Hoptail Privacy Policy
Effective date: 11 October 2026
Hoptail lets you check on and answer the coding agents running on your Mac from your iPhone. It’s built so your work stays on your machines: your iPhone talks to your own Mac, and the only server involved is a small relay that delivers push notifications it can’t read.
This policy covers the Hoptail iPhone app, the Hoptail daemon you install on your Mac, and the Hoptail push relay. “We” means Dmitrii Emelianov PR Računarsko programiranje Novi Sad, a sole proprietorship registered in Serbia, the developer of Hoptail.
The short version
- No account and no sign-in.
- No analytics, ads, tracking or third-party SDKs in the app.
- Your sessions, terminal output, files and agent conversations stay on your Mac and the iPhones you pair with it. They never pass through our servers.
- To deliver notifications, the relay stores your iPhone’s push token in encrypted form, plus a few technical fields listed below. Notification content is end-to-end encrypted, so the relay can’t read it.
- Demo mode runs on sample data built into the app and sends nothing anywhere.
Who we are
Hoptail is developed by Dmitrii Emelianov PR Računarsko programiranje Novi Sad, a sole proprietorship registered in Serbia. A sole proprietorship in Serbia isn’t a separate legal entity: it’s Dmitrii Emelianov acting as a business.
- Registered with the Serbian Business Registers Agency (APR), registration number (matični broj) 67225627, tax ID (PIB) 113970406.
- Based in Novi Sad, Serbia.
- Email: feedback@hoptail.app.
We are the controller (rukovalac) of the personal data described in this policy.
How Hoptail works
The Hoptail daemon runs on your Mac. It watches your tmux sessions and the coding agents in them (such as Claude Code) and serves that information to the iPhones you’ve paired. Your iPhone connects to your Mac directly over your own network, usually your Tailscale tailnet. The connection is encrypted with TLS, and the app checks your Mac’s certificate fingerprint that it saved at pairing.
We don’t operate a server that sees your sessions. Tailscale is a separate service that you set up under your own account and its own privacy policy; we have no access to your tailnet.
Data on your Mac
The daemon keeps its data in your user account on your Mac:
- settings, the list of paired devices (each device’s model name, such as “iPhone 16”, when it was paired and when it was last seen) and the TLS certificate, in
~/Library/Application Support/Hoptail/; - a cache in
~/Library/Caches/Hoptail/and a log in~/Library/Logs/Hoptail/.
To show your sessions, the daemon reads what your agents and terminals already produce on your Mac: tmux windows, agent transcripts and changes in your project folders. It also adds hooks to Claude Code’s settings so it knows when an agent is waiting. This data is sent only to your paired iPhones. The daemon doesn’t read or store your Claude account credentials or API keys.
You can remove all of it with hoptail uninstall --purge (see Set up your Mac).
Data on your iPhone
- Pairing, in the iOS Keychain: your Mac’s address, the access token your Mac issued to this iPhone, your Mac’s certificate fingerprint, and the key used to decrypt notifications. These items are shared only with Hoptail’s notification extension on the same iPhone.
- Small app settings, in the app’s storage: for example, when you last opened a project’s artifacts. This stays on your iPhone.
- Camera: used only to scan the pairing QR code on your Mac. Images aren’t saved or sent anywhere.
- Attachments: a photo or file you choose to attach is sent only to your Mac.
When you pair, your iPhone tells your Mac its model name (for example, “iPhone 16”) so you can recognise it in the device list. It doesn’t send your personal device name.
Push notifications and the relay
Notifications let your Mac reach you when an agent needs you. Apple delivers them through the Apple Push Notification service (APNs). Because sending to APNs requires a key that can’t be shared with every Mac, notifications go through our relay:
- Your iPhone registers its push token with the relay and gets an opaque identifier (a “handle”).
- For each paired Mac, your iPhone creates a separate send key and passes it to that Mac over your private connection.
