EnvoyMesh family apps are built local-first. There is no central EnvoyMesh account server that stores your chat inbox, coding transcripts, contacts, or vault. Identity is cryptographic (Ed25519 keys → DIDs) and lives on devices you control. This policy explains what data is processed, where it stays, and what third parties (if any) may see.
1. Who we are
This Privacy Policy covers the EnvoyMesh project software, including the home node / desktop apps (EnvoyMesh), the social mobile companion (EnvoyGo), and the coding-agent control plane (EnvoyDev desktop and EnvoyDev Mobile). Product pages and review tools may be hosted at envoymesh.cn.
2. Scope of products
| Product | Role |
|---|---|
| EnvoyMesh | Home / desktop node: identity, bonds, chat, vault, AI agent, policy engine, optional relays |
| EnvoyGo | Mobile thin client: pairs to your home node; chat, contacts, agent, calls, push alerts |
| EnvoyDev | Coding-agent control plane (desktop) and thin-client companion (EnvoyDev Mobile): pairs to your EnvoyDev daemon; projects, transcripts, approvals |
When you pair EnvoyGo or EnvoyDev Mobile to a machine you own, that machine’s operator (often you) controls what is stored there. We do not operate a shared multi-tenant “Envoy cloud inbox” or coding transcript store.
3. Core principles
- No central EnvoyMesh account — you are not required to register with us to use the mesh.
- Self-sovereign identity — keys and peer IDs are generated and stored on your devices.
- Policy-gated sharing — trust tiers, bonds, and mandates limit what peers and agents can access.
- Signed messages — mesh envelopes are Ed25519-signed; recipients verify sender identity.
- Local vault by default — knowledge and files stay on the home node unless you explicitly share.
4. Data we process
“Process” here means handled by the software on your devices or by services you (or your home operator) configure — not necessarily collected by a central EnvoyMesh company database.
Categories
- Identifiers — owner / device / agent / peer IDs derived from public keys; session and pairing tokens.
- User content — chat messages, attachments, voice/video call media, vault files, profile display names you set.
- Device permissions data — camera frames for QR pairing; microphone/camera for calls; notification tokens for push.
- Technical / connection data — relay or WebSocket endpoints you configure, reachability hints, audit events on the home node.
- AI prompts & context — only when you enable a model provider or local agent; subject to that provider’s terms if remote.
5. EnvoyGo (mobile)
EnvoyGo stores pairing/session material on-device (e.g. platform secure storage / Keychain) and talks to the home node you paired with.
- Camera — used to scan home-node pairing / family invite QR codes. Images are not uploaded to an EnvoyMesh cloud for analytics.
- Microphone / camera (calls) — used during voice or video calls with mesh peers; media follows the call path (P2P / home signaling), not a vendor social network.
- Photos / attachments — optional; sent via your home / mesh when you choose to send them.
- Push notifications — Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) device tokens may be registered with your home node so it can wake the app for chat or calls. Those platforms process tokens under their own policies.
- Local database — caches such as chat threads / contact lists needed for offline UX remain on the device until you clear app data or uninstall.
EnvoyGo does not require access to your phone’s system Contacts database for mesh contacts — peer profiles come from the paired home node.
6. EnvoyDev (desktop & mobile)
EnvoyDev is the coding-agent control plane. The desktop app and daemon run on a machine you own; EnvoyDev Mobile is a thin client that pairs to that daemon. Provider API keys and agent credentials stay with the coding agents on the desktop — the phone never holds them.
- Pairing / session tokens — stored on the phone in the platform Keychain / Keystore; used only to authenticate to your EnvoyDev daemon.
- Camera — optional QR scan for pairing. Images are not uploaded to an EnvoyDev cloud.
- Photos / attachments — optional images you attach to a message; sent to your daemon over the pairing channel.
- SSH hop credentials — only if you paste them for a hop; stored in secure storage on the phone; never sent to an EnvoyDev cloud service.
- Transcripts & projects — read from your desktop daemon’s local state. EnvoyDev does not operate a hosted coding inbox.
- No EnvoyDev account — there is no central EnvoyDev signup; reachability uses the same EnvoyMesh identity / discovery family as the other products.
7. EnvoyMesh (home / desktop)
- On-disk profile — keys, trust store, peer directory, chat/journal data, vault index, and audit logs typically live under the node profile directory you choose.
- AI / models — local inference stays on your machine; remote providers only receive prompts/context you approve through configured tools and policy.
- Audit — JSONL audit events may record allow/deny decisions and summaries for security; they are local unless you export them.
- Family / pairing invites — tokens authorize a device to bond; treat invite QR codes like passwords and revoke or rotate when done.
8. Relays & network
To connect when peers are behind NAT or on cellular, traffic may pass through relays or WebSocket bridges you (or your community) configure. Relay operators can see connection metadata (who connects when, addressing). Message payloads are intended for end peers under the mesh protocol; do not assume a random relay is a confidential vault. Prefer direct / LAN paths when available.
9. Third-party services
Depending on how you configure the products, third parties may include:
- Apple / Google — app distribution, APNs / FCM push delivery.
- Firebase (if used in your EnvoyGo build) — messaging / related Google services for push.
- Model providers (OpenAI-compatible APIs, local runners, external agents such as HomeClaw) — only if you enable them on the home node or on an EnvoyDev desktop agent.
- Community or private relays — connectivity only; operators are independent unless you run them yourself.
We do not control those parties’ independent privacy practices. Review their policies before enabling them.
10. Retention & deletion
- On EnvoyGo — unpair and/or uninstall the app to remove local caches and session material from that device.
- On EnvoyDev Mobile — unpair and/or uninstall to remove pairing tokens and local caches; project and transcript data remain on the desktop daemon you paired with.
- On the home / EnvoyDev desktop — the machine’s operator controls retention of chats, vault files, coding projects, transcripts, invites, and peer records. Deleting data or wiping a profile is done on that machine.
- Push tokens — become inactive when you revoke them on the home or uninstall; platform retention follows Apple/Google rules.
Because there is no central EnvoyMesh account mailbox, there is no “delete my cloud inbox with EnvoyMesh HQ” button — deletion is device- and home-local.
11. Children
The software is not directed at children under 13 (or the minimum age in your jurisdiction). Do not use EnvoyGo / EnvoyMesh to knowingly collect personal information from children without appropriate parental authority and compliance with local law.
12. Your choices & rights
- Refuse camera / mic / notification permissions (pairing, calls, or push will be limited).
- Use LAN / direct paths and avoid third-party relays when possible.
- Disable remote model providers; keep inference local.
- Rotate or expire pairing / family invite tokens; revoke device certificates where supported.
- Export or delete local profile data you control on the home machine.
If applicable law (e.g. GDPR / CCPA) grants you rights regarding personal data processed by a home operator or a service you configured, exercise those rights with that operator or provider. Contact us (below) for questions about the software’s design.
13. Changes
We may update this page when product behavior or store requirements change. The “Last updated” date at the top will change. Continued use after an update means you accept the revised policy for that software version.
14. Contact
Privacy questions about EnvoyMesh / EnvoyGo / EnvoyDev:
- Web: https://www.envoymesh.cn/
- Source / issues: github.com/allenpeng0705/EnvoyMesh
For App Store / Play listings, use this page URL (after you publish it), for example:
https://www.envoymesh.cn/privacy