Security & privacy
BirdyBeep sends lifecycle status and limited metadata. It does not send code or prompts or store notification titles or bodies. The MIT-licensed CLI and adapters are public on GitHub.
What's sent
Adapters send lifecycle status and limited metadata. They do not send code or prompts. BirdyBeep stores event metadata and hashes but does not store notification titles or bodies. It hashes or redacts absolute paths and keeps only repository or workspace labels.
Token storage
Your machine token is shown once at pair time and stored only as a peppered hash on our
servers — never logged. Locally it lives in your OS keychain (or
~/.config/birdybeep/ with strict permissions) and is never written into repos or harness
config files. The pairing QR carries a short-lived, single-use code, not a durable token. You can
rotate or revoke a machine from the app at any time; revoking immediately deny-lists the token and
drops its sessions.
Private Mode
Private Mode is free for everyone. With it on, a push carries only generic, category-derived copy — “an agent needs your approval” — and never your repo, branch, path, command, or any agent-emitted title/body. The original content is never read when composing the redacted push.
Retention & deletion
A daily sweep deletes agent event metadata and stale completed sessions older than 30 days. Aggregate usage counters are retained longer for billing and abuse prevention. Deleting your account revokes your devices, machines, and integrations and hard-deletes your sessions, metadata, and settings — see the Privacy Policy and account deletion page.