Agent Commander

Privacy Policy

Last updated: September 29, 2026

Application: Agent Commander

This policy describes what data Agent Commander handles, where that data lives, and what control you have over it. It is written to comply with international data protection standards such as the GDPR (Europe) and Decree 13/2023/NĐ-CP (Vietnam PDPA).

Agent Commander lets you drive the coding agent on your computer from your phone: Claude Code CLI, Codex CLI, or Antigravity as an experimental option. You type a request on your device, a server runs the assistant against the project directory you configured, and the result comes back to your device.


1. How this application is built, and why it changes everything below

There is no account. Agent Commander has no sign-up, no login, and no user profile. You pair the app with a server by scanning a code; holding that code is what identifies you.

We do not run a server that holds your work. The server is software you install and run on your own machine. Your conversations, your source code, your working sessions and your files stay on that machine, under a data directory you chose. We — the publisher of this app — have no access to it and no copy of it.

Two things do leave your machines, and only two. Section 3 covers them: the content you send is processed by the AI provider of the agent you chose in order to answer you, and — only if you turn notifications on — your device's notification token passes through a small relay we operate.


2. Data the application handles

  • Content you send to the assistant: the prompts and messages you type, images and files you attach, the project name and working directory path you configure, and the list of files in that directory when you use the path-suggestion feature. This is sent to the AI provider of the agent you chose (section 3).
  • Working session content: the turn-by-turn transcript, the log of tools the assistant ran, the source code it read or modified at your request, source diffs, and result files. Stored on your server.
  • Tasks and comments: the content of tasks you write in the app, their comments, and files you attach to them. Stored on your server.
  • Operational metrics: the number of tokens used and the estimated cost of each turn, shown to you so you can track spending. Stored on your server.
  • Device session: a device identifier and a session token issued by your server when you pair. Held on your phone in the operating system's secure storage.
  • Notification token: if — and only if — you enable notifications, your device's push token is sent once to our notification relay, together with which platform you are on. See section 3.
  • Crash reports: anonymous crash reports containing device model, operating system version and the technical context of the failure. They carry no conversation content and are not linked to any identity, because there is no account.

We do not collect your name, your email address, your location, your contacts, your calendar, health data, or any advertising identifier. The app contains no advertising and does not track you across other apps or websites. We do not sell your data, and there is nothing about you for us to sell.


3. Third parties

  • The AI provider of the agent you chose. This is the processor that matters most to you. The content you send to the assistant — prompts, attached files, and the source code the assistant must read to carry out your request — is sent to the models of the provider behind the agent running the conversation, under your own account with that provider: Anthropic for Claude Code (Anthropic's Privacy Policy), OpenAI for Codex (OpenAI's Privacy Policy), Google for Antigravity (Google's Privacy Policy). Each conversation runs on the agent you pick when you start it; if that agent hands part of the work to an agent from another provider, that part of the content goes to that provider as well. Please do not put secrets you do not want leaving your own systems into a conversation — passwords, private keys, certificates, or other people's personal data.
  • Our notification relay. An app distributed through the app stores can only receive push notifications through the publisher's Firebase project, and your own server cannot hold that key. So notifications take one detour: when you enable them, your device token goes once to a relay we operate, which hands you back a secret. Your server stores that secret and uses it to ask the relay to deliver a notification. The relay stores nothing. The secret *is* your device token in encrypted form; the relay decrypts it, forwards one message to Google, and forgets. What it sees in passing is the secret, a short title and body, and identifiers such as the conversation and session ids — never conversation content. Secrets expire 90 days after they are issued.
  • Firebase Cloud Messaging (Google). Carries the notification from the relay to your device. Governed by the Firebase Terms of Service.
  • Firebase Crashlytics (Google). Receives anonymous crash reports so stability problems can be found and fixed. No personally identifying information, no conversation content.

4. Security

  • Pinned connection to your server. The app records your server's TLS certificate fingerprint when you pair, and refuses to talk to anything that does not present that exact certificate afterwards. Unencrypted connections are blocked outright.
  • Secrets in secure storage. The session token, the device identifier and the notification secret are held in the operating system's secure enclave — Keychain on iOS, Keystore on Android.
  • Local cache. Conversation content is cached on the device so you can read it without a connection. Unpairing wipes that cache, along with the session and the notification secret.
  • One owner. The server is designed for a single owner — the person holding the pairing code. It is not a multi-tenant service and must not be exposed to people you would not give shell access to.

