Privacy
This service exists so agentflow can email you your machine's current link and show your machines on one page. It stores as little as that needs.
What is stored
- Your email address, recorded as soon as a sign-in code is requested for it (whether or not sign-in is completed), and when it was recorded, first verified and last changed.
- For each machine you sign in on: its machine id (a random id agentflow creates, not your hostname), its name (as reported by agentflow, usually the hostname), the transport (Tailscale or Cloudflare), its current link, the agentflow version, and timestamps: when it was added, last seen, when the link last changed and when it was last emailed, plus the last link emailed.
- Sign-in codes: only a keyed hash of each code, with the email it was sent to, the IP address that asked for it (for IPv6, only its /64 network), when it was sent and how many attempts were made. These are deleted about a day after the code expires.
- Sessions: a hash of each sign-in token (for the agentflow command line or this dashboard), when it was created and last used, and the user agent that signed in. Signed-out sessions are deleted about a day after signing out; dashboard sessions end after 30 days without use.
What is never stored
No passwords (there are none), no device or pairing tokens, and nothing from your terminal: no session contents, commands, files or transcripts. Nothing stored here lets anyone open your machines; opening a link still requires pairing with that machine.
Who else handles it
When sending email is enabled, emails (sign-in codes and link emails) are sent through Brevo, which receives your email address and the email's content in order to deliver it. The service's operational logs may include an email address when an email is not sent or sending it fails.
Deleting your data
Sign in on this page and choose Delete account. That immediately deletes your email, every machine and every session, and any sign-in codes still stored for your address. To remove a single machine, choose Remove next to it. Signing out of the agentflow command line with agentflow account logout ends that computer's session. Database backups, where the operator keeps them, are overwritten on their own schedule.