CLOAK
How it worksWhat you getSecurityContact
npx cloak-remoteGet it on Google Play
Legal

Privacy Policy

Cloak is built so that your data stays on your own devices. There is no account, no cloud server that stores your content, and no tracking inside the app. This page explains exactly what that means.

Last updated: 30 June 2026

Who this applies to

This policy covers the Cloakmobile app and this website (collectively, “Cloak”). Cloak is a private remote for your coding agent. A host agent runs on your own machine, where Claude Code is already logged in, and the app on your phone drives it — a chat view to approve or reject the agent’s edits and commands, and a full terminal mirror. Your phone authenticates to your machine, never to Claude or to any vendor cloud we run.

Cloak is operated by Adityan Mishra (“we”, “us”). If you have any questions, contact us at adityanmishra36@gmail.com.

The short version

  • We do not require an account or any sign-up.
  • We do not run a cloud server that stores your terminal sessions, prompts, code, or chat. Your session history lives on your own machine.
  • Traffic between your phone and your machine is end-to-end encrypted with AES-256-GCM (above TLS), so the connecting tunnel cannot read its contents.
  • Your code and your Claude credentials never leave the host machine — only encrypted chat and tool input/output flow over the wire.
  • Your encryption keys are generated on, and never leave, your paired devices.
  • There is no advertising, no third-party analytics SDK, and no tracking inside the app, and we never sell or share your personal data.

How the connection works

You pair your phone and your machine by scanning a QR code. Pairing uses an ECDH P-256 key exchange — no secret key is ever transmitted — and every message after that is encrypted with AES-256-GCM. To reach your machine from anywhere, the app connects through a free outbound tunnel (Cloudflare Tunnel); your machine opens no inbound ports. Because the payload is end-to-end encrypted before it enters the tunnel, the tunnel provider relays only ciphertext and cannot read your content.

Data the app handles

To do its job, the app processes the following — on your device and in transit between your own devices, not on servers we operate:

  • Pairing keys and identifiers.When you link a device, encryption keys and a pairing identifier are stored locally in your operating system’s secure storage (Keychain / Keystore). These stay on your devices.
  • Session content. The chat, terminal output, prompts, code, and any photos or screenshots you attach are relayed end-to-end encrypted between your phone and your machine. We cannot read this content, and it is not stored on any server we operate. Session history is kept on your own machine.
  • Paired-device labels. So you can manage and revoke access, your machine keeps a list of paired devices and optional labels you set. This list is stored on your machine, not by us.

Permissions the app asks for

  • Camera— used only to scan your agent’s pairing QR code. The image is processed on your device and is not uploaded or retained.
  • Photos— used only when you choose to attach a photo or screenshot to your chat so the agent on your machine can see it. It is sent over the encrypted tunnel to your machine, not to us.
  • Face ID / biometrics— used only to unlock the app on your device. Biometric data is handled entirely by your operating system and never reaches us.
  • Notifications— Cloak shows local, on-device notifications, triggered by events arriving over your existing encrypted connection. The app does not register a remote push token and sends nothing to any third-party push service.
  • Run-in-background (Android foreground service)— used only to keep your encrypted connection alive while you are using a session.

What we do not collect

The Cloak app does not collect personal information for advertising, contains no third-party advertising or analytics SDKs, and does not build a profile of you. We do not collect your location or contacts, and we do not access your photos beyond a single image you explicitly choose to attach.

This website

This marketing website uses privacy-friendly, aggregate analytics (Vercel Analytics) to understand overall traffic. It does not use cookies to identify you personally. If you send us a message through the contact form, we use the details you provide solely to reply to you.

Data retention & deletion

Because your session content and history live on your own devices and are not stored on our servers, you control them directly. On the phone, uninstalling the app clears the keys held in secure storage; on your machine, you can revoke a paired device at any time and delete the host’s local session history. Any message you send us by email is kept only as long as needed to handle your request.

Children

Cloak is a developer tool and is not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page. Continued use of Cloak after an update means you accept the revised policy.

Contact

Questions about your privacy or this policy? Email adityanmishra36@gmail.com or use the contact page.

CLOAK
A private remote for your coding agent · Works with Claude Code today
ContactPrivacynpmGitHubLinkedInGet it on Google Play© 2026