Legal
Privacy Policy
Last updated July 21, 2026
This Privacy Policy explains how [COMPANY NAME] ("Exori," "we," "us," or "our") collects, uses, and protects information in connection with the Exori mobile application, the Bridge companion application, associated relay infrastructure, and related services (collectively, the "Service").
1. Overview
Exori is a developer tool built around a core principle: your source code stays under your control. Code is transported exclusively via git to remotes you configure (e.g., GitHub, GitLab) — we do not operate a custom file-sync system that copies your code to our servers for storage. Where your data does pass through infrastructure we operate (the relay), it is to enable connectivity, not to collect or retain your code.
2. Information We Collect
2.1 Account Information
If the Service requires an account, we collect information such as your email address and authentication details necessary to create and manage that account.
2.2 Device and Pairing Information
To connect your phone to Bridge, we process pairing metadata (e.g., device identifiers, pairing tokens generated at QR-code scan time) necessary to establish and maintain the connection between your phone and your Mac.
2.3 Relay Traffic
When you build or connect out-of-network, traffic between your phone and Bridge is routed through relay infrastructure we operate. This traffic is end-to-end encrypted between your devices; the relay is designed to move ciphertext, not to read, log, or store the content of your code, commands, or build output. We may log connection metadata (timestamps, connection duration, error codes) for reliability and abuse-prevention purposes.
2.4 Credentials
Credentials used to authenticate with third-party services (e.g., GitHub, GitLab, Apple Developer, package registries) are stored in macOS Keychain on your Mac, not on our servers. We do not have access to these credentials.
2.5 Diagnostic and Usage Data
We may collect crash reports, performance metrics, and feature-usage data (e.g., which scaffolding templates are used, LSP request latency) to maintain and improve the Service. Where feasible, this data is aggregated or anonymized.
2.6 What We Do Not Collect
We do not collect, store, or have access to:
- The contents of your source code or repositories
- Your git commit history or repository contents
- Files on your Mac outside of what is minimally required to relay a connection
- Credentials stored in your macOS Keychain
3. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Service (including pairing and relay connectivity)
- Diagnose and fix bugs, crashes, and performance issues
- Detect, prevent, and address abuse, fraud, or security issues
- Communicate with you about the Service (e.g., updates, security notices)
- Comply with legal obligations
We do not sell your personal information. We do not use your source code to train any models.
4. Third-Party Services
The Service integrates with third-party services you choose to connect, including but not limited to GitHub, GitLab, and Apple Developer services. When you connect these services, your use of them is governed by their own privacy policies. We are not responsible for the data practices of third parties.
Build automation (e.g., Fastlane) and package registries invoked by Bridge run using your existing local configuration and may transmit data to those third parties as part of normal operation (e.g., publishing a build, resolving dependencies). This occurs on your Mac, under your existing accounts and agreements with those services.
5. Data Storage and Security
- Relay infrastructure: Designed for end-to-end encrypted transit; not intended for long-term storage of code or build content.
- Bridge: Runs locally on your Mac. Bridge's access to your filesystem, git configuration, and Keychain is local to your machine and is not transmitted to us except as needed to relay your own commands to your own Mac.
- Encryption: Connections between your phone and Bridge are encrypted in transit.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain account information for as long as your account is active. Connection and diagnostic logs are retained for a limited period for operational and security purposes and then deleted or anonymized, except where longer retention is required by law.
7. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at hello@exori.app.
You can revoke Bridge pairing at any time from within the app, which removes the phone's ability to connect to that Mac.
8. Children's Privacy
The Service is not directed to children under 13 (or the relevant minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
9. International Data Transfers
If you access the Service from outside [COUNTRY], your information may be transferred to and processed in [COUNTRY] or other jurisdictions with different data protection laws than your own.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other reasonable means. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this Privacy Policy can be directed to hello@exori.app.