Privacy & Security Policy
100% Local. Zero Cloud. Zero Telemetry.

Last Updated: September 2026 • Publisher: TKR Desk • Microsoft Store Certified Standards (Policy 10.5 & 10.2)

🛡️ 1. Ecosystem Executive Privacy Guarantee

The TKR Desk Ecosystem encompasses the unified TKR Desk Master Suite and its 6 focused standalone portable utilities (TKR-Drop, TKR-Remote, TKR-Kvm, TKR-Cast, TKR-Seat, and TKR-Print). All software built under this ecosystem is strictly engineered on a local-first, peer-to-peer (P2P) architectural paradigm.

Direct Guarantee: Because no user data or hardware traffic leaves your private physical network, your personal documents, screen sessions, keystrokes, and print jobs cannot be monitored, collected, or accessed by us or any third parties.

2. Per-App Hardware Permissions & Data Boundary Matrix

In accordance with Microsoft Store Certification Policy Section 10.5, every standalone application requests only the minimal local Windows capabilities necessary for its specific utility:

⚡

TKR-Drop — Local File Transfer Utility

Binary: TKRDesk-Drop.exe • Standalone 02
File Transfer Engine

Purpose: High-speed direct file, folder, and archive transfer between Windows workstations across local Wi-Fi / LAN.

Port & Capability Type Exact Purpose
TCP 5727 Inbound & Outbound Receives and sends high-throughput file data streams directly between LAN endpoints.
UDP 5721 Local Broadcast Beacon Announces local PC station name and IP to nearby workstations for one-click pairing.
File System Storage Local User Profile Reads only files selected by user for transfer. Writes received files to %USERPROFILE%\Downloads\TKRDesk-Drop.
Data Integrity Assurance: Every file transfer is validated end-to-end with an automated SHA-256 cryptographic checksum. Incoming streams are isolated in temporary atomic .part buffers and verified before landing. Directory traversal sequences (such as ../) are strictly sanitized.
Strict Negative Disclosure: TKR-Drop does NOT access your webcam, does NOT access your microphone, does NOT capture your display screen, does NOT record keystrokes, does NOT scan unselected directories, and transmits NO metadata outside your local network.
🖥️

TKR-Remote — Remote Desktop & WOL

Binary: TKRDesk-Remote.exe • Standalone 01
Remote Control

Purpose: Low-latency 60 FPS remote desktop viewing, mouse and keyboard control, and Wake-on-LAN power management across LAN.

Port & Capability Type Exact Purpose
TCP 5720 TLS 1.3 Encrypted Socket Transmits compressed desktop video frames and returns user mouse/keyboard input events.
UDP 7 / 9 Broadcast Magic Packet Wake-on-LAN magic packet transmission to power on sleeping workstations on LAN.
DXGI Desktop Duplication RAM Video Pipeline Captures display frames directly from GPU framebuffer solely during active, attended sessions.
Attended Security Architecture: Remote sessions require explicit pairing authentication via dynamic rotating connection PINs or user acceptance. When an active session is in progress, an unmistakable visual overlay badge is displayed on the host screen.
Strict Negative Disclosure: Desktop video is processed strictly frame-by-frame in volatile RAM and is NEVER recorded, saved to disk, or sent to external relays. Zero cloud session recordings exist.
🖱️

TKR-Kvm — Virtual KVM Switch & Audio Bridge

Binary: TKRDesk-Kvm.exe • Standalone 03
Hardware Redirection

Purpose: Control multiple physical PCs with a single mouse and keyboard by gliding across display edges, with synchronized clipboard and audio.

Capability Type Exact Purpose
Input Hooking (WH_MOUSE_LL, WH_KEYBOARD_LL) Ephemeral Win32 Hook Captures mouse coordinates at screen borders and redirects mouse/keyboard events to paired PC.
Win32 Clipboard API Local Memory Sync Synchronizes text and bitmap images between connected machines upon explicit copy/paste.
WASAPI Audio Loopback 48kHz PCM Stream Directly streams audio output to paired workstation speakers without disk caching.
Active Boundary Isolation: Input interception triggers ONLY when the user intentionally pushes the mouse cursor beyond the boundary of the local monitor into the adjacent screen.
Strict Negative Disclosure: TKR-Kvm contains NO keylogging mechanisms. Keystrokes are NEVER recorded, NEVER written to a log file, and NEVER stored in persistent storage. Input packets are streamed transiently in real-time over the encrypted LAN socket.
📡

TKR-Cast — Classroom & Lab Screen Presenter

Binary: TKRDesk-Cast.exe • Standalone 04
Multicast Broadcaster

Purpose: Broadcast instructor or presenter display simultaneously to 50+ student PCs over LAN with sub-frame synchronization.

