Flockdeck

Privacy policy

Last updated: 13 September 2026

Flockdeck is made by Jim Wright, an individual based in the United Kingdom. This policy explains what personal data is involved when you use the Flockdeck desktop app, the Flockdeck relay at remote.flockdeck.ai, and this website, and what your rights are. Jim Wright is the controller of that data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have a question or a request, email privacy@flockdeck.ai.

The short version

The desktop app

The app runs entirely on your computer. It keeps its settings, layouts, conversations with built-in API agents, any API keys you give it, and a record of which models routing chose for a fan-out's tasks (the rules' names and the models, never the tasks) in Flockdeck's configuration folder on your computer. The routing record also names each fan-out's project folder, by its full path, and the pane each task ran in.

The same folder also holds:

If the app fails to start, it writes the error to a file there, error.log, which can include the paths of files and folders on your computer. Nothing there is sent anywhere by Flockdeck.

Outside that folder, the app writes to one file of another program's. When a fan-out carries Claude Code's folder trust over to the worktrees it creates, it records in Claude Code's own configuration file (~/.claude.json) that those worktrees are trusted, as the folder they came from already was.

To show what each agent has spent, the app reads what the agents report about their own usage on your computer: the tokens, cost estimate and usage limits Claude Code hands its status line, and the token counts of the built-in API agents. It keeps those figures in memory only. Flockdeck sends them nowhere itself; if you turn on remote access, they are part of the state of your panes that your own paired devices receive through the relay, as What passes through describes.

The app makes these network connections of its own.

Flockdeck also starts programs you choose, such as Claude Code, Codex or Gemini CLI, and opens its window in a browser already installed on your computer. Those programs make their own connections under their own terms and privacy policies. Flockdeck does not control them.

The relay (remote access)

Remote access lets you use your desktop's Flockdeck from another device, such as a phone, tablet or laptop, through the relay. It is off until you turn it on.

What is stored

For each account:

The account is not linked to an email address, a name or a password.

For each desktop you connect:

For each device you pair:

The relay also stores pairing codes, as hashes, until they are used. One that is never used expires after ten minutes, and is deleted within ten more.

What passes through

Your devices and your desktop reach the relay over encrypted connections (TLS). To route your traffic, the relay decrypts it: your terminal output, what you type, and the state of your panes pass through it. That state includes what each pane's agent has spent, its usage limits, and which model routing chose for it. Remote access is not end-to-end encrypted.

The relay does not record, store or log the content of that traffic. It never receives your API keys, unless you type one in through remote access. Where a pane opens as a conversation rather than a terminal (a Claude Code pane, or Flockdeck's own chat client), that conversation passes through the relay the same way, and the relay stores none of it. Searching that conversation runs on your desktop, against what it has already kept; only the query you type and the matches it finds pass through the relay, the same way the rest of the conversation does. A photo you attach to a message from your phone passes through it too, but is kept only on your desktop, in Flockdeck's own folder, never your project, and removed after about a week.

Muting a single pane's notifications from a phone is held only in that desktop's memory while it keeps running: it is not persisted there or anywhere else, and the relay stores nothing about it. Which paired devices have a pane open right now, shown as a small phone glyph naming the device on the desk's own window, is worked out from those same connections and kept the same way — in memory only, forgotten the moment the pane is closed or the device disconnects.

Notifications are the exception. When an agent has been waiting on you for a while and you haven't touched this computer — no keyboard or mouse input in any application for two minutes, or its screen is locked — your desktop encrypts a notification for each device you turned notifications on for, with that device's own keys, before it leaves your computer. Whether you are at this computer is worked out here, on this computer, and is never sent anywhere, encrypted or not. The relay adds its signature and posts the notification to the device's push service, and neither can read it. It says which pane needs you, with its project, and on which desktop; if you choose notifications without names, it says only how many agents need you, and on which desktop.

When a paired device reaches your desktop, the relay passes your desktop the device's IP address, its identifier and its name, along with the headers its browser sends with every request, such as its browser type and language. That lets your own Flockdeck tell your devices apart. Your desktop keeps them only in memory.

IP addresses and logs

How long it is kept

To delete everything the relay holds about you, turn remote access off on each of your desktops (flockdeck remote disable). If a desktop can no longer be reached, remove it from one of your paired devices, or email us.

Cookies

The relay sets a cookie on a device you pair, that keeps it signed in. It is strictly necessary for remote access to work, lasts up to 30 days, and is removed when you sign out. Opening a desktop's own window (Full interface) sets a second cookie, __Host-fdr_desk, scoped to that desktop's own address alone, so a page from one desktop cannot use another's session; it carries no permission of its own, is checked against your account on every request, and stops working the moment the device or the desktop is removed. Getting there uses a one-time code, kept in the relay's memory for 60 seconds and good once, never written to a cookie or stored any longer. The relay's web client also remembers three display preferences in your browser's local storage: notifications, zoom and fit to screen. It keeps a message you've started typing to an agent there too, per pane, so switching away and back doesn't lose it — on your device only, and never sent anywhere until you send it. It also remembers, per desktop, when you last had that desktop's list of panes open, so it can show what's changed since, and whether an agent's helpers are folded or shown — the same way, on your device only. None of this is used for tracking, or shared with anyone.

This website

flockdeck.ai sets no cookies, runs no analytics and loads nothing from third parties; its fonts are served from the site itself. Its web server keeps no access logs, though the load balancer in front of it may, as described above. Downloads from dl.flockdeck.ai may get its content delivery network's security cookie, as Who else is involved describes.

Why this data is used (lawful basis)

Who else is involved

The relay and this website are hosted by DigitalOcean, in its London region. DigitalOcean provides the servers, the database and DNS, and serves releases and update downloads from dl.flockdeck.ai through its content delivery network, which answers from locations around the world. That network is Cloudflare's, and Cloudflare sets a short-lived security cookie, __cf_bm, on downloads from dl.flockdeck.ai to tell people from bots. It is strictly necessary, it is set by Cloudflare rather than by Flockdeck, and the app's update checks send no cookies. GitHub mirrors every release. TLS certificates come from Let's Encrypt, which receives no personal data about you. These providers process data on our behalf or as independent services, under their own terms.

If you turn on notifications on a device, each notification goes through the push service that device's browser uses: Google's for Chrome and most Android browsers, Apple's for Safari, Mozilla's for Firefox, and Microsoft's for Edge on Windows. It receives the notification encrypted, the device's push address, and when it was sent, and it cannot read the notification. You chose that service when you chose your browser, and it works under its own terms.

DigitalOcean and GitHub are United States companies. Where your data is handled outside the UK, it is protected by the safeguards UK law requires, such as the UK International Data Transfer Addendum or the UK–US data bridge.

No personal data is sold, rented or shared for advertising.

Your rights

Under UK data protection law you have the right to:

Most of this you can do yourself, by renaming or removing desktops and devices in Flockdeck. For anything else, email privacy@flockdeck.ai. Because accounts carry no email address, we may ask you to prove a desktop or device is yours, for example from the desktop itself.

If you're unhappy with how your data is handled, you can complain to the Information Commissioner's Office at ico.org.uk. We'd appreciate the chance to put it right first.

Children

Flockdeck is a developer tool and isn't aimed at children under 13.

Changes

If this policy changes, the new version will be posted here with a new date. Material changes will also be noted in the release notes.