Legal

Privacy Policy

Last updated August 28, 2026

The short version

Codeaton shows what your coding agents are doing. To do that it needs to know an agent’s name, its state, and a short message. It does not need your code, and it never asks for it.

What we collect

Account information

Authentication is handled by Clerk. We store the identifier Clerk issues for your account so we can associate your agents with you. Your email address and any login credentials are held by Clerk under their privacy policy, not by us.

Agent status

Every event your agents send may include:

  • An agent key, display name, host name and kind (for example claude-code@macbook)
  • A state — started, progress, tool call, waiting for input, completed, failed or idle
  • A short human-readable message, truncated to 200 characters
  • An optional progress value between 0 and 100
  • Timestamps

Run metrics

When a run finishes, an agent may report tokens consumed and produced, cached tokens, the model used, how many tools it called, how many files it changed, and how long it took. These are used to compute your usage totals and Rankings.

Credentials

API keys are stored only as SHA-256 hashes; we cannot recover the plaintext of a key after it is created. Pairing codes are short-lived and single-use.

What we deliberately do not collect

There is no field anywhere in the Codeaton API for source code, diffs, file contents, prompts, or model output. We do not read your repository, we do not receive your terminal output, and we have no mechanism to do so. Please note that the free-text message field is written by your own agent configuration — if you put sensitive content in it, that content reaches us and appears on your Lock Screen.

How it is used

  • To display live status on your paired devices
  • To compute usage totals and Rankings
  • To operate, secure and debug the service

We do not sell your data, we do not use it for advertising, and we do not use your agent activity to train machine learning models.

Processors

  • Clerk — authentication and account management
  • Convex — database and backend hosting
  • Apple — delivery of push notifications and Live Activity updates to your device

Retention

Event history is retained according to your plan — 24 hours on Free, 30 days on Pro, 90 days on Team — after which events are deleted. Aggregate usage totals persist while your account is open. Deleting your account removes your agents, events, runs, usage records and keys.

Your choices

  • Revoke any API key at any time from the dashboard
  • Unpair a device, which stops all delivery to it
  • Request access to, export of, or deletion of your data by emailing bryce@brycedev.com

Children

Codeaton is a developer tool and is not directed at children under 13. We do not knowingly collect information from them.

Changes

If this policy changes materially we will update the date at the top of this page and, where the change affects what we collect, notify account holders directly.

Contact

Questions about this policy: bryce@brycedev.com