# Privacy policy

> What Clair's app, agent, relay and website collect, where it goes, how long it's kept, and how to have it deleted.

Effective September 25, 2026. Clair is an app for your Android phone and Wear OS watch, an agent for your computer, a relay that connects them, and this website. This policy covers all four. I build and run Clair myself, so "I" here means me, Jeffrey Walter Mixon.

## The short version

- Clair has no accounts. It never asks for your name, your email address or your Claude login.
- What Claude Code asks you is encrypted end to end between the Clair agent on your computer and the Clair app on your phone. The relay in between can't read it.
- The relay does see what it needs to deliver messages: which pairings are active, when and how much they send, IP addresses, and the push token that wakes your phone.
- Release builds of the phone and watch apps send crash reports and basic usage analytics to Google's Firebase unless you turn that off in their settings. There are no ads, and the apps don't use the advertising ID.
- This website sets no cookies. It counts page views and a few clicks, and measures how fast pages load, with Vercel's analytics, which keeps no ID in your browser.
- I don't sell your personal information or share it for advertising.

## Who is responsible

Clair is run by Jeffrey Walter Mixon, a sole proprietor in California. I decide how the data described here is used, which makes me its controller under laws like the GDPR. Privacy questions and requests go to privacy@claircode.app.

Clair is an independent app. It isn't made, sponsored or endorsed by Anthropic, and this policy doesn't cover Claude Code itself: what Claude Code sends to Anthropic falls under Anthropic's own terms and privacy policy, not this one.

## The Clair agent on your computer

The agent receives what Claude Code passes to its hooks and its status line. Depending on the event, that includes:

- the tool Claude wants to use and its input, such as a shell command, a file path or the text of an edit
- the questions and plans Claude puts to you
- the prompts you type, and Claude's last message at the end of a turn
- the session's id, working directory and model, and your token usage

It also reads your computer's name (the first part of its hostname) and how long you've been idle. On macOS and Linux, idle time comes from your terminal. On Windows it's the time since your last keyboard or mouse input anywhere on the desktop. The agent passes on a number of milliseconds and nothing about what you typed.

The agent seals all of this on your computer, so only your paired phone can open it, and sends it to the relay. It has no telemetry, analytics or crash reporting. Its one other connection is to claircode.app, to check for updates.

On your computer, the agent keeps its keys, its settings and the phones it's paired with in its config folder, and it writes a log. The log records ids, sizes, timings, errors and your phone's name, never the contents of a prompt. Before it changes Claude Code's `settings.json`, it saves a timestamped backup of the file beside it. None of this leaves your computer.

## The phone and watch apps

The phone app opens the sealed messages from your computer and shows them on the phone and, if you have one, the watch. It keeps a short history on the phone: your current sessions, their recent activity and any prompts waiting for you. A session is removed 10 minutes after it ends, and one that stays silent for 6 hours is ended.

What the phone sends back is sealed the same way: your answers, any reason you type or dictate, the phone's name and your delivery settings.

The phone passes prompts to the watch over Wear OS's own phone-to-watch connection, which Google Play services runs. Clair's encryption doesn't cover that hop.

To wake the phone when a message is waiting, the app gets a push token from Firebase Cloud Messaging and gives it to the relay. It holds a token only while a computer is paired through the relay. A push carries only the pairing's id and a position in its mailbox, never the message.

Clair has no microphone or camera permission. Dictation goes through your phone's keyboard or your watch's system input, so their speech service (usually Google's) handles the audio under its own terms. When you scan a pairing code, Google Play services' code scanner reads it and hands Clair only what the code says.

Pairing keys are stored encrypted under a key held in Android's keystore. Both apps opt out of Android backup, so nothing they store is copied to Google Drive or moved to a new phone.

## Crash reports and analytics

Release builds of the phone and watch apps use two Google services, Firebase Crashlytics and Google Analytics for Firebase:

- When the app crashes, Crashlytics sends a report with the stack trace, app version, device model, OS version and a Firebase installation ID. If the crash happened while the app was handling a prompt, the report can include part of it.
- Analytics records the events it collects on its own, such as the app being opened, updated or used for a while, or a subscription being bought, with the same installation ID, device and version details, and an approximate location worked out from your IP address. Clair doesn't log events of its own.

Advertising ID collection and ad personalization are switched off. I use these reports to find and fix bugs and to know roughly how many people use Clair.

