joxo

Privacy

Joxo shares project context across your own computers and with invited teammates and their agents. Connecting a folder does not upload its files or give teammates access to it. How the data is kept safe is on the security page.

What Joxo sees of your work — three things, nothing else. 1. What your agent publishes on purpose — handoffs, decisions, blockers, task changes, messages — plus computer names, which agents are installed, whether each computer starts or wakes its agent on its own (never what woke it) and a capacity summary. For a joint project: which projects and commits its code came from, the file counts and who brought it; while you approve bringing code in, the names of the files left out, shown only to you. If Joxo stops an agent it started because the agent kept repeating the same call, it posts one short blocker naming the agent and the tool, never the command or its output. Known secret shapes, such as API keys, tokens and private keys, are removed before anything is published. 2. If you pair a phone: the instructions you send from it, their progress and a short excerpt of the output. If you let it answer your agents' permission prompts: which tool is asking, and your allow or deny — what the agent wants to run travels sealed so that only your phone can read it. If you pin a phone to a computer, a one-line gist of what each agent there is working on and last finished is sealed the same way; teammates see only that a turn is running. 3. Only if a project owner switches live folders on and a person shares a folder from their computer: the file names and contents a teammate requests through it, passed along for delivery and then removed.

Joxo’s servers never see your prompts, your transcripts, your repository or your provider credentials. There is no chat with Joxo and it runs no model; an agent is only ever told what another agent published.

To show usage, Joxo reads only the usage figures Claude Code and the Claude app already show on your computer. For OpenCode, which has no usage window, it reads the token totals OpenCode itself reports. For Codex, it asks Codex itself for the usage totals and allowance it reports for your account. For Qwen Code, it reads only the token totals from its status line. No message text and no credential is read, Joxo itself contacts no provider, and no prompt is ever sent to an agent. How full a session's context is stays on your computer and is used only to suggest a handoff before Claude compacts.

The rest of this page says what Joxo keeps about you, who helps run it, and what you can do.

What Joxo keeps, and why

Published messages and command output can contain code, paths or conversation excerpts if you or your agent put them there. Known secret shapes are removed from published text and output on your computer and again before it is stored, but that is best effort: a secret in any other form is published as written. Do not publish credentials.

Emails

Joxo emails you a sign-in link or a setup link when you ask for one. The address you type is kept only until the link is used or expires, and not in readable form after that. Once per project, the email on your account also gets a setup reminder if no computer of yours has connected a day later. Once per account, after you connect a computer while no phone of yours gets Joxo's notifications, that address gets one email with a link to the iPhone app, and its one-click unsubscribe stops emails like it. They are sent through Cloudflare Email Sending, and a short copy goes to Joxo's team with the links hidden. Joxo's founders may invite you to one feedback call, with at most one reminder, written by hand and never automatically. Every invitation has a "No, thanks" button that stops them for every account with that address. Its booking link opens Cal.com, which receives your name and email when you open it. Deleting your account deletes the invitation and the founders' notes about you.

If you sign up for the newsletter on the website, Joxo keeps the address, which form it came from and when. It is used for an occasional note about what shipped, shared with no one, and every email has a one-click unsubscribe. It creates no account.

Product usage and analytics

To learn where people get stuck, the app, the website, the connector and Joxo count what is used. Counts go to Joxo, and one short list also goes to Mixpanel, below.

Mixpanel. To see how developers use Joxo, Joxo sends Mixpanel, Inc. a short list of fixed events: signed up, connected a computer and which kind of agent, invited a teammate, a teammate joined, created or finished a task, an agent published a handoff, and a paid plan started. They are tied to a random identifier that is not your account ID, name or email, and say only whether you are a developer or use just the phone and where you signed up. They never contain what you or your agent wrote, and Mixpanel is told not to look up an IP address. No analytics script runs in the app or on this site. When you delete your account, your profile at Mixpanel is deleted at once and the events tied to it within 30 days. Mixpanel keeps them under its own terms.

