What the app stores, and where

All of it is on the device, in the app's own local settings storage (iOS UserDefaults).

WhatWhyWhere in the code
Saved servers: a name, host address, port, surface name, grid size, artwork size, text size, layout options, favourite flag, last-used time So you can reconnect in one tap CompanionMobile/Models.swift
The current connection and surface settings, auto-reconnect and auto-connect choices, and which saved server was used last So the app opens the way you left it CompanionMobile/Models.swift, CompanionMobile/SatelliteClient.swift
Dashboard key picks, Operator roles you shared or joined (name, keys, a random token), and the theme and keep-awake choices So the Dashboard and roles are there next time CompanionMobile/SatelliteClient.swift, CompanionMobile/InstanceLibrary.swift, CompanionMobile/SurfaceGridView.swift
A random surface serial made by the app on first launch (companion-mobile: plus a random UUID) So Companion recognises this device as the same surface each time CompanionMobile/SatelliteClient.swift

The serial is random. It is not your Apple device identifier, advertising identifier, or anything tied to you.

What goes over the network

  • The app opens one WebSocket connection to the host and port you enter — your own Bitfocus Companion server, normally on your local network.
  • It sends Companion Satellite API messages: the surface registration (surface name, random serial, grid size), button presses and releases, page changes, encoder turns, and keep-alive pings.
  • It receives button text, colours and pictures, page numbers, and variables from Companion, and shows them on screen. Nothing received is kept after the app closes.
  • For Operator mode it also reads one Companion custom variable (surfaceremote_roles) from the same Companion server's HTTP API, to check a shared role has not been revoked.
  • The app sends nothing to the developer or to any other party.

Local Network permission

iOS asks once whether the app may use your local network. It needs this to reach your Companion server. Change it any time in iOS Settings › Privacy & Security › Local Network; with it off the app cannot connect.

Camera permission (Operator mode)

The camera is used only when you tap Connect › Operator, to scan an Operator QR code shown on another phone. The scan runs on the device with Apple's scanner. No picture is saved or sent anywhere. Change it any time in iOS Settings › Privacy & Security › Camera.

What the app does NOT do

  • No developer server. No cloud, no sync, no backup by the app itself. (Your own iCloud device backup may include the app's local settings, under Apple's terms, like any other app.)
  • No third-party code. No advertising, analytics, crash-reporting or social SDKs.
  • No other permissions. No microphone, photos, location, contacts or notifications.
  • No accounts, no web views. The one in-app purchase (Multi-Instance) goes through Apple; the developer receives no personal data from it.

Your Companion server

Your Companion server is run by you, not by the developer. What Companion does with the messages it receives is governed by Companion and whoever runs it. Satellite Surface Remote is not affiliated with, endorsed by, or sponsored by Bitfocus.

Children

The app is a production tool and is not directed at children. It collects no personal information from anyone.

Your choices

  • Forget a server: delete it from the Servers list.
  • Forget everything: delete the app. There is no server-side copy to ask us to delete, because there is none.
  • Local Network: iOS Settings › Privacy & Security › Local Network.

Changes

If a future version ever sends data anywhere other than your own Companion server, this policy will change first and the change will be described in the app's release notes.

Contact

Tom Brown
Support: appstoresupportwithasmile@icloud.com (the same address as the App Store support contact).