- When an agent needs you, your Mac encrypts the notification with a key that only your iPhone has and sends the encrypted notification to the relay, which passes it to Apple.
What the relay stores for each registration:
- your iPhone’s APNs push token, encrypted with a server key;
- the handle;
- the push environment (development or production);
- the app version;
- when the registration was created and last refreshed, and when a notification was last sent;
- for each paired Mac: a random identifier, a one-way hash (SHA-256) of its send key and the same timestamps.
What the relay doesn’t store or see:
- Notification content. The project name, the agent’s question and everything else in the notification are end-to-end encrypted on your Mac and decrypted only on your iPhone. If decryption fails, your iPhone shows a generic “An agent needs you”.
- Your IP address. The relay uses it only in memory to limit how many registrations one address can make, and doesn’t write it to its database or logs. Railway, which hosts the relay, may keep standard network logs, including IP addresses, for a short time to run and protect its service.
- Your send and management keys in readable form, only their hashes.
Logs. The relay logs technical events, such as the event type, the response status and a short prefix of the handle. It never logs push tokens, keys or notification content.
How long it’s kept. When you unpair a Mac, the app removes that Mac’s send key from the relay, so it can’t send to you anymore. The registration itself is deleted when Apple reports that the push token is no longer valid, or automatically after 60 days without a refresh from the app.
The relay is hosted on Railway; where, see “International transfers”.
Demo mode
“Try the Demo” shows Hoptail on sample sessions built into the app. In demo mode the app doesn’t connect to any Mac or server, doesn’t register for notifications and doesn’t touch your pairing. Nothing you do in demo mode leaves your iPhone.
Services by other companies
- Apple delivers notifications (APNs) and distributes test builds through TestFlight, under Apple’s privacy policy. If you send feedback or share crash reports in TestFlight, Apple passes us what you send: your comment, screenshots, crash logs, technical details of your device (such as its model, iOS version, language and free storage), and the name and email address you joined TestFlight with, if Apple shares them. We use them only to fix problems and improve Hoptail.
- Tailscale connects your devices if you use it. It’s your own account, under Tailscale’s privacy policy.
- Railway hosts the relay and processes the data listed above on our behalf.
- Cloudflare serves this website, counts visits to it, keeps the beta notification list and forwards email (see “Website and email” and “Beta notification list”).
- Google hosts the mailbox that receives email sent to feedback@hoptail.app and that we send the beta email from.
- Coding agents such as Claude Code run on your Mac under your own accounts and their providers’ terms. Hoptail doesn’t send your data to them; it shows and relays what you and they already exchange on your Mac.
We don’t sell or share your data, and we don’t use it for advertising.
Website and email
- hoptail.app is a static website served by Cloudflare. Cloudflare processes your IP address and request details to deliver and protect the site. To count visits we use Cloudflare Web Analytics. It records the page address, the page you came from, your browser’s user agent, your country (worked out from your IP address) and how fast the page loaded. It doesn’t keep your IP address for analytics, sets no cookies, stores nothing in your browser, uses no identifiers and builds no profiles. We see only totals. Cloudflare does this as our processor, under the data processing agreement that is part of Cloudflare’s terms.
- Email sent to feedback@hoptail.app is forwarded by Cloudflare Email Routing to a Gmail mailbox (Google). We keep emails only as long as we need them to answer you and to follow up on what you reported, then delete them.
Beta notification list
If you leave your email address in the “Notify me” form on hoptail.app, we keep:
- your email address;
- when you signed up;
- which version of the text under the form you saw.
We don’t keep your IP address or browser details with it. To stop abuse, the form holds your IP address in memory for about a minute to limit how often it can be sent, and doesn’t write it anywhere. Sending the same address again changes nothing and doesn’t show whether it’s already on the list.
We use your address for one thing: a single email when the TestFlight beta opens. We don’t send newsletters or marketing, and we don’t share the list with anyone. Right after that email goes out, we delete the list, along with our copy of the sent email. If the beta hasn’t opened within 12 months of your sign-up, we delete your address anyway.
