Security & privacy
BirdyBeep is built to send a beep while collecting as little as possible. The CLI and every adapter are open source under MIT, so you can verify exactly what's sent.
What's sent
Adapters send small lifecycle events — never your code or prompts. We store notification metadata and hashes, never the title or body of a beep. Absolute paths are hashed or redacted by default; we keep repo/workspace labels, not full paths.
Token storage
Your machine token is shown once at pair time and stored only as a peppered hash on our
servers — never logged. Locally it lives in your OS keychain (or
~/.config/birdybeep/ with strict permissions) and is never written into repos or harness
config files. The pairing QR carries a short-lived, single-use code, not a durable token. You can
rotate or revoke a machine from the app at any time; revoking immediately deny-lists the token and
drops its sessions.
Private Mode
Private Mode is free for everyone. With it on, a push carries only generic, category-derived copy — “an agent needs your approval” — and never your repo, branch, path, command, or any agent-emitted title/body. The original content is never read when composing the redacted push.
Retention & deletion
A daily sweep deletes agent event metadata and stale completed sessions older than 30 days. Aggregate usage counters are retained longer for billing and abuse prevention. Deleting your account revokes your devices, machines, and integrations and hard-deletes your sessions, metadata, and settings — see the Privacy Policy and account deletion page.