Privacy Policy
Last updated 16 July 2026 · applies to the DevFob apps for iOS, Android, Wear OS, watchOS and macOS, and to the devfob.com website
The DevFob apps are built so that there is nothing to collect: no account, no analytics, no advertising, no tracking. The apps move an end-to-end encrypted connection between devices you own and paired together — your data never reaches us, because there is no server of ours for it to reach. The website keeps a small set of anonymous, first-party purchase-funnel counts, enumerated in full in §7 — and nothing else.
The short version:
• We do not collect, store, sell, or share any personal data from the apps.
• No account, no sign-in, no analytics SDKs, no ad SDKs.
• If you buy a license, Paddle (our merchant of record) processes the payment — we keep only your email, the order id, and the issued key (see §6).
• The website counts a handful of anonymous events (like "pricing seen", "buy clicked") — no cookies, no IP addresses stored, no identifiers that survive closing the tab (see §7).
• The content you see in the app (session output, prompts, working-directory paths, the commands you send) travels only between your own paired devices, sealed with end-to-end encryption.
• An optional relay, used only when your devices aren't on the same network, can route that traffic but only ever sees ciphertext — and you can self-host it.
1. Who we are
DevFob ("DevFob", "we", "us") is software published by the DevFob project. You can reach us at hello@devfob.com. Our website is devfob.com.
2. What DevFob does
DevFob lets you monitor and respond to AI coding-agent sessions (such as Claude Code) running on your own Mac from your phone and watch. The Mac is the host; the phone and watch are remote monitors and controllers that you pair to it with a one-time code.
3. Data we collect
None. The developer does not collect, receive, or store any personal or usage data from the apps. There are no analytics, crash-reporting, advertising, or tracking SDKs in the build.
4. Data the app transmits between your devices
To do its job, the app transmits your own session data between the devices you have paired — for example: recent terminal/session output, the working-directory path of a session, permission prompts, and the instructions or replies you choose to send back. This is your data moving between your devices. Specifically:
- End-to-end encrypted. Devices are paired with a Curve25519 handshake; every message is sealed with ChaCha20-Poly1305, authenticated, and replay-guarded.
- Direct on your network. When your devices are on the same local network they talk directly (via Bonjour/mDNS discovery); nothing leaves that network.
- Relay sees ciphertext only. When your devices are apart, traffic may pass through a relay so they can reach each other. The relay cannot read any of it — it forwards sealed frames. The relay can be self-hosted on your own infrastructure.
- The watch holds no keys. The Wear OS / watchOS app mirrors through your phone, so the watch never stores your Mac's pairing keys.
We never receive this content. It is not stored on any server operated by us.
5. Data we share
From the apps: none. Because the apps collect no data, there is nothing to share or sell, and no third-party SDKs are in any build. The website runs on Cloudflare (hosting and, for the anonymous counts in §7, storage) and uses Paddle for checkout (§6) — neither receives anything about your use of the apps.
6. Purchases on devfob.com
If you buy a DevFob for Mac license, the order is processed by Paddle, our merchant of record, on Paddle's own checkout — your card details never touch our site or our code. To issue your license we receive from Paddle only the email address you entered at checkout and the order identifier, and we store those alongside the issued key so we can recover it for you if it's lost. That is the entire record: no account is created, and nothing about your use of the apps is ever attached to it. The license key itself lives on your Mac and is verified offline — the app never phones home to validate it. Paddle's handling of your payment data is described in Paddle's privacy policy.
7. What the website measures — the complete list
To learn which pricing and wording works, devfob.com counts a small set of interaction events, first-party only. This is the entire list: "pricing section seen", "page section seen" (which parts of a page were scrolled into view), "buy clicked", "checkout opened", "checkout completed", "download clicked", "purchase page viewed", and (server-side, when a purchase completes) "purchase" with the price paid and, where a test is running, which variant of the page was shown.
- No cookies, nothing stored on your device. A random session id lives in the page's memory and disappears when you close the tab. It is never written to disk, never sent to Paddle or anyone else, and cannot be connected to a later visit or to you.
- No IP addresses, no fingerprints, no user-agent strings are stored.
- Aggregate and short-lived: events are stored as counts on Cloudflare's analytics infrastructure and expire after about three months.
- Checkout is the exception you opt into: clicking Buy loads Paddle's checkout code, which uses its own cookies as our payment processor — Paddle's privacy policy covers those. Until you click Buy, no third-party code runs on this site.
8. Device permissions
The app requests only the permissions it needs to function locally on your device:
- Camera — to scan the pairing QR code shown by the Mac app. Images are processed on-device and never uploaded.
- Notifications — to alert you when a session needs your attention; delivered locally.
- Network / Wi-Fi state & multicast — to discover your Mac on the local network and to maintain the encrypted connection.
These permissions are not used to collect data about you.
9. Data retention and deletion
From the apps we store nothing about you, so there is nothing to retain or delete. Any data the app keeps (such as your pairing keys and cached session state) lives locally on your devices and is removed when you unpair a device or uninstall the app. Website funnel counts (§7) are anonymous and expire automatically after about three months; purchase records (§6) are kept as long as your license needs supporting.
10. Children
DevFob is a developer tool and is not directed to children under 13.
11. Changes to this policy
If this policy changes we will update this page and revise the date above. Material changes will be reflected here before they take effect.
12. Contact
Questions about privacy? Email hello@devfob.com.