Privacy
Last updated 10 October 2026.
Gesturewin works without an account. An account only exists to keep your settings in step between your computers. This page lists everything the account server keeps.
Your account
- Your email address, and your name if you give one. There is no password: you sign in with a code we email you, or with Google.
- If you sign in with Google: your Google account's ID and email address. Nothing else from Google.
- Your sessions: when each one started and was last used, whether it is the app or this website, and the app's or browser's user agent. The session token itself is stored only as a keyed hash.
- The sign-in codes we email you, as keyed hashes. They stop working after 15 minutes, or once one is used.
Your settings
The gesture, button and device settings Gesturewin syncs, as one document, with the time it last changed.
What we don't do
No analytics, no tracking, no ads, no third-party scripts. The only cookie is the one that keeps you signed in on this site. Nothing is sold or shared for marketing.
Who else handles it
- Resend sends our emails, so it receives your address and the message.
- Cloudflare carries traffic between you and the server.
- Google, if you choose to sign in with Google.
Abuse protection and logs
To slow down code guessing and floods of email, the server counts recent attempts per IP address and per email address, in memory only, for 15 minutes. The server logs errors so they can be fixed; the logs hold no codes, tokens or settings.
Deleting it
Deleting your account removes everything above at once: the account, its sessions, its Google link and its settings. An account whose sign-in code is never used is deleted after 7 days. Expired sessions and codes are cleared out on their own. For anything else, write to hello@gesturewin.com.