Both are on until you turn them off. On the phone, switch off Send crash reports and usage data under Privacy in Clair's settings. The watch has its own switch, Send crash & usage data, in its settings, and each device keeps its own choice. Turning it off stops both Crashlytics and Analytics on that device, deletes crash reports still waiting there to be sent, and clears its analytics ID. Reports already sent stay in Firebase for the times listed under How long it's kept. The switch doesn't affect the push token that wakes your phone.

## The relay

The relay (relay.claircode.app) carries sealed messages between your computer and your phone, which often can't reach each other directly. It can't read or forge a prompt, a plan or an answer. To deliver messages and hold off abuse, it stores or sees:

- the public keys that identify your computer and phone, and the ids of their pairings
- each sealed message, until the other side collects it
- when each device was last active, and how many messages and bytes each pairing sends
- a hint on each message saying how urgently to wake the phone, which says nothing about what's inside
- your phone's push token
- the IP address each request comes from, and the app or agent version its User-Agent names

Rate limits keep an IP address in the relay's database for about an hour. The hosting platform also sees IP addresses in its request logs and firewall.

A pairing link opens a page on the relay if Clair isn't installed. That page has no scripts or analytics, and the pairing secret sits after the # in the link, a part browsers never send to a server.

## This website and downloads

claircode.app is a static site hosted by Vercel. It sets no cookies, serves its own fonts, and has no ads. Apart from its own code, it runs only Vercel's two measurement scripts, described below, which load from claircode.app itself. Vercel logs each request the way any web host does, with the IP address, the page, the time and the browser's User-Agent. I read those logs only to troubleshoot or to stop abuse.

The install scripts and every copy of the agent download from this site, which sees the same details. An installed agent checks claircode.app for updates a few minutes after it starts and about every six hours after that. Each check sends the computer's IP address and a User-Agent naming the agent's version, operating system and processor type. Setting `"autoUpdate": false` in `agent.json` stops the checks.

The site measures itself with Vercel Web Analytics and Vercel Speed Insights. Neither sets a cookie or keeps an ID in your browser. For each page you view, Web Analytics records the page's address, the site that linked you to it, your browser, operating system and device type, and your country, region and city, which Vercel works out from your IP address. Instead of a cookie, Vercel tells visitors apart with a hash made from the request, and discards each visitor's session after 24 hours. Web Analytics also records a few clicks by name:

- copying a command, with the command you copied
- following the Google Play link, or a button that leads to it or to the docs
- starting the trailer
- clicking an email address, with the address

None of these records anything you type. Speed Insights measures how quickly each page loads and responds, and records it with the page's address, your browser, operating system, device type, connection speed and country. I use both to see which pages people read, how they found the site, and where it's slow. Blocking scripts on claircode.app stops both.

## Email and subscriptions

If you email support@claircode.app or privacy@claircode.app, I get your address and whatever you send, such as what `clair status` prints. I use it to answer you, and keep it only while it helps with that or until you ask me to delete it.

Subscriptions are sold through Google Play. Google handles payment, so I never see your card details. Google gives me order details, such as the order number, date, price, and the buyer's country and region, which I keep for tax and accounting for as long as the law requires.

To know whether you can answer prompts, the phone app asks Google Play about your subscription. It keeps the answer on the phone, along with when you subscribed and whether it started as a free trial, and shows the status on your watch. It doesn't send any of this to the relay.

## Who else handles it

These service providers run parts of Clair for me and handle data only to do that:

| Provider | What it does |
| --- | --- |
| Vercel | Hosts this website and the relay, keeps their request logs, and runs this website's analytics. |
| Neon | Runs the relay's database. |
| Google Firebase | Delivers push notifications, and collects crash reports and analytics from release builds of the apps. |
| Google Play | Sells subscriptions, runs free trials, handles payment, cancellations and refunds, and delivers the app and its updates. |
| Google Play services | Carries prompts between your phone and watch, and reads pairing codes. |
| My email provider | Delivers and stores email to and from me. |

Beyond that, I share personal information only when the law requires it, to protect Clair and its users from fraud or abuse, or as part of a sale or transfer of Clair, in which case this policy keeps applying to it.

I don't sell personal information, and I don't share it for cross-context behavioral advertising.

