RHMRA Phone Dashboard Terms of Use
Effective August 4, 2026.
These Terms govern use of RHMRA Phone Dashboard, an open-source, installable, read-only viewer for encrypted RHMRA dashboard snapshots. By using the app, you agree to these Terms and the Privacy Policy.
Read-only viewer
The phone app displays information supplied by a paired RHMRA laptop dashboard. It does not contain brokerage credentials and cannot place, change, or cancel trades. Do not treat the phone view as an order-entry system, brokerage statement, tax record, or authoritative record of account activity.
No financial advice
The app and displayed information are provided for informational purposes only. They are not investment, financial, legal, accounting, or tax advice and do not recommend any security, strategy, or transaction. You remain responsible for independently verifying information and making your own decisions.
Your responsibilities
- Use the app only with accounts, devices, and data you are authorized to access.
- Keep private pairing links, QR codes, decryption keys, and devices secure.
- Review snapshot age and connection status before relying on displayed information.
- Use phone Forget this device, stop laptop sharing, laptop Disconnect Google Drive, or Google Account third-party connections when the corresponding access should end.
- Do not misuse the app, interfere with its operation, or attempt to access another person's data.
Google Drive, OAuth relay, and third-party services
The phone PWA uses Google Sign-In and the Google Drive API directly to access only its hidden app-data folder. Google processes those requests under Google's terms and privacy policy. The companion laptop Agent uses a maintainer-operated Cloudflare Worker as a transient OAuth token relay: it forwards the one-time Google authorization code and S256 PKCE verifier, or a refresh token, to Google and returns Google's token response. The relay code does not log or store those values and never receives dashboard snapshots, Drive files, pairing keys, brokerage credentials, or trading data.
Cloudflare provides the relay infrastructure and processes the transient token request, response, and associated network metadata as a service provider under Cloudflare's terms and privacy policy. GitHub Pages or another configured static host may serve the application files under that provider's terms. Availability of Google, Cloudflare, and static-hosting services is outside the maintainer's control.
Availability, accuracy, and expiry
Snapshots can be delayed, unavailable, expired, or incomplete because of network, browser, Google Drive, OAuth relay, Cloudflare, laptop, market-data, or upstream-system conditions. The app attempts to label stale and disconnected views, but you must verify important facts through authoritative sources.
Open-source software and disclaimer
The software is provided under its repository license and on an “as is” and “as available” basis, without warranties of any kind to the extent permitted by law. The maintainer does not guarantee uninterrupted operation, accuracy, fitness for a particular purpose, or preservation of any snapshot.
Limitation of liability
To the maximum extent permitted by applicable law, the maintainer and contributors are not liable for trading losses, lost profits, lost data, loss of access, or any indirect, incidental, special, consequential, or punitive damages arising from use of or inability to use the app.
Ending access and deleting data
You may stop using the app at any time. On the phone, Forget this device removes only the phone-local pairing, cached encrypted snapshot, and in-memory token; phone disconnect clears only its in-memory token. Neither phone action revokes Google's shared grant or clears the laptop credential. Stopping sharing from the laptop removes the active encrypted Drive file but retains pairing.
On the laptop, Disconnect Google Drive requests Google revocation and clears the Agent's local in-memory and DPAPI-protected Google credential while retaining the phone pairing. Because the laptop and phone share one Google application grant, the phone may need to reconnect. If remote revocation could not be confirmed, remove RHMRA from Google Account third-party connections. The Agent's local credential has already been cleared. You may also uninstall the phone PWA or clear its site data.
Changes
These Terms may be updated as the app changes. The effective date above identifies the current version. Continued use after an update means you accept the revised Terms.
Support
Questions and security reports may be submitted through the project issue tracker. Never publish confidential account or pairing information.