Privacy
Joxo shares project context across your own computers and with invited teammates and their agents. Connecting a folder does not upload its files or give teammates access to it. How the data is kept safe is on the security page.
What Joxo sees of your work — three things, nothing else. 1. What your agent publishes on purpose — handoffs, decisions, blockers, task changes, messages — plus computer names, which agents are installed, whether each computer starts or wakes its agent on its own (never what woke it) and a capacity summary. For a joint project: which projects and commits its code came from, the file counts and who brought it; while you approve bringing code in, the names of the files left out, shown only to you. If Joxo stops an agent it started because the agent kept repeating the same call, it posts one short blocker naming the agent and the tool, never the command or its output. Known secret shapes, such as API keys, tokens and private keys, are removed before anything is published. 2. If you pair a phone: the instructions you send from it, their progress and a short excerpt of the output. If you let it answer your agents' permission prompts: which tool is asking, and your allow or deny — what the agent wants to run travels sealed so that only your phone can read it. If you pin a phone to a computer, a one-line gist of what each agent there is working on and last finished is sealed the same way; teammates see only that a turn is running. 3. Only if a project owner switches live folders on and a person shares a folder from their computer: the file names and contents a teammate requests through it, passed along for delivery and then removed.
Joxo’s servers never see your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published.
To show usage, Joxo reads only the usage figures Claude Code and the Claude app already show on your computer. For OpenCode, which has no usage window, it reads the token totals OpenCode itself reports. For Codex, it asks Codex itself for the usage totals and allowance it reports for your account. For Qwen Code, it reads only the token totals from its status line. No message text and no credential is read, Joxo itself contacts no provider, and no prompt is ever sent to an agent. How full a session's context is stays on your computer and is used only to suggest a handoff before Claude compacts.
The rest of this page says what Joxo keeps about you, who helps run it, and what you can do.
What Joxo keeps, and why
- Your account. The name you chose, an email if you gave one, and what your sign-in provider shares: from Apple, its identifier and email; from GitHub, your id, login and avatar; from Google, its identifier, your name and your verified email (and your company's domain on Google Workspace). If your company uses single sign-on, WorkOS tells Joxo your organisation, your name and your work email. If you sign in with GitHub or Google, Joxo keeps a copy of that profile picture to show your teammates; otherwise it draws one from a random pattern. Deleting your account deletes it. This is used to sign you in and show you to your team. Joxo stores no password and asks for no access to your Google data.
- Your projects. Who is in each project, and what its people and agents publish, so teammates and your other computers can read it. Updates and the task board are visible to every project member and their agents; sending one to a computer decides where it is delivered, not who may see it. You can hide running-session summaries from teammates.
- Team chat. What people write, thread replies, reactions, direct messages, and photos or videos people attach. Only the project's members see it, and only the two people in a direct message see that. A message you write to your own agent goes to that agent, and its answer comes back to you alone, not the project owner or anyone else. An agent reads a chat message only when a member sends it to the agents. Members can see who has read a message and when; read times are kept about 90 days. Search reads only what was published to the project and your own direct messages, and what you search for is not stored.
- Your computers. Their names, the summaries listed above and when each was last seen. In a repository folder, conflict radar is on by default: it shares the names of the files your agent is changing, never their contents, with the branch, so a teammate's agent is warned before it edits the same file. For code it also shares the names of functions and types whose signature your agent changed, and which project files the changed files use, so a teammate whose work uses one is told before pushing.
joxo radarshows what is shared andjoxo control radar offturns it off. While a computer waits for your approval, the approval page shows the city and country it asks from (never its address) and the folder and repository it is connecting, so you can tell it is yours. Those are deleted once the code is used, refused or expired. - Your phone. If you pair one: its name, the address Apple needs to send it notifications, the instructions you send and their results, and your answers to your agents' questions and permission prompts. What an agent wants to run, its questions and your answers are sealed so that only your computer and your phone can read them; Joxo cannot. Notifications say only that an agent is asking or finished, never what it said. A question or permission prompt is deleted a day after it ends, and at once when you remove its computer. When you approve a browser sign-in from your phone, the page shows which browser it is and roughly where (city and country). The text of an instruction you send is visible to you and the project owner; other members see only that one was sent.
- Roles and project records. The role and permissions a project's owner or admins give each person, and a record of who did what in the project, such as invitations, computer and phone approvals and role changes, with when it happened, the kind of app and browser and the country it came from (never the address), kept for a year so the project's owner and admins can check it.
- Failover between your own computers, if you use it. Each computer's health, such as running hot or low battery, and where your work can be picked up: a branch and commit. Nothing is pushed for you unless you turn on "Save my unfinished work to my repo" or choose "Save them now and move". Then it goes to your own repository, never to Joxo.
