Privacy Policy
Effective date: September 27, 2026 · First published: June 3, 2026
Agents At Work is a product of AnswerSolutions LLC (www.answersolutions.net). This policy explains what data we collect, why we collect it, and how we protect it. We have tried to keep it short and readable. If anything is unclear, email us at privacy@answersolutions.net.
1. What is Agents At Work?
Agents At Work is a mobile + desktop system that lets you monitor and control AI agents running on your Mac or Linux computer from your iPhone, iPad, or Android phone. Supported agents include Claude Code (Anthropic), Codex (OpenAI), Gemini CLI (Google), Grok (xAI), Cursor (Anysphere), and Scoot, our own CLI, which runs local AI models with Ollama entirely on your own hardware without any third-party API, plus cloud models such as OpenAI and Anthropic when you add your own API key.
On your computer, the agents are watched by aaw-core,
our open-source engine. The macOS menu bar app bundles it, and on Linux
the aaw command-line tool installs it. aaw-core captures
agent events, encrypts them, and sends them to your phone through a
relay: a server that passes encrypted messages between
your computer and your phone. You can use the relay we host at
relay.agentsatwork.app, or run your own. The mobile app
decrypts and displays those events and lets you answer permission
prompts and send messages to your agents.
Features and data handling details may change as the product evolves; this page describes the current version. See our Terms of Use for the full disclaimer.
2. Data we collect
2a. No accounts
Agents At Work has no user accounts. There is no sign-in on the phone apps, on the Mac app, or on Linux, and we do not ask for your name, email address, or password to use the apps.
A phone is paired with a computer only by scanning a QR code shown by
the Mac app (Link Mobile) or printed by the Linux tool
(aaw link). The QR code carries a random computer ID, the
computer's name, the relay address, an encryption key, and a token that
identifies the phone to the relay. The pairing happens between your
devices. The encryption key in the QR code is never sent to us.
2b. Agent session data
While an agent runs on your computer, aaw-core sends the following through the relay to your paired phones, and your phones send commands back the same way:
- The conversation with the agent: your prompts and the agent's responses, including tool-call summaries such as "Wrote UserService.kt" or "Run: npm run build"
- Permission prompts and questions from the agent, and your answers (Yes / No / custom text)
- Messages and scheduled prompts you send to the agent from the mobile app
- File paths, and the contents of files you choose to open from the phone
End-to-end encryption. All of this content is encrypted with AES-256-GCM on your computer or your phone before it is sent. The key is exchanged once through the QR code and never leaves your devices. The relay stores and forwards only ciphertext, and AnswerSolutions cannot read your prompts, responses, questions, answers, file paths, or file contents.
What our hosted relay stores. If you use the relay at
relay.agentsatwork.app, a server we operate on DigitalOcean,
it stores:
- Encrypted events from your computer, for up to 90 days
- Encrypted commands from your phone (prompts you send and scheduled prompts), for up to 30 days or until the computer has received them
- Routing metadata, which is not encrypted: the random computer ID, the computer's name, session IDs (these are the names of your project folders), agent names, session status, and timestamps
- A record for each paired phone: a random routing token, the phone's platform (iOS or Android), its push notification token, and when it was last seen
- Which events each phone has already received
We keep nightly backups of the relay database for 14 days. The relay's server logs record the IP addresses of connections and short prefixes of tokens. We use these logs to operate the relay and to prevent abuse.
Self-hosted relays. If you run your own relay, your data does not reach our servers at all. In that case, the mobile app receives updates while it is open, but background push notifications do not work.
On your computer. aaw-core keeps its state and logs on
your computer, in ~/.aaw. It sends nothing to us except
through the relay as described above, and it contains no analytics or
tracking.
2c. Push notification tokens
When a phone is paired, the mobile app gives its push notification token to the relay, which stores it with that phone's record. Our relay sends push notifications through Google Firebase Cloud Messaging, which delivers them to iPhones and iPads through the Apple Push Notification service. The notification carries the encrypted text and the routing IDs it needs, and the phone decrypts it on the device. We use push tokens only to deliver notifications; we never sell or share them.
2d. Subscription and billing data
Agents At Work offers paid subscriptions (Personal and Pro) purchased through the Apple App Store (iOS) or Google Play (Android). We do not handle payment card numbers or billing details directly. Those are managed entirely by Apple or Google under their respective privacy policies.
The mobile app reads your plan from the store on the device. We do not receive your payment details.
