Controller
Nikolai Skorobogatko
Belgrade, Serbia
Email: [email protected]
1. The short version
- Your projects, code, canvases, prompts, and agent conversations stay on your Mac. They never go to our server.
- Our server knows your email and your devices. That's what it needs for sign-in and updates.
- Remote control messages between your phone and your Mac are end-to-end encrypted. Our server passes them along and can't read them.
- The app has no analytics, telemetry, crash reporting, or ads.
- We don't sell your data.
2. Scope
This policy covers the Buzzpot desktop app, the phone web app at app.buzzpot.app, our server, the website at buzzpot.app, and email with us.
It doesn't cover the AI agent tools you run through Buzzpot (Claude Code, Codex, Grok CLI and others) or your email provider. They have their own privacy policies.
3. What stays on your Mac
Buzzpot stores its data in ~/Library/Application Support/Buzzpot:
- your canvases, cards, and agent conversations,
- your settings,
- your account details and sign-in session,
- a local log of recent agent runs (the last 50), used for troubleshooting.
This data doesn't leave your Mac, except as described in section 5 (Remote control). It's not included when you delete your account; see Delete your account.
What agents send to AI providers is up to the agent tools you use and their providers, not Buzzpot.
4. What our server stores
| Data | Why | How long |
|---|---|---|
| Email address | Sign-in, sign-in codes, account emails | Until you delete your account |
| Account dates (created, email confirmed, trial start and end) | Beta access | Until you delete your account |
| Devices: your Mac's name (as set in macOS, which may include your name), device type and platform, when it was last seen; for phones, a general name such as "iPhone" | Device limits, showing your devices, removing them | Until you delete your account, including devices you have removed |
| Sign-in sessions (stored only as secure hashes) | Keeping you signed in | Until you sign out, remove the device, or delete your account |
| Sign-in codes and phone pairing links (stored only as secure hashes) | Confirming sign-in and connecting a phone | Valid for 10 minutes; records kept until you delete your account |
| Phone notification subscription (the push address and keys from your phone's browser) | Sending notifications to your phone | Until you remove the phone or turn notifications off |
| Server error logs (no IP addresses) | Fixing errors | Rotated by size and cleared with every server update |
| Backups of the database | Recovery | 30 days |
Our server doesn't write IP addresses to its logs. To limit sign-in attempts, it counts recent requests per IP address in memory only; these counters are never saved.
If you type an email into the sign-in window, we create an account record for it, even if you never enter the code.
5. Remote control and notifications
Remote control is off by default. When you turn it on:
- your Mac shows a QR code. The key that encrypts messages is part of that code and is never sent to our server,
- messages between your phone and your Mac are encrypted (AES-256-GCM). Our relay passes them along, keeps them for at most 60 seconds for delivery, and can't read them,
- your phone's browser stores its session and the encryption key locally,
- phone notifications contain only a card's name (up to 120 characters) and whether the agent finished or is waiting for you. They pass through our server without being stored, and are delivered through your browser's push service (Apple, Google, or Mozilla, depending on your phone).
6. Other network requests the app makes
Besides our server, the app connects to:
- GitHub (github.com), to download updated agent definitions when it starts,
- our update storage (Cloudflare R2), to download app updates, only if updates are turned on,
- AI providers, to show your usage quotas. For Claude Code and Codex, the app asks the installed tools. For Grok, Buzzpot reads the xAI key from your Grok CLI settings on your Mac and sends it directly to xAI (cli-chat-proxy.grok.com) to read your remaining credits. The key isn't sent anywhere else or stored by us.
When you click "Send feedback" or "Report a bug", the app opens your email app or the public buzzpot-support issue tracker on GitHub. Anything you post there is public.
7. The website
- buzzpot.app uses self-hosted, privacy-friendly analytics (analytics.skorobogatko.com) (Umami) to count page views. It doesn't use cookies and isn't used for advertising or cross-site tracking.
- If you joined the beta list, your email is stored with Kit (ConvertKit). You can unsubscribe from any email. We only send Buzzpot news.
- The Download App button downloads the app from GitHub (github.com).
- Fonts are served from our own site.
8. Who else handles data
| Provider | What for | Data | Where |
|---|---|---|---|
| Hetzner | Server hosting | Everything in section 4 | Germany |
| Cloudflare | DNS, network protection, storage for backups and app updates | Traffic data including IP addresses; backups | Global network |
| Resend | Sending emails (sign-in codes, account deletion) | Email address, email content | USA |
| Apple, Google, Mozilla push services | Delivering phone notifications | Encrypted notification | Depends on your browser |
| GitHub | Agent definitions, public bug reports | IP address; what you post | USA |
| xAI | Your Grok quota, only if you use Grok CLI | Your xAI key, sent by your app | USA |
| Kit | Beta list | Email address | USA |
When data goes outside the European Economic Area, we rely on the provider's legal transfer safeguards, such as the EU–US Data Privacy Framework or Standard Contractual Clauses.
9. Deleting your account
You can delete your account in the app (Settings → Account → Delete account). We email you a link, valid for 24 hours. When you confirm, we delete immediately:
- your account and email address,
- all your devices, sessions, and phone connections,
- notification subscriptions, sign-in codes, and pairing links.
What stays:
- Backups for up to 30 days.
- Data on your Mac. Delete the folder
~/Library/Application Support/Buzzpotto remove it.
If you no longer have the app, email us. See Delete your account.
10. Why we process data (legal bases)
- Contract: your account, sign-in, updates, Remote control, and notifications.
- Legitimate interests: security, server logs, abuse prevention, backups, website analytics.
- Consent: the beta mailing list.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your data, to restrict or object to processing, and to withdraw consent. To use these rights, email [email protected]. We may need to confirm your identity first. We reply within one month.
You can also complain to the data protection authority in your country. In Serbia, that's the Commissioner for Information of Public Importance and Personal Data Protection.
12. What we don't do
We don't sell or rent your data, show ads, track you across apps or sites, profile you for marketing, or use your data to train AI models.
13. Children
Buzzpot isn't meant for children under 13. If we learn that a child under 13 has an account, we'll delete it.
14. Security
We use HTTPS everywhere, store sign-in codes and sessions only as hashes, encrypt Remote control messages end-to-end, limit access to our servers, and rate-limit sign-in attempts. No system is perfectly secure.
15. Changes
We may update this policy. If a change is significant, we'll update the date above and tell you in the app or by email.
16. Contact
Email: [email protected]
Controller: Nikolai Skorobogatko, Belgrade, Serbia