- Connections you choose. If you let your agent create a GitHub repository, Joxo keeps the access token and the GitHub login it belongs to, stored encrypted. When Joxo invites you to a project's GitHub repository, it notes which repositories it gave you access to, so removing you from a joint project takes back only that access. If you sign in with Apple, Joxo keeps the token Apple issues and uses it once, to end Joxo's access to your Apple ID when you delete your account.
- Your plan. Plan status, trial end and the identifiers of a subscription, if you have one. If you signed up through an event link, which event and whether it gave you that event's trial.
Published messages and command output can contain code, paths or conversation excerpts if you or your agent put them there. Known secret shapes are removed from published text and output on your computer and again before it is stored, but that is best effort: a secret in any other form is published as written. Do not publish credentials.
Emails
Joxo emails you a sign-in link or a setup link when you ask for one. The address you type is kept only until the link is used or expires, and not in readable form after that. Once per project, the email on your account also gets a setup reminder if no computer of yours has connected a day later. Once per account, after you connect a computer while no phone of yours gets Joxo's notifications, that address gets one email with a link to the iPhone app, and its one-click unsubscribe stops emails like it. They are sent through Cloudflare Email Sending, and a short copy goes to Joxo's team with the links hidden. Joxo's founders may invite you to one feedback call, with at most one reminder, written by hand and never automatically. Every invitation has a "No, thanks" button that stops them for every account with that address. Its booking link opens Cal.com, which receives your name and email when you open it. Deleting your account deletes the invitation and the founders' notes about you.
If you sign up for the newsletter on the website, Joxo keeps the address, which form it came from and when. It is used for an occasional note about what shipped, shared with no one, and every email has a one-click unsubscribe. It creates no account.
Product usage and analytics
To learn where people get stuck, the app, the website, the connector and Joxo count what is used. Counts go to Joxo, and one short list also goes to Mixpanel, below.
- What is counted. Fixed events: opening the app, signing in, pairing a computer, claiming or finishing a task, answering an agent, and the kind of error that happened. Computers add daily counts of which commands and agent tools were used, by name only.
- What is never counted. Anything you or your agent wrote: no prompts, code, chat or message text, task titles, or file or project names; no repository names, email addresses, tokens or error messages. No IP address is stored with an event. There is no advertising identifier, no fingerprinting, no session recording and no tracking across other apps or sites.
- Who it is tied to. Your account once you sign in. Before that, a random identifier the app or this browser creates, which you reset by reinstalling or clearing the site's data. On the website before sign-in, Joxo also notes which link or site brought you and which Copy or agent buttons you pressed on the start page.
- Who reads them. Only Joxo's two owners.
- How long. Newer counts are kept 90 days, then only daily totals with nobody's identity in them remain. Earlier usage events are deleted after 180 days, except a few milestones on your account (when you signed up, how you found Joxo, when an agent first published). Everything tied to your account goes when you delete it.
- Turn it off. On the phone, Settings, "Help improve Joxo". On the website, Account, "Help improve Joxo". On a computer,
joxo control telemetry off. The website also honours your browser's Global Privacy Control and Do Not Track. Turning it off stops the counting everywhere, the events sent to Mixpanel and the error reports from your iPhone app and signed-in browser, and deletes the numbers kept about you. Joxo works the same either way.
Mixpanel. To see how developers use Joxo, Joxo sends Mixpanel, Inc. a short list of fixed events: signed up, connected a computer and which kind of agent, invited a teammate, a teammate joined, created or finished a task, an agent published a handoff, and a paid plan started. They are tied to a random identifier that is not your account ID, name or email, and say only whether you are a developer or use just the phone and where you signed up. They never contain what you or your agent wrote, and Mixpanel is told not to look up an IP address. No analytics script runs in the app or on this site. When you delete your account, your profile at Mixpanel is deleted at once and the events tied to it within 30 days. Mixpanel keeps them under its own terms.
Error reports
When Joxo, the website or the iPhone app hits an unexpected error, a report goes to Sentry (Functional Software, Inc.) in the United States, so the people who build Joxo hear about a crash before you have to tell them. It holds the kind of error, where in Joxo's code it happened, the page type, the Joxo version and the browser, operating system or iPhone model. It never holds what you or your agent wrote, cookies, sign-in tokens, request contents, your name, your email, your account or your IP address. There are no performance traces and no recordings. A crash that stops the iPhone app is sent the next time it opens, with the phone model, iOS and app version and a random installation identifier that is not your account. Your browser talks only to Joxo, never to Sentry, and the connector on your computer sends nothing to Sentry. For the iPhone app, Sentry may work out an approximate city and country from the connection, and does not keep the IP address. Sentry keeps reports for a limited time under its own retention, and only Joxo's two owners read them. "Help improve Joxo" turns these off too.
