“We can’t see your code” is easy to say. Here is what it means in practice, including the parts we can see.

What the relay does

The relay is a dumb pipe. It accepts connections from your computer and your phone, matches them up and forwards encrypted frames. It runs on Cloudflare Workers with Durable Objects.

What it can see

  • That a device connected, and when.
  • The size of each message.
  • The devices’ public keys.
  • If you sign in, your Google name and email and which computers you linked.

What it cannot see

Terminal output, what you type, commands, files, approvals, questions and answers, earlier conversations and git changes. The keys that protect them exist only on your phone and computer, so a breach of our servers would not expose them.

Alerts carry nothing

Push alerts go through the phone makers’ push services. We send an empty push and the phone shows a fixed message such as “A session needs you”. The command or question never goes through Apple, Google or us.

Logs

Operational logs hold what happened, not the content. Secrets such as tokens and pairing codes are removed before anything is written, and the logs never include commands, questions or terminal output.

The privacy policy lists every category of data we handle and which provider holds it.