brocodedDownload
legal

Privacy Policy

Brocoded connects your phone to the terminal sessions on your computer. This page says what that involves for your data, in plain language. Last updated .

The short version

  • We can’t read your work. Your terminal output, commands, files and AI conversations are end-to-end encrypted between your phone and your computer. Our relay only passes along data it cannot open.
  • An account is optional. Without one, nothing about you is stored on our servers. With one, we keep your Google name and email and which computers you linked, and nothing else.
  • No ads, and only light usage analytics. We don’t sell data or run advertising. We count visits and a few milestones (like “paired a computer”) to see what works. See “Analytics” below. None of it includes your terminal, commands, files or conversations.
  • You can delete it. Deleting your account in the app removes it, and you can remove any computer or phone at any time.

What we handle

This is everything Brocoded’s own servers receive or keep. Nothing else about you or your work reaches us.

WhatWhyWhere it lives
Your Google name, email and Google IDonly if you sign inTo recognise your account and link your computers to it.Our database (Cloudflare D1)
Linked computersa public address, the name you gave it, when it was linked and last seenTo show which computers share your account.Our database
Sign-in sessionsa random token, stored only as a hashTo keep you signed in on your phone.Our database
Daily connection countone number per account per dayTo apply fair-use limits.Our database
Connection detailswhen a computer or phone connected, the size of messages, the devices’ public keysTo run the relay, keep it reliable and stop abuse.Operational logs (Cloudflare Workers Logs)
Error reportserror text and stack trace, app version, the page pathTo find and fix crashes.Operational logs, and optionally Grafana Cloud

Your IP address reaches Cloudflare, which carries the connection, as it does for any website. We use it briefly to limit abuse and don’t store it with your account.

What we can’t see

Your phone and your computer set up encryption keys between themselves when you pair them by scanning a QR code. The keys are made on those two devices and the private halves never leave them. After that, everything about your sessions travels encrypted:

  • terminal output and what you type,
  • commands and the files an agent touches,
  • approvals, questions and answers,
  • earlier conversations and git changes you open on your phone.

Our relay forwards this data without being able to open it. A leak or breach of our servers would not expose it, because we don’t hold the keys.

Notifications are empty on purpose. If you turn on alerts, your computer asks our relay to send a push through Apple, Google, Mozilla or Microsoft’s push service. The push carries no content. Your phone shows a fixed message such as “A session needs you”, and you open the app to see what it is.

How we use it

  • To connect your phone and computer and keep the connection working.
  • To sign you in, link computers to your account and apply fair-use limits.
  • To find and fix errors, and to protect the service from abuse. We may suspend an account that abuses it.

We don’t sell or rent your data, use it for advertising, build profiles from it, or use it to train AI models. We have nothing to train on: your content is encrypted.

Who else is involved

Brocoded runs on a few providers. Each only gets what its part of the job needs.

  • Cloudflare hosts the website, the web app, the relay and the account database.
  • Google handles “Continue with Google”. We load Google’s sign-in script only on the sign-in screens, and receive your name, email and Google ID. Google’s own policy covers what it collects.
  • Apple, Google, Mozilla and Microsoft push services deliver the empty alerts, if you turn them on.
  • Cloudflare Web Analytics counts page visits on the website and the app without cookies.
  • PostHog (US) receives anonymous usage events: pages viewed on the website, clicks on download and app links, and app milestones such as pairing started, pairing succeeded or failed (with a reason like “timed out”), session connected, first action sent, and “computer linked” (sent by our relay when you link a computer to your account, with its operating system). Events never include terminal content, what you type, computer addresses, keys or pairing codes (we strip the part of the address after the page name). Session recording is off. If your browser sends Do Not Track, PostHog stays off. When you sign in, events are linked to a random-looking id derived from your account (not your email, name or Google ID), so we can see whether people who sign in get as far as using Brocoded. Signing out starts a fresh anonymous identity. PostHog may keep a small identifier in your browser to tell visits apart.
  • Grafana Cloud can receive the operational logs and error reports, when it’s configured for the relay.
  • Pinata and Filebase (IPFS) serve the app downloads. When you download, they see your IP address, as any download host would.
  • YouTube serves the demo video on the home page. The video loads from YouTube when you scroll to it on the home page (muted, and paused when you scroll past), using the privacy-enhanced (no-cookie) player. Nothing loads from YouTube anywhere else.

The website and the app don’t use advertising cookies. Cloudflare Web Analytics sets no cookies. PostHog may store an anonymous identifier in your browser. Google’s sign-in and YouTube may set their own cookies when you use them.

What stays on your devices

  • On your phone, in the browser’s or app’s storage: your private key, the computers you paired, your sign-in, the guest name if you continue as a guest, and a few preferences such as font size and conversation names.
  • On your computer, in the Brocoded app’s folder and the system keychain: its private key, the list of paired phones, and its logs.

When you ask for earlier conversations or git changes, your computer reads them from its own disk and sends them to your phone over the encrypted link. They never go to us.

On Android, Brocoded is a shell around the same web app and keeps the same data in the same way. It has no ads or tracking libraries, and Android backups of its storage are turned off so your keys don’t end up in a backup.

How long we keep it

  • Account data stays until you delete your account, or until you ask us to.
  • Sign-in sessions expire after a while, and when you sign out or delete the account.
  • Problem reports you send from the app are stored in Brocoded’s own database: your message, the app version, your device type, the connection check result if you attach it, and your email only if you choose to leave one. Please don’t include passwords or code. We read them to fix problems and delete them after 90 days; ask us to delete one sooner at the contact address below.
  • Connection problems are counted by type, per hour, in Brocoded’s own database: for example “computer offline” or “pairing timed out”, with the app version. No account, computer address, IP address or message is stored with them, and they are deleted after 30 days. You can also run “Connection check” in the app, which only reports its result type.
  • Operational logs and error reports are kept only as long as the logging service holds them for debugging and security. They contain no terminal content, and secrets such as tokens and pairing codes are removed before anything is written.

Your choices

  • Delete your account. In the app, open You and choose Delete account. We remove your account, its linked computers, sign-in sessions, link codes and usage counts. Your sessions and chats stay on your own computers, and everything goes back to guest.
  • Sign out. This signs your computers out of your account and removes them from the phone. It doesn’t delete anything on the computers.
  • Remove a phone or a computer. Use Devices on the computer’s page, or the computer’s own window. That cuts off access straight away.
  • Turn alerts off in the Inbox, or in your phone’s settings.
  • Clear everything on a phone by clearing the site’s data in your browser, or uninstalling the app. You’ll need to pair again.
  • Ask us. You can ask what we hold about you, to correct it, or to delete it, by emailing [email protected]. We’ll reply within a reasonable time. If you live in the EU, UK or a similar region, you also have the right to complain to your data protection authority.

Where the law asks for a legal basis, we process account data to provide the service you asked for, and operational data for our legitimate interest in keeping the service running and secure.

Children

Brocoded is a developer tool and isn’t aimed at children under 13 (or the higher age your country sets). We don’t knowingly collect data from them. If you think a child has signed in, email us and we’ll delete the account.

Changes to this page

If we change how Brocoded handles data, we’ll update this page and its date. If the change is significant, we’ll say so in the app or on the home page too.

Contact

Questions, requests or concerns about privacy: [email protected].