POCKETSHELL // PRIVACY · POLICY · EFFECTIVE 2026-05-07 · UPDATED 2026-07-10
Privacy Policy
PocketShell prefers authenticated WebRTC between your phone and host. Direct and TURN-relayed WebRTC traffic is protected by DTLS end to end. While WebRTC is starting or unavailable, terminal and coding-agent traffic can use a WSS/TLS fallback that our application servers can read while relaying.
Our backend handles sign-in, pairing, WebRTC coordination, subscriptions, presence, alerts, lightweight metric history, and fallback paths. We collect the account, device, connection, audit, and service data needed for those functions.
Who we are
The data controller for PocketShell is A.G. Software Technologies, based in Lucknow, India. We do not currently have an EU representative; if you are in the EEA and wish to exercise your rights, write to support@pocketshell.app.
Privacy contact: support@pocketshell.app
Support contact: support@pocketshell.app
What we collect
Account data, device identifiers and public keys, connection metadata, bounded audit events, subscription data, and lightweight background snapshots used for presence, alerts and history. Background snapshots exclude process tables, command lines and logged-in users.
Content paths and fallbacks
Terminal and agent traffic normally uses WebRTC/DTLS, but can use a server-readable WSS/TLS fallback. File data uses WebRTC when available; signaling operations normally add an X25519/HKDF/ChaCha20-Poly1305 envelope, but paths, listings and small operations can become server-readable if file key exchange fails. Large streaming transfers require WebRTC.
Your rights
Under GDPR and CCPA you have the right to access, rectify, erase, restrict, object to processing, and receive a portable copy of your data. Exercise these rights in-app at Settings → Account → Delete Account, or by emailing support@pocketshell.app. We respond within 30 days.
Cookies & analytics (website)
The marketing site uses Google Analytics 4 behind a consent banner (deny-by-default via Google Consent Mode v2). The analytics cookie is only set after you click Accept; declining leaves the site cookieless. Google Analytics is not present in the mobile app. To revisit your choice, clear ps_consent_v1 from local storage for pocketshell.app and reload.
Account deletion
Settings → Account → Delete Account performs a synchronous cascade delete: every host unpaired, every device revoked, push tokens removed, audit-log PII scrubbed. A minimal hashed tombstone is retained for fraud prevention.
Enable JavaScript for the full document. The full text is identical and is also available by emailing support@pocketshell.app.