Privacy policy

Last changed October 8, 2026

This policy covers Pocket Hawk: the Android app, the hooks and the pockethawk command you install on your computer, the server they talk to, and this site. Pocket Hawk is made by Playful Pixel LLC, in Oregon, USA ("we"). Questions about this policy or your data go to support@pockethawk.app.

Your messages stay sealed

When one of your coding agents tells Pocket Hawk something, the hooks on your computer seal its message (the title, the words, the summary, the actions, which agent, session, repository and branch it came from, and what stopped the agent, such as a rate limit) to your phones' keys before it leaves your computer. Only your phones can open it. The server never holds a message's words, or a key that opens one.

On the free plan, the server also locks each sealed message a second time with a key of its own, and your phone asks for that key when you open the message. That's how the free plan counts the messages opened each day. The server still can't read them, but it does learn when each one is opened.

What the server keeps

The server is run for us by Supabase. It keeps this, and only this:

  • From signing in: the email address, name, profile picture and account id that account shares (and your username, on GitHub), and when you last signed in. For each session you're signed in with, its IP address and the browser or app it came from. While you sign in with GitHub, the access token GitHub hands over, which can read your GitHub profile and email addresses, until the app finishes signing you in, or for a day if it never does; nothing uses it, and the app doesn't keep it.
  • Your account: when it was made; your plan, free or Pro, and until when; and, on the free plan, until when its daily limit is lifted.
  • For each phone you register: its public key, its platform and model, the address notifications reach it at (a Firebase push token), how it was checked when it registered, when it registered, and how you set its notifications for each kind of event. While a phone registers, a one-time challenge for it, for 10 minutes.
  • For each source (a computer or agent you connect): the name you give it, a fingerprint of its key (never the key itself) and the key's last four characters, and when it was made, last used and turned off.
  • For each event: the sealed message, which source sent it, its kind (Done or Needs you, for example), its size, which of your phones it's sealed to, and when it arrived and is deleted; and, once you act on it, when you first marked it seen (Ack) and when you archived it.
  • On the free plan: a key of the server's own for your account, made new each day, that locks your messages a second time, and when each message was first opened and whether it counted toward the day's limit.
  • For our own developers only: a note that their account may register a test phone.

Nothing else. We never use your email address to write to you, unless you write to us first.

What stays on your phone and computer

Your phone keeps your messages still sealed to its own key, and opens each with that private key when it shows it; the key is made in the phone's secure hardware and never leaves it (only its public key is sent, so your messages can be sealed to it). It keeps the names you gave your sources, so it can show them before the server answers. A watch paired with your phone shows Pocket Hawk's notifications as your phone does, their words included. It keeps your sign-in too: the session that keeps you signed in, with the email address and the service you signed in with, which Settings shows; and its registration: the id the server knows it by, and the push address it last gave the server. None of it is backed up or moved to a new phone. Your computer keeps the hooks' settings and each source's key; what your agent writes for its notification, until its turn ends and the hooks send it; and a log of what the hooks did (when, and whether a message was sent), never a message's words or the key. The server makes a source's key when you add the source and hands it over once, keeping only its fingerprint; after that the key comes with each call the source makes, to show it's yours.

How we use it

Only to run Pocket Hawk for you: to sign you in, deliver your messages to your phones, hold the free plan's limits, and keep the service safe (checking a phone is genuine when it registers, and limiting how much any account can send). In the GDPR's terms, that's to perform our agreement with you, and, for keeping the service safe, our legitimate interest in it.

Who handles data for us

  • Supabase runs the server, its database and signing in, in the United States (on Amazon Web Services, in Ohio).
  • Cloudflare serves this site and the address the app and the hooks call, and passes their requests to the server. It also forwards the email you send to support@pockethawk.app to our mailbox.
  • Google: signing in with Google; Firebase Cloud Messaging, which gives your phone its push address, carries the sealed notifications to your phone and sees each one's kind, which source sent it and when, but never its words; Play Integrity, which checks a phone is genuine when it registers; and Gmail, which holds our mailbox. Google Play also delivers the app.
  • GitHub: signing in with GitHub.

Each sees what its part needs, under its own privacy policy. We never sell your data, and we don't share it with anyone else or for advertising.

What Pocket Hawk doesn't do

No ads. No analytics or tracking, in the app or on this site. No crash-reporting kit: we see crashes only through Google Play's Android vitals, which your phone shares with Google if you allow it, and which never hold your messages. This site sets no cookies and loads nothing from other sites. If any of this changes, this policy will change first.

How long we keep it

  • An event, sealed message and all: 7 days after it arrives on the free plan, and 30 days on Pro, by the plan it arrived on.
  • The server's daily key for your account: replaced each day, and deleted once no event it locked is kept.
  • The record of a message being opened: deleted once the message is gone and a day has passed.
  • A session you're signed in with, and its IP address: until you sign out of it.
  • Your account, phones, sources and settings: until you delete your account.
  • Logs of requests to the server, with IP addresses, and the database's backups: up to 7 days.
  • Email you send us, and our answers: in our mailbox for up to a year after the last one.

Keeping it safe

Messages are sealed on your computer and opened only on your phones. Everything travels encrypted (HTTPS). Source keys are kept only as fingerprints, phones' private keys never leave the phones, and each person can read only their own data on the server.

Your rights

You can see what we keep about you, have it corrected, get a copy, or have it deleted: write to support@pockethawk.app from the email address you sign in with. To delete your account, see Delete your Pocket Hawk account. We answer within 30 days. If you're in the EU or the UK, you can also complain to your data protection authority.

Children

Pocket Hawk isn't for children under 13, or under 16 in the EU and UK, and we don't knowingly keep anything about them.

Changes

We'll post any change here, with its date at the top.