The list is kept in a Cloudflare D1 database in our account, stored in the EU. We send the email from feedback@hoptail.app through our mailbox at Google.
Changed your mind? Write to feedback@hoptail.app and we’ll delete your address. Withdrawing your consent doesn’t affect anything we did with it before.
Legal bases
We process personal data under Serbia’s Law on Personal Data Protection (ZZPL) and, for people in the European Union, the GDPR:
- Delivering notifications (the relay registration: push token, handle, send-key hashes and timestamps): to perform our agreement with you, that is, to provide the service you asked for (ZZPL Art. 12(1)(2), GDPR Art. 6(1)(b)).
- Protecting the relay (your IP address, in memory, for rate limits; technical logs), protecting the signup form (your IP address, in memory for about a minute) and answering you (email, TestFlight feedback and crash reports): our legitimate interest in running a secure service, preventing abuse and supporting testers (ZZPL Art. 12(1)(6), GDPR Art. 6(1)(f)).
- Website analytics (page address, referring page, user agent, country and load times, seen only as totals): our legitimate interest in knowing how many people visit the site and which pages help them (ZZPL Art. 12(1)(6), GDPR Art. 6(1)(f)).
- Beta notification list (your email address, when you signed up and which version of the form text you saw): your consent, which you give by sending the form (ZZPL Art. 12(1)(1), GDPR Art. 6(1)(a)). You can withdraw it at any time, see “Beta notification list”.
You don’t have to give us any personal data. Without notifications Hoptail still works, you just won’t be alerted. We don’t make automated decisions about you, and we don’t profile you.
International transfers
We’re based in Serbia. The companies that process data for us are:
- Railway (EU, Netherlands), which hosts the relay. The relay’s data is stored in the EU. Railway is a US company, so its staff in the United States may access that data remotely to run the service, which counts as a transfer to the United States;
- Apple (APNs, TestFlight), Cloudflare (website, website analytics, beta notification list, email forwarding) and Google (mailbox), which process data in the United States and other countries.
Serbian law treats EU countries and countries with an EU adequacy decision as adequate (ZZPL Art. 64(2)). Apple, Cloudflare and Google take part in the EU-U.S. Data Privacy Framework, which the European Commission has found adequate. For Railway we rely on its data processing agreement with the EU Standard Contractual Clauses (ZZPL Art. 65, GDPR Art. 46). Its access from the United States is also necessary to perform our agreement with you, that is, to deliver the notifications you asked for (ZZPL Art. 69(1)(2), GDPR Art. 49(1)(b)).
Security
The connection between your iPhone and your Mac is encrypted and pinned to your Mac’s certificate. Notification content is end-to-end encrypted. On the relay, push tokens are encrypted at rest and keys are stored only as hashes. No system is perfectly secure, but we’ve designed Hoptail so that even the relay holds nothing that reveals your work.
Your rights
You can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct it;
- delete it;
- restrict how we use it;
- give it to you in a portable format;
- stop using it where we rely on our legitimate interest;
- stop using it where we rely on your consent, by withdrawing that consent.
Write to feedback@hoptail.app. We answer within 30 days. The relay knows you only by an opaque handle, so we may ask for details that help us find your registration. Much of it you can also remove yourself, see “Your choices”.
You can complain to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs) or, if you live in the EU, to the data protection authority in your country.
Your choices
- Unpair in the app’s Settings to remove the pairing from your iPhone and your Mac.
- Revoke another device’s access in Settings, or with the daemon on your Mac.
- Turn off notifications in iOS Settings, or set Hoptail to Mute.
- Uninstall the daemon with
hoptail uninstall --purgeand delete the app.
Children
Hoptail is a tool for software developers and isn’t directed at children under 16.
Changes
If this policy changes, we’ll update this page and its effective date. For significant changes, we’ll also say so in the TestFlight release notes.
Contact
Questions about privacy: feedback@hoptail.app