PRIVACY POLICY
Last updated: July 18, 2026
1. Scope and Privacy Commitment
This policy explains how the Otherside CLI, companion app, Design experience, website, and backend service process information. Otherside is built to keep coding-session content confidential while collecting the operational metadata required to authenticate accounts, pair devices, synchronize sessions, prevent abuse, and operate the service.
2. End-to-End Encrypted Session Content
Supported current clients encrypt remote-session content on your device before it reaches the Otherside backend. This includes prompts, AI responses, tool and permission events, terminal data relayed to a companion, and encrypted session fields such as title, project, and branch. The backend stores and relays ciphertext so your paired devices can synchronize the current remote session and briefly recover its history after disconnection, but it does not hold the private keys needed to decrypt it.
The protocol uses X25519 key agreement, HKDF-SHA-256 key derivation, and XChaCha20-Poly1305 authenticated encryption with random 24-byte nonces and a per-sender symmetric ratchet. HMAC-SHA-256 protects local integrity records. Public keys and wrapped session keys are transmitted; private device keys remain on your devices.
3. Information We Process
- Account data: identity-provider subject, email address, account and authentication-session identifiers, and account lifecycle records.
- Device and pairing data: device or environment identifiers, device labels and kind, fingerprint hashes, public pairing material, pairing records, wrapped session keys, push tokens, and presence state.
- Session metadata: session, session-incarnation, and environment identifiers; provider, model, permission mode, status, event type and counter; creation, update, disconnection, and expiration timestamps; encrypted payloads; and encrypted title, project, and branch fields.
- Operational and security data: IP address, User-Agent, referrer, requested URL and query data, request ID, service logs, rate-limit and audit records, crash or error details, and feedback you choose to submit.
- Website and Design analytics: page URL and path, referrer, filtered query parameters, approximate region, and device, browser, and operating-system dimensions. Vercel Analytics does not use third-party cookies for this measurement.
Otherside does not intentionally send plaintext source code or coding-session content to the broker. Content is sent to an LLM provider or tool only when you select or invoke that provider or tool from a client.
4. How We Use Information
We use this information to authenticate you, link trusted devices, route encrypted events, restore session state, deliver push notifications, provide requested AI and Design features, operate and secure the service, diagnose failures, enforce limits, respond to feedback, and meet legal obligations. We do not sell personal information or use coding sessions for advertising.
5. Service Providers and External Destinations
- Google and Apple process sign-in information when you choose their identity services.
- The LLM provider you select receives the prompts, context, files, tool results, or other content required for your request under that provider's terms and privacy policy.
- Cloudflare provides network delivery and security; Vercel hosts the website and Design experience and provides privacy-focused analytics.
- Apple Push Notification service and Firebase Cloud Messaging receive device tokens and generic event or session identifiers needed to deliver notifications, not decrypted session content.
- Infrastructure hosting and monitoring providers process operational data needed to run and protect the service.
6. Retention and Deletion
- Your local CLI transcript is the canonical session history. Remote synchronization is not an archival or backup service.
- The backend retains encrypted session events, wrapped session keys, and related session records while the remote session is connected and for one hour after it disconnects. Reconnecting within that hour cancels the pending expiration.
- After the one-hour window, an application-managed cascade deletes the remote session incarnation and its encrypted events, key wraps, device state, pending notifications, and related Design session records. Reconnecting later creates a new remote incarnation that the CLI may seed from its local transcript. Manual session deletion is permanent and is never reseeded.
- Account identity, pairing, environment, and device records remain until you explicitly remove them or request account deletion. Account deletion is scheduled 30 days after your request.
- Vercel Analytics derives a request-based visitor session that is discarded after 24 hours. Push tokens remain until they are revoked, replaced, or the related account or device is removed.
7. Your Choices and Rights
You can unpair devices, delete remote sessions, sign out, revoke push access, and request account deletion from the product interfaces. Depending on where you live, you may also request access, correction, deletion, restriction, portability, or an explanation of the personal information associated with your account. We may need to verify your identity before fulfilling a request.
8. Security and Policy Changes
We use encryption in transit, end-to-end encryption for supported remote-session content, access controls, rate limits, restricted service networking, and security monitoring. No system is completely secure. We will update this page when our processing practices or legal obligations materially change and will revise the date above.
9. Contact
For privacy questions or requests, use Settings → Report an Issue in the authenticated companion app and identify the request as privacy-related. Do not include credentials, private keys, source code, or other sensitive session content in your report.