Privacy Policy
Effective August 17, 2026 · Last updated September 14, 2026
Armadai is built local-first. Your projects, terminals, session recordings, browsing, and everything your agents do stay on your Mac. An email account is required to use Armadai. This policy explains the limited data we handle when you sign in, request a download link, use account features, visit the website, or contact us.
1. Who this covers
This Privacy Policy applies to the Armadai macOS application, the armadai.sh website, and the account and licensing services that support them (together, “Armadai,” “we,” “us”). It does not cover third-party products you choose to run inside Armadai — such as AI coding agents, websites you browse, or code repositories you connect — which are governed by their own providers’ policies.
2. Information we collect
We deliberately collect as little as possible. The categories below are the whole of it.
Account information
Armadai requires your email address. We send a one-time code to that address; there is no password. We store your email and the authentication state needed to keep you signed in.
Subscription & billing
Payments are processed by Stripe. Checkout happens in your web browser, on Stripe’s pages — the app never sees or stores your card number. We receive from Stripe the information needed to manage your subscription (for example, plan, status, trial and renewal dates, and a customer identifier), not your full payment details.
Requested download emails
If you ask us to email a download link, we use your email to send that one message through Resend. This does not create an account or enroll you in marketing. We keep the request, delivery status, campaign tags, and whether its link was opened for 30 days, with daily cleanup. A keyed hash of the requesting IP address is used to limit abuse; the request table does not store the IP address itself.
Support communications
If you email us, we keep your message and contact details to respond and to improve the product.
Website & app operational data
Our website host and backend keep standard technical logs (such as IP address and request metadata) to operate the service securely and prevent abuse. The app contacts our servers to check for product updates and, to authenticate your account and check your plan entitlement.
3. What stays on your device
The core of Armadai runs entirely on your Mac. The following never leave your device through Armadai, and we cannot see them:
- Your code & projects
- Files you open, edit, or build stay in your local file system.
- Terminals & agents
- Terminal output and agent sessions run locally. Anything sent to an AI provider is sent by that agent’s own tool, under its own policy — not by Armadai.
- Session recordings
- Off by default. When enabled, recordings are stored only on your Mac (see below).
- Browsing
- Browser tiles keep cookies, history, and site data locally in the app’s storage.
- Workspace state
- Your canvas layout, notes, and task boards are saved locally.
4. How we use information
We use the limited information we collect to:
- sign you in and keep your session secure;
- create and manage your subscription, trial, and renewals;
- send a download link you request and provide customer support;
- measure aggregate website visits, demo plays, download starts, and verified signups to improve the download experience;
- operate, secure, and improve the service and prevent fraud or abuse;
- comply with legal obligations.
We do not sell your personal information. When you allow optional website measurement, X receives website-event and browser information to help attribute visits and downloads to ads. Email addresses and app workspace content are not sent to X.
5. Session recording
Armadai can record a terminal’s output so a work session can be turned into a provenance record. This feature is off by default and asks for your consent the first time. When it is on:
- only terminal output is saved — never the keystrokes you type;
- recordings are written only to your Mac, in a private folder, and are never uploaded by Armadai;
- you can turn recording on or off at any time, and delete, export, or set automatic retention and disk limits from Settings.
Because terminal output can include commands, file paths, and secrets printed to the screen, you control whether it is captured and how long it is kept.
6. Third-party services
We rely on a small number of providers to run Armadai. They process data only as needed to provide their service:
- Stripe — payment processing and subscription management.
- Supabase — authentication and subscription-entitlement backend.
- Vercel and Cloudflare — website hosting and installer delivery.
- Resend — delivery of requested emails.
- X — optional website advertising measurement, only with your permission.
Products you choose to use inside Armadai — for example AI agents (such as Claude Code or Codex), a code host you connect to publish a pull request, or websites you browse — send data according to their terms and privacy policies, not this one. Armadai facilitates those tools locally but is not their operator.
7. Cookies & analytics
We count website visits, demo plays, and download starts by date, device category, button, and campaign tags. These first-party aggregate counters do not store IP addresses, email addresses, browser fingerprints, or cross-visit user identifiers. A random event ID prevents counting the same event twice and is deleted after seven days. Campaign tags may be kept in your browser’s session storage for 30 minutes to connect a visit with its download button.
Optional X measurement is off until you select “Allow measurement.” X may then use cookies or similar browser identifiers to associate website visits and actions with ads, under X’s privacy policy. We do not send email addresses or app data to X. We respect Global Privacy Control signals by not loading X measurement. You can change your choice using “Privacy choices” on the homepage. Your choice is saved in local storage; required authentication and billing storage is separate.
Download-email requests can be matched to subsequently verified accounts with the same email for internal campaign reporting. Other signups remain unattributed. Campaign attribution is retained with the account until that account is deleted; the original email request is still removed after 30 days. These account-level matches are not sent to X.
8. Data retention
We keep account and subscription information for as long as your account is active and as needed to provide the service, meet legal and accounting obligations, and resolve disputes. Download-email requests and abuse-prevention hashes are removed by a daily cleanup after 30 days. Event deduplication IDs are removed by a daily cleanup after seven days. Aggregate totals may be retained without the underlying identifiers. Operational logs are kept for a limited period. Local data on your device — including recordings — is retained under your control and removed when you delete it or per the limits you set.
9. Your rights & choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:
- manage or cancel your subscription through the customer portal;
- sign out to remove your stored credentials from your device;
- delete local data — recordings, browser data, and workspace state — from within the app;
- contact us to request access to or deletion of the account data we hold.
We will respond to verified requests as required by applicable law. We will not discriminate against you for exercising these rights.
10. Security
We use reasonable technical and organizational measures to protect your data, including encrypted transport, scoped credentials, and local files written with restrictive permissions. No system is perfectly secure, but we design Armadai to keep the most sensitive material — your code and terminal activity — on your device rather than on our servers.
11. Children
Armadai is intended for professional developers and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, please contact us and we will delete it.
12. Changes to this policy
We may update this policy as Armadai evolves. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of Armadai after an update means you accept the revised policy.
13. Contact us
Questions about privacy, or a request about your data? Email privacy@armadai.sh. For general support, support@armadai.sh.