Privacy Policy

Last updated: June 28, 2026

We never collect your data or your prompts

We never collect, read, store, sell, or train on your prompts, your code, your agent output, or your files. Everything runs on your Mac, and remote control runs over an encrypted private relay that keeps nothing once you disconnect. The only data we hold is the minimum needed to run your account and subscription, described below.

1. Introduction

RemoteCode ("we", "our", or "us") explains here how we collect, use, store, and protect your personal information when you use our Service. By using RemoteCode, you consent to the practices described in this policy.

2. What we never collect

We have no access to and never collect, read, store, sell, or use for training:

  • Your prompts: What you ask your AI coding agents never reaches our servers.
  • Your code and files: Your repository stays on your Mac. We do not host, sync, or copy it.
  • Your agent output: Terminal output, command results, and agent responses stay local to your machine.

Remote control passes through an encrypted private relay that holds no content and retains nothing after the connection ends.

3. What we do collect

To run your account and subscription, we collect only the following:

  • Account information: Your email address and a hashed password when you register.
  • Subscription data: Subscription status, plan, and billing events processed through our payment provider Lemon Squeezy.
  • Session metadata: Information needed for account access, billing, and push notification delivery (e.g., session state, timestamps). We do not store the content of your code or commands.
  • Push notification tokens: Device tokens used to deliver notifications to your mobile device, managed via Firebase Cloud Messaging.
  • Usage data: Anonymised logs and error reports to monitor service health and fix issues.

4. Website analytics and heatmaps

On our public website (remotecode.io) we run our own first-party, privacy-respecting analytics. There is no Hotjar, FullStory, or session replay, and no third party receives this data. It is entirely separate from the product: it never touches your prompts, code, agent output, or files. In anonymised and aggregated form we measure:

  • Pageviews & traffic sources: which pages are viewed, the referring site or campaign (UTM) that brought you, and an approximate country derived from your IP. We do not store your IP address.
  • Engagement & read-depth: how far down a page you scroll and which sections hold attention, so we can improve our content.
  • Heatmaps: aggregated click and scroll positions, stored only as counts in a coarse grid. We do not store the contents of a form field, what you type, or anything that identifies you.
  • Device information: coarse device type, browser, and operating system.

This uses a first-party anonymous identifier stored in your browser and is not linked to your account for these purposes. We honour the Do Not Track and Global Privacy Control browser signals: if either is enabled, website analytics is switched off. Raw events are retained for at most 90 days; only aggregates are kept longer.

5. How we use your information

We use your information to:

  • Provide, operate, and maintain the Service
  • Process subscription payments and manage your account
  • Send push notifications to your registered mobile device
  • Send transactional emails (account confirmation, password reset, billing receipts)
  • Measure traffic, page views, and usage trends to improve the Service
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell, rent, or share your personal information with third parties for marketing purposes.

6. Third-party services

We use the following third-party providers to operate the Service:

  • Lemon Squeezy: payment processing and subscription management. Your payment card details are handled exclusively by Lemon Squeezy and are never stored by us.
  • Firebase (Google): push notification delivery. Device tokens are transmitted to Firebase Cloud Messaging to send notifications to your device.
  • Google Analytics: website analytics and page view measurement. We use it to understand traffic and improve the Service.
  • Reddit Ads and X Ads: ad attribution and conversion measurement. We use browser pixels and server-side conversion APIs to understand whether ads lead to trials or paid subscriptions.

Each provider operates under its own privacy policy and data processing agreements.

7. Data storage and security

Your data is stored on secure servers. We use technical and organisational measures to protect your information against unauthorised access, alteration, disclosure, or destruction. These include encrypted connections (TLS), hashed passwords, and access controls.

No transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

8. Data retention

We retain your account data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.

9. Your rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to certain types of processing

To exercise any of these rights, please contact us at hello@remotecode.app. We will respond within 30 days.

10. Cookies and local identifiers

We use functional browser storage (localStorage) to remember your language preference and authentication session, plus a first-party anonymous identifier for the website analytics described in Section 4 (disabled under Do Not Track / Global Privacy Control). We also use Google Analytics, Reddit Ads, and X Ads, which may set cookies or similar identifiers, to measure site traffic, page views, and ad conversions.

11. Children's privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via an in-app notice. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at hello@remotecode.app.