Back to ompanion

Privacy Policy

Last updated: September 27, 2026

ompanion is a client for omp, an open-source coding agent, on machines you own. This policy describes exactly what the app stores and what it sends. It describes the shipped app; it is not legal advice.

The short version

  • There is no account and no sign-up. The one service we run is the notification relay, which is used only if you turn on push notifications on a phone, and which only ever sees encrypted notifications.
  • The app has no analytics, no crash reporting, no advertising and no tracking of any kind.
  • The app talks to machines you own, over SSH. With push notifications on, a phone also registers with Google's Firebase Cloud Messaging, and your machines send it notifications through our relay, encrypted with a key only your phone and your machines have.
  • What you type goes to the agent on your machine, which calls the AI providers you configured there.

What the app stores on your device

  • Machine definitions: the name you gave a machine, its host and port, the user name, the authentication method (key, password, keyboard-interactive, SSH config or agent), the list of jump hosts in the order they are dialed, and whether it is a mesh VPN peer. This is in the app's local database on the device.
  • SSH keys and passwords: a key you generate or import is stored as a key pair. The private key, its passphrase, and any password you choose to save for a machine are kept in the platform's secure storage (the Keychain on Apple platforms, Keystore-backed encrypted storage on Android). Only the public key and its fingerprint are in the app's database. The app never sends a private key, passphrase or saved password anywhere; it signs on the device.
  • Host keys you have trusted, so a machine that changes its key is flagged instead of trusted.
  • Settings: your preferences (theme, which panels are open, which projects are collapsed in the session list), and a random id the app creates once per install. The app puts that id in its requests to omp on your machines, so that when several of your devices share a session, each one recognises the replies to its own requests.
  • Push notifications, on a phone where you turned them on: the notification key the phone made (the Keychain on iOS, the app's private storage on Android) and the Firebase installation ID Google issued for this install.
  • Read markers: per session file, the modification time up to which you have read it.
  • Images from your machines: when the app shows an image file from one of your machines, it fetches it over SSH (a large file as a smaller preview, when the machine has ffmpeg to make one) and caches it in the app's cache directory, up to 256 MB, oldest first out.
  • Session data: the transcript you see is read from the machine over SSH. Messages, files and attached files live on the machine, in your own project and session directories. What you are typing, pasted attachments and terminal scrollback stay in memory and are gone when the app closes.

Nothing in that list is a copy of your AI provider credentials. Those stay on your machine, in omp's own configuration, and the app never reads them. If you type a provider API key or another secret setting into the app, it goes over SSH to omp on your machine, and the app keeps no copy.

On iOS, the app's database is part of your own device backups, as for any app, and the secure-storage items above are part of encrypted ones; the image cache is not backed up. On Android, the app opts out of backup.

The desktop builds from GitHub can also run omp on the computer itself ("this computer"), read your ~/.ssh/config, ~/.ssh/known_hosts and Tailscale peer list to fill in machines, and sign with your ssh-agent's keys. Those files, that list and those keys never leave the computer; the phone and tablet builds do none of it.