5. Your rights, and how to exercise them

  • Consent. You are asked for consent the first time you open the app, before any non-essential data is collected. You can change that choice at any time in Settings → Manage Consent.
  • Turning off notifications. Toggle notifications off in Settings. Your server immediately stops sending them and asks the relay to drop the secret.
  • Deleting your data. There is no account to delete. Everything lives on devices you control, and the data deletion page walks through each place and how to clear it: unpair or uninstall on the phone, delete the data directory on your server.
  • Deleting one item. You can delete an individual task, together with all of its attachments, from inside the app without touching anything else.
  • Access and portability. Your data is already in your possession, in files on your own machine — there is nothing for us to export to you, and no export feature in the app.

6. Retention

  • On your server: kept until you delete it. A task you delete in the app is erased immediately and permanently, together with its attachments.
  • On your phone: kept until you unpair or uninstall the app.
  • At the notification relay: nothing is kept. A notification secret stops working 90 days after it was issued.
  • Crash reports: kept for a maximum of 90 days.
  • Files inside your project directory: not under our control and not part of the app's data. They live on the machine you designated, and nothing described here deletes them.

7. Children

Agent Commander is a developer tool and is not directed at children. We do not knowingly collect data from children, and since there is no account and no profile, the app has no data about any user's identity or age.


8. Changes to this policy

If this policy changes, the updated version is published at agentcmd.app/privacy-policy with a new date at the top, and ships inside the next release of the app. Material changes will be described rather than quietly folded in.


9. Contact

Questions, concerns, or requests about this policy:

Email: agentcmd@sframework.com

Please do not include your server address, your pairing code, or conversation content in that email.

Chính Sách Quyền Riêng Tư (Privacy Policy)

Ngày cập nhật: 29/09/2026

Ứng dụng: Agent Commander

Chính sách này mô tả Agent Commander xử lý những dữ liệu gì, dữ liệu đó nằm ở đâu, và bạn kiểm soát được những gì. Nội dung được viết để tuân thủ các tiêu chuẩn bảo vệ dữ liệu quốc tế như GDPR (Châu Âu) và Nghị định 13/2023/NĐ-CP (PDPA Việt Nam).

Agent Commander là ứng dụng để bạn điều khiển agent lập trình trên máy tính của bạn từ điện thoại: Claude Code CLI, Codex CLI, hoặc Antigravity ở dạng thử nghiệm. Bạn gõ yêu cầu trên máy, một máy chủ chạy trợ lý trên thư mục dự án bạn đã khai báo, rồi trả kết quả về máy bạn.


1. Cách ứng dụng này được xây dựng, và vì sao nó quyết định mọi điều bên dưới

Không có tài khoản. Agent Commander không có đăng ký, không có đăng nhập, không có hồ sơ người dùng. Bạn ghép nối app với một máy chủ bằng cách quét mã; ai giữ mã đó chính là danh tính.

Chúng tôi không vận hành máy chủ nào giữ công việc của bạn. Máy chủ là phần mềm do chính bạn cài và chạy trên máy của mình. Hội thoại, mã nguồn, các lượt làm việc và tệp của bạn nằm lại trên máy đó, trong một thư mục dữ liệu do bạn chọn. Chúng tôi — nhà phát hành ứng dụng này — không truy cập được và không giữ bản sao nào.

Chỉ có đúng hai thứ rời khỏi máy của bạn, và mục 3 nói rõ cả hai: nội dung bạn gửi được nhà cung cấp AI của agent bạn chọn xử lý để trả lời bạn, và — chỉ khi bạn bật thông báo — mã thông báo của thiết bị đi qua một relay nhỏ do chúng tôi vận hành.


