Privacy, without a relay.
This policy covers the Cookbox.ai Android app (package ai.cookbox.app) and the cookbox.ai website, operated by the Cookbox.ai project.
The app does not send your work to us
Cookbox.ai has no account, advertising SDK, product analytics SDK, or Cookbox.ai relay. SSH and terminal traffic goes directly between the app and hosts you configure. We do not receive your host addresses, SSH keys, terminal contents, repositories, prompts, recordings, agent credentials, or usage data.
Saved connections and private keys are kept in the app's private storage on your device and are encrypted at rest with a key generated inside the Android Keystore, which cannot be read back out of it. A key is decrypted into memory only while a connection is using it. Recordings stay on your device unless you choose to upload or forward one. Files uploaded through Cookbox.ai are sent to your chosen host.
Services you choose
Your SSH host, network provider, agent provider, Android speech-recognition service, and any page you open through port forwarding operate under their own terms and privacy practices. Dictation may be processed by the speech-recognition service configured on your device. Cookbox.ai does not receive that audio or transcript.
Website analytics
The website uses Cloudflare Web Analytics for aggregate page views, referrers, device/browser categories, approximate country, and page-performance measurements. Cloudflare says this service uses no cookies or local storage, does not fingerprint visitors, and does not collect or use visitors' personal data. Cloudflare also processes ordinary network information needed to deliver and protect the site under its own privacy policy. We do not use advertising trackers.
Testing invites and iOS updates
If you submit a website signup form, we store your email address, your chosen platform (Android or iOS), language, signup date, and the version of the consent you accepted in Cloudflare D1. The Android list is used for testing invitations and testing updates. The iOS list is used for availability and iOS updates. Joining one list does not subscribe you to the other. These are website signup lists, not Cookbox app accounts. Signup data is not sent to Web Analytics.
We keep your signup while the relevant testing or iOS update list is active, and delete it within 90 days after that list closes, or sooner if you withdraw consent. You can unsubscribe or request deletion by emailing privacy@cookbox.ai. A testing request does not grant immediate Google Play access.
Email you choose to send
If you email support or diagnostics, we use your address and message only to respond and investigate, and delete them within 90 days after the issue is closed unless law requires longer retention. Do not send private keys or passwords.
Legal basis and sharing
Where data-protection law applies, we process signup information with your consent and minimal site-delivery/security data for our legitimate interest in operating a reliable site. We do not sell personal data or share it for advertising. Data is handled only by the providers needed to host the site, store signup information, and deliver email, subject to their contractual and legal safeguards.
Your choices and rights
You can remove app data by deleting saved connections or uninstalling the app. You can withdraw from the waitlist or request access, correction, or deletion of email you sent by writing to privacy@cookbox.ai. Depending on where you live, you may also object to or restrict processing and complain to your local data-protection authority.
Children and changes
Cookbox.ai is a server-administration tool and is not directed to children under 13. We do not knowingly collect their personal information. Material changes to this policy will be posted here with a new effective date before the changed practice begins.
Contact
Privacy questions and requests: privacy@cookbox.ai.