Privacy Policy
Effective Date: July 23, 2026
Who We Are
TextJam, Inc. operates Shellcaster, a macOS workspace for driving AI coding agents — your terminal, browser, and editor in one window, with annotation and live session sharing built in. This policy explains what we collect, what we can and cannot see, and the controls you have. Questions? Email privacy@shellcaster.com.
Where Your Data Lives
Shellcaster handles your data in three distinct ways. Most of this policy is just the detail behind these three categories:
- On your Mac, never sent to us: your terminal scrollback and shell history, your AI agent conversations, your project files, annotations and screenshots for sessions you haven't shared, voice audio and transcription (speech models run entirely on your device), and your local settings.
- Stored by us, but end-to-end encrypted so we cannot read it: the content of private shared sessions — annotation threads, comments, screenshots, shared file contents and every version of them as they change, and diffs. This is encrypted on your device under session keys that only exist on participants' devices.
- Stored by us and readable by us: your account and profile, session metadata (described honestly below), the content of public sessions, community posts, feedback you send us, usage telemetry, and billing records.
The full cryptographic design — algorithms, key handling, and an itemized account of exactly what our servers can and cannot observe — is published in our security whitepaper.
Account and Profile Information
You sign in with Google or GitHub. Your account is your provider-attested email address — we never operate or store passwords. From your provider we receive your email, name, and profile picture.
Your account page holds your profile. Your first and last name are required — the people you collaborate with need to know who you are. Beyond that, you can optionally add a job title, company, portfolio URL, LinkedIn URL, and GitHub username.
Each Mac you use registers as a device on your account with its device name (your Mac's name, like "Pete's MacBook Pro"), platform, and a public encryption key. You can see and revoke your devices from your account settings. Device names and key fingerprints are shown to your collaborators during session admission so they can verify which machine is joining — that's a security feature, described in the whitepaper.
What Other Users Can See
- Your name and company may be displayed to other users when you choose to share something publicly — a public session or a link you submit to the community feed.
- Collaborators in a session with you see your name, and the session host can see each participant's email address — invitations and session admission work by email, so the people you share with know how to reach you.
- Your email is never shown to other users unless you are in a sharing session together.
- Job title, portfolio, LinkedIn, and GitHub username are part of your community profile: along with your name and company, they may be shown to other Shellcaster users as a networking feature, so colleagues can find and connect with you. All of these except your name are optional — leave one blank and there's nothing to show.
Private Sessions: End-to-End Encrypted
When you share a session privately, everything in it — annotation text, comments, screenshots, shared file contents and every subsequent version as files change on disk — is encrypted on your device before it leaves. The session key is created on your Mac and delivered to each invited person's device in a sealed lockbox only that device can open. Our servers store, order, and relay ciphertext they cannot read. Only the people on the session's roster can decrypt the content — not us, not our database, not our storage or realtime providers.
Two things about a private session are deliberately visible to us, so that invites and your session list can work before a recipient holds the key: the session name (a label you review and can edit before sharing — it's prefilled with your project folder's name) and an optional call link if you attach one. Everything else stays sealed. Even the names of what you share are hidden from us: file paths and URLs are stored as blinded cryptographic identifiers, never in plaintext.
Because we never hold the keys, we also can't recover private session content for you if you lose access to all of your devices, and we cannot produce its plaintext for anyone — including ourselves.
What We Can See About Private Sessions
End-to-end encryption protects content, not the fact of communication. Being straight about that: for a private session, we can observe
- Who: the roster — host and participant identities and emails, join times, and device names and public keys
- When: event timing, sizes, and counts; session start and end; who is online
- The session name you chose, and that a file or URL is being shared (as a blinded identifier — not which file or URL)
Plainly: we can know that Alice shared a file with Bob on Tuesday and that they exchanged nine encrypted comments — and we cannot know what any of it said or contained, nor even the file's name. Section 11 of the whitepaper is the complete accounting.
Public Sessions and Community
Public sessions are not encrypted — that's what makes them public, and the app tells you so when you choose. Their content is stored in plaintext and viewable by anyone who is signed in and has the link. A session's visibility is fixed for its lifetime: a private session can never be retroactively made public.
Public sessions are unlisted by default. They appear in the community feed only if you opt in to listing when you share (a live listing shows your name, the session title, and how many people are collaborating) or if we feature content that was submitted to the community.
Community features — polls, comments, and link submissions — store what you submit along with the name and email you provide. Poll votes are keyed to an anonymous device identifier so they work before sign-in, and results are only ever displayed as aggregates across users — we never publicly show who voted for what.
Usage Telemetry
The app records feature usage and timings — which features get used and how they perform — so we can improve Shellcaster. Telemetry is counters and timing statistics like "edit created" or "share started," labeled by surface (shell, code, web…) and trigger (button, keyboard, voice…). It never includes your content: no file contents, paths, filenames, URLs, project names, keystrokes, or terminal text. Events are tied to your device identifier and app version, and to your account when you're signed in.
