Privacy Policy
Last updated: September 10, 2026
This policy covers Pragma, the desktop application, and Pragma Go, its companion app for iPhone, Android, and the browser. Both are open source; the code described here can be read at https://github.com/pragma-sh/pragma.
The short version
Pragma runs on your computer, and Pragma Go talks to the copy of Pragma you pair it with. Your projects, your code, and your agent conversations stay on machines you control.
As of the date above, we operate no service that receives your data — there is no analytics SDK, no crash reporter, no advertising identifier, and no tracking in either app. The sections below describe both what happens today and what would apply if that changes, so you can see the rules we hold ourselves to either way. We do not sell or rent personal information, we do not share it with data brokers, and we do not build advertising profiles — and those three commitments are not conditional on anything below.
What Pragma (desktop) stores
Everything Pragma keeps stays on your computer, in your home directory and in your projects:
- Your projects, git worktrees, terminal sessions, and agent transcripts, held on your local disk.
- Settings and keyboard shortcuts in
~/.pragma/and in each project’s.pragma/directory. - A GitHub access token, if you choose to connect GitHub, written to a file readable only by your user account.
None of this is transmitted to us.
What Pragma Go stores on your device
- Connection details. The address and access token of the Pragma desktop you paired with, held in the operating system keychain (iOS Keychain, Android Keystore) or, in the browser build, in the browser’s own storage.
- An installation identifier. A random value generated on your device so your paired desktop can list which devices are connected and let you revoke one. It is not derived from your identity or from any device or advertising identifier.
- Local interface state, such as which items you have dismissed.
Unpairing removes the connection details and revokes the device on the desktop.
What Pragma Go sends, and where
Pragma Go sends your workspace requests to a destination you choose: the Pragma desktop you paired with, reached over a network address you supply during pairing. Those requests carry your access token, the installation identifier, the device platform and name, and the app version. Your workspace data, agent messages, and anything you type into an agent travel between your phone and your own computer.
If you reach your desktop through a tunnelling service (for example ngrok or Cloudflare Tunnel), that service is chosen and configured by you, and its own privacy policy applies to traffic passing through it. Pragma does not select one for you.
Analytics and diagnostics
Neither app currently collects analytics, usage statistics, or crash reports. If we introduce them, they will be limited to product and stability data — which features are used, performance measurements, error and crash diagnostics, and coarse environment details such as app version, operating system version, and device model.
Whatever form they take, these rules apply: diagnostics will never include the contents of your code, your prompts, your agent conversations, your file paths, your repository names, or your credentials. They will not be used for advertising or sold to anyone. Collection will be disclosed on this page before it begins, with the date above updated, and the change will be visible in the repository’s public history.
Services we may operate
Pragma has no accounts, and the only server running Pragma itself is the one on your own computer. The one exception today is this website’s support form: submitting it sends your name, email address, and message to Splitforms, a form-processing service, which emails the request to us. Splitforms is bound to use that data only to deliver the submission; see its own privacy policy. We may later offer further optional hosted services — for example an account, a relay that reaches your desktop without you configuring a tunnel, sync between your devices, or a licensing and payment system.
If we do, this page will describe each service before it launches: what it receives, how long it is kept, and who processes it on our behalf. Such services will be optional and additive — running Pragma against your own machine, with no account, will remain supported. A relay, if we build one, is intended to pass encrypted traffic through without reading its contents.
Push notifications
If you allow notifications, Pragma Go registers a push token with Expo’s push notification service, which relays through Apple Push Notification service or Firebase Cloud Messaging. Your paired desktop sends alerts — such as an agent waiting on your approval — through that relay, so the alert text and the push token pass through Expo and Apple or Google on the way to your device. Denying the notification permission, or never pairing, means no push token is ever created.
Camera
Pragma Go asks for camera access for one purpose: scanning the pairing QR code your desktop displays. Frames are examined on the device to find the code and are never stored, uploaded, or used for anything else. You can skip the camera entirely and type the pairing details by hand.
Third parties
Depending on what you set up, these third parties may receive data at your direction:
- AI model providers. Coding agents you run on the desktop send your prompts and the code they read to the model provider you configured. That provider’s terms and privacy policy govern that data.
- GitHub, if you connect it, for the repositories and pull requests you act on.
- Expo, Apple, and Google, for delivering push notifications, as described above.
- Your tunnelling provider, if you use one to reach your desktop remotely.
- Splitforms, which receives your name, email address, and message when you submit the support form, so it can deliver your request to us.
Any processor we engage for a service of our own will be named on this page, and will be bound to use the data only to provide that service to us.
Children
Pragma is a developer tool and is not directed at children. We do not knowingly collect information from anyone under 13.
Your choices and your rights
Because your data lives on your own machines, you control it directly: unpair a device to revoke its access, delete ~/.pragma/ to remove desktop settings, disconnect GitHub to invalidate the stored token, and uninstall either app to remove its local storage. There is no account to delete, because there is no account.
Should we later hold data about you, you may ask us what we hold, ask for a copy, ask us to correct or delete it, and object to a particular use — and analytics, if introduced, will be something you can turn off.
Changes
When this policy changes, the date at the top changes with it. Changes that expand what is collected take effect only going forward, and are published here before the collection begins. Every revision is visible in the public git history of this site.
Contact
Questions about this policy, or a request about your data: open an issue at https://github.com/pragma-sh/pragma/issues. Note that issues are public — do not include anything confidential.