Privacy Policy & Zero-Trust Mandate
How ITsf Assistant (assistant.itsf.gr) secures, processes, and respects user data under air-gapped environments
LAST UPDATED: 02/08/2026Scope of this Policy
This Privacy Policy explains how Assistant ITsf.gr (the "App," "Service," or "we") collects, uses, stores, and protects user data and information collected through our mobile application (the "Client App"), desktop executables, and associated services (the "Backend Server"). To guarantee absolute compliance with the zero-trust paradigm, our storage architecture operates under a Zero-Knowledge mandate—meaning we design systems so that even our administrators cannot read your private communications.
1. Information We Collect
A. Personal Data (Provided by You)
| Data Type | Purpose | Retention Period |
|---|---|---|
| Account Details Username, Email, Passwords |
Account provision, login authentication, and secure workspace access. | Active Membership + 7-day deletion grace |
| Session Security & Protection Session Tokens, Tab Expiry State |
Auto-halting background requests on 401/403 session end to protect client IPs from false Fail2Ban bans; 2-minute login page inactivity redirect. | Transient Browser Session Instant redirect to /login |
| User-Generated Content & AssistantBER Transfers Files, documents, & AssistantBER media stream downloads |
Encrypted storage and secure file routing in personal My Files storage. Legal Disclaimer: End-users assume 100% sole legal responsibility and copyright compliance for all streams and files processed via AssistantBER or saved to My Files. |
Active Membership Deleted immediately on user request |
| Wiki Knowledge Base & Confluence Imports Documentation pages, spaces, & Markdown content |
Application-layer zero-trust encryption (EncryptedText) with space-level RBAC clearance isolation (Resistance, Logismos, General). |
Encrypted RDBMS Zero-trust access controlled |
| Real-Time Socket & Notification Security WebSocket events, Targeted Rooms, Adaptive Ping |
Strict server-side room targeting (user_<id>) ensures channel data is never broadcast globally to unauthorized sockets. 25-second ping interval reduces client CPU and battery consumption. |
Zero-Trust Targeted Low-Battery Adaptive Ping |
| Dynamic DNS (DDNS) Subdomains Custom subdomains, external IP updates, secret tokens |
Updates DNS A-records for user-registered subdomains (<subdomain>.itsf.gr) via secret update tokens. Logs caller external IP addresses strictly for dynamic A-record mapping and sub-millisecond Redis DNS routing. |
Dynamic A-Record Redis & Oracle DB synced |
| Zero-Trust ASS3 Sovereign Vault & Weekly Key Rotation Physical Server Credentials (.env) |
Physical .env bootstrap credentials are encrypted on disk with ASS3: hardware-bound ciphers tied to /etc/machine-id. Decrypted strictly in RAM with automated 7-day background key rotation (APScheduler) and admin trigger (POST /api/admin/vault/rotate_keys). |
ASS3 Sovereign Vault Weekly Key Rotation |
| RustDesk Remote Support & Fleet Focus Machine ID, Alias, Peer Status, Audit Logs |
Self-hosted remote desktop coordination on assist.itsf.gr. Connects workstations via end-to-end encrypted tunnels. Audit logs are preserved locally for compliance with access restricted to Right 114 administrators. |
Self-Hosted Relay assist.itsf.gr / Right 114 |
| Native Machine-Code Binaries & Source Obfuscation Cython & GCC ELF .so Binaries, Build Seal |
100% of Python backend modules are compiled to native Linux ELF .so shared objects with 0 plaintext .py source files in production. Prevents reverse-engineering, tampering, and source inspection while delivering maximum C-level execution speeds. |
100% Native ELF .so HMAC-SHA256 Build Sealed |
| LG webOS Smart TV Studio & Remote Control Luna Service Bus, Wake-on-LAN, VNC Bridge |
Local network orchestration of rooted LG webOS Smart TVs with Right 188 authorization. All command executions, toast dispatches, and Wake-on-LAN packets are restricted to authenticated operators. | Right 188 (lgtv) Local Air-Gapped SSH & VNC |
| Dev-Only Git & Tools Isolation (Air-Gapped Clean State) Local Git Inspector & Dev Tools Hub |
The Git Inspector (/dev/git) and Dev Tools Suite (/dev/tools) modules are exclusively operational in the local development environment. Production builds strictly exclude all .git repository directories, dev tools endpoints, and commit histories, maintaining 100% air-gapped isolation. |
Dev Only (Air-Gapped) Excluded from Production |
| Channel IP Cameras, CCTV Feeds & Meeting Recordings RTSP/HTTP Streams, Tile & Full Meeting Compositor, 5-Min MP4 Recordings |
Camera access credentials and stream URLs are encrypted at rest using application-layer Fernet cryptography (EncryptedString / EncryptedText). Live streams are proxied through zero-trust authenticated backend endpoints without exposing raw credentials to client browsers. Real-time camera controls and Full Meeting studio recordings are strictly restricted to Channel Managers, Channel Admins, and Right 114 administrators. Meeting recordings are segmented into 5-minute seekable MP4 clips and stored directly into the Channel's folder (chat_files/channels/<id>/Recordings), accessible exclusively by channel managers. Individual tile recordings are saved into the user's personal My Files/Recordings directory. |
Encrypted Credentials Managers Only Channel Folder |
B. Sensitive Device Permissions
| Permission | Purpose | Data Transfer & Storage Status |
|---|---|---|
| Camera | QR-code login provision & real-time WebRTC video calls. | No Data Transmitted Processed transiently in-memory |
| Microphone | Real-time voice chats, LiveKit calls, and VoIP. | No Data Transmitted No recording is ever saved |
| Telephony / Call State | Monitors active cellular calls to auto-disconnect VoIP sessions. | Local Processing Only Managed entirely on-device |
| Biometric Scan | Local application unlock & secure token storage. | 100% Local (OS Chip) Zero access by the server |
| Dual-Layer Hardware & App Fingerprint X-Hardware-Fingerprint, X-Device-Fingerprint |
Cryptographic SHA-256 HMAC binding (CPU, RAM, GPU, Screen) to enforce per-user concurrent device limits (default: 2 physical devices, 2 apps/device) and prevent session hijacking. | HMAC Signed Hash Only No raw PII hardware specs stored |
| File Picker & Vaults | Enables manual file uploads inside secure vaults. | Encrypted Transfer Transmitted over TLS to vault |
| Meeting Recordings & Invitator Isolation | Meeting recordings (spotlight hero layout with participant filmstrip) are uploaded directly to the Channel repository (chat_files/channels/<id>/Recordings) and strictly restricted to authenticated Channel Managers. Right 180 (Invitator) is strictly bounded to new member invitations with zero access to meeting clips, audits, or administrative telemetry. |
Managers Only Right 180 strictly isolated |
2. Cryptographic Zero-Trust Controls
Identity Key Generation
Private Identity Keys are negotiated locally on client devices using the X25519 Elliptic Curve. These keys are never transmitted to our servers and reside in Secure Enclave hardware, preventing man-in-the-middle decryption.
Encrypted Blob Storage
Symmetric chat room keys are encrypted locally under target participant public keys prior to cloud upload. Message payloads, files, and location data are stored on databases strictly as encrypted JSON blobs.
3. Account Deletion & Grace Period
You retain the right to delete your profile, credentials, and data logs at any moment. Requests can be triggered via the Mobile App Settings or the web route /delete-account.
For cryptographic audits or privacy queries, contact our Security Response Team: