Hivepod Privacy Policy

Effective date: May 18, 2026 · Last updated: July 15, 2026

1. Introduction

This Privacy Policy ("Policy") describes how Hivepod ("the App", "we", "us") handles your information across the iOS mobile app, the macOS / Windows / Linux desktop app, and the optional Relay service. Please read it carefully before using the App.

The App is developed and operated by Shenzhen Resopod Technology Limited Company. For any question about this Policy, contact us at support@resopod.cn.

2. Who We Are

Hivepod is a desktop graphical front-end for command-line AI agents such as Claude Code, Kimi, and Codex. The desktop app integrates these AI agents into a unified graphical interface and adds voice input, personas, and a skill system. The iOS mobile app is a remote client of the desktop app, letting you reach a Hivepod instance running on your own computer from your phone. Hivepod itself does not run any AI model — all AI execution happens through the underlying AI agent installed on your own computer.

3. Design Principles

The App is designed to be local-first:

  • Your conversations, settings, installed skills, and personas are stored locally on your device by default (under ~/.hive/ on desktop).
  • We do not operate a user account system and do not require your name, ID number, phone number, or other personal identifiers.
  • We do not perform server-side analytics on your conversations or usage behavior.
  • The mobile app does not run any AI service; it is purely a remote front-end of the desktop.

4. Information We Handle

4.1 Local Data (Stored by Default)

The following is stored on your device by default. We do not operate a cloud copy; content leaves the device only when you actively use a feature described in 4.2 or 4.3:

  • Conversation history with AI agents
  • Application configuration and preferences
  • Skills, personas, MCP tools you install, along with their configuration
  • Local files or snapshots you import or create

You can remove all local data by deleting the ~/.hive/ directory (desktop) or uninstalling the App (mobile).

4.2 AI Provider Data Forwarding

When you interact with an AI agent through Hivepod:

  • Prompts, user-selected files or images, voice recordings or transcripts, and related conversation context are sent to your paired desktop. The underlying agent or transcription service on your computer may then send relevant content directly to the AI or speech-to-text provider you configured (Anthropic, Moonshot, OpenAI, Alibaba, Tencent, Zhipu AI, and others).
  • We do not operate a conversation-history cloud. Our Relay cannot decrypt this content, and we do not receive or store it on Hivepod-operated application servers.
  • Handling of that content is governed by the relevant AI provider's own privacy policy, which you should review separately.
  • The Hivepod mobile app does not hold or proxy any third-party API credentials.

4.3 Remote Connection (Optional)

If you enable remote connections between the desktop and mobile apps, you can choose from four peer-level transport options — all uniformly protected by end-to-end encryption (TweetNaCl):

  • Our optional Relay server — a WebSocket relay we operate
  • Direct LAN — device-to-device on your local network
  • Tailscale — your own Tailscale virtual network
  • User-operated tunnels — e.g. ngrok or self-hosted

All messages are end-to-end encrypted; intermediate servers (including our Relay) cannot decrypt message content. You may bypass our infrastructure entirely by choosing LAN, Tailscale, or a user-operated tunnel.

Our production Relay is hosted in Hangzhou, Mainland China. It forwards encrypted payloads in memory and does not persist message content or room state. For access control, it stores only:

  • An authorization public key and the activation-code record used to authorize it
  • Authorization time, code status and limits, and an optional operational note or label if one is assigned for support

Authorization records are retained while Relay access remains active. You may request revocation and deletion of the authorized-device record by contacting us. WebSocket request URLs are excluded from access logs, and application logs are minimized and size-rotated.

4.4 Activation Codes

To gate access to our optional official Relay, the Relay service uses activation codes (invite codes):

  • Activation codes are bound to authorization public keys and are not linked to your personal identity.
  • Activation code state (active / revoked) and the list of authorized devices are maintained by our Relay service.
  • You can request revocation and deletion of the associated authorized-device record at any time.
  • No Hivepod Relay activation code is required for LAN, Tailscale, or a user-operated tunnel.

4.5 Mobile App Specifics

  • The mobile app is a remote front-end and cannot operate as a complete product on its own. Settings and pairing guidance are available without a desktop; conversations, files, and remote actions require a paired desktop Hivepod instance.
  • The mobile app does not run any AI service itself and does not hold or proxy any third-party API credentials.
  • The mobile app requests the following system permissions, each used only when you actively trigger the corresponding feature:
    • Camera — to scan pairing QR codes and capture image attachments
    • Photo Library — to attach images to messages
    • Microphone — for voice input
    • Local Network — to connect to a paired desktop on the same LAN
  • The mobile app does not integrate third-party analytics, advertising, or behavioral tracking SDKs.