## How long it's kept

| Data | Kept for |
| --- | --- |
| Sealed messages | Until the other side collects them, and never more than 24 hours. Revoking a pairing deletes the messages still waiting for the side that revoked it. |
| Pairings | Until revoked, then 30 days as a record that the pairing ended. A pairing where either side has been silent for 30 days is revoked automatically. |
| Push token | Until your phone has no pairings and hasn't contacted the relay for 30 days. |
| IP rate limits | About an hour. |
| Request logs | For Vercel's log retention period. |
| Website analytics | For Vercel's retention period for Web Analytics and Speed Insights. |
| Crash reports | 90 days, in Crashlytics. |
| Analytics | The retention period set in Firebase, at most 14 months. |
| Phone history | 10 minutes after a session ends. A session silent for 6 hours is ended. |
| Email | While it helps me answer you, or until you ask me to delete it. |
| Order records | As long as tax and accounting law requires. |
| Your devices | Until you delete it. The next section says how. |

## Your choices and rights

Clair has no accounts, so most of your data lives on your own devices and you control it directly:

- Revoke a computer in the phone app, or run `clair unpair` on the computer. Either one ends the pairing, deletes its keys on that device, and deletes the messages waiting for that device on the relay.
- `clair unpair` also takes Clair's hooks and status line back out of Claude Code's settings. To remove the agent completely, run `clair service uninstall`, then delete its config folder, its log, the `settings.json.bak-*` backups beside Claude Code's settings, and the `clair` program.
- Turn off crash reports and usage data in Clair's settings, separately on the phone and the watch.
- Uninstalling the app deletes everything it stored on your phone or watch. The relay revokes that phone's pairings once they've been silent for 30 days, and deletes its push token after that.

You can also ask me to access, correct, delete or export the personal information I hold about you, to restrict or object to how I use it, or to withdraw consent where I rely on it. Email privacy@claircode.app. I'll reply within 30 days, and I won't treat you any differently for asking.

Without accounts I usually can't link relay or Firebase data to you by name. To help me find yours, include what `clair status` prints, or your phone's model and roughly when you used Clair. I'll use those details only to handle your request.

If you're in the European Economic Area or the UK, you can also complain to your local data protection authority.

## Legal bases in the EEA and UK

- Performing our contract: pairing, delivering prompts and answers, push notifications, checking your subscription, updates and support.
- Legitimate interests: keeping the relay secure and free of abuse with rate limits and logs, finding bugs with crash reports and analytics, and seeing how this website is used and how fast it loads. You can object to these, and switch off crash reports and analytics yourself in the app.
- Legal obligation: keeping order records for tax.

## Where data is processed

I'm in the United States, and the relay runs in Vercel's region near Washington, DC. Google processes Firebase data in the United States and elsewhere. If you're outside the US, your data is transferred there, and where the law requires it, those transfers rely on the providers' standard contractual clauses.

## California residents

California law gives you the right to know what personal information I collect and why, to delete or correct it, and to opt out of its sale or sharing. The sections above say what I collect, where it comes from, why, and who handles it. In the law's categories, that's identifiers (IP addresses, device keys, push tokens and the Firebase installation ID), internet activity (request logs, and website and app analytics), approximate location worked out from IP addresses, commercial information (Google Play subscription and order records), and whatever you send me by email.

I don't sell or share personal information, and I don't use sensitive personal information to infer anything about you. Neither this site nor the relay tracks you across other sites, so Do Not Track and Global Privacy Control signals have nothing to switch off, and every visitor is treated the same either way.

You, or an agent you authorize, can make a request at privacy@claircode.app. I may ask for details to confirm the request is yours.

## Security

Prompts and answers are sealed with XChaCha20-Poly1305 between the agent and the phone, with keys agreed when you scan the pairing code, and the secret in that code never passes through the relay. Every request to the relay is signed, and the agent installs an update only if it's signed with the release key built into it.

No system is perfectly secure. If I learn of a breach that affects your personal information, I'll post a notice on this site and tell the authorities and the people affected as the law requires.

## Children

Clair is a tool for software developers and isn't directed at children under 13, or under 16 in the EEA and UK. I don't knowingly collect their personal information. If you think a child has sent me some, email privacy@claircode.app and I'll delete it.

## Changes to this policy

When the way Clair handles data changes, I'll update this page and its effective date. For a significant change, I'll also post about it in Updates before it takes effect. Ask me and I'll send you an earlier version.

[Clair updates](https://claircode.app/updates/index.md)

## Contact

Jeffrey Walter Mixon, at privacy@claircode.app. For help with the app or the agent, email support@claircode.app.

Canonical page: https://claircode.app/privacy-policy/
