Connect Privacy Policy
Version: Release Candidate 1.0
Last updated: 2026-10-04
Effective date: 2026-10-04
This Privacy Policy explains how 武凯迪 (Ketty Wu) (the "Connect Operator," "we," or "us") handles and protects information when you use the Connect Mac app, the Connect iPhone companion, and official Connect websites that link to this Policy. The Connect Operator can be reached at w494892858@gmail.com.
Connect is a local-first tool. It has no Connect account or hosted model service. The app's primary data stays on the Mac and iPhone you control. The iPhone companion connects directly to your own Mac over a private network only after explicit pairing.
1. Scope
This Policy applies to:
- the Connect Mac app and Connect iPhone companion;
- official Connect download, support, and compatibility pages that link to this Policy; and
- support or privacy requests you choose to send us.
This Policy does not govern Claude, Codex, Tailscale, Apple, or other independent third-party services. Your relationship with those services is governed by their own terms and privacy policies.
2. Key Points
- We do not collect your project files, terminal content, prompts, model responses, pairing records, or credentials through Connect-operated servers.
- Connect contains no advertising, behavioral tracking, analytics SDK, or automatic crash or diagnostic upload.
- We do not sell personal information, share it for cross-context behavioral advertising, or create advertising profiles.
- Connect does not read Claude or Codex authentication files and does not store, proxy, or upload their tokens, passwords, or API keys.
- Content may reach a third-party provider only when you explicitly run its CLI or send an image.
3. Information Processed on Your Devices
Connect processes the following information on your devices to provide features you request. Except for user-directed third-party actions described in Section 5, the Connect Operator cannot access it.
| Category | Where it is processed | Purpose |
|---|---|---|
| Workspace paths, file contents, file names, and Git status | Your Mac | Browse and edit files and run workflows |
| Terminal input, output, and session state | Your Mac; an authorized iPhone may view or enter encrypted content | Run your own Shell, Claude, or Codex CLI |
| Collaboration task state, room history, attachments, and artifact summaries | Your Mac | Local history, recovery, and orchestration |
| Recent projects, layouts, launch commands, avatar, theme, and language | The relevant device | Save local preferences |
| Pairing public keys, device name, private-network address, scopes, and revocation time | Secure storage on your Mac and iPhone | Authenticate, authorize, connect, and revoke devices |
| Content-free security audit and performance timing records | The relevant device | Diagnose authorization, protocol, and performance issues |
Workspace files remain in the location you selected. Removing a project from Connect's recent list does not delete the original files.
4. Direct Mac-to-iPhone Connection
The mobile bridge is off by default. It listens on one specific Tailscale or private LAN address only after you enable it in Mac settings. Connect does not use a public relay, Tailscale Funnel, UPnP, or NAT port mapping.
Pairing requires scanning a QR code and comparing a short authentication string on both devices. Connections use application-layer encryption and device identity verification. New devices are read-only by default. Write access must be granted separately on the Mac and may be withdrawn or revoked at any time. Security audit records do not contain terminal content, prompts, model responses, file contents, or tokens.
5. Third-Party CLIs and Services
Claude and Codex
You install, license, and sign in to Claude Code and the Codex CLI yourself. Connect only starts and orchestrates local CLIs. It does not provide third-party accounts, models, tokens, subscriptions, or credits.
When you explicitly send a command, image, or collaboration task to Claude or Codex, that CLI may send the following to its provider: your input, selected images, workspace content read to complete the task, and technical metadata generated by the CLI. What is sent, retained, used for model improvement, and processed by region depends on your third-party account settings and the provider's policy. See:
- Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
- OpenAI Privacy Policy: https://openai.com/policies/privacy-policy/
Connect does not accept provider terms for you or bypass provider login and first-use confirmation. You select these services independently; the Connect Operator does not appoint them to collect app data on our behalf. If we later appoint a provider to process app data for us, we will update this Policy before enabling that processing and require protections no less protective than this Policy and applicable law.
Tailscale
If you choose Tailscale, Connect uses the private address assigned to your devices to establish a direct connection. Connect does not bundle the Tailscale SDK or manage your Tailscale account. Tailscale may process device and connection metadata under its own policy: https://tailscale.com/privacy-policy.
Apple
Apple may independently process information for App Store distribution, system permissions, system diagnostics, and store transactions. That processing is governed by Apple's policies and your Apple settings. The Connect Operator does not receive Apple system diagnostics through the app unless you affirmatively choose to send them to us.
6. Device Permissions
- Camera: Used only to scan the pairing QR code displayed by your Mac. Connect does not record, retain, or upload photos or video.
