Controller

Privacy Policy

Effective October 1, 2026 · Operated by Max Weinbach

This policy covers Controller for Mac, its iPhone and iPad companion ControllerMobile, the Controller Connect account service, and this website. It explains what information is processed, why, and the choices you have.

1. Your workspace and coding providers

Your host Mac stores your projects, files, conversation history, agent settings, and usage records locally. ControllerMobile connects to that Mac; it does not run the coding agents or maintain a separate copy of the Mac’s durable workspace. Remote clients can store a limited, temporary cache of recent conversations, listings, and images on the device to make reopening the app faster. These caches expire and are discarded when access is removed or a connection is reset.

When you use a coding agent, your prompts, attachments, selected project context, tool results, and other information needed for the task can be processed by the agent and the providers you configure. Their own terms, privacy policies, account settings, and retention practices apply. Controller does not make a promise about those providers’ training or retention practices. Agents can access files, commands, browser content, and other tools within the permissions you grant.

The invitation username reviewer opens a public, prepared workspace downloaded from this website. It does not create or authenticate a private Connect account. The downloaded projects, conversations, provider listings, and pending approvals are illustrative content. Prompts, attachments, and changes made in this workspace stay in its isolated local adapter and are not sent to a Mac, coding provider, or the published dataset. Signing out discards that workspace; signing in again downloads fresh content. The download creates an ordinary website request, subject to the infrastructure metadata described below.

2. Controller Connect account information

Connect processes the information needed to sign you in and authorize your devices:

We use these records to authenticate you, manage login methods, register and revoke devices, find your Macs, protect sign-in, and deliver the features you request. Social-provider tokens are encrypted in storage. Passkey private keys remain with your device or credential provider. App session tokens and private device keys are kept in the device’s Keychain; an enrollment credential may be shared through iCloud Keychain where available.

The Connect account directory does not store your chat transcripts, repository files, or coding-provider credentials. Hosted conversation traffic travels between your client and Mac through the host connection, with device authentication and end-to-end encrypted application frames.

3. Notifications and Live Activities

When you enable remote-work notifications or use Live Activities, Connect processes your device’s push token and, where applicable, stores Live Activity registration information. Your Mac sends chat and Mac names, identifiers, task statuses, timing information, and alert text through Connect to Apple Push Notification service for delivery. Chat titles and statuses are therefore processed by the service even though full conversations are not stored in the account directory. Notification content is forwarded rather than retained as a chat archive.

Notifications can appear on the Lock Screen or in the Dynamic Island according to your system settings. Turn them off in Controller’s settings or your device’s notification settings. Disabling Connect alerts unregisters the device’s alert token; signing out or revoking a device removes its push registrations and activities.

4. Optional Apple sync

When available, selected preferences may sync through your system iCloud account. Preference sync is enabled by default when the build and account support it and can be turned off in Connect settings. The sync list includes preferences such as favorite models and display choices; it excludes conversation bodies, local paths, coding-provider credentials, and host enablement.

Automatic device enrollment can use iCloud Keychain. A notification fallback can use private CloudKit records containing chat titles, identifiers, notification kind, and creation time, without conversation bodies. The app schedules cleanup of these fallback records after 24 hours. Signing in to Connect does not sign your device in to iCloud.

5. Browser, attachments, and diagnostics

Controller’s Mac browser stores browsing history, saved tabs, cookies, website storage, and other browser data in a local app-owned profile. Sites you visit receive ordinary web request information and may collect additional data under their own policies. You can manage browsing history and website data from Controller’s browser settings.

Photos and files you choose to attach are processed for your conversation and sent to the host Mac and relevant coding provider as needed. The app requests system permissions where required. Only share material you intend the agent to use.

The apps keep local diagnostic information and can prepare a report for you to share. If you send a bug report, support email, screenshot, or TestFlight feedback, we receive what you submit; Apple may also make beta crash and diagnostic information available through TestFlight. Review reports before sharing them. Public GitHub issues are visible to others, so do not include private code, credentials, or personal information there.

6. Service providers and this website

Cloudflare hosts this website, the Connect portal, and the account database. Apple and Google process the sign-in method you choose; Apple also provides push notifications, iCloud Keychain, and CloudKit when used. OpenTunnel provides the hosted connection relay when enabled. Configured coding providers and websites you visit process information needed for their respective services. Infrastructure providers may process network information such as IP addresses, timestamps, and request metadata to deliver and secure those services. Processing can occur in the countries where these providers operate.

Controller and this website do not contain advertising or analytics scripts, and we do not sell your personal information or share it for targeted advertising. The account portal uses cookies necessary for sign-in and security. This marketing website has no sign-in form, tracking cookies, or embedded third-party advertising.

7. Retention, deletion, and your choices

Local workspace information remains under your control on your Mac. You can delete conversations and manage files locally. Removing the Connect account does not delete local Mac conversations or repository files, or information already held by a coding provider.

Account information is retained while your account exists. Expired authentication records are cleaned up regularly. Choose Delete Account in app settings or on the Controller account page to remove the account, login methods, passkeys, registered devices, environments, sessions, and push registrations. Deletion requires a recent sign-in and explicit confirmation. All registered devices lose account access. Deleted information may remain in infrastructure backups until their retention period ends.

You can manage sign-in methods and passkeys on your account page, revoke device access in the apps, turn off hosting or notifications, disable preference sync, and stop automatic sign-in on new devices. For questions about access, correction, export, or deletion, contact us below. Applicable privacy rights depend on where you live. We may need to verify your identity before fulfilling a request.

8. Children and policy changes

Controller is a developer tool and is not directed to children under 13. If you believe a child has provided personal information to the account service, contact us so we can review and remove it as appropriate.

We may update this policy when features or practices change. The effective date at the top identifies the latest version. Material changes will be communicated through the website or product where appropriate.

Contact

Max Weinbach operates Controller and Controller Connect. Email maxweinbach5@gmail.com with privacy questions or requests. For product help, visit our support page.