policy reflects that.

1. Who we are

ScreenSteer is a product of Foto Master Ltd, registered at Ilan Ramon 5, Ness Ziona, Israel. For any privacy question, or to exercise your rights, contact us at billing@screensteer.com.

2. Our two roles: controller and processor

ScreenSteer is sold to businesses that embed it in their own applications to offer remote support to their users. That means we act in two distinct capacities:

  • As a controller for the data we decide the purposes of: agent and account data, billing records, website analytics, and support correspondence with our customers.
  • As a processor for the end-user and session data that flows through a support session. Here our business customer is the controller; they decide why a session happens and are responsible for giving notice to, and obtaining consent from, their own end users. We process that data only to provide the service and per our customer's instructions.

If you are the end user of an app that uses ScreenSteer and have questions about a session, please contact the business whose app you were using; they are the controller. A Data Processing Addendum (DPA) is available to customers on request at billing@screensteer.com.

3. Information we collect

Account & agent data. When an agent creates or signs in to the console (by email/password or “Sign in with Google”), we collect their name, email address, organization membership and role, and authentication metadata. We never receive your Google password.

Live session data (as processor). During a support session we relay, in real time, the screen frames a user has chosen to share, pointer and interaction events, and the registered actions an agent invokes. Regions your app marks as sensitive are masked before the frame leaves the device (pre-publication redaction), and control is only ever exercised after the user grants consent. By default we do not create or store recordings of sessions; live media is relayed, not persisted.

Device & technical data. Device model, operating system, app name and version, session identifiers, consent and audit events, coarse network quality metrics, IP address, and standard server logs.

Billing data. Purchases are handled by our Merchant of Record, Paddle (see section 6). We receive limited billing metadata such as plan, subscription status, billing country, and the last four digits/brand of a card. We do not receive or store full payment card numbers.

Cookies. A small number of strictly necessary cookies, described in section 11.

4. How we use information

  • To provide, operate, secure, and support the console, SDKs, and live sessions.
  • To authenticate agents and enforce organization-scoped access.
  • To maintain the consent and audit trail that every session produces.
  • To process subscriptions and prevent fraud and abuse (with Paddle).
  • To diagnose problems, monitor reliability, and improve performance.
  • To communicate service, security, and billing notices.
  • To comply with legal obligations and enforce our Terms.

We do not sell personal data, and we do not use the contents of support sessions for advertising or to train machine-learning models.

5. How we share information

We share data only with the sub-processors that run the service, and only as needed to deliver it. Our current sub-processors are:

ProviderPurposeLocation
SupabaseDatabase, authentication, and storage for account and session recordsUnited States (AWS us-east-1)
LiveKit CloudReal-time relay of audio, video, and data channels during live support sessionsUnited States / global edge
VercelApplication hosting and content deliveryUnited States / global edge
GoogleOptional 'Sign in with Google' authentication for agentsUnited States
PaddlePayment processing and Merchant of Record for all purchasesUnited Kingdom / European Union

We may also disclose data to comply with the law, to enforce our agreements, or in connection with a merger, acquisition, or asset sale (with continued protection of your data). We maintain a current sub-processor list and will update this section before adding a new one.

6. Payments and Merchant of Record

All purchases are sold and processed by Paddle.com Market Limited and its affiliates, our Merchant of Record, not by Foto Master Ltd directly. Paddle handles the transaction, invoicing, and applicable sales tax/VAT, and its own terms and privacy policy govern your payment. See Paddle's Buyer Terms and Privacy Policy. For billing questions you can also reach us at billing@screensteer.com.

7. International transfers

ScreenSteer operates globally and several of our sub-processors are located in the United States. Where personal data is transferred out of the EEA, the United Kingdom, or Israel, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or transfers to jurisdictions recognized as providing adequate protection.

8. Data retention

We keep account data for as long as an organization's account is active, and session audit records for the period our customer requires to operate their support program and to meet legal obligations, after which they are deleted or anonymized. Because sessions are not recorded by default, there is no session video to retain. Customers may request deletion of their organization's data as described in their agreement with us.

9. Security

Security is built into the product, not bolted on. Media and data channels are encrypted in transit; sensitive regions are masked before they ever leave the device; an agent can view or control only after explicit, separate user consent; there is exactly one controller at a time; and every command is validated on the device against session, expiry, sequence, controller, and layout checks, so raw input injection does not exist. We restrict internal access on a need-to-know basis. No system is perfectly secure; to report a vulnerability, email billing@screensteer.com.

10. Your rights and choices

Depending on where you live (for example under the EU/UK GDPR, the California CCPA/CPRA, or the Israeli Privacy Protection Law), you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. To exercise these rights over data we control, contact billing@screensteer.com. Where ScreenSteer acts as a processor, please direct your request to the business whose app you used, and we will assist them as their processor. You also have the right to lodge a complaint with your local supervisory authority.

11. Cookies

We use only strictly necessary cookies: a session cookie to keep signed-in agents authenticated, and, while the site is in limited release, a gate cookie that remembers early-access authorization. We do not use advertising or cross-site tracking cookies.

12. Children

ScreenSteer is a business tool and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact billing@screensteer.com and we will delete it.

13. Changes to this policy

We may update this policy as the product and our legal obligations evolve. Material changes will be reflected by a new effective date at the top of this page and, where appropriate, a notice in the console.

14. Contact us

Foto Master Ltd
Ilan Ramon 5, Ness Ziona, Israel
Contact: billing@screensteer.com