4.6 Crash and Error Reports (Opt-in)

The desktop App can send anonymous crash and error reports to a self-hosted error tracking service we operate. This feature is off by default and is enabled only after your explicit opt-in:

  • Automatic reports may include crash stack traces, device context (OS version, app version, locale, hardware class), an anonymous installation ID, and technical breadcrumbs.
  • When you explicitly submit feedback from the desktop app, the report includes your description, basic system information, and a scrubbed recent log excerpt that you can preview before submission.
  • Reports are scrubbed to remove secrets and direct identifiers. Please do not include conversation content, files, API keys, activation codes, or other secrets in a feedback description.
  • Data is sent to a self-hosted server we operate, located in mainland China (ICP-filed under our company entity).
  • Retention: 30–90 days.
  • You can disable it any time in Settings → Privacy, or email to request deletion of all reports tied to your installation.

The iOS mobile app does not currently integrate any crash-reporting SDK. If we add one in the future, we will disclose it in a release update and this Policy revision.

5. Cookies and Similar Technologies

Neither the desktop nor the mobile app uses cookies. If you visit our websites (https://resopod.ai/products/hivepod, https://resopod.ai, https://www.resopod.cn), cookie usage there is covered by those websites' own notices.

6. Data Sharing

We do not share your data with third parties except in these cases:

  • AI and speech-to-text providers — when you actively configure and invoke them (see 4.2).
  • Network providers you choose — such as Tailscale or a tunnel provider, when you choose that connection path.
  • App distribution platforms — such as Apple App Store or Google Play, when you obtain the App through them; their own privacy policies apply.
  • Legal compliance — when required by applicable law in the jurisdiction where we operate.

We do not use your data for advertising, we do not sell it, and we do not trade it.

7. Data Security

  • The security of local data depends on the security of your device. We recommend enabling a device lock and safeguarding your API keys.
  • Remote connections are protected by end-to-end encryption (TweetNaCl) on top of transport-layer security.
  • We apply reasonable administrative and technical measures to protect any connection metadata retained on our Relay.

8. Your Rights

You may:

  • Access your local data (by inspecting ~/.hive/ or through in-app settings).
  • Delete your local data (by removing the directory or uninstalling the App).
  • Revoke an authorized device to stop its further official Relay usage.
  • Provide feedback or complaints via support@resopod.cn.

If you reside in the EU, UK, California, Mainland China, or other jurisdictions with specific data protection regimes (GDPR / UK GDPR / CCPA / PIPL), you have additional rights including access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. Contact support@resopod.cn to exercise them; we will reply within a reasonable timeframe.

9. Children

The App is not intended for children under 13 and we do not knowingly collect information from children under 13. If you are a parent or guardian and believe your child has provided information to us, contact us and we will delete it.

10. International Data Transfers

  • The current production Relay is located in Hangzhou, Mainland China and does not route Relay traffic through overseas Relay nodes.
  • If you configure an AI provider located outside Mainland China, the AI agent on your own computer connects directly to that provider under your configuration and the provider's privacy terms. The Relay cannot read that content.
  • If we introduce an overseas Relay node in the future, we will update this Policy and obtain separate consent before cross-border transfer where applicable law requires it.

11. Policy Changes

We may update this Policy from time to time. When we do, we will notify you in-app, on our website, or through the contact channels shown in this Policy. Continued use of the App after an update constitutes acceptance of the updated Policy.

12. Contact Us

For any question, suggestion, or complaint regarding this Privacy Policy:

Email: support@resopod.cn

Public support phone: +86 186 2801 2255

Hivepod product page (international): https://resopod.ai/products/hivepod

Hivepod product page (Mainland China): https://resopod.cn/products/hivepod

Company website: https://resopod.ai (international) / https://www.resopod.cn (Mainland China)

Controller: Shenzhen Resopod Technology Limited Company

Registered address: Room 408, Building B, Jinbaixing, No. 24 Jingnan Road, Longzhu Community, Buji Subdistrict, Longgang District, Shenzhen, China

Website ICP Filing No.: 粤ICP备2026040915号-1

APP Filing No.: 粤ICP备2026040915号-2A