2. Dữ liệu ứng dụng xử lý

  • Nội dung bạn gửi cho trợ lý: câu lệnh và tin nhắn bạn gõ, ảnh và tệp bạn đính kèm, tên dự án và đường dẫn thư mục làm việc bạn khai báo, và danh sách tệp trong thư mục đó khi bạn dùng tính năng gợi ý đường dẫn. Phần này được gửi tới nhà cung cấp AI của agent bạn chọn (mục 3).
  • Nội dung lượt làm việc: bản ghi hội thoại theo từng lượt, nhật ký các công cụ trợ lý đã chạy, mã nguồn trợ lý đọc hoặc sửa theo yêu cầu của bạn, khác biệt mã nguồn, và tệp kết quả. Lưu trên máy chủ của bạn.
  • Việc và bình luận: nội dung các việc bạn ghi trong app, bình luận, và tệp đính kèm của chúng. Lưu trên máy chủ của bạn.
  • Số liệu vận hành: số token đã dùng và chi phí ước tính của mỗi lượt, hiện cho bạn xem để theo dõi mức tiêu. Lưu trên máy chủ của bạn.
  • Phiên thiết bị: một mã định danh thiết bị và một mã phiên do máy chủ của bạn cấp lúc ghép nối. Giữ trên điện thoại, trong kho lưu trữ an toàn của hệ điều hành.
  • Mã thông báo: chỉ khi bạn bật thông báo, mã push của thiết bị được gửi một lần tới relay thông báo của chúng tôi, kèm nền tảng bạn đang dùng. Xem mục 3.
  • Báo cáo sự cố: báo cáo ẩn danh gồm kiểu máy, phiên bản hệ điều hành và bối cảnh kỹ thuật lúc lỗi. Không chứa nội dung hội thoại và không gắn với danh tính nào, vì không có tài khoản nào.

Chúng tôi không thu thập tên, địa chỉ email, vị trí, danh bạ, lịch, dữ liệu sức khoẻ hay bất kỳ mã định danh quảng cáo nào. Ứng dụng không có quảng cáo và không theo dõi bạn qua các ứng dụng hay trang web khác. Chúng tôi không bán dữ liệu của bạn, và cũng không có gì về bạn để bán.


3. Bên thứ ba

  • Nhà cung cấp AI của agent bạn chọn. Đây là bên xử lý quan trọng nhất với bạn. Nội dung bạn gửi cho trợ lý — câu lệnh, tệp đính kèm, và phần mã nguồn trợ lý phải đọc để thực hiện yêu cầu — được gửi tới các mô hình của nhà cung cấp đứng sau agent đang chạy hội thoại, dưới tài khoản của chính bạn với nhà cung cấp đó: Anthropic với Claude Code (Chính sách quyền riêng tư của Anthropic), OpenAI với Codex (Chính sách quyền riêng tư của OpenAI), Google với Antigravity (Chính sách quyền riêng tư của Google). Mỗi hội thoại chạy trên agent bạn chọn lúc mở; nếu agent đó giao một phần việc cho agent của nhà cung cấp khác, phần nội dung đó cũng đi tới nhà cung cấp ấy. Đừng đưa vào hội thoại những bí mật bạn không muốn rời khỏi hệ thống của mình — mật khẩu, khoá riêng, chứng chỉ, hay dữ liệu cá nhân của người khác.
  • Relay thông báo của chúng tôi. Ứng dụng phát hành qua cửa hàng chỉ nhận được push thông qua Firebase project của nhà phát hành, mà máy chủ của bạn thì không thể cầm khoá đó. Vì vậy thông báo phải đi vòng một lần: khi bạn bật, mã thiết bị đi một lần tới relay do chúng tôi vận hành, và relay trả về một bí mật. Máy chủ của bạn giữ bí mật đó và dùng nó để nhờ relay gửi thông báo. Relay không lưu gì cả. Bí mật ấy *chính là* mã thiết bị của bạn ở dạng đã mã hoá; relay giải mã, chuyển tiếp một thông điệp tới Google, rồi quên. Thứ nó thấy khi đi qua là bí mật, một dòng tiêu đề và nội dung ngắn, cùng các mã định danh như mã hội thoại và mã lượt — không bao giờ có nội dung hội thoại. Bí mật hết hạn 90 ngày sau khi được cấp.
  • Firebase Cloud Messaging (Google). Chuyển thông báo từ relay tới thiết bị của bạn. Theo Điều khoản dịch vụ Firebase.
  • Firebase Crashlytics (Google). Nhận báo cáo sự cố ẩn danh để tìm và sửa lỗi ổn định. Không có thông tin định danh cá nhân, không có nội dung hội thoại.

