shubat / for OpenCode
Privacy Policy
Last updated: 29 September 2026
Shubat is a client and connection service for the OpenCode coding agent. It connects your phone to a server that you run and control, through our hosted relay. This policy explains what the website, relay, and apps do and do not do with your data.
What the app stores
- Connection settings — the address of your server or relay and the pairing token you provide are stored locally on your device (in the OS keychain / app storage) so you don't have to re-enter them. They are used only to connect to your own server.
- The app itself has no login. You pair the app to your server with a link or QR code; the app does not ask for an account.
Your website account
To subscribe and manage your connector you create an account on shubat.org. For that account we store:
- An identity from the sign-in method you choose — your email address (email magic link), or a stable account identifier from GitHub or Google. We use it only to sign you in and contact you about the Service.
- Subscription and entitlement records — whether you have an active plan, free-trial or promotional access, and referral credit. Payments are processed by PayPal; we receive the subscription status and identifiers needed to grant access, but we never receive your card or bank details — those stay with PayPal, under PayPal's privacy policy.
- A referral code and a count of sign-ups you referred, so referral rewards work. We do not expose who referred whom.
We send transactional email (your sign-in link and, where relevant, account or billing notices). We do not send marketing email and do not use advertising or ad-tracking SDKs.
What travels over the network
- The app communicates with the OpenCode server you point it at. Your prompts, the agent's output, and file contents flow between your phone and your machine.
- If you use the optional relay, it forwards the encrypted tunnel between your phone and your machine so you can connect without exposing your machine directly. The relay is a transport: it does not run agent logic, and it is not designed to store your session contents. You can self-host the relay to remove it from the path entirely.
- All connections use TLS/HTTPS in transit.
What we do not do
- We do not sell or rent your data.
- We do not use third-party advertising or ad-tracking SDKs.
- We do not collect your source code, prompts, or agent output for our own use.
Diagnostics
The app may report anonymous crash information provided by the operating system (Apple / Google) to help fix bugs. This contains no source code or session contents. Beta builds are distributed through Apple TestFlight and Google Play, whose own privacy terms apply to the distribution.
Your control
- Deleting the app removes the locally stored connection settings and pairing token from your device.
- You can permanently delete your website account and its data at any time from the account page on shubat.org. Deletion removes your identity, subscription bindings, referral and promo records, and revokes your connector; it cannot be undone. To cancel billing without deleting your account, cancel the subscription from your PayPal account.
- Because your prompts, source code, and session contents live on your own server, you control their retention there.
Contact
Questions about this policy, or requests about your data: fnc12345@gmail.com.