Shidou
Privacy

Privacy policy

Shidou connects to agents through a daemon on your own computer, without a Shidou account. Configured desktop release builds send usage analytics unless you opt out. This page covers the apps, the optional demo server, and this website.

Last updated 5 September 2026

1. The apps

This covers the Desktop Client for macOS, Windows, and Linux, the iOS Client for iPhone and iPad delivered through TestFlight, and the Browser Client. When connected to your own daemon, these apps send prompts to that daemon and its providers, not to a Shidou-hosted agent service. The optional demo and desktop usage analytics are described separately below.

Local storage. Projects, tasks, transcripts, tool activity, provider session IDs, and Git checkpoints are stored on the computer running your daemon and shared with connected clients. On iPhone and iPad, the app saves the paired daemon's addresses and display name, and stores its access token in the iOS Keychain.

Browser credentials. The Browser Client saves your daemon's address and access token in browser sessionStorage by default. With Remember enabled, it uses localStorage instead, so those credentials persist across browser sessions until cleared. These credentials are not stored in the iOS Keychain. Use the browser app's Forget daemon action or clear its site data to remove them.

Where your prompts go. Your daemon drives coding-agent command-line tools installed on its computer, under your own logins and configuration. What you type is passed to whichever agent you chose, and that agent communicates with its provider under that provider's privacy policy. Shidou also stores the task transcript locally on the daemon's computer.

Remote connections. The iOS and Browser Clients connect to the daemon address you configure, rather than through a Shidou relay. This can be over your local network or Tailscale. Transport protection depends on the address and network: a plain ws:// connection does not itself encrypt traffic or the access token. iOS requests local-network permission to reach local daemon addresses.

Camera. The iPhone and iPad app asks for camera access for one purpose: scanning the pairing code your desktop app displays. Frames are processed on device to read the code and are never stored or transmitted.

Desktop usage analytics. Release builds with an analytics endpoint and website ID configured at build time send usage events to that endpoint when sharing is enabled. Sharing defaults to enabled. Debug builds and builds without that configuration do not send these events. The iOS and Browser Clients do not use this desktop analytics worker.

Events include launch and feature usage, task and project counts, provider and model names, turn numbers, workspace type, attachment counts, whether input is present, turn outcomes and durations, permission decisions, rewinds, and forks. They include app version, OS, architecture, language, and a persistent, randomly generated analytics ID stored on your device. They do not include prompt text, transcript text, file contents, or access tokens. Like other network requests, they expose your IP address to the receiving host.

Turn off Share anonymous usage data in Settings → General to stop sending these events. The setting takes effect immediately and is saved. You can also launch the desktop app with SHIDOU_DISABLE_ANALYTICS=1. The label does not mean events are unlinkable: the persistent analytics ID links events from the same installation.

Update checks. macOS uses Sparkle to check releases.shidou.dev/appcast.xml. Windows checks an architecture-specific appcast on the same host and verifies the downloaded installer's signature. These requests expose your IP address and request metadata to the release host. Automatic checks can be controlled in Settings; manual checks remain available. Linux has no in-app updater: rerunning the install script requests the release manifest and archive.

2. The demo server

The iPhone and iPad app offers a Try the demo option so you can see the app work without a computer running Shidou. Tapping it connects you to a demo server we operate at demo.shidou.dev. Connecting to the demo is your choice; unlike your own daemon, it receives demo messages on a server we operate.

The demo server is a fixture. It replays a scripted session, runs no code, touches no repository, and holds no credentials of any kind. It has no account system, so nothing it receives is tied to an identity.

What we log there. Messages you type into the demo are sent to that server, and they appear in its server logs along with your IP address and the time of the request. We keep those logs so we can tell whether the demo is working and fix it when it is not. They are deleted after 7 days. We do not sell them, do not share them with anyone, and do not use them to train anything.

Because those messages are logged, please treat the demo as a public place: do not paste real code, credentials, or anything else you would not want in a server log.

3. This website

Analytics. Production builds of this website load a visit analytics script from u.egoist.dev. Development builds do not load it. Loading the script and sending analytics requests exposes your IP address and request metadata to that host. Website visit analytics are separate from the desktop usage events described above.

Downloads. Download links point at our release host and at GitHub. Fetching a file makes an ordinary web request to whichever host serves it, and that host sees your IP address.

4. Children

Shidou is a developer tool and is not directed at children under 13. We do not knowingly collect information from them.

5. Changes

If this policy changes, the date at the top of the page changes with it, and the history of every edit is public in the Shidou repository.

6. Contact

Questions about this policy, or about anything above, go to testflight@shidou.dev.