Privacy Policy
Last updated: June 16, 2026
Terminull lets you remote-control AI coding agents running on your own computer from your phone. This policy explains what we collect, what we don't, and why. The short version: your code, prompts, and agent output are end-to-end encrypted between your phone and your Mac, and our servers cannot read them.
What we collect
- Account info — the email address you use to sign in, so we can authenticate you and pair your devices.
- Device & pairing data — identifiers for the phone and Mac you pair, and the timestamps of pairings/sessions, so the service can route your connection to the right machine.
- Usage & diagnostics — limited usage events (e.g. when a session starts or ends, which agent was used, session counts) and crash/error reports, tied to your account, to operate and improve the service. This is metadata only — never your prompts, code, files, or agent output.
What we do not collect
- Your session content. Prompts, code, files, terminal output, and agent responses are encrypted on your phone and decrypted only on your paired Mac (and vice versa). Our relay connects the two ends but cannot decrypt what passes through it.
- Notification content. Push notifications are encrypted before they leave your Mac; Apple's push service and our servers see only a generic title, not the body.
How your data is protected
- End-to-end encryption. Each session derives a per-session key on your phone and your Mac (X25519 key exchange); content is encrypted with AES-GCM.
- Secrets at rest. Authentication tokens and one-time codes are stored hashed, not in plaintext.
- Least access. Capability gates (terminal, screen share) are enforced on your own machine and only when you enable them.
- Local-only option. In LAN-only mode your phone and your machine pair and talk directly over your local network — no account, and nothing is sent to our servers at all.
Third parties
- Apple — for push notifications (Apple Push Notification service), which never receive your content.
- Our infrastructure providers — the relay and API run on hosted servers that route encrypted traffic and store account/device records.
- Email delivery — to send sign-in codes and account email.
- Product analytics & crash reporting — a privacy-focused analytics service (hosted in the EU) and a crash-reporting system we host ourselves help us understand usage and diagnose errors. They receive event metadata only — never your session content — and you are identified only by a pseudonymous account identifier, never by name.
We do not sell your personal data, we do not use it for advertising, and we do not allow third-party advertising or cross-app tracking.
Data retention & deletion
We keep account and pairing data while your account is active. You can unpair a device at any time, and you can request deletion of your account and associated data by contacting us. Session content lives only on your own devices.
Children
Terminull is not directed to children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data.
Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date.
Contact
Questions about privacy? Email privacy@terminull.dev.