Privacy Policy
Last updated: 20 August 2026
Offsite is a terminal and remote-development client for iOS, macOS and watchOS. It connects to servers that you control and does not run any account system of its own. This policy explains what data the app handles and who, if anyone, it is shared with.
Data that stays on your device
The server connection details you enter (hostnames, usernames, ports) and any credentials such as passwords or SSH keys are stored encrypted in the iOS Keychain on your device. They are used only to establish your own SSH connections and are never transmitted to us or to any third party other than the server you choose to connect to.
Push notifications
If you enable notifications, Offsite uses Firebase Cloud Messaging (a Google service) to deliver alerts about your sessions, for example when a coding agent finishes a turn or needs your input. To do this, a device push token (an identifier tied to your app installation) is processed. It is not linked to your identity and is not used for advertising or tracking.
A notification has to be readable text, so it is not encrypted end to end. It carries the name of the session and of the workspace it belongs to, the event type, a timestamp, and identifiers for your host, workspace and session. For example "api-refactor needs your input". Note that agent sessions can name themselves after the work they are doing; you can rename any session, which always overrides that. Nothing else travels: no terminal output, no code, no prompts, no file contents, no paths. Notifications are also only sent to a device that is not currently connected in the foreground. While the app is open and attached, the same event arrives over your own encrypted connection.
Feedback you send us
If you use the feedback form in the app, what you typed is transmitted to us, together with the platform, the app version, an optional screenshot you attach and an optional email address if you want an answer. It is stored on our Firebase project and forwarded to our private team channel. Nothing is sent unless you press send.
Crash and diagnostic data
None is collected. Offsite contains no crash reporter and no analytics SDK; an earlier version used Firebase Crashlytics and it was removed in July 2026.
Voice dictation (optional)
If you use the optional voice-to-text feature, the audio you record is sent to OpenAI's API for transcription using the API key you configure. That audio is processed under OpenAI's own privacy terms and is not stored by Offsite. If you never use dictation, no audio ever leaves your device.
What we do not do
- No accounts, no sign-up, no profile.
- No advertising and no third-party analytics or tracking SDKs.
- We never sell or rent your data.
Third-party services
- Google Firebase (Cloud Messaging, plus storage for feedback you send): firebase.google.com/support/privacy
- Discord (only feedback you send, forwarded to our private team channel): discord.com/privacy
- OpenAI (only if you use voice dictation): openai.com/policies/privacy-policy
Retention and your choices
Credentials and settings live on your device and are removed when you delete the app. You can turn off notifications at any time in iOS Settings or per device in Offsite, which stops push-token processing. Feedback you sent us stays until you ask us to delete it; email the address below.
Children
Offsite is a developer tool and is not directed to children under 13.
Changes
If this policy changes, the updated version will be posted on this page with a new date.
Contact
Questions about privacy? Email robin@offsite.sh.