Privacy Policy

Effective 10 October 2026

PocketConsole is an iPhone app for working on your own servers over SSH, including running Claude Code on them. This policy explains what the app and its small notification relay do with your data. If you have a question, email pocketconsole.app@gmail.com.

The short version

On your iPhone

Claude Code and other tools on your server

PocketConsole doesn't send anything to an AI service itself. Claude Code, made by Anthropic, runs on your own server under your own Claude account. Prompts, files and attachments you send to it from PocketConsole go to your server over SSH, and Claude Code sends them to Anthropic under Anthropic's terms and privacy policy. The same goes for any other tool you run on your server, such as the GitHub CLI: it works under that service's own terms.

When you sign Claude Code or the GitHub CLI in, PocketConsole shows their own sign-in page in a browser inside the app. What you enter there goes to Anthropic or GitHub, not to us. For Claude, PocketConsole reads only the one-time code shown at the end and types it into Claude Code on your server.

Notifications and the relay

Notifications ("Claude needs your permission", "Claude finished") come from a small hook PocketConsole installs on your server when you turn notifications on for it. Apple only delivers an app's notifications from a service that holds the app's push key, so your server sends them through a relay we run at pocketconsole-relay.fly.dev. If you never allow notifications, the relay never hears from your iPhone.

What the relay stores

While notifications are allowed, PocketConsole registers with the relay each time it starts. The relay keeps one record for your iPhone, containing:

It also keeps:

Each server gets its own push credential. Credentials are sealed tokens that only the relay can open, so the relay doesn't need to store them, and doesn't. The app also sends its version number when it registers; the relay doesn't keep it. The records are stored with our database provider, Upstash, in the United States.

How long it's kept

What the relay can read

Notifications are end-to-end encrypted. The hook on your server encrypts each notification (title, message, server name, folder and session details) with a key shared only between your server and your iPhone. The relay and Apple pass along the encrypted message with a generic "New activity on your server" placeholder, and your iPhone decrypts it. The relay can't read your notifications; besides the encrypted message it sees only which iPhone it's for, an opaque grouping ID and whether it's time-sensitive.

Live Activities are not end-to-end encrypted. While Claude Code works, your server sends the relay its status (working, needs input, finished or error), the name of the tool it's using (such as Bash or Edit), how many tools it has used, when the turn started and was last updated, the random ID PocketConsole gave that server, and an opaque ID for the session. The relay passes these to Apple without storing them. The session name is encrypted. To turn Live Activities off, use the switch in PocketConsole's Settings → Notifications: from the next time the app starts, the relay has no way to start new ones on your iPhone.

IP addresses

The relay receives the IP address of every request, from your iPhone and from your server when it sends a notification. Your iPhone's IP address is used only to limit how often registrations can be made, in a counter held in the relay's memory for about an hour. IP addresses aren't stored in the database or written to logs.

Logs

The relay logs only error messages, without push tokens, IP addresses or notification content. Our host keeps them for no more than 30 days.

Subscriptions

Payment is handled by Apple; we never see your payment details. PocketConsole uses RevenueCat (RevenueCat, Inc.) to check whether your subscription is active. RevenueCat receives an anonymous app user ID it generates, your App Store purchase and transaction history, and basic device information (app version, iOS version, device model, locale and country, and IP address), under RevenueCat's privacy policy. None of it is linked to your name or email. You can manage or cancel your subscription in iOS Settings → [your name] → Subscriptions.

DigitalOcean

This only applies if you choose to create a server on DigitalOcean from the app. The API token you paste is sent only from your iPhone to DigitalOcean's API. PocketConsole saves it in this iPhone's Keychain (on this device only, not synced) so it can delete that server for you later, and erases it when you remove the server from the app. It's never sent to us. Creating the server adds PocketConsole's SSH public key to your DigitalOcean account.

Service providers

Each receives only what's described above.

Children

PocketConsole is a developer tool. It isn't directed at children under 13 (or the minimum age in your country), and we don't knowingly collect children's data.

Your choices

Changes

If this policy changes, the new version will appear here with a new effective date, and significant changes will be noted in the app's release notes.