Core principle
BotBus task content is end-to-end encrypted: it is encrypted on your devices before it passes through the Relay, and the keys needed to decrypt it exist only on your devices. We cannot read it, and we do not use task content for advertising or AI model training. To sync your devices, the Relay temporarily stores encrypted data and a small amount of metadata, as described below.
Data flow
The agent on your computer reads local tasks. After pairing, task titles, status, recent output, project paths, device names, and action results are encrypted with a key shared by your group of devices (AES-256-GCM) before passing through Cloudflare Relay to your phone or watch. Full conversations are fetched only when you open them. Messages, images, and files you send, notification titles and bodies, and remote-control screens and input are encrypted the same way.
The key is handed to your phone through the QR code on your computer’s screen (or a pairing link you copy) and never passes through the Relay. It is then kept with your pairing credentials in each device’s system keychain. The Relay stores credential hashes needed for verification, pairing relationships, and encrypted sync snapshots, pending commands, and files.
The Relay can see only the metadata it needs to route data: pairing and device identifiers, online status, task and command identifiers and times, notification categories, and the size of each encrypted item. Developer previews (sharing a local web page from your computer to your phone) require the Relay to proxy web requests, so they are not end-to-end encrypted; they are reachable only while you share them.
Retention
Encrypted sync snapshots remain in the Relay while a pairing exists. If no device connects to a pairing for 30 consecutive days, its snapshots, commands, and conversation records are cleared. The latest on-demand conversation is available to the client for about five minutes, though its backend record may remain until replaced or the pairing is deleted. Uploaded images and files are deleted after seven days by default. The original task records on your computer remain under the relevant agent’s control.
AI services and permission before sending
BotBus remotely controls agents on your computer. When you start or continue a task, answer a question, or approve a task, your phone or watch encrypts the message, images, selected answers and command and sends them through the Relay to your paired computer. To perform the task, the computer's agent may send those contents, relevant conversation history, and code or files it reads to the AI model provider you configured. This may include personal information, used for model inference and carrying out your requested task.
Common default providers are OpenAI for Codex and Anthropic for Claude Code. Custom connectors, proxies, models or endpoints may use other providers. The actual recipient depends on your computer's agent configuration, which BotBus cannot automatically verify. Before each of these actions, including retries, the app explains the data and protection boundaries, asks you to verify or enter the actual provider and review its privacy policy, and requires you to choose “Agree and continue.” Cancelling, closing the confirmation or not confirming prevents the images for that operation from being uploaded and the command from being sent. You can still view existing records, interrupt or deny. Permission covers only that operation and is not synced with phone/watch pairing credentials. Viewing existing records does not initiate new AI inference through BotBus.
BotBus end-to-end encryption covers synchronization between your devices and the Relay, not requests from your computer's agent to its model provider. The model provider receives the plaintext needed to process the task. Storage, training use, retention and deletion depend on the service, account and configuration you use. Review the OpenAI Privacy Policy, Anthropic Privacy Policy, or your actual provider's policy. We require third parties with whom BotBus shares user data to provide the same or equal protection required by this policy and applicable rules. A model service configured by you is not a processor selected by BotBus, and we cannot guarantee its protections on its behalf. If you cannot confirm the recipient or equal protection, cancel and do not send personal information.
Third parties
Cloudflare hosts the Relay and likewise has access only to encrypted data and the metadata above. The iPhone and Android apps use Firebase Analytics for a fixed set of pairing and action events, without sending task content, messages, project paths, device names, or pairing codes. Firebase may process technical data such as app and device identifiers and app interactions. When Android notifications are enabled, the app registers a Firebase installation identifier with the Relay so it can route messages through Firebase Cloud Messaging (FCM). Firebase and Cloudflare process the identifiers and delivery metadata needed for push delivery; notification titles and bodies remain encrypted until your Android device decrypts them. The iPhone app sends information needed for delivery to Apple APNs; notification titles and bodies are encrypted and decrypted on your iPhone.
Website analytics
The botbus.io website uses Cloudflare Web Analytics to count visits. It sets no cookies, stores nothing in your browser, and does not record URL query strings; it only aggregates the pages visited, referring sites, country or region, and browser and device type.
When you download the installer from the website, or BotBus on your computer checks for and downloads an update, the website server records one download entry: the file name, whether it was a website download or an in-app update, the country or region as determined by Cloudflare, the page on this site where you clicked download, and the campaign parameters in that page’s address (utm_source, utm_medium, utm_campaign). The entry contains no IP address, cookie, or device identifier, is used only to count downloads and measure promotion, and is kept by Cloudflare for three months before being deleted automatically.
Your choices and data deletion
To delete a BotBus pairing’s sync data from the Relay, open Settings on a paired phone, choose “Unpair All,” and confirm. This clears that phone’s pairing credentials and asks the Relay to delete the pairing’s encrypted snapshots, commands, conversation records, and related metadata. If the Relay request fails, the phone warns that cloud data may remain; keep access to the paired computer and contact us using the address below for help. You can also remove an individual computer or phone in Settings to revoke its access.
Uploaded images and files are deleted when they expire, by default within seven days. Original task records saved on your computer by agents such as Codex or Claude Code are not deleted when you unpair BotBus; manage those records in the relevant agent. Firebase handles app analytics and push identifiers under its service rules. You can manage notification permission in your device settings.
To request help with deletion, email support@botbus.io. Tell us that you want to delete BotBus pairing data and whether you can still use a paired device. Do not email pairing codes, keys, or task content.
Contact
Questions about privacy or data deletion? Contact us at support@botbus.io. We will show a new effective date here when this policy changes.