Privacy Policy

Last updated: September 11, 2026

1. Introduction

This policy covers the iPhone and iPad app, the Mac, Linux and Windows companion servers, and the account and web services. Your projects run on your own computer. Optional account, Relay, notification and analytics features process the data described below.

The data controller is Shanghai TacticSpace Technology Co., Ltd. You can contact us at [email protected].

Tactic Remote is provider-neutral. You choose, install, and configure any compatible AI coding agent or service. Your use of each third-party service is governed by your agreement with that provider.

2. Data handling

Tactic Remote uses a local-first architecture:

  • The Mac server runs entirely on your own machine.
  • In LAN mode, the iOS app connects directly to your Mac server.
  • When you choose Tactic Relay, application frames are end-to-end encrypted between your client and host before crossing our relay. The relay processes routing metadata, timestamps, and ciphertext sizes, but cannot read plaintext session content and does not store session content.
  • Your repositories remain on the host. We do not receive plaintext code, terminal output, prompt content, or command text through LAN or Tactic Relay.
  • When you sign in, Google Cloud Identity Platform processes your sign-in credentials. We and this authentication provider store your email address, verification status, account identifiers, sign-in provider and display name when supplied. Our account service also stores public passkey credentials, hashed session tokens, device identifiers and names, linked host metadata, and security timestamps. These data are linked to your account and used for sign-in, account management, computer binding, access revocation and security, not advertising or tracking. Our email delivery provider processes the recipient address and authentication email when such an email is requested. Account and identity records are retained for account operation; use account settings to request deletion or contact support for authentication-provider record deletion. Signing out does not delete an account. Agent credentials, private passkey keys and plaintext remote sessions are not stored by the account service.
  • Account settings let you request deletion. Account sessions and managed Relay access are locked immediately; account and public passkey data are deleted after Relay credentials are durably revoked. Expired ceremonies are removed at expiry, revoked or expired sessions after 7 days, unused invitations after 30 days, and redeemed invitation metadata after 90 days. A pseudonymous Relay revocation tombstone remains to prevent stale credentials from restoring access. Deletion does not erase local data on your devices.
  • Our apps, servers, and CLI include limited pseudonymous product-improvement telemetry, described below; website analytics are described in Section 10.

Optional push notifications: If you enable notifications, our push service and the relevant system push provider process a random host identifier, authentication data, notification settings, the current notification payload, and either an APNs device token or a browser PushSubscription endpoint with its public encryption keys. Registrations remain until you disable or revoke notifications, unsubscribe, the provider reports them invalid, or you request deletion. Notification payloads are not added to the registration database. Persistent routing state is encrypted at rest, and hosted logs do not contain subscription endpoints, encryption keys, project names, session names, or token fragments.

Optional Cloud Speech-to-Text: If you manually enable the Cloud STT dictation engine in Settings, audio recordings are sent to a cloud speech-recognition provider for transcription. To support local data-protection and data-residency requirements, the provider and processing region may differ depending on your country or region. Audio is processed only to return the transcript and is not stored by us or used for product analytics. This feature is off by default. The default dictation engine uses Apple's on-device speech recognition and does not send audio externally.

Optional product analytics: Only after you confirm the in-product disclosure, our apps and connected server components may send limited pseudonymous feature-usage, reliability, performance, crash, app-version, device-class, OS-version, and subscription-tier data to our product-analytics processor in the EU. After consent, analytics includes a normalized country or region code and its source, and app language. The app derives country or region from the App Store storefront or device region; the website uses edge geolocation. Raw storefront, device-region, locale, preferred-language, timezone, and IP values are not analytics properties. We do not send code, prompts, commands, terminal output, file paths, project names, direct identifiers, or advertising identifiers, and we do not use this data for advertising or cross-app tracking. Events are retained for up to 12 months and pseudonymous profiles for up to 24 months, or for a shorter period where required by applicable law. Processing and retention follow the requirements that apply in your country or region. Where applicable law requires a separate notice or choice before a cross-border transfer, we provide it before transmission. You may decline or later turn sharing off in Settings > Product Improvement; servers and the CLI also support --no-telemetry or TACTICREMOTE_TELEMETRY=0.