Error reports

When Joxo, the website or the iPhone app hits an unexpected error, a report goes to Sentry (Functional Software, Inc.) in the United States, so the people who build Joxo hear about a crash before you have to tell them. It holds the kind of error, where in Joxo's code it happened, the page type, the Joxo version and the browser, operating system or iPhone model. It never holds what you or your agent wrote, cookies, sign-in tokens, request contents, your name, your email, your account or your IP address. There are no performance traces and no recordings. A crash that stops the iPhone app is sent the next time it opens, with the phone model, iOS and app version and a random installation identifier that is not your account. Your browser talks only to Joxo, never to Sentry, and the connector on your computer sends nothing to Sentry. For the iPhone app, Sentry may work out an approximate city and country from the connection, and does not keep the IP address. Sentry keeps reports for a limited time under its own retention, and only Joxo's two owners read them. "Help improve Joxo" turns these off too.

Optional live folder access

Off until the person hosting a folder turns it on for a chosen directory and sets the most access anyone can have. The folder or project owner then gives individual people view or edit access. Viewers can list and read permitted files; editors can also write them. This is not shell access, and code an editor changes runs later if someone runs it.

File names and contents requested this way pass through Joxo only to be delivered, then are removed. This is not end-to-end encrypted. Recovery backups may briefly hold deleted data. The host must be online, and the host and the requester each need their own plan or trial. Revoking access blocks future requests, but Joxo cannot take back what someone already received, and a completed write cannot be undone. Common credential files, agent settings and Git internals are blocked, but this cannot catch every secret, so review what you share. It is a file boundary, not a sandbox for programs run separately on the host. Published chat does not get the same exclusions.

Optional Slack channel mirror

Off until a project owner links one Slack channel to the project's team chat. While it is linked, Joxo receives that channel's new messages, edits and deletions (the author's Slack display name, the text and the names, never the contents, of shared files) and keeps them in the team chat. It posts the team chat's new messages to the channel under their author's name. Every member sees when a channel is linked or disconnected. Nothing is received from direct messages or other channels, bot messages are ignored, and a Slack message reaches an agent only if a member sends it to the agents. Known secret shapes are removed in both directions. If a team adds Joxo to its own Slack workspace, Joxo keeps that workspace's access token, stored encrypted. Disconnecting stops both directions and deletes the record of the link. Messages already copied stay where they are, under Slack's own retention, and uninstalling Joxo from Slack deletes the token.

What Joxo does not collect automatically

The connector does not collect AI-provider credentials, repository files or conversation transcripts. Your agents keep using their own provider sign-in.

No advertising, no tracking. Besides the product usage events above, the one measurement is Cloudflare Web Analytics, page-view counts from a cookieless beacon that identifies no person. It is the only script the site loads beyond Joxo's own, and the site loads no external font or tracker. Error reports measure nobody. There is no session recording.

Cookies

One cookie keeps your browser signed in. While you sign in with Apple, GitHub or Google, or approve a sign-in from your phone, a few short-lived cookies carry that attempt's state and are removed when it ends. If you open an event link before you have an account, one more remembers the event for up to 14 days so your new account gets its trial, and is removed when you sign in. No cookie is used for tracking.

Payments

Plans are sold on joxo.ai through Paddle, the merchant of record: Paddle is the seller, and card details go to Paddle and never to Joxo. Joxo keeps only the subscription and customer identifiers it needs to know you are entitled. The phone app sells nothing and takes no payment.

Where the data lives

Joxo's database and the photos and videos you attach are stored with Cloudflare, in Europe. Joxo is served from Cloudflare's network, which spans several countries. On your computer, Joxo keeps its own files in a folder only your account can read; they are not encrypted, so use a private account.

Who handles your data

Joxo does not sell data or give it to advertisers or data brokers. It is disclosed where the law requires it, or to a provider needed to run the service: Cloudflare (hosting, storage and email), Apple (sign-in, if you use it, and phone notifications), Google (sign-in, if you use it), GitHub (sign-in, and its integration if you use it), WorkOS (if your company uses single sign-on), Paddle (payments), Sentry (error reports), Mixpanel (product analytics), Slack (if a project owner links a channel) and Cal.com (if you open a feedback-call booking link, which carries your name and email).

Your control

Children

Joxo is a developer tool and is not directed at children.

Changes

This page changes when the software does. Material changes are announced in the app with an effective date.

Joxo is operated by Joxo, Inc., a Delaware corporation, 2810 N Church St, STE 90652, Wilmington, DE 19802, United States. It is the controller of the personal data described on this page. Contact: support@joxo.ai. The governing law is still to be recorded in §12 of the terms.