AI Shuffle · HobbyCoders
Privacy policy
AI Shuffle runs on your machines, and your prompts and files go from there straight to the AI provider you choose. This policy covers what reaches us: from this website, the app’s update and license checks, the connection service, remote access, and billing.
Effective September 23, 2026
In short
- We never receive your prompts, files, conversations or AI provider sign-ins.
- There are no analytics, ads or tracking cookies on this website or in the apps.
- We don’t sell or share personal information, and we don’t train AI on it.
- Remote access, if you turn it on, passes through Cloudflare under our account.
Every address the app contacts, and why
| What | Address | When | What is sent |
|---|---|---|---|
| Update check (every worker and the desktop app) | hobbycoders.com/v1/desktop/manifest and /v1/desktop/sources/…; on macOS and Linux, /v1/desktop/installers and /v1/desktop/installer/… | When the app starts, then once a day. The desktop app waits 15 seconds after launch. | An HTTPS request for the signed release manifest, and the release file when you update. Once licensing is live, it carries the worker’s current license lease in an X-Shuffle-Lease header (see Update checks). No account, prompts or usage data. Like any web request it carries your IP address and a user agent. |
| License activation and check (once licensing is live) | Our license service at hobbycoders.com/v1/license/… | When you activate a worker, then about once a day per worker. | On activation: the license key, a random install ID, a fingerprint (a SHA-256 hash of that install ID and the computer’s machine ID), the computer’s host name as the worker’s display name, and the app version. Each day: the install ID, its install token, the fingerprint and the app version. See License checks. |
| Connection service (only if you sign in or link a worker) | hobbycoders.com/v1/… | Sign-in, pairing and linking; a linked worker checks for new devices about every 4 minutes. | Worker name, identifier and address; device names and identifiers; sign-in records. Once licensing is live, a linked worker also sends its license lease (X-Shuffle-Lease) when it turns remote access on. See Account and connection service and Remote access. |
| Remote access (only if you turn it on) | Cloudflare, through a tunnel for your worker at shuffle-<id>.hobbycoders.com | While remote access is on. | All traffic between your phone or remote browser and your worker. See Remote access. |
| AI providers you set up | The providers you connect: any of Anthropic (through Claude Code), OpenAI, OpenRouter, xAI, fal.ai or others you add | Whenever an agent runs. | Your prompts, files and tool results, sent directly from your installation to the provider. Not to us. |
| Claude Code itself | Anthropic | When you choose Claude and install it from Settings or setup, Anthropic’s own installer downloads Claude Code. It is reinstalled at worker start only while Keep Claude Code installed is on. Claude Code then updates itself and talks to Anthropic as it normally does. | Governed by Anthropic’s terms and privacy policy. |
| Integrations you connect | For example GitHub, Telegram, Discord, Slack, WhatsApp, LINE, Microsoft Teams, Google or Spotify | Only after you connect one. | What that integration needs to do its job, sent directly from your installation. |
| Android app | hobbycoders.com/v1/…, Clerk, and your worker | Sign-in, opening a worker, and voice calls you start. | Sign-in and device records; your chats go to your worker directly or through its tunnel. Voice calls stream microphone audio from the phone to your worker, which relays it to the speech provider you configured there (OpenAI unless you chose another). Not to us. |
Local use needs none of the connection-service or remote-access rows. The update check runs without asking, on launch and daily, like other desktop apps; beyond the request itself it sends only the license proof described under Update checks.
This website
hobbycoders.com runs on Cloudflare. Cloudflare processes each request, including your IP address and browser details, to serve and protect the site. The website sets no cookies and has no analytics.
Waitlist
If you join the waitlist, we keep your email address, the page you joined from and the time, in Cloudflare Workers KV, and send a copy to our support inbox. We use it only to email you when the beta opens. We keep no IP address or cookie with it. To be removed, email support@hobbycoders.com from that address.
Update checks
Workers and the desktop app ask hobbycoders.com for a signed release manifest when they start and once a day, and download the release when you update. The request carries what any HTTPS request does, your IP address and a user agent, and, once licensing is live, proof of your license:
- A worker with a license sends its current license lease in the
X-Shuffle-Leaseheader: the record our license service signed for it, with the license and account identifiers, the worker’s random install ID, the plan, the number of workers allowed, and when the lease was issued and ends. The update service checks the signature and forgets it. - A first desktop install has no lease yet. If the update service asks for a license, the installer asks you for your license key, sends it with the update requests, and keeps it in a file only you can read on that computer until the app has a lease, then deletes it. The update service passes the key to our license service to check that it is active, and stores and logs neither.
On macOS and Linux the desktop app asks for the signed list of installers instead, and downloads the new installer only when you choose Download. Those requests carry no lease, license key or account.
The update service doesn’t store update checks in its database. Release files are stored with GitHub; our service fetches them for you, so your device does not contact GitHub for an update.
License checks
Once licensing is live, you activate each worker with your license key, in Settings or, if you gave the key when installing (the desktop installer, or LICENSE_KEY for Docker and Unraid), automatically on its first start. Activation sends:
- the license key;
- a random install ID the worker makes for itself;
- a fingerprint: a SHA-256 hash of that install ID and the computer’s machine ID. The machine ID itself is not sent;
- the computer’s host name, used as the worker’s display name on your account page and in the list of workers holding seats;
- the app version.
