Shaliach / Privacy
Privacy
Short version: the Shaliach apps send nothing to us. We run no server for them, and we have no account system, analytics or ads in them. This website keeps anonymous visit counts and nothing else.
Last updated 4 October 2026.
The apps (iPhone, Mac) and the server
Shaliach is software you install and run yourself. The iPhone and Mac apps connect only to the Shaliach server that you install, on your own Mac or server. Your messages, files, agent workspaces and settings stay on that machine. We, the developers, never receive them and cannot see them.
- No data collected by us. The apps contain no analytics, crash reporting, advertising or tracking code, and they don't link your activity across other companies' apps or websites.
- No accounts with us. You pair a phone or Mac with your own server using a one-time code. Each paired device gets its own token, kept on your server only as a hash. You can revoke it there at any time.
- Microphone and speech. The apps use the microphone only while you hold the mic button, record a voice message or are on a call. When the app turns speech into text itself, it uses Apple's speech recogniser, which may process audio on Apple's servers under Apple's privacy policy. The text goes to your own server.
- Camera and photos. These are used only when you choose to take or attach a photo to send to one of your agents. The photo goes to your own server.
- Notifications. These come from your own server, and from ntfy only if you set it up there.
Services you choose to connect
Your server talks to outside services only when you set them up, under your own accounts and keys:
- Anthropic. Every agent is the official Claude Code CLI, signed in with your own Claude account or API key. What it sends to Anthropic follows Anthropic's own terms and privacy policy.
- OpenAI (optional, for live voice calls). If you add your own OpenAI API key to your server, then during a live call the app streams your voice directly to OpenAI's Realtime service. It does this with a short-lived key your server creates for that call. With no key added, nothing goes to OpenAI.
- Anything your agents use for you. Websites they browse, and connectors you install, such as GitHub, are used under the accounts you give them.
We are not a party to any of these, and we receive nothing from them.
This website (shaliach.me)
- Visit counts. Each page view adds one to a few public counters on abacus: views per day, views per page, and which kind of site sent you (for example Hacker News or GitHub). Copying an install command adds one to a counter too. No cookies, no local storage for tracking, no identifiers, and nothing that tells one visitor from another.
- Theme. Your light or dark choice is saved in your browser's local storage, only on your device.
- Hosting and fonts. The site is hosted on GitHub Pages and loads fonts from Google Fonts. Like any web server, they receive your IP address and browser details when your browser fetches a page or font, under their own privacy policies.
Children
Shaliach is a developer tool, not directed at children under 13.
Contact and changes
Questions or requests: open an issue on GitHub. If this page changes, the date above changes, and the history is public in the repository.