armadai
Features Coordinate Tiles
Download
Legal

Privacy Policy

Effective August 17, 2026 · Last updated September 14, 2026

Armadai is built local-first. Your projects, terminals, session recordings, browsing, and everything your agents do stay on your Mac. An email account is required to use Armadai. This policy explains the limited data we handle when you sign in, request a download link, use account features, visit the website, or contact us.

The short version. We collect your email to sign you in and subscription details to manage your access. You can also request a one-time download email without creating an account. We never see your code, your terminal output, your recordings, or your browsing — those live only on your device. We don’t sell your data. Optional X website measurement runs only when you allow it; we never send your email, code, or terminal content to X.

Contents

  1. Who this covers
  2. Information we collect
  3. What stays on your device
  4. How we use information
  5. Session recording
  6. Third-party services
  7. Cookies & analytics
  8. Data retention
  9. Your rights & choices
  10. Security
  11. Children
  12. Changes to this policy
  13. Contact us

1. Who this covers

This Privacy Policy applies to the Armadai macOS application, the armadai.sh website, and the account and licensing services that support them (together, “Armadai,” “we,” “us”). It does not cover third-party products you choose to run inside Armadai — such as AI coding agents, websites you browse, or code repositories you connect — which are governed by their own providers’ policies.

2. Information we collect

We deliberately collect as little as possible. The categories below are the whole of it.

Account information

Armadai requires your email address. We send a one-time code to that address; there is no password. We store your email and the authentication state needed to keep you signed in.

Subscription & billing

Payments are processed by Stripe. Checkout happens in your web browser, on Stripe’s pages — the app never sees or stores your card number. We receive from Stripe the information needed to manage your subscription (for example, plan, status, trial and renewal dates, and a customer identifier), not your full payment details.

Requested download emails

If you ask us to email a download link, we use your email to send that one message through Resend. This does not create an account or enroll you in marketing. We keep the request, delivery status, campaign tags, and whether its link was opened for 30 days, with daily cleanup. A keyed hash of the requesting IP address is used to limit abuse; the request table does not store the IP address itself.

Support communications

If you email us, we keep your message and contact details to respond and to improve the product.

Website & app operational data

Our website host and backend keep standard technical logs (such as IP address and request metadata) to operate the service securely and prevent abuse. The app contacts our servers to check for product updates and, to authenticate your account and check your plan entitlement.

3. What stays on your device

The core of Armadai runs entirely on your Mac. The following never leave your device through Armadai, and we cannot see them:

Your code & projects
Files you open, edit, or build stay in your local file system.
Terminals & agents
Terminal output and agent sessions run locally. Anything sent to an AI provider is sent by that agent’s own tool, under its own policy — not by Armadai.
Session recordings
Off by default. When enabled, recordings are stored only on your Mac (see below).
Browsing
Browser tiles keep cookies, history, and site data locally in the app’s storage.
Workspace state
Your canvas layout, notes, and task boards are saved locally.

4. How we use information

We use the limited information we collect to:

  • sign you in and keep your session secure;
  • create and manage your subscription, trial, and renewals;
  • send a download link you request and provide customer support;
  • measure aggregate website visits, demo plays, download starts, and verified signups to improve the download experience;
  • operate, secure, and improve the service and prevent fraud or abuse;
  • comply with legal obligations.

We do not sell your personal information. When you allow optional website measurement, X receives website-event and browser information to help attribute visits and downloads to ads. Email addresses and app workspace content are not sent to X.

5. Session recording

Armadai can record a terminal’s output so a work session can be turned into a provenance record. This feature is off by default and asks for your consent the first time. When it is on:

  • only terminal output is saved — never the keystrokes you type;
  • recordings are written only to your Mac, in a private folder, and are never uploaded by Armadai;
  • you can turn recording on or off at any time, and delete, export, or set automatic retention and disk limits from Settings.

Because terminal output can include commands, file paths, and secrets printed to the screen, you control whether it is captured and how long it is kept.

6. Third-party services

We rely on a small number of providers to run Armadai. They process data only as needed to provide their service:

  • Stripe — payment processing and subscription management.
  • Supabase — authentication and subscription-entitlement backend.
  • Vercel and Cloudflare — website hosting and installer delivery.
  • Resend — delivery of requested emails.
  • X — optional website advertising measurement, only with your permission.

Products you choose to use inside Armadai — for example AI agents (such as Claude Code or Codex), a code host you connect to publish a pull request, or websites you browse — send data according to their terms and privacy policies, not this one. Armadai facilitates those tools locally but is not their operator.

7. Cookies & analytics

We count website visits, demo plays, and download starts by date, device category, button, and campaign tags. These first-party aggregate counters do not store IP addresses, email addresses, browser fingerprints, or cross-visit user identifiers. A random event ID prevents counting the same event twice and is deleted after seven days. Campaign tags may be kept in your browser’s session storage for 30 minutes to connect a visit with its download button.

Optional X measurement is off until you select “Allow measurement.” X may then use cookies or similar browser identifiers to associate website visits and actions with ads, under X’s privacy policy. We do not send email addresses or app data to X. We respect Global Privacy Control signals by not loading X measurement. You can change your choice using “Privacy choices” on the homepage. Your choice is saved in local storage; required authentication and billing storage is separate.

Download-email requests can be matched to subsequently verified accounts with the same email for internal campaign reporting. Other signups remain unattributed. Campaign attribution is retained with the account until that account is deleted; the original email request is still removed after 30 days. These account-level matches are not sent to X.

8. Data retention

We keep account and subscription information for as long as your account is active and as needed to provide the service, meet legal and accounting obligations, and resolve disputes. Download-email requests and abuse-prevention hashes are removed by a daily cleanup after 30 days. Event deduplication IDs are removed by a daily cleanup after seven days. Aggregate totals may be retained without the underlying identifiers. Operational logs are kept for a limited period. Local data on your device — including recordings — is retained under your control and removed when you delete it or per the limits you set.

9. Your rights & choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:

  • manage or cancel your subscription through the customer portal;
  • sign out to remove your stored credentials from your device;
  • delete local data — recordings, browser data, and workspace state — from within the app;
  • contact us to request access to or deletion of the account data we hold.

We will respond to verified requests as required by applicable law. We will not discriminate against you for exercising these rights.

10. Security

We use reasonable technical and organizational measures to protect your data, including encrypted transport, scoped credentials, and local files written with restrictive permissions. No system is perfectly secure, but we design Armadai to keep the most sensitive material — your code and terminal activity — on your device rather than on our servers.

11. Children

Armadai is intended for professional developers and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, please contact us and we will delete it.

12. Changes to this policy

We may update this policy as Armadai evolves. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of Armadai after an update means you accept the revised policy.

13. Contact us

Questions about privacy, or a request about your data? Email privacy@armadai.sh. For general support, support@armadai.sh.

↑ Back to top

armadai
Privacy Terms X
© 2026 armadai.sh