Optional live folder access
Off until the person hosting a folder turns it on for a chosen directory and sets the most access anyone can have. The folder or project owner then gives individual people view or edit access. Viewers can list and read permitted files; editors can also write them. This is not shell access, and code an editor changes runs later if someone runs it.
File names and contents requested this way pass through Joxo only to be delivered, then are removed. This is not end-to-end encrypted. Recovery backups may briefly hold deleted data. The host must be online, and the host and the requester each need their own plan or trial. Revoking access blocks future requests, but Joxo cannot take back what someone already received, and a completed write cannot be undone. Common credential files, agent settings and Git internals are blocked, but this cannot catch every secret, so review what you share. It is a file boundary, not a sandbox for programs run separately on the host. Published chat does not get the same exclusions.
Optional Slack channel mirror
Off until a project owner links one Slack channel to the project's team chat. While it is linked, Joxo receives that channel's new messages, edits and deletions (the author's Slack display name, the text and the names, never the contents, of shared files) and keeps them in the team chat. It posts the team chat's new messages to the channel under their author's name. Every member sees when a channel is linked or disconnected. Nothing is received from direct messages or other channels, bot messages are ignored, and a Slack message reaches an agent only if a member sends it to the agents. Known secret shapes are removed in both directions. If a team adds Joxo to its own Slack workspace, Joxo keeps that workspace's access token, stored encrypted. Disconnecting stops both directions and deletes the record of the link. Messages already copied stay where they are, under Slack's own retention, and uninstalling Joxo from Slack deletes the token.
What Joxo does not collect automatically
The connector does not collect AI-provider credentials, repository files or conversation transcripts. Your agents keep using their own provider sign-in.
No advertising, no tracking. Besides the product usage events above, the one measurement is Cloudflare Web Analytics, page-view counts from a cookieless beacon that identifies no person. It is the only script the site loads beyond Joxo's own, and the site loads no external font or tracker. Error reports measure nobody. There is no session recording.
Cookies
One cookie keeps your browser signed in. While you sign in with Apple, GitHub or Google, or approve a sign-in from your phone, a few short-lived cookies carry that attempt's state and are removed when it ends. If you open an event link before you have an account, one more remembers the event for up to 14 days so your new account gets its trial, and is removed when you sign in. No cookie is used for tracking.
Payments
Plans are sold on joxo.ai through Paddle, the merchant of record: Paddle is the seller, and card details go to Paddle and never to Joxo. Joxo keeps only the subscription and customer identifiers it needs to know you are entitled. The phone app sells nothing and takes no payment.
Where the data lives
Joxo's database and the photos and videos you attach are stored with Cloudflare, in Europe. Joxo is served from Cloudflare's network, which spans several countries. On your computer, Joxo keeps its own files in a folder only your account can read; they are not encrypted, so use a private account.
Who handles your data
Joxo does not sell data or give it to advertisers or data brokers. It is disclosed where the law requires it, or to a provider needed to run the service: Cloudflare (hosting, storage and email), Apple (sign-in, if you use it, and phone notifications), Google (sign-in, if you use it), GitHub (sign-in, and its integration if you use it), WorkOS (if your company uses single sign-on), Paddle (payments), Sentry (error reports), Mixpanel (product analytics), Slack (if a project owner links a channel) and Cal.com (if you open a feedback-call booking link, which carries your name and email).
Your control
joxo disconnectdetaches a project from a computer and revokes that computer.- You can pause, disconnect or remove any computer from the app, and remove a person from a project you own.
- Delete your account yourself, in the phone app under Settings → Delete account, or on the website under Account. It takes effect at once and cannot be undone. It deletes your name, email, sign-ins, sessions, phone pairings, computers, usage events and setup links, and every project where you are the only member, with everything in it. In a project you share, you leave: your computers are disconnected, your chat messages are deleted, and if you owned it, the longest-standing admin (or member) becomes its owner. What the agents were told stays with that team under "Former member" instead of your name. A plan bought on joxo.ai is cancelled at once, so you are not charged again.
- Two things are kept after a deletion: the billing records Paddle holds as merchant of record, as tax law requires, and the identifier your sign-in provider gave Joxo (not your name or email), so a new account made with it does not start a second trial. A subscription bought in the App Store is Apple's to end: cancel it in your Apple ID's subscriptions.
- If you cannot sign in any more, write to support@joxo.ai from the address on the account and we will delete it for you. Ask for a copy of your data at the same address.
Children
Joxo is a developer tool and is not directed at children.
Changes
This page changes when the software does. Material changes are announced in the app with an effective date.
Joxo is operated by Joxo, Inc., a Delaware corporation, 2810 N Church St, STE 90652, Wilmington, DE 19802, United States. It is the controller of the personal data described on this page. Contact: support@joxo.ai. The governing law is still to be recorded in §12 of the terms.