Privacy, made understandable.
This notice describes the current Commander deployment and available controls. Contact your deployment operator for account and data requests.
What we receive
When social sign-in is enabled, Commander receives a provider identifier and verified email address from Google or Apple. Your provider password is not sent to Commander. We also store workspace membership, registered device metadata, access grants, and recorded tool activity.
How work moves through the service
Working files remain on your device. To fulfill a request, relevant file contents and command output are processed by the relay and returned to your connected AI client. Those contents may therefore also be handled under the AI provider’s policies. Commander is not an end-to-end encrypted file vault.
Cookies and access
HTTP-only cookies maintain sign-in sessions and protect login and connection requests. A browser preference stores your selected theme. These pages do not include advertising trackers.
Retention and your controls
Revoking a device or AI connection stops its authorized access. It does not erase historical activity or local files. Data retention and deletion requests are handled by the operator of your Commander deployment; an automatic account-deletion flow is not currently provided.