Privacy Policy
Last updated August 28, 2026
The short version
Codeaton shows what your coding agents are doing. To do that it needs to know an agent’s name, its state, and a short message. It does not need your code, and it never asks for it.
What we collect
Account information
Authentication is handled by Clerk. We store the identifier Clerk issues for your account so we can associate your agents with you. Your email address and any login credentials are held by Clerk under their privacy policy, not by us.
Agent status
Every event your agents send may include:
- An agent key, display name, host name and kind (for example
claude-code@macbook) - A state — started, progress, tool call, waiting for input, completed, failed or idle
- A short human-readable message, truncated to 200 characters
- An optional progress value between 0 and 100
- Timestamps
Run metrics
When a run finishes, an agent may report tokens consumed and produced, cached tokens, the model used, how many tools it called, how many files it changed, and how long it took. These are used to compute your usage totals and Rankings.
Credentials
API keys are stored only as SHA-256 hashes; we cannot recover the plaintext of a key after it is created. Pairing codes are short-lived and single-use.
What we deliberately do not collect
There is no field anywhere in the Codeaton API for source code, diffs, file contents, prompts, or model output. We do not read your repository, we do not receive your terminal output, and we have no mechanism to do so. Please note that the free-text message field is written by your own agent configuration — if you put sensitive content in it, that content reaches us and appears on your Lock Screen.
How it is used
- To display live status on your paired devices
- To compute usage totals and Rankings
- To operate, secure and debug the service
We do not sell your data, we do not use it for advertising, and we do not use your agent activity to train machine learning models.
Processors
- Clerk — authentication and account management
- Convex — database and backend hosting
- Apple — delivery of push notifications and Live Activity updates to your device
Retention
Event history is retained according to your plan — 24 hours on Free, 30 days on Pro, 90 days on Team — after which events are deleted. Aggregate usage totals persist while your account is open. Deleting your account removes your agents, events, runs, usage records and keys.
Your choices
- Revoke any API key at any time from the dashboard
- Unpair a device, which stops all delivery to it
- Request access to, export of, or deletion of your data by emailing bryce@brycedev.com
Children
Codeaton is a developer tool and is not directed at children under 13. We do not knowingly collect information from them.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects what we collect, notify account holders directly.
Contact
Questions about this policy: bryce@brycedev.com