Privacy Policy

Last updated: September 7, 2026

1. Introduction

CodeAgent Mobile ("we", "our", or "us") operates the CodeAgent Mobile application (the "App") and the website at www.codeagent-mobile.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Display name
  • Encrypted password

2.2 Session & Pairing Data

When you pair your mobile device with an IDE plugin, we collect:

  • Session identifiers (randomly generated UUIDs)
  • Plugin identifiers for session isolation
  • IDE type (e.g., VS Code, WebStorm, Cursor)
  • Agent type (e.g., Copilot, Claude, Windsurf)

2.3 Prompts, Output & Session History

When you send prompts through the App, the text of your prompts, the AI agent's responses, and the task context you attach (for example a team-chat excerpt you selected to start a task) are relayed through our servers for real-time streaming and stored as that session's history so you can reopen it from any device. Session history is deleted when you delete the session or your account (see Data Retention).

2.4 Device & Usage Information

We may automatically collect:

  • Device type, operating system, and version
  • App version
  • Product usage analytics (via PostHog and Vercel Analytics — no prompt or message content)
  • Error and crash reports (via Sentry — no prompt or message content)

3. How We Use Your Information

We use the collected information to:

  • Provide and maintain the Service
  • Authenticate your identity and manage sessions
  • Relay prompts and responses between your mobile device and IDE
  • Improve the Service and fix bugs
  • Communicate with you about updates or issues

4. Data Storage & Security

We take the security of your data seriously:

  • Account data is stored in a secure database with encrypted passwords (bcrypt)
  • Session data uses randomly generated identifiers and plugin-level isolation
  • Session history and integration tokens are stored encrypted at rest on Google Cloud Platform
  • All communications between the App, plugins, and our servers use HTTPS encryption
  • Sessions are validated with both session ID and plugin ID to prevent cross-session data leakage

5. Sub-processors & Third Parties

We do not sell, trade, or rent your personal information to third parties. To run the Service we rely on the following sub-processors:

  • Google Cloud Platform — hosting (Cloud Run), database, and secret storage; United States (Privacy Policy)
  • Vercel — web hosting for this site and the web dashboard (Privacy Policy)
  • Cloudflare — CDN and the tunnels that serve in-app previews (Privacy Policy)
  • PostHog — product analytics; receives no prompt or message content (Privacy Policy)
  • Sentry — error monitoring; receives no prompt or message content (Privacy Policy)
  • GitHub — repositories, Codespaces, and sign-in (Privacy Policy)
  • AI model providers — the provider behind the agent you choose:Anthropic,OpenAI,Google, andMiniMax (the built-in CodeAgent Cloud agent). The content of a task, including any team-chat excerpt you selected, is sent to the model provider of the agent you chose.

6. Third-party integrations (Agent Toolkit: Slack, Microsoft Teams, GitHub, Jira, Linear and others)

The Agent Toolkit lets you connect third-party services so your coding agent can use them on your behalf. When you connect an integration:

  • We store its OAuth token encrypted at rest (envelope encryption; the root key lives in Google Secret Manager) and never on your workspace machine.
  • The agent accesses the service on demand, on your behalf, and only for tasks you start. We do not sync, index, or store the service's content.
  • The one exception is the excerpt you explicitly select to start a task (for example a Slack thread in "Start from conversation"). That excerpt becomes part of that session's history and is deleted with the session or your account.
  • Disconnecting revokes the token at the provider (for Slack, via auth.revoke) and removes it from any open sessions. Revoking from the provider's side (for example removing the app in Slack) also deletes our copy.

6.1 Slack

CodeAgent Mobile for Slack uses a user token: the agent acts as you, in the channels and conversations you already have access to. We request the following user scopes and no bot scopes:

channels:read, channels:history, groups:read, groups:history, im:read, im:history, mpim:read, mpim:history, chat:write, reactions:write, users:read

Read scopes let the agent read the thread you point it at; chat:writeand reactions:write let it post replies and reactions as you; users:read resolves names in a thread.

7. Camera Permission

The App requests camera access solely for scanning QR codes during the device pairing process. No images or video are captured, stored, or transmitted. The camera is only activated when you explicitly open the QR scanner screen.

8. Data Retention

  • Account data — retained until you delete your account
  • Session history (prompts, agent output, attached context) — retained until you delete the session or your account
  • Integration tokens — retained until you disconnect the integration, revoke access at the provider, or delete your account
  • Analytics data — retained per third-party provider policies

9. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Withdraw consent for data processing at any time
  • Export your account data

To exercise any of these rights, please contact us at the email address below.

10. Children's Privacy

Our Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the new Privacy Policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

support@codeagent.dev

CodeAgent MobileCodeAgent Mobile — Built by developers, for developers.
HomeGitHub© 2026
ONLINE·PRIVACY POLICY·v2026.09·WORKSTATION-X9