EnvoyDev is built local-first. Your code never leaves your machine, there is no central EnvoyDev account, and your model keys stay with the coding agents on your desktop — the phone is a thin client that never holds them. This policy explains what data the software processes, where it stays, and what third parties (if any) may see.
1. Data storage
Projects, tasks, transcripts, approval records, and agent configuration are
stored locally on the computer where the EnvoyDev desktop daemon runs, under
the EnvoyMesh home directory (typically <home>/EnvoyDev/).
EnvoyDev does not operate a hosted coding inbox or a cloud transcript store.
- Your code and agent transcripts remain on your own machine.
- Nothing is automatically synced to an EnvoyDev cloud — no such cloud exists.
- When you join another machine as a thin client (Paired homes), data stays on that home machine.
2. No account
EnvoyDev never asks you to register or sign in. Identity is cryptographic (Ed25519 keys) generated and stored on your devices, using the same identity and pairing system as the rest of the EnvoyMesh apps family. There is no email address, phone number, or password held by EnvoyDev.
3. Coding agents & model keys
EnvoyDev does not try to be an agent — it is the control plane that drives coding agents (Envoy Harness, Claude Code, Codex, OpenCode, Cursor, DeepSeek Harness, and more) on your machine.
- Provider API keys and agent credentials stay with the agent that uses them, on your desktop. EnvoyDev never proxies them and never uploads them.
- AI prompts, files, and tool outputs go only to the model provider or local runner you configured for that agent — subject to that provider's own terms.
- Local model inference stays entirely on your machine.
- Risky tool calls require your approval in the permission dock before they run.
4. EnvoyDev Mobile
EnvoyDev Mobile (iOS and Android) is a thin client. It pairs to your EnvoyDev desktop daemon and never runs an agent itself.
- Pairing / session tokens — stored in the platform Keychain (iOS) / Keystore (Android); used only to authenticate to your own daemon.
- Camera — optional, used only to scan a desktop pairing QR code. Frames are not uploaded anywhere.
- Attachments — optional images you attach to a message are sent to your daemon over the pairing channel.
- SSH hop credentials — only if you paste them; held in secure storage on the phone and never sent to an EnvoyDev cloud service.
- Projects & transcripts — read live from your desktop daemon; the phone keeps at most a local cache until you clear app data or uninstall.
- No provider keys — model credentials never leave the desktop; the phone never holds them.
5. Pairing & network
The desktop and phone connect using the EnvoyMesh family discovery ladder: LAN → public address → peer-to-peer → bootstrap → community relay, in that order. Pairing codes and links stay valid until you revoke them on the desktop (Settings → This machine) or Forget the host on the phone.
- Mesh envelopes are Ed25519-signed; recipients verify sender identity.
- When a direct path is unavailable, traffic may pass through a community relay. Relay operators can see connection metadata (addressing, timing) but message payloads are intended for the end peers — do not treat an arbitrary relay as a confidential vault.
- For SSH pairing, EnvoyDev opens a local-forward through your SSH hop; it does not dial loopback remotely.
6. Third-party services
Depending on how you configure EnvoyDev, third parties may include:
- Apple / Google — app distribution and, on mobile, APNs / FCM push delivery (device tokens are registered with your own daemon).
- Model providers (OpenAI-compatible APIs, local runners, external agents) — only if you enable them for an agent on your desktop; review that provider's own privacy policy.
- Community or private relays — connectivity only; relay operators are independent of EnvoyDev.
- Git remotes — Team jobs share work through Git (e.g. your origin remote), not through the mesh.
We do not control those parties' independent privacy practices.
7. Data security
- Cryptographic identity with Ed25519 keys and signed mesh messages.
- Pairing tokens held in platform secure storage (Keychain / Keystore).
- Policy-gated tool execution: scope and risk are shown before approval.
- Pairings are revocable at any time from either side.
8. Retention & deletion
- On the phone — Forget the host and/or uninstall EnvoyDev Mobile to remove pairing tokens and local caches from that device. Projects and transcripts remain on the desktop you paired with.
- On the desktop — the machine's operator controls retention of projects, transcripts, agent configuration, and issued pairing codes. Delete them on that machine (or wipe the
<home>/EnvoyDev/directory). - Paired devices — revoke a phone or thin client under Settings → This machine; its codes stop working immediately.
Because there is no central EnvoyDev account or cloud mailbox, there is no “delete my data with EnvoyDev HQ” button — deletion is device- and home-local, and entirely under your control.
9. Children
EnvoyDev is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. The software has no account system and collects no registration data.
10. Your choices & rights
- Refuse camera or notification permissions on the phone (QR pairing and push will be limited; address/SSH pairing still works).
- Prefer LAN / direct connections or your own SSH hop; avoid community relays when possible.
- Use only local model runners, or disable remote providers you do not trust.
- Revoke or rotate pairing codes; Forget hosts on the phone.
- Delete local project, transcript, and profile data on the desktop whenever you like.
If applicable law (e.g. GDPR / CCPA) grants you rights regarding data processed by a machine operator or a service you configured, exercise those rights with that operator or provider. Contact us for questions about the software's design.
11. Changes to this policy
We may update this page when product behavior or store requirements change. The “Last updated” date at the top will change. Continued use after an update means you accept the revised policy for that software version.
12. Contact us
Privacy questions about EnvoyDev:
- Email: shilei.peng@qq.com · shileipeng@gmail.com
- Source / issues: github.com/allenpeng0705/EnvoyCoder
- Family project: github.com/allenpeng0705/EnvoyMesh
By using EnvoyDev, you consent to this Privacy Policy.