2e. Website collaboration / enterprise inquiry form
If you submit the collaboration/enterprise inquiry form on this
website, we store your work email address, optional
name, optional company name, and optional message in a separate
Firestore collection (early_access). This collection is
write-only from the website. The website cannot read, update, or
delete records. We use this data only to respond to your inquiry; we
do not share it with third parties.
2f. Moving from the earlier version
Earlier versions of Agents At Work used accounts and stored data in Google Firebase (Authentication and Firestore). For one transition release, a phone that still follows a computer running the earlier version keeps using that earlier Firebase path. The earlier account and its data remain in Firestore after you unlink the phone or move to the new version, because unlinking signs the phone out but does not delete the account. We delete that data on request: email support@answersolutions.net.
3. Data we do NOT collect
- Names, email addresses, or passwords for using the apps (there are no accounts)
- The readable contents of your conversations or files: what passes through the relay is encrypted, and we do not have the key
- Keystrokes, clipboard contents, or screenshots
- Location data
- Analytics or advertising identifiers
- Payment card details
4. How we use your data
- To provide the service: routing encrypted agent events from your computer to your phone, and your commands back, in real time, and holding them on the relay while your phone or computer is offline.
- To send push notifications: delivering permission prompts and status updates to your device.
- To operate the relay and prevent abuse: using the relay's server logs.
- To respond to inquiries: if you submitted the website form.
We do not sell your data. We do not use it for advertising.
5. Data sharing
We share data only with:
- DigitalOcean: hosts the server that runs our relay, and so stores the relay data described in section 2b.
- Google Firebase: Cloud Messaging delivers push notifications (through the Apple Push Notification service for iPhones and iPads), and Firestore stores website form submissions and, during the transition, data from the earlier version. Google processes this data as a subprocessor under their standard terms. See firebase.google.com/support/privacy.
We do not share your data with any other third party unless required by law.
6. Data retention
- Encrypted events on our relay: up to 90 days.
- Encrypted commands on our relay: up to 30 days, or until the computer has received them.
- Relay database backups: 14 days.
- Phone records and push tokens: when you unlink a phone (Settings → Unlink this Phone in the mobile app, or removing a computer from the app), the phone tells the relay to delete its token and push token.
- Data on your computer:
aaw uninstall, or Uninstall in the Mac app, removes the local data from your computer. - Other relay data expires on the schedule above. For any other deletion request, email support@answersolutions.net and we will process your request within 30 days.
- Collaboration/enterprise inquiry submissions: retained until you ask us to remove your entry (email us with the address you submitted).
7. Security
All data is transmitted over HTTPS/TLS, including the connections to our relay.
End-to-end encryption: conversation content (prompts, responses, questions, answers, tool-call summaries, file paths, and file contents) is encrypted with AES-256-GCM on your computer or phone before transmission. The encryption key is exchanged through a QR scan between your devices and is never sent to our servers. The relay receives and stores only ciphertext.
Key storage. On iOS, the encryption key is
stored in the operating system's Keychain. On Android, the key is
stored via Jetpack Security's encrypted file storage, backed by the
Android Keystore system (hardware-backed where the device supports
it). On your Mac or Linux computer, aaw-core stores the key in a file
under ~/.aaw/ readable only by your user account.
The collaboration-inquiry collection is append-only from the website. It cannot be read or modified via the public API. Payment card details are never transmitted to or stored by us; all billing is processed by Apple or Google.
Breach notification. If we become aware of a security breach that compromises your personal information, we will notify you and any applicable regulators as required by applicable law, without undue delay.
8. Children
Agents At Work is a developer tool intended for users 13 years of age or older. We do not knowingly collect data from children under 13. If you believe a child has submitted personal information to us, please contact us and we will delete it promptly.
9. Your rights
Depending on your location, you may have the right to access, correct, or delete the personal data we hold about you. To exercise any of these rights, email privacy@answersolutions.net. We will respond within 30 days.
California residents (CCPA/CPRA). If you are a California resident, you have the right to know what personal information we collect about you, the right to delete that information, and the right to non-discrimination for exercising these rights. We do not sell or share your personal information, so there is no "opt-out of sale" mechanism to provide. To exercise your California rights, email privacy@answersolutions.net.
10. Changes to this policy
We may update this policy as the product evolves. If we make material changes, we will update the effective date at the top of this page. We encourage you to review it periodically.
11. Contact
AnswerSolutions LLC
www.answersolutions.net
privacy@answersolutions.net