Privacy Policy
DevTool for iOS lets you follow and answer the coding agents running in the DevTool desktop app. It has no accounts, no ads, no analytics and no third-party SDKs. This page explains what data exists, where it lives and who can see it.
End-to-end encryption
Your phone and your desktop talk through a relay server, relay.devtool.awantech.sk, unless you set up your own. Everything they exchange — project, task and tab names, agent status, chat transcripts, your replies and approvals — is encrypted on one device and decrypted only on the other (Noise protocol, keys created on your devices when you pair). The relay forwards the encrypted messages and cannot read or change them.
On your phone
- Device keys. The app creates its own keys on first launch and keeps them in the iOS Keychain, on this device only.
- Pairings. For each paired desktop: its name, public key and relay address.
- Offline copy. The last inbox of each desktop and the latest part of recently opened chats, so you can read them while the desktop is offline. This stays in the app's storage and is deleted when you remove the desktop in the app or delete the app.
- Camera. Used only to scan the pairing QR code. No image is saved or sent.
- Face ID. If you turn on “Require Face ID for approvals”, iOS checks your face or passcode. The app only learns whether the check passed.
On the relay
To route messages, the relay necessarily sees:
- device IDs and public keys of desktops and phones, and which phone is paired with which desktop;
- IP addresses, connection times, and the size and timing of encrypted messages.
It stores only the list of pairings (device IDs, public keys and when they were made) until the desktop unpairs the phone. Its logs contain device IDs, IP addresses and connection events, never message contents, and are rotated so that only recent entries are kept. They are used only to run the service and investigate faults.
Push notifications
If you enable notifications, iOS gives the app an Apple push token. The app sends it to the DevTool push gateway (part of the relay), which seals it with a key only the gateway knows and hands the sealed value back. The token itself is not stored by the gateway; it keeps only a counter per device so that older sealed values stop working.
When an agent needs you, your desktop encrypts the notification text for your phone. The gateway passes it to Apple, and your phone decrypts it on the device. Apple and the gateway see that a notification was sent, but not what it says — without the key, only the generic text “An agent needs you” is visible.
What we don't do
- No tracking across apps or websites, and no advertising.
- No selling or sharing of data with anyone.
- No access to your code, prompts or chats — they never leave your devices unencrypted.
Your choices
- Remove a desktop in the app to delete its pairing and cached data from the phone. Unpair the phone in the desktop's Settings → Mobile to remove the pairing from the relay as well.
- Turn notifications off, or per category, in the app's Settings.
- Run your own relay: the relay is open source and the app accepts any relay address in the pairing code.
- Delete the app to remove everything it stored on the phone.
Children
DevTool is a developer tool and is not directed at children.
Changes and contact
If this policy changes, the new version will be posted here with a new date. Questions or requests about your data: open an issue in the DevTool repository.