Privacy Policy
Last updated: September 29, 2026
Application: Agent Commander
This policy describes what data Agent Commander handles, where that data lives, and what control you have over it. It is written to comply with international data protection standards such as the GDPR (Europe) and Decree 13/2023/NĐ-CP (Vietnam PDPA).
Agent Commander lets you drive the coding agent on your computer from your phone: Claude Code CLI, Codex CLI, or Antigravity as an experimental option. You type a request on your device, a server runs the assistant against the project directory you configured, and the result comes back to your device.
1. How this application is built, and why it changes everything below
There is no account. Agent Commander has no sign-up, no login, and no user profile. You pair the app with a server by scanning a code; holding that code is what identifies you.
We do not run a server that holds your work. The server is software you install and run on your own machine. Your conversations, your source code, your working sessions and your files stay on that machine, under a data directory you chose. We — the publisher of this app — have no access to it and no copy of it.
Two things do leave your machines, and only two. Section 3 covers them: the content you send is processed by the AI provider of the agent you chose in order to answer you, and — only if you turn notifications on — your device's notification token passes through a small relay we operate.
2. Data the application handles
- Content you send to the assistant: the prompts and messages you type, images and files you attach, the project name and working directory path you configure, and the list of files in that directory when you use the path-suggestion feature. This is sent to the AI provider of the agent you chose (section 3).
- Working session content: the turn-by-turn transcript, the log of tools the assistant ran, the source code it read or modified at your request, source diffs, and result files. Stored on your server.
- Tasks and comments: the content of tasks you write in the app, their comments, and files you attach to them. Stored on your server.
- Operational metrics: the number of tokens used and the estimated cost of each turn, shown to you so you can track spending. Stored on your server.
- Device session: a device identifier and a session token issued by your server when you pair. Held on your phone in the operating system's secure storage.
- Notification token: if — and only if — you enable notifications, your device's push token is sent once to our notification relay, together with which platform you are on. See section 3.
- Crash reports: anonymous crash reports containing device model, operating system version and the technical context of the failure. They carry no conversation content and are not linked to any identity, because there is no account.
We do not collect your name, your email address, your location, your contacts, your calendar, health data, or any advertising identifier. The app contains no advertising and does not track you across other apps or websites. We do not sell your data, and there is nothing about you for us to sell.
3. Third parties
- The AI provider of the agent you chose. This is the processor that matters most to you. The content you send to the assistant — prompts, attached files, and the source code the assistant must read to carry out your request — is sent to the models of the provider behind the agent running the conversation, under your own account with that provider: Anthropic for Claude Code (Anthropic's Privacy Policy), OpenAI for Codex (OpenAI's Privacy Policy), Google for Antigravity (Google's Privacy Policy). Each conversation runs on the agent you pick when you start it; if that agent hands part of the work to an agent from another provider, that part of the content goes to that provider as well. Please do not put secrets you do not want leaving your own systems into a conversation — passwords, private keys, certificates, or other people's personal data.
- Our notification relay. An app distributed through the app stores can only receive push notifications through the publisher's Firebase project, and your own server cannot hold that key. So notifications take one detour: when you enable them, your device token goes once to a relay we operate, which hands you back a secret. Your server stores that secret and uses it to ask the relay to deliver a notification. The relay stores nothing. The secret *is* your device token in encrypted form; the relay decrypts it, forwards one message to Google, and forgets. What it sees in passing is the secret, a short title and body, and identifiers such as the conversation and session ids — never conversation content. Secrets expire 90 days after they are issued.
- Firebase Cloud Messaging (Google). Carries the notification from the relay to your device. Governed by the Firebase Terms of Service.
- Firebase Crashlytics (Google). Receives anonymous crash reports so stability problems can be found and fixed. No personally identifying information, no conversation content.
4. Security
- Pinned connection to your server. The app records your server's TLS certificate fingerprint when you pair, and refuses to talk to anything that does not present that exact certificate afterwards. Unencrypted connections are blocked outright.
- Secrets in secure storage. The session token, the device identifier and the notification secret are held in the operating system's secure enclave — Keychain on iOS, Keystore on Android.
- Local cache. Conversation content is cached on the device so you can read it without a connection. Unpairing wipes that cache, along with the session and the notification secret.
- One owner. The server is designed for a single owner — the person holding the pairing code. It is not a multi-tenant service and must not be exposed to people you would not give shell access to.
5. Your rights, and how to exercise them
- Consent. You are asked for consent the first time you open the app, before any non-essential data is collected. You can change that choice at any time in Settings → Manage Consent.
- Turning off notifications. Toggle notifications off in Settings. Your server immediately stops sending them and asks the relay to drop the secret.
- Deleting your data. There is no account to delete. Everything lives on devices you control, and the data deletion page walks through each place and how to clear it: unpair or uninstall on the phone, delete the data directory on your server.
- Deleting one item. You can delete an individual task, together with all of its attachments, from inside the app without touching anything else.
- Access and portability. Your data is already in your possession, in files on your own machine — there is nothing for us to export to you, and no export feature in the app.
6. Retention
- On your server: kept until you delete it. A task you delete in the app is erased immediately and permanently, together with its attachments.
- On your phone: kept until you unpair or uninstall the app.
- At the notification relay: nothing is kept. A notification secret stops working 90 days after it was issued.
- Crash reports: kept for a maximum of 90 days.
- Files inside your project directory: not under our control and not part of the app's data. They live on the machine you designated, and nothing described here deletes them.
7. Children
Agent Commander is a developer tool and is not directed at children. We do not knowingly collect data from children, and since there is no account and no profile, the app has no data about any user's identity or age.
8. Changes to this policy
If this policy changes, the updated version is published at agentcmd.app/privacy-policy with a new date at the top, and ships inside the next release of the app. Material changes will be described rather than quietly folded in.
9. Contact
Questions, concerns, or requests about this policy:
Email: agentcmd@sframework.com
Please do not include your server address, your pairing code, or conversation content in that email.