Who this applies to
agmux is a macOS app for AI coding agents (Claude, Codex, Gemini, Kimi, Pi, OpenCode, Grok, Cursor, Cline, Hermes, local models, and related tools). This policy covers:
- The marketing site at agmux.dev
- The desktop app and its optional cloud features
- Phone remote at remote.agmux.dev, its agmux.dev/remote mirror, the agmux iPhone app, and the remote relay
- Teams at teams.agmux.dev
- The optional beta program at agmux.dev/beta
When we say "we" or "agmux," we mean the people who operate these services. The desktop app is free to download. You do not need an agmux account for normal local use.
The short version
- Chats, code, and terminal history stay on your Mac for ordinary desktop use. Providers you connect (Anthropic, OpenAI, xAI, and others) have their own policies for what you send them.
- Remote moves session traffic between your Mac and your phone through our relay so you can control agents away from the desk. We store pairing and device credentials. We do not keep a permanent archive of your chat transcripts on the relay.
- Teams metrics upload usage counters and short labels after you join and link a device. Optional Team Knowledge separately stores the decisions and summaries you choose to share.
- Product analytics is enabled by default in the desktop app and can be switched off in Settings. It records basic app and feature usage without conversation content.
- We don't sell personal information and we don't run ads against your product data.
Desktop app (local by default)
The app stores project memory, thread state, settings, and related data under your user account on the Mac (for example under ~/.agmux/). Session logs for third-party agents often live in those tools' own folders (Claude, Codex, Grok, and so on). That data is on your disk. We receive the data described below when the relevant feature or setting is enabled. Product analytics is enabled by default.
When you use cloud models, prompts and tool traffic go to that provider under their terms — not to agmux as a middleman that trains on your code. Local model inference runs on your machine. Runtime setup, catalog searches, and model downloads contact external services, including Hugging Face. Optional web search and connected tools can also send data over the network.
Auto-update checks may contact GitHub and, when a beta token is turned on, agmux.dev to see if a newer release exists. That is a normal update check, not a content upload.
Desktop product analytics
Product analytics is separate from Teams and enabled by default. The app sends a random installation identifier, app and operating-system versions, processor architecture, release channel, and a daily heartbeat to owner.agmux.dev. It also sends a limited set of feature events, such as starting an agent and changing the workspace layout. These events exclude prompt text, replies, code, project paths, and terminal output.
Turn it off in Settings → General → Privacy → Product analytics to stop future reports. This does not delete previously received records.
Debug Mode
Debug Mode records performance information locally when you enable it. Captures remain on your Mac after a restart. If you ask a cloud coding agent to inspect a capture, information it reads may be sent to that provider as part of the conversation.
Beta program
Applying at agmux.dev/beta is optional. We collect the email, name, and optional note you submit. If we approve you, we email a short-lived sign-in link and store a hash of a tester token (not the token itself, except briefly so we can show it to you once). Session cookies keep you signed in on the site. You can sign out or we can revoke access. Beta builds may be unstable.
Website (agmux.dev)
Visiting the site can generate ordinary web logs: IP address, user agent, pages requested, and roughly when. Hosting and CDN infrastructure (for example Cloudflare and the platform that deploys this site) may process those logs to keep the site up and block abuse.
If analytics are enabled for the site, we may use Google Analytics and/or Cloudflare Web Analytics to see aggregate traffic (which pages get hits, rough geography, referrers). Cloudflare Web Analytics is designed to be privacy-oriented; Google Analytics may use cookies or similar identifiers depending on configuration and your browser settings. You can block analytics scripts with browser tools or extensions. There are no ads on the site.
Download links point at public GitHub release assets. Clicking download goes to GitHub, which has its own privacy policy.
Phone remote
Remote is optional. You turn it on in the desktop app, pair a phone with a short code (or QR link) at remote.agmux.dev or in the agmux iPhone app, and control sessions on your Mac from that phone.
