Privacy
Privacy Policy
port22 is a remote control for coding agents that already run on your own Mac. It is built so that we never need to see your work — and we don't.
Last updated July 29, 2026
01The short version
port22 has no accounts and no sign-up. We do not operate a service that stores your code, your prompts, or your agent transcripts. Everything you see in the app is read live from your own Mac and sent to your own paired phone.
We collect no personal data, run no analytics or advertising SDKs, and have no ability to read the contents of your sessions. The only exceptions are described under Purchases and Notifications below.
02What stays on your devices
The following never leaves the devices you control, and is never transmitted to us:
- Your source code, files, and repositories
- Agent transcripts, prompts, responses, and tool output
- Terminal output and command history
- Project and directory names, and session titles
- Your pairing code and device pairing records
- Any API keys or credentials used by the agents on your Mac
This data is stored locally on your Mac and, for the parts you have viewed, cached locally on your iPhone. Deleting the app removes the local cache; removing the Mac agent removes its local state.
03How your devices talk to each other
On the same network
When your phone and Mac are on the same local network, they connect directly over your LAN. Your Mac is found using Apple's Bonjour discovery, and the connection is authorised by a six-character pairing code shown on your Mac. Nothing is routed through the internet, and nothing touches our infrastructure.
Away from your network
When you are away, traffic is optionally routed through a relay server we operate, purely so your two devices can find each other across networks and NAT. The relay is a blind pipe: payloads are encrypted end-to-end between your Mac and your phone using an ephemeral X25519 key exchange and AES-256-GCM. The relay only ever sees ciphertext. We cannot decrypt it, and we do not log or persist message contents. Transient connection metadata (an opaque room identifier, timestamps, and coarse volume) exists only for as long as needed to move a message between your devices.
04Apple iCloud
port22 uses Apple's CloudKit private database to let your own devices find one another and share presence. This data lives in your iCloud account, is governed by Apple's privacy policy, and is not accessible to us. If you have iCloud disabled, port22 continues to work over your local network.
05Purchases and notifications
Purchases
Subscriptions are handled by Apple and by RevenueCat, our purchase-management provider. RevenueCat receives an anonymous identifier and your subscription status, so the app knows whether Pro is active. It never receives your name, email, code, prompts, or transcripts. See RevenueCat's privacy policy.
Notifications
If you enable notifications, Apple issues a device token which your own Mac uses to alert you when an agent needs input. The notification body is encrypted; the token identifies a device, not a person.
06Analytics, tracking, and advertising
port22 contains no analytics SDK, no crash-reporting SDK, no advertising identifiers, and no third-party trackers. We do not build user profiles, and we do not track you across apps or websites. No data is sold or shared with data brokers. The only third-party SDK in the app is RevenueCat, which exists solely to tell the app whether your subscription is active — see section 05.
If Apple provides us with aggregate, anonymous App Store metrics such as download counts or opt-in crash reports, those are supplied by Apple in aggregate form and cannot identify you. You control that in Settings → Privacy & Security → Analytics & Improvements on your device.
07If you contact us
If you email us for support, we receive your email address and whatever you choose to include in your message. We use it only to reply to you and to fix the problem you reported. Support email is kept only as long as it is useful for that purpose, and you can ask us to delete it at any time.
08Third parties
The AI coding agents you run — such as Claude Code, Codex, OpenCode, or Aider — are installed and configured by you on your own Mac, under your own accounts and API keys. When you send a prompt from your phone, that prompt is executed by the agent on your Mac and travels to that agent's provider under that provider's privacy policy, not ours. port22 does not add, intercept, or duplicate that traffic.
The only other third parties are Apple, for the App Store and push delivery, and RevenueCat, for subscription status — both covered in section 05.
09Your rights
Because we hold no personal data about you, there is generally nothing for us to export, correct, or delete. Where you have emailed us, you may request access to or deletion of that correspondence. Depending on where you live, you may have rights under the GDPR, the UK GDPR, or the CCPA/CPRA; we honour those requests at the address below. We do not sell or share personal information as those terms are defined under California law.
10Children
port22 is a developer tool and is not directed at children under 13. We do not knowingly collect information from children.
11Changes
If this policy changes, the updated version will be posted here with a new date. If a change materially affects how your data is handled, we will make that clear in the app before it takes effect.
12Contact
Questions about privacy, or a request about your data? Mail me here.