Port & Capability Type Exact Purpose
UDP 5724 IGMP Multicast Stream Broadcasts compressed desktop presentation frames to joined multicast group subscribers.
GPU Encoder (NVENC / AMF / QSV) Hardware Acceleration Real-time low-overhead frame encoding for multi-client distribution.
Student Device Privacy: Receiver clients operate in passive display mode. The instructor/presenter station cannot read, inspect, or modify student files or private personal applications.
Strict Negative Disclosure: Multicast streams are strictly bounded by router subnet borders and do NOT traverse WAN or cloud routers. No telemetry of student viewing habits is generated.
👥

TKR-Seat — Dual-Seat Workstation Virtualization

Binary: TKRDesk-Seat.exe • Standalone 05
Multi-User Engine

Purpose: Allow two independent users to operate simultaneously on a single PC tower using dedicated secondary monitors, keyboards, mice, and sound cards.

Capability Type Exact Purpose
DirectInput / Raw Input API Hardware Isolation Binds specific USB hardware IDs (Keyboard 2, Mouse 2) to Desktop Seat 2.
Windows Terminal Services / Multi-Session Native OS Accounts Maintains isolated Windows user accounts with independent %USERPROFILE% security contexts.
Complete User Isolation: Each seat logs into a separate standard Windows user account. File permissions, browser sessions, and personal documents remain completely confidential between users based on Windows NTFS access control lists.
Strict Negative Disclosure: TKR-Seat does NOT inspect cross-session user activities, does NOT record screen sessions, and does NOT export hardware profiles off the machine.
🖨️

TKR-Print — Smart Wi-Fi Print Spooler

Binary: TKRDesk-Print.exe • Standalone 06
Print Server

Purpose: Share USB and local printers wirelessly across LAN without complex Windows Active Directory domains or cloud print accounts.

Port & Capability Type Exact Purpose
TCP 9100 / TCP 8989 RAW JetDirect / Spooler Accepts raw printer data streams (PostScript, PCL, EMF) from client workstations.
winspool.drv Win32 API Spooler Pipeline Directly hands print jobs to the local Windows Print Spooler service for physical printing.
Immediate Job Purging: Print jobs are spooled to volatile memory or temporary spool buffers and are permanently purged the instant the physical printer reports successful completion.
Strict Negative Disclosure: Document contents, text, images, or metadata are NEVER analyzed, indexed, stored in a document repository, or transmitted over the internet.
⭐

TKR Desk Master Suite — Unified Flagship Cockpit

Binary: TKRDesk.exe • Unified Suite (All 11 Features)
Flagship Command Center

Architecture: The Master Suite unifies all 11 enterprise features into a single tabbed cockpit by referencing shared, modular class libraries (TkrDesk.Contracts, TkrDesk.Transfers, TkrDesk.Printing.Windows, etc.).

When utilizing the Master Suite, each activated module operates under the identical isolated privacy boundaries detailed in the standalone sections above. Modules not actively engaged remain completely dormant in RAM and do not open listening sockets or hook system resources.

⚖️ 3. Microsoft Store & Regulatory Compliance

This policy is authored to fully satisfy the Microsoft Store App Certification Requirements:

📁 4. Local Machine Storage & Clean Uninstallation

All application state remains strictly inside your local Windows user profile:

🏢 5. Publisher Information & Verified Contact

Legal Publisher
TKR Desk
Lead Developer
Tkrsahu7751
Official Portal
https://tkrdesk.com
Privacy & Security Inquiries
[email protected]
Open Source Code Auditing: The entire codebase and network transfer protocols are open for security review and independent verification on our public GitHub Repository.