What the app sends, and where

  • To your machines, over SSH. Connection setup, host-key checks, the session list, transcripts, prompts you send, files you open, save or attach, terminal input, configuration changes, and the small companion extension the app uploads to ~/.ompanion/companion/ on the machine and omp loads with -e, so that omp exposes the events the client needs.
  • To GitHub, when you ask the app to install omp on a machine that lacks it. The machine downloads the release itself when it has curl or wget (or PowerShell on Windows); otherwise the app downloads it from github.com and streams it to your machine over SFTP. Either way the machine checks the file against a SHA-256 checksum the app carries. This is a request for a public open-source file; it carries no information about you beyond what any web request carries, and it goes only to GitHub.
  • To the host of a link or image, only when you tap it. Links open in your browser, including provider sign-in pages for OAuth logins in omp. A web image named in a model reply is fetched by the app from its own URL only after you tap Load image, and never on its own. While a sign-in is open, the app listens on the device's own loopback address for the provider's redirect and relays it over SSH to omp on your machine, which completes the sign-in and keeps the token there.
  • To a place you choose, when you export machines. The export holds machine names, hosts, ports, user names, authentication methods, key fingerprints, jump hosts and trusted host keys, never a private key, passphrase or password. It goes to the clipboard or to a file you pick.
  • To your machines and to Google, when you turn on push notifications on a phone. The phone registers this install with Google's Firebase Cloud Messaging, which identifies it by a Firebase installation ID that Google keeps until the install deletes it. Nothing about Firebase runs before you turn push notifications on. The phone then leaves a small file under ~/.ompanion/push/ on each machine it connects to: the phone's random id, the installation ID, the notification key, the name the app gave that machine and which notifications you want.
  • From your machines, through our relay, to your phone. When a session on a machine asks a question, finishes or fails, omp's companion encrypts a notification (the session title, the machine name and a line of text) with the phone's key and sends it to our relay at push.ompanion.app, which hands it to Firebase Cloud Messaging, which delivers it through Google Play services on Android and Apple's push service on iPhone. The relay, Google and Apple see the installation ID and the encrypted bytes, never the text; the relay also sees the machine's IP address, as any web server does. The relay keeps nothing and logs no installation ID, no notification and no address.
  • Nowhere else. The app has no other server of ours and no telemetry endpoint. The one third-party SDK that reports anything is Firebase Messaging, and only on a phone with push notifications on: besides the installation ID, it sends Google the diagnostic data about message delivery that Firebase's own privacy disclosures list. The app has no update check of its own either: the startup.checkUpdate setting in the app's settings screen belongs to omp on your machine, and that check, if you turn it on, happens from your machine and nowhere else.

Your AI providers

The app does not talk to AI providers. The agent on your machine does, using the accounts you configured in omp on that machine. When you send a prompt, it travels over SSH to your machine and from there to your provider, under that provider's terms and privacy policy, with your credentials. Model access, data retention and pricing are therefore between you and the provider you chose — the same as running omp in a terminal.

Some pages of the app ask omp on your machine to go online: the usage page has omp fetch your subscription limits from your providers, and the plugin and skill pages have omp query its plugin marketplaces and skill registry. Those requests come from your machine, not from the device.

This website

This site sets no cookies and runs no analytics. It loads nothing from a third party: no web fonts from a CDN, no scripts, no images and no embeds. Every asset on the page is served from this domain with the page itself.

The pages are hosted on Cloudflare, which receives visitors' IP addresses in its server logs as any web server does. That logging is Cloudflare's, under the Cloudflare Privacy Policy.

What we do not do

  • We do not collect, see, sell or share your data. There is no analytics SDK, no crash-reporting SDK, no advertising SDK and no identifier that we could tie to you: the relay passes each notification on and keeps nothing.
  • We do not require an account, an email address or a phone number to use the app.
  • We do not read your prompts, your files, your keys or your provider credentials.
  • The app does not use the Advertising Identifier or any other tracking mechanism.

Children

ompanion is a developer tool. It connects to machines with SSH credentials, runs commands on them, and shows whatever the agent on those machines produces, without any moderation of its own. It is not directed to children, and we recommend it only for adults who administer the machines they connect to.

Retention and deletion

Your data lives on your device and on your machines, and you delete it by deleting it:

  • Remove a machine in the app: everything the app stored for it is deleted from the device: its definition, its jump hosts, its saved passwords, its read markers, its session-list settings, the host keys you trusted for it that no other machine of yours uses, and the images cached from it. Nothing is deleted on the machine itself.
  • Delete a key in the app: its private key and passphrase are deleted from secure storage.
  • Turn off push notifications on a phone: it deletes its notification key and its Firebase installation, and removes its file from the machines it is connected to; the other machines lose theirs the next time the phone connects to them.
  • Uninstall the app: on Android, everything the app stored on the device goes with it. On iOS, the database and caches go with it, but the Keychain can keep private keys, passphrases and saved passwords after the app is deleted; delete your keys and machines in the app first to remove them.
  • On the machine: sessions, transcripts and files uploaded for a session live on the machine, in your own directories, and are yours to delete there. The app also keeps its own files under ~/.ompanion/: the companion extension, one file per omp version, one push registration per phone that turned push notifications on, and the input and output streams of each running session, which it deletes once that session's omp has exited. Deleting that directory removes all of it.
  • There is no server-side copy for us to delete.

Changes

This policy is part of the source repository, so every change to it is a public commit. The date at the top changes whenever the text changes. If a future version of the app collects anything, this document will say what, why and how to turn it off before that version ships.

Contact

Questions, corrections or a privacy concern: open an issue at github.com/edde746/ompanion/issues. That is also the support and bug-report channel.