4. Bảo mật

  • Kết nối ghim tới máy chủ của bạn. App ghi nhớ vân tay chứng chỉ TLS của máy chủ lúc ghép nối, và về sau từ chối nói chuyện với bất cứ thứ gì không đưa ra đúng chứng chỉ ấy. Kết nối không mã hoá bị chặn thẳng.
  • Bí mật nằm trong kho an toàn. Mã phiên, mã định danh thiết bị và bí mật thông báo được giữ trong vùng an toàn của hệ điều hành — Keychain trên iOS, Keystore trên Android.
  • Bộ đệm cục bộ. Nội dung hội thoại được đệm trên máy để bạn đọc được khi không có kết nối. Ngắt ghép nối là xoá sạch bộ đệm đó, cùng với phiên và bí mật thông báo.
  • Một chủ sở hữu. Máy chủ được thiết kế cho đúng một người chủ — người giữ mã ghép nối. Nó không phải dịch vụ nhiều người thuê, và không nên phơi ra cho những người bạn sẽ không trao quyền truy cập máy.

5. Quyền của bạn và cách thực hiện

  • Sự đồng ý. Bạn được hỏi ý kiến ở lần mở app đầu tiên, trước khi có bất kỳ dữ liệu không thiết yếu nào được thu thập. Bạn đổi lựa chọn đó bất cứ lúc nào ở Cài đặt → Quản lý đồng ý.
  • Tắt thông báo. Gạt tắt thông báo trong Cài đặt. Máy chủ của bạn ngừng gửi ngay lập tức và nhờ relay bỏ bí mật.
  • Xoá dữ liệu. Không có tài khoản nào để xoá. Mọi thứ nằm trên các thiết bị bạn kiểm soát, và trang xoá dữ liệu hướng dẫn từng nơi cùng cách dọn: ngắt ghép nối hoặc gỡ app trên điện thoại, xoá thư mục dữ liệu trên máy chủ.
  • Xoá từng phần. Bạn xoá được một việc riêng lẻ cùng toàn bộ tệp đính kèm của nó ngay trong app mà không đụng tới thứ gì khác.
  • Truy cập và mang dữ liệu đi. Dữ liệu của bạn vốn đã nằm trong tay bạn, dưới dạng tệp trên chính máy của bạn — không có gì để chúng tôi xuất cho bạn, và app cũng không có chức năng xuất.

6. Thời hạn lưu trữ

  • Trên máy chủ của bạn: giữ tới khi bạn xoá. Một việc bạn xoá trong app bị xoá ngay và vĩnh viễn, cùng tệp đính kèm.
  • Trên điện thoại: giữ tới khi bạn ngắt ghép nối hoặc gỡ cài đặt app.
  • Ở relay thông báo: không giữ gì. Một bí mật thông báo hết tác dụng 90 ngày sau khi được cấp.
  • Báo cáo sự cố: giữ tối đa 90 ngày.
  • Tệp trong thư mục dự án của bạn: không thuộc quyền kiểm soát của chúng tôi và không phải dữ liệu của app. Chúng nằm trên máy do bạn chỉ định, và không thao tác nào mô tả ở đây xoá chúng.

7. Trẻ em

Agent Commander là công cụ dành cho người phát triển phần mềm, không hướng tới trẻ em. Chúng tôi không cố ý thu thập dữ liệu của trẻ em, và vì không có tài khoản lẫn hồ sơ, app không có dữ liệu nào về danh tính hay độ tuổi của bất kỳ người dùng nào.


8. Thay đổi chính sách

Nếu chính sách này thay đổi, bản cập nhật được đăng tại agentcmd.app/privacy-policy kèm ngày mới ở đầu trang, và đi cùng bản phát hành kế tiếp của app. Những thay đổi có ảnh hưởng thật sự sẽ được nói rõ chứ không lặng lẽ gộp vào.


9. Liên hệ

Câu hỏi, thắc mắc hay yêu cầu liên quan tới chính sách này:

Email: agentcmd@sframework.com

Vui lòng không kèm địa chỉ máy chủ, mã ghép nối hay nội dung hội thoại trong thư đó.