PhoneCode Privacy Policy

Last updated 10 July 2026

This policy explains how PhoneCode handles data. PhoneCode is an on-device AI coding client published by Deyan Todorov. The developer does not operate a PhoneCode backend and does not receive your prompts, files, credentials, or usage data.

1. Data stored on your device

PhoneCode stores API keys, Git credentials, and third-party sign-in tokens with Android Keystore-backed encryption. If secure storage is unavailable, PhoneCode does not save credentials. It also stores projects, workspace files, linked-folder references, chat history, configuration, settings, and any optional Linux packages you install.

Android cloud backup is disabled. Manual exports contain supported chats and settings, are not encrypted, and do not contain credentials.

2. Files and photos you choose

PhoneCode can access a file, photo, or folder only after you select it through Android's system picker. A linked folder remains accessible until you unlink it, revoke access, clear app data, or uninstall PhoneCode. According to your settings and instructions, the agent may read, create, change, rename, or delete content within that folder.

Files remain on your device unless you direct the agent to send relevant content to an AI provider, Git host, search service, MCP server, or another destination.

3. Services you choose

PhoneCode does not contain an AI model. The app sends your prompt and necessary context directly to the provider you select. This may include text, source code, attachments, tool results, and content the agent reads from an app workspace or linked folder. You may connect a supported provider, ChatGPT, a Git host, or a custom endpoint. Credentials are sent only to authenticate with the service they belong to.

The selected service's privacy policy, retention rules, and terms apply once it receives data. These transfers are optional and initiated by features you choose. The developer cannot access or delete data held by those services.

4. Other network requests

Depending on the features you use, PhoneCode may connect to Git hosts, DuckDuckGo or a model's search service, models.dev for public model metadata, Alpine Linux package repositories, and MCP or custom servers you configure. Prompts and workspace files are not included when refreshing metadata from models.dev. Receiving services can see normal network information such as your IP address.

5. Developer collection

PhoneCode contains no advertising SDK, analytics, telemetry, or remote crash reporting. The developer does not receive or sell personal data from the app. User-directed transfers to third-party services are described above.

6. Security

Credentials use Android Keystore-backed encryption and are excluded from exports. Connections use HTTPS where supported. Custom endpoints and software installed by the agent are under your control and may have different security properties. Revoke provider credentials if you believe they were exposed.

7. Retention and deletion

Local data remains until you delete it in PhoneCode, clear app storage, or uninstall the app. Unlinking a folder removes saved access but does not delete the folder. To access or delete data held by a third party, use that service's controls. PhoneCode has no account of its own.

8. Children

PhoneCode is not directed to children under 13. You must also meet the age requirements of every service you connect.

9. Changes and contact

This policy may change as PhoneCode changes. For privacy questions, use the contact form. You can also visit the source repository.