- Photo picker: Only images you explicitly select enter a terminal or room transfer. Connect does not request access to browse your entire photo library.
- Local network: Used to connect to your own Mac. If denied, you can restore access in system settings.
You can withdraw system permissions in iOS Settings at any time. Features that require a withdrawn permission will stop working, while unrelated features remain available.
7. Official Websites and Support Communications
Official Connect pages use no advertising, tracking pixels, or analytics scripts. To deliver pages and prevent abuse, the hosting or CDN provider may temporarily process IP address, request time, requested path, browser or User-Agent, response status, and security events. Before public release, we must select providers subject to appropriate confidentiality and security obligations, and ordinary access logs must be configured for retention of no more than 30 days, except when longer retention is necessary for a security incident or legal obligation.
If you contact us by email or another support channel, we process your contact details, message, and files you choose to attach only to respond, troubleshoot, and keep required compliance records. Ordinary support records are retained for no more than 24 months after closure, unless law, dispute handling, or your earlier deletion request requires otherwise. Do not send passwords, tokens, private keys, or unnecessary project content.
8. Retention and Deletion
| Data | Default retention | How to delete or stop processing |
|---|---|---|
| Live terminal content | Exists with the PTY session; security audits do not copy it | Close the terminal or quit the app |
| Room history, task state, and local artifacts | Stored on your Mac until you clear/delete them or remove app data | Use in-app clear/delete actions; manage original workspace files separately |
| Temporary terminal images | About two minutes at most, or until submission/app exit | Automatically deleted |
| Room attachments | Stored with the related local room history | Clear room history or remove app data |
| Mac security audit | Current and one rotated file, each up to 5 MiB | Remove Connect app data from the Mac |
| Mac performance timing | Current and one rotated file, each up to 2 MiB | Remove Connect app data from the Mac |
| iPhone performance timing | Up to 1,024 local records | Remove app data |
| Pairing records | Retained while active; revoked records remain as local security tombstones | "Unpair" removes the iPhone connection profile; Mac revocation immediately stops access; removing app data deletes local records |
| Device private keys | Managed by macOS/iOS secure storage and never provided to the Operator | Controlled by the device secure-storage lifecycle; the Operator has no copy to delete |
Uninstalling the Mac app alone may leave data in Application Support. In Finder, use Go to Folder and
remove ~/Library/Application Support/connect if you want to remove local room history, task state,
settings, pairing, and audit records. Removing Connect data does not automatically delete selected
workspace files or data held in your Claude, Codex, Tailscale, or Apple accounts.
9. Security
Connect uses measures such as Workspace Trust, canonical-path and symlink boundaries, a sandboxed renderer, system secure storage, device pairing, authenticated encryption, least-privilege scopes, revocation, rate limits, and bounded content-free audit records. Public Mac builds also require Developer ID signing and Apple notarization. No software or transmission method can guarantee absolute security. Trust only workspaces you understand, and protect your devices, third-party accounts, and private network.
10. International Processing
The Connect Operator does not transfer local app data to its own servers. Third-party CLIs, Tailscale, Apple, website hosting/CDN providers, or support services you choose may process information in the countries where they operate and use transfer mechanisms described in their own policies. You decide whether to use these independent services.
11. Your Rights and Choices
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to our processing of personal information; withdraw consent; obtain a copy; and complain to a regulator. Because primary app data stays only on your devices, we normally have no server copy to return or delete. You can inspect, modify, or delete it directly on the device. For website logs or support records you sent us, contact w494892858@gmail.com. We may need to verify a request, and legal exceptions may apply.
We do not sell or share personal information for cross-context behavioral advertising, use sensitive personal information to infer characteristics, or discriminate against you for exercising a privacy right.
12. Children
Connect is a developer tool. It is not directed to children under 16 and is not intended for the App Store Kids Category. We do not knowingly collect children's personal information through a Connect service. Contact us if you believe a child submitted information through a support channel.
13. Changes to This Policy
We will update this Policy when product capabilities, third-party recipients, or legal requirements change, and will revise the "Last updated" date. We will give appropriate notice of material changes in the app, on the official website, or through another suitable channel. If Connect later adds an account, cloud sync, telemetry, crash upload, advertising, or another remote service, we will update this Policy and required user choices before enabling it.
14. Contact Us
For privacy questions, requests, or complaints:
- Operator: 武凯迪 (Ketty Wu)
- Email: w494892858@gmail.com
You may also complain to the data protection authority with jurisdiction where you live.