Privacy Policy for Agentflow
Last Updated: September 2026
Overview
Agentflow is committed to protecting your privacy. This policy explains how we handle data with end-to-end encryption.
It covers the hosted DreamStation relay at https://agentflow-api.dreamstation.dev. If you self-host an Agentflow server, the person or organisation running it holds that data and sets its own policy.
What We Collect
Encrypted Data
- Messages and code: Agent conversations and code snippets are encrypted on your device before transmission. We store ciphertext and cannot decrypt it.
- Encryption keys: When you pair devices, keys are transmitted between your devices in encrypted form. We cannot access or decrypt those keys.
Metadata (Not Encrypted)
- Message IDs for ordering and synchronization
- Timestamps
- Device IDs for pairing
- Session IDs for coding-agent sessions
- Push notification tokens for Expo push delivery
Analytics (PostHog)
The app may collect basic usage events through PostHog to improve the product.
- Events use an anonymized ID derived from a secret key
- We do not track message content, code, or personal information in analytics
- You can disable analytics in app settings
This website (agentflow.dreamstation.dev) does not run analytics.
What We Don't Collect
- Your actual code or conversation content (we cannot decrypt it)
- Payment card details (Agentflow does not sell in-app purchases)
- Location data
- Advertising identifiers
How We Use Data
- Encrypted data is stored only so your devices can synchronize
- Metadata keeps message order, pairing, and notifications working
- Push notifications are generated on your devices; Expo is used as a delivery mechanism
Data Security
- End-to-end encryption for session content
- Zero-knowledge: we cannot read your content
- Open source, MIT-licensed implementation
- Default relay:
https://agentflow-api.dreamstation.dev
Data Retention
- Encrypted messages are retained until you delete them
- Deleted data is removed from our servers within 30 days
Your Rights
You may delete your data through the app, export encrypted data, audit the source, and use the product without providing a legal name.
Data Sharing
We do not sell your data. We do not share session content with third parties. Push delivery uses Expo. Analytics, when enabled, uses PostHog.
Changes
Material changes will be noted in the app or on this page. Continued use after changes constitutes acceptance.
Contact
Privacy questions: GitHub issues
Website: https://agentflow.dreamstation.dev