After that each worker renews its license about once a day, sending its install ID, a per-install token, the fingerprint and the app version. The license service stores a hash of your license key, your install IDs, their host names and fingerprints, the app version, the time of the last check, the leases it issued, and request-throttling identifiers derived from IP addresses. A worker that has not checked in for 21 days gives up its seat. The license service never receives prompts, files or anything about your AI providers.
Billing
When checkout opens, Stripe processes payments. We receive your name, email address, billing country, card brand and last four digits, and your subscription status. We never see your full card number. Stripe handles payment data under its own privacy policy.
After a purchase, the license service emails your license key and your image pull token to the address you paid with. The email is sent through Resend, which receives your email address and the message. It has no tracking or images.
Account and connection service
Signing in is optional. It enables linking workers to an account, the Android app and remote access. Clerk provides sign-in, including through supported account providers; sign-in requests basic identity, profile and email information, which Clerk and the provider you choose process to authenticate you.
The connection service stores your Clerk identity identifier and issuer, an internal account identifier, your username, and whether you have completed username setup. It does not store a separate email address or profile picture in its account database. Legacy password accounts store a username and hashed password and recovery credentials.
It also stores worker names, identifiers, addresses, account membership and connection status; phone and browser authorization identifiers, device names and platform, last-seen times and revocation status; and the records needed for sign-in, pairing, sessions and one-use enrollment tickets. Credentials and pairing codes are stored as hashes where the service only needs to compare them. It uses hashed request-throttling identifiers derived from IP addresses, and for legacy password sign-in usernames, to limit repeated attempts.
Clerk uses cookies and browser storage for sign-in. For worker browser sign-in, the service uses a temporary browser cookie and temporary OAuth request state, nonce and PKCE verifier, and stores the initiating browser’s origin and a hash of its one-time completion code. The records live in Cloudflare D1.
Remote access and the Cloudflare tunnel
If you turn on remote access for a worker, we create a Cloudflare Tunnel for it and an address such as shuffle-<id>.hobbycoders.com under our Cloudflare account. The worker runs Cloudflare’s connector and keeps an outbound connection to Cloudflare. Your phone and remote browsers then reach the worker through Cloudflare Tunnel.
All of that traffic passes through Cloudflare’s network: chats and live streams, file downloads and attachments, the browser panel, voice, and worker-to-worker sync when your workers aren’t on the same network. Encryption between your device and Cloudflare ends at Cloudflare’s edge, as it does for any site behind Cloudflare, so Cloudflare processes that traffic to deliver it. Sync between your workers is also encrypted end to end, so Cloudflare cannot read it. The connection service issues authorization but does not store your chat messages, and we don’t record the content of tunnel traffic. Cloudflare keeps request metadata under its own privacy policy.
Once licensing is live, an account without a paid license gets one remote connection and a licensed account three. To tell them apart, a linked worker sends its license lease (X-Shuffle-Lease) when it turns remote access on. The connection service passes the lease, license and install IDs to our license service, never your name or email, and keeps those IDs and the license status the license service reported with your account until you delete it.
Local use, and pairing with a direct HTTPS address you manage yourself, don’t use our tunnel at all.
Android app permissions
The camera scans pairing QR codes. Microphone and location access require Android permissions. Phone tools are off by default. If you enable them, actions need their local approval, and location or selected screen information may be sent to your connected worker and conversation. Cross-app screen access also needs the Android accessibility service and an allowed-app selection. Voice chat runs in the chat page and streams microphone audio to your worker, which relays it to the speech provider you configured there, when you start a voice call. The app keeps account and worker credentials in encrypted local storage.
Service providers
- Cloudflare: website, connection service, databases, waitlist storage, DNS, tunnels and email forwarding.
- Clerk: account sign-in.
- Stripe: payments, once checkout opens.
- Resend: sends the license email (your email address, license key and pull token), once checkout opens.
- GitHub: stores release files that our update service delivers.
- Google Play: Android app distribution.
Read the Cloudflare, Clerk, Stripe and Resend privacy policies for how they handle data. Your AI providers and integrations publish their own.
Keeping and deleting your information
Sign-in requests, pairing codes, sessions and tickets expire, and scheduled cleanup removes them. Account, worker and device records can remain after sign-out or revocation; revoked device identifiers are retained to prevent old authorizations from being reused.
To delete your account, open Delete your AI Shuffle account, verify your sign-in and confirm. That revokes access and removes your hosted account records, linked sign-in identity, managed tunnels and DNS entries. Cleanup retries if a connected service is unavailable. A limited deletion receipt and a hashed identity marker expire 24 hours after completion. Copies on your own workers, devices and AI providers are outside this service, and provider-managed backups and security logs follow their own retention.
Once licensing is live, deleting your account also ends the licenses bought or viewed while signed in to it: any subscription is cancelled at once, the licenses are revoked, their worker records (install IDs, host names, fingerprints) and leases are deleted, and your email address is removed from the license service. What stays is what accounting needs: the Stripe identifiers, plan and dates, and a hash of the license key. Stripe keeps its own payment records.
We keep billing records as long as tax law requires. Waitlist entries are deleted when you ask, or once the list is no longer needed after the beta opens.
Your choices and requests
You can ask to see, correct or delete information we hold about you by emailing support@hobbycoders.com. We answer within 30 days. Don’t send passwords, API keys, pairing codes or sign-in codes. For conversations and files, contact the operator of the worker where they are stored.
AI Shuffle is not directed at children under 13, and we don’t knowingly collect their information.
Changes
We will update this page when what we collect changes, and change the effective date above. For a material change we will also email paying customers.
Contact
HobbyCoders, Florida, United States. Email support@hobbycoders.com.