The iPhone app shows the same remote interface. It keeps its pairing in the iPhone Keychain so that iOS clearing app storage does not sign you out; "Forget this Mac" removes it. The app asks for camera or photo access only when you choose to attach an image, and sends that image to your Mac through the relay like any other message. The app has no analytics, advertising, or tracking.
Third-party AI. Messages and photos you send from the phone go to agmux on your Mac, where the coding agents you run (for example Claude Code, Codex or Gemini) send them to their AI providers, such as Anthropic, OpenAI or Google, under the accounts you set up on your Mac. Those providers handle that data under their own terms and privacy policies. The iPhone app asks for your permission before your first message and lets you withdraw it in Settings.
Notifications. If you allow notifications, the relay stores this iPhone’s push token and which alerts you turned on in Settings. When an agent needs approval or finishes while agmux is closed, the relay sends a short alert (for example the session title and tool name) through Apple’s push service. Forgetting the Mac or revoking the phone removes the token.
What we store on the remote relay: device identifiers, pairing state, hashed desktop secrets and phone tokens (and short prefixes so you can recognize devices in settings), optional device/Mac names, and similar connection metadata. Phone tokens expire after 90 days; you can revoke a phone or all phones from the Mac. Turning remote off disconnects paired phones.
What passes through the relay: WebSocket messages needed to list sessions, stream conversation/terminal views, send messages, stop runs, and approve or deny tools. That traffic exists so your phone can control your Mac. Transport is protected with TLS, but messages are not end-to-end encrypted against the relay: the relay processes readable session messages. It forwards messages between your paired devices; it is not a product feature for long-term chat storage. If both sides are online, content can be in memory or transit on the path between them. Treat remote like remote access: only pair phones you control, and revoke anything you don't recognize.
Remote does not require a separate agmux "user account." Pairing is the authentication model.
Teams (teams.agmux.dev)
Teams is a separate, optional product for org-level usage analytics. You choose to link a device, sign in, and join a team. Nothing about Teams runs until you opt in.
Account data. Sign-in uses GitHub or Google OAuth with basic profile scopes (identity, email, display name, avatar URL). We store enough to run membership, roles (owner / manager / employee), invites, and the dashboard. Device credentials for Teams live on your Mac under the app's Teams storage path.
Metrics. Reporting covers verified sessions started in agmux; imported or unverified history is excluded. Reports may be incomplete, and cost figures are estimates. The desktop uploads hourly aggregates only: token totals, estimated cost, active agent time, session/turn/tool counts, tool kinds, failure counts where available, file-change counts (not the files), provider/model names, project basenames or an opaque hash, coarse work-hour patterns, approval wait counts, and similar counters. Optional GitHub org leaderboard features use PR counts and size tiers from repositories your team owner selects — not pull request bodies or code.
What Teams metrics exclude: prompt text, agent replies, chat history, diffs, file contents, absolute paths, terminal output, secrets, keystrokes, screenshots, or live "watch someone code" streams. Team Knowledge is a separate sharing feature, described below.
The metrics disclosure appears in the desktop join flow and on Teams. For the live checklist, open teams.agmux.dev privacy / disclosure.
Team owners and managers can see scoped dashboards for their team (employees see their own stats). Budgets, alerts, exports, and an audit log of admin actions (membership, roles, invites, budgets, exports — not prompt content) are stored to support those features. Authorized platform staff can also access team dashboards through a read-only web preview.
Team Knowledge and paid Teams features
Team Knowledge is off by default. A team owner must enable it, and members must accept its disclosure before sharing. It stores selected decisions, notes, and session summaries, including titles, outcomes, file-name lists, project and provider labels, and attribution. It is separate from the automatic metrics upload. Review what you share: content filters can miss sensitive information.
Agent access to team records is a separate setting, also off by default. When enabled, connected agents can read the records permitted by the team policy. Raw conversation transcripts and file contents are not supported Knowledge upload fields.