3. Local Data Storage

The following data is stored locally on your devices:

  • iOS App: Server URL, API key, and connection preferences stored in the iOS Keychain.
  • Mac Server: API key, allowed paths, and server configuration stored in the macOS Keychain and Application Support folder.

This data is stored using system-provided secure storage and is never transmitted to us or to any third party by us.

4. Network Connections

Tactic Remote may establish the following network connections:

  • Direct Connection: Between your iOS device and Mac server over your local network.
  • Cloudflare Tunnel (Optional): If you configure remote access, traffic is routed through Cloudflare's network with TLS encryption.

We do not have access to your network traffic, Cloudflare account, or tunnel configuration.

5. In-App Purchases and Subscriptions

Tactic Remote offers optional in-app purchases, including auto-renewable subscriptions (Pro Monthly, Pro Yearly) and a one-time lifetime purchase (Pro Lifetime).

Payment processing: All payments are processed by Apple through the App Store. We do not collect, store, or have access to your payment card information or billing details. Payment data is handled solely by Apple in accordance with Apple's Privacy Policy.

Purchase verification: The app verifies purchases using Apple StoreKit. When you use a Tactic account to manage Pro purchases, the app also sends Apple-signed transaction information to our account service, which verifies the purchase with Apple to confirm its authenticity and current validity.

To establish purchase ownership, provide Pro features, and prevent duplicate claims, we retain account identifiers, product and transaction identifiers, the purchase environment, expiry or revocation status, and verification timestamps. Purchase ownership records remain after account deletion to prevent the same purchase from being claimed by another account. These records do not include payment card information. Contact our support team for information about retained purchase records.

Usage quota tracking: The free tier includes a monthly Cloud Speech-to-Text quota of 5 minutes. This counter is stored only on your device and is never transmitted to us or any third party.

6. Third-Party Services

Tactic Remote may work with third-party services you choose or enable. Review the privacy terms for the services you configure:

  • AI coding agents and provider services: Tactic Remote connects only to tools and accounts you choose and configure. We do not provide those services; their processing is governed by your agreement with the relevant provider.
  • Cloudflare Tunnel: An optional service for remote access. See Cloudflare's Privacy Policy.
  • Regional cloud speech recognition: An optional cloud dictation feature. When enabled, audio is sent to a speech-recognition provider and processing region selected for your country or region to support applicable data-protection and data-residency requirements.

7. Children's Privacy

The Services are not intended for children under 13, and we do not knowingly collect information from children under 13.

8. Security

We take security seriously. Tactic Remote includes these security measures:

  • API key authentication for all connections.
  • Path sandboxing to restrict file-system access.
  • TLS encryption for network communications.
  • Secure storage using system keychains.

If you discover a security vulnerability, contact [email protected].

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Services after a change means you accept the updated policy.

10. Website Usage Statistics

Our marketing website tacticremote.com uses pseudonymous analytics to understand general traffic patterns. After consent, events include the selected page language and normalized country or region information supplied by the edge network; we disable analytics GeoIP enrichment and do not include the visitor's IP address as an event property. We do not collect directly identifying information, prompt content, or command text through the website. Where required by law, we ask for your consent before any analytics scripts load. You can change your preferences at any time using the controls at the bottom of this page.

11. Contact Us

If you have questions about this Privacy Policy, contact [email protected].

Pro experience research

If you apply, we collect your contact email, device and software choices, Pro status, optional workflow description, application source, consent time, and review history. We store these in our Google Cloud hosted backend for selecting participants, research contact, and reward administration. Only authorized staff can access applications. Form answers are not sent to website analytics or included in internal alert emails. Applying does not subscribe you to marketing emails. We retain identifiable applications for the research and reward administration period. Contact [email protected] to withdraw or request deletion; we verify the request before removing personal records. Research applications are separate from product accounts, so account deletion does not automatically delete an application.

Current analytics choice: Not set