Privacy

Light Remote processes account credentials only during authorization and does not return passwords or access tokens through MCP tools. Remote commands, file paths, file content, process output, and device metadata are processed only to fulfill the user-requested remote operation. Tool responses omit cryptographic keys, auth secrets, transport telemetry, and unnecessary internal identifiers.

Device-local policy remains the final authorization boundary.