Free Teams analytics is available for up to three members. Team Knowledge and the GitHub PR Leaderboard require paid access or an eligible trial. Stripe handles paid subscriptions; we store the customer and subscription identifiers and billing status needed to manage access.
Third-party services
Depending on which features you use, data may be processed by:
- Cloudflare — website/CDN, Web Analytics (if enabled), Workers and storage for remote relay, Teams, and product analytics
- Google Analytics — site traffic (if enabled)
- GitHub — release downloads, update metadata, Teams sign-in and optional leaderboard org data
- Vercel — website hosting and private beta file storage
- Neon — beta application, tester, and sign-in records
- Stripe — Teams checkout and subscriptions
- Hugging Face — local-model search and downloads
- Resend — beta application and sign-in emails
- Google — Teams sign-in when you choose Google
- AI providers you configure (Anthropic, OpenAI, xAI, OpenRouter, local servers, and others) — whatever you send them from the agents you run
Those companies process data under their own policies. agmux is not responsible for how a third-party model provider uses prompts you send it.
Cookies and similar tech
The marketing site may set cookies or use local storage if analytics or similar tools are enabled. Teams sessions use the auth mechanism needed to keep you signed in (cookies or equivalent session storage). The beta program uses httpOnly session cookies after a magic-link sign-in. Remote pairing stores tokens on the phone and Mac so you don't re-pair every visit. You can clear site data in your browser; for remote, revoke devices in the desktop app.
Storage and deletion
- Local data remains until removed from your disk. Uninstalling the app does not necessarily remove its data folders or provider histories. Settings → Cleanup removes selected generated titles and disposable caches, not conversations or project memory.
- Remote credentials can expire or be revoked. That stops access; it is not a promise that all connection metadata is erased at the same time.
- Teams metrics use a 90-day window, trimmed when new metrics are received. Leaving a team removes access and stops new uploads, but does not erase historical team aggregates.
- Team Knowledge can be removed from normal views without immediately erasing stored content. Explicit purge is a separate action. Do not rely on automatic expiry to remove shared summaries.
- Product analytics records are stored separately from Teams. Switching analytics off stops future reports; it does not erase existing records. No automatic deletion period is currently configured.
Your choices
- Disable desktop Product analytics in Settings to stop future reports
- Leave Remote, Teams, and Team Knowledge off if you do not need them
- Revoke phones and disable remote from the Mac at any time
- Leave a team or unlink Teams from settings
- Block analytics on the marketing site with your browser
- Delete local app data by removing the app data directories on disk (and uninstalling if you want a clean break)
If you need a copy of account data we hold on Teams, or want an account deleted and can't finish it in the product UI, contact us through the channels below. We'll respond in a reasonable time.
Security
Traffic to our sites and Workers uses HTTPS/TLS. Remote tokens are stored hashed on the relay; Teams device credentials are kept on the Mac with restricted file permissions. No setup is perfect. If you find a vulnerability, report it privately via a GitHub security advisory or issue on the releases repository rather than posting exploit details in public.
Children
agmux is built for developers and teams. It is not directed at children under 13, and we don't knowingly collect personal information from them. If you think a child under 13 has given us personal data, contact us and we'll delete it.
International users
Services may be hosted in the United States or other regions where our providers operate. If you use the product from elsewhere, you understand that processing may happen outside your country, including places with different data-protection rules.
California and similar privacy laws
We do not sell personal information as that term is commonly used in California law, and we don't share it for cross-context behavioral advertising. Depending on your situation you may have rights to know, delete, or correct certain personal information we hold. Use the contact options below to make a request. We won't discriminate against you for exercising those rights.
Changes
If we change this policy, we'll update the date at the top. For material changes to how optional cloud features work, we'll try to surface a notice in the product or on the site when that's practical. Keep using the cloud features after a change means you accept the updated policy for those features.
Contact
Privacy questions and data requests: open an issue at github.com/neelsatyavolu/agmux/issues. Teams-specific disclosure is at teams.agmux.dev/#/privacy. Related: Terms of service.