Telemetry is recorded on your device and sent periodically. You can inspect it fully:
- The in-app telemetry viewer shows exactly what's recorded, and lets you view the actual file we send
- shellcaster.com/telemetry shows you everything we've received about your usage
- Turn it off anytime in the app at Settings → Advanced — off means recording and sending both stop
Your telemetry is deleted when your account is deleted.
Feedback
When you send feedback from the app, we receive what you write, the survey choices you select, your app version, and any files you attach. You choose how to identify yourself — signed in, by typed name and email, or anonymously. The files you attach are stored securely, but they're not end-to-end encrypted — the point of sending feedback is for our team to see it, and that includes what you attach. Feedback confirmations and replies come from hello@shellcaster.com.
Billing
Payments are processed by Stripe on Stripe-hosted checkout pages — your card number never touches our servers. We store your subscription status, purchase history, and credit usage. Stripe's handling of your payment details is governed by Stripe's own privacy policy.
We send transactional email (security codes, receipts, session invites, feedback confirmations) and, if you keep them on, optional categories like product announcements. Every optional email includes an unsubscribe link, and you can manage preferences from your account page. Transactional messages that protect your account — like the account-deletion confirmation code — can't be opted out of. We record delivery, bounce, open, and click events so we can stop mailing addresses that bounce and understand which mail is useful.
Email is delivered through Postmark, our email provider.
Website, Cookies, and Analytics
- Essential cookies: a sign-in session cookie and a device identifier, used only to keep you logged in
- Product analytics: we use PostHog to understand how the website is used (served through our own domain, not a third-party tracker on the page)
- No advertising: no ad cookies, no tracking pixels, and we never sell your data
Voice, AI Agents, and Your Machine
Voice dictation runs entirely on your device — speech models download once and run offline. Your audio never leaves your Mac.
Shellcaster is a cockpit for AI coding agents — tools like Claude Code, Codex CLI, and Gemini CLI that you install and sign into separately. Your prompts and the agents' responses flow directly between your machine and your agent provider under your own account and agreement with them. Shellcaster's servers never see, proxy, or store your agent conversations.
The app checks our servers for updates (via the standard Sparkle updater). That request carries ordinary web request information and nothing more. The app contains no third-party analytics or crash-reporting SDKs.
Server Logs and IP Addresses
We keep the IP address and browser details submitted with a few specific web forms — waitlist signups, download-link requests, enterprise inquiries, and account-deletion requests — for abuse prevention. Device and session records include the user agent that created them. IP addresses are otherwise used transiently for rate limiting and are not stored with your content or telemetry.
Data Retention
- Private session events (encrypted) persist so replies and catch-up keep working, until the host deletes the session; the bulky content blobs — screenshots and file versions — expire after 30 days
- Live-moment sessions (ones not kept as a lasting thread) are queued for deletion 24 hours after they end
- Removing user access means ending the session and re-sharing it with the new roster: the re-shared session gets a fresh key, so nothing shared afterward is ever readable with the old one. Adding is different — the host can invite new collaborators to a live session at any time
- Account data, telemetry, feedback, and community posts are kept while your account is active
- Deleted accounts: see the next section
Deleting Your Account
You can delete your account from your account page. Deletion is confirmed with a code we email you, then takes effect immediately. What happens:
- Your profile, devices, sign-in sessions, telemetry, and preferences are deleted
- Sessions you hosted end, and their stored content is deleted
- Your comments in other people's sessions and community posts are anonymized
- Purchase records are retained without your identity, as tax and accounting law requires
- Your customer record at Stripe is deleted
- We keep a one-way cryptographic hash of the deleted email address to prevent abuse — the address itself can't be recovered from it
Data is removed from our live systems immediately and from backups within 30 days.
Your Rights
Wherever you are, you can access your data, correct it, and delete it using the controls described above. If you're in the EU, UK, or California, you have additional statutory rights including portability and the right to object to certain processing. We don't sell personal information and we don't use it for targeted advertising. To exercise any right that the product controls don't already cover, email privacy@shellcaster.com.
Security
Private session content is end-to-end encrypted as described above and in the security whitepaper. Everything else is protected with industry-standard measures: TLS in transit, encryption at rest, secure AWS infrastructure, and provider-attested sign-in with no passwords to steal. We will notify affected users promptly of any security incident. Found a vulnerability? Please report it to security@shellcaster.com — we practice coordinated disclosure and won't pursue action against good-faith research on your own accounts and sessions.
Age Requirements
Shellcaster is for adults. You must be at least 18 years old to use it.
Changes to This Policy
We may update this policy as Shellcaster evolves. We'll notify you of significant changes by email or in the product, and the effective date at the top always tells you when it last changed.
Contact Us
Questions about this privacy policy? Email us at privacy@shellcaster.com.