Legal · plain language on purpose
Privacy Policy
The short version: there is no server of ours in this product. Your voice, your prompts, and Claude's replies travel between your phone and your own Mac over your own Tailscale network. We never see any of it.
- No accounts. There is nothing to sign up for and no identity to attach data to.
- No analytics, no tracking, no ads. The app contains no analytics or advertising SDK of any kind.
- No server of ours. The only machine the app talks to is your own Mac, over your own Tailscale network.
- We collect nothing. No data of any kind is transmitted to the developer.
What the app does with your microphone
Robje listens only while a voice session is active, so your spoken prompts can be turned into text and sent to the Claude Code sessions running on your Mac. Audio is handled in one of two ways, and you choose which in Settings:
- Apple speech recognition (the default). Transcription uses Apple's Speech framework, built into iOS. Depending on your device, iOS version, and language, Apple may process that audio on your device or on Apple's servers, under Apple's privacy terms. This is the same speech recognition system iOS offers every app; we add no service of our own on top of it.
- ElevenLabs (optional, off by default). If you enter your own ElevenLabs API key, audio is streamed directly from your phone to ElevenLabs for transcription, and Claude's replies can be synthesized into speech the same way. That traffic goes straight from your device to ElevenLabs under your account and ElevenLabs' privacy policy — it never passes through anything of ours. Your API key is stored in the iOS Keychain on your device and is sent only to ElevenLabs.
The app never records audio in the background, never stores audio recordings, and never sends audio anywhere except the transcription service you chose above.
Where your prompts and transcripts go
Transcribed prompts travel over an encrypted WebSocket connection across your own Tailscale network to the Robje companion app on your Mac, which types them into the Claude Code sessions already running in your tmux panes. Claude's replies come back the same way. There is no relay server, no cloud middleman, and no public listener — if your phone and your Mac are not on the same tailnet, nothing connects at all.
The conversation transcript shown in the app lives on your device. What Claude Code itself does with your prompts is governed by your own Claude Code setup and Anthropic's terms. Robje is a remote control for sessions you already run, and it never becomes a party to them.
Camera
The camera is used for exactly one thing: scanning the pairing QR code shown by the Mac companion app, the first time you connect. No photos or video are captured or stored, and the camera is not used again after pairing unless you re-pair.
Face ID
The app requires Face ID to open by default (you can turn this off in Settings), so picking up your phone doesn't hand someone a live Claude Code session. Authentication is performed entirely by iOS. The app never sees your biometric data; it only receives a yes or no from the system.
What is stored on your device
- The pairing token that authenticates your phone to your Mac — stored in the iOS Keychain.
- Your ElevenLabs API key, if you provide one — stored in the iOS Keychain.
- App preferences (voice, verbosity, Face ID lock, and similar settings) — stored locally on the device.
Unpairing from Settings deletes the stored token. Deleting the app removes all of the above.
What we collect
Nothing. The developer receives no data from the app: no audio, no transcripts, no usage data, no crash reports of our own, no device identifiers. There is no mechanism in the app that could send us any of it. If you choose to share TestFlight feedback or App Store reviews, those go through Apple's standard channels.
Third parties, complete list
- Apple: speech recognition (default), and the normal operation of iOS.
- ElevenLabs: only if you opt in with your own API key, for speech-to-text and text-to-speech.
- Tailscale: carries the encrypted connection between your devices, either through the Tailscale app or through the iOS app's built-in Tailscale node (beta). The Tailscale account is yours and held separately; the app simply uses the private network it provides.
There are no others. No analytics providers, no ad networks, no data brokers.
Children
Robje is a developer tool. It is not directed at children, and it collects no data from anyone, children included.
Changes to this policy
If the app's data handling ever changes, this page will be updated and the effective date above revised. Given the design — no server, no accounts, no collection — meaningful changes would be a change in the product's architecture, not fine print.
Contact
Questions about privacy: robin@foursuitstudio.com.