Privacy Policy

Last updated: 5 August 2026

Coderex runs your terminals on your own computer. This policy explains the limited data our service handles to make that work remotely, and — just as importantly — what we are technically unable to see.

The short version

  • We cannot read your terminals. Remote sessions are end-to-end encrypted between your computer and your browser. Our relay forwards sealed frames and holds no key that opens them.
  • Your code never reaches us. Files, repositories, commands and terminal output stay on your machine.
  • No advertising, no tracking, no data sales. This website loads no analytics and no third-party fonts or scripts.
  • We store the minimum needed for accounts, device pairing, billing and usage limits.

Who we are

Trasmonte Holdings, LLC, a Virginia limited liability company doing business as Coderex ("Coderex", "we", "us"), provides the Coderex desktop application, the web application at app.coderex.com, and the connection service that links them. For data-protection purposes we are the controller of the data described below. Contact privacy@coderex.com.

What we collect

Account

You sign in with GitHub or Google. We receive and store your email address and basic profile identifiers from that provider, plus a record of which version of our Terms you accepted and when. We never receive your password for those services.

Devices

For each computer you pair we store a device identifier, a label and platform you can see and edit, the device's public key, and timestamps for creation, sign-in and last-seen. Pairing codes and access tokens are stored only as irreversible hashes.

Usage, for plan limits

To enforce plan limits we record the number of active seconds of remote use per device per calendar month, and the bytes you upload through Remote Clipboard per day. These are counters. They do not describe what you did, which project you were in, or what any session contained.

Settings sync

If you use settings sync we store two opaque blobs per computer: your settings file, and the structure of your session — the shape of windows, workspaces and tabs. Terminal transcripts and scrollback are never included, and our backend does not parse either blob.

Remote Clipboard files

When you send an image or file between your devices, the bytes are stored on our object storage so the other device can fetch them. We record the filename, size, content type, upload time and expiry. These files expire automatically, and you can revoke a link before then.

Payments

Subscriptions are handled by Stripe. Card details go directly to Stripe and are never seen or stored by us; we keep only your subscription status and plan.

Operational data

Our infrastructure providers process connection metadata such as IP address and timestamps to route traffic and resist abuse. During device pairing your computer is shown the IP address the connection came from, so you can recognise an unexpected request and refuse it.

What we cannot see

This is a property of the design, not a promise about our conduct. Remote sessions use an end-to-end encrypted channel established directly between your computer and your browser, verified by a six-digit code you compare on both screens. The relay routes sealed frames and never holds the keys. We therefore cannot read terminal output, keystrokes, file contents, or the names of your projects — and could not produce them in response to a request, because we do not have them.

Cookies and this website

This marketing site sets no cookies and loads no analytics. Fonts are served from our own servers, so reading these pages does not disclose your IP address to a third party. If we later add measurement it will run only after you allow it in the consent banner, and you can change that decision at any time from the "Cookies" link in the footer.

The web application at app.coderex.com uses strictly necessary storage to keep you signed in and to remember per-device preferences. That storage is required for the product to work and is not used for tracking.

Third parties we use

  • Cloudflare — hosting, object storage, and the relay.
  • Convex — application database and backend functions.
  • Stripe — payments.
  • GitHub and Google — sign-in, at your choice.

These providers process data on our instructions to deliver the service. We do not sell personal data and we do not share it for advertising.

AI coding agents

Coderex can launch agents such as Claude Code, Codex, Gemini and OpenCode. Those run on your machine under your own accounts and API keys, and talk to their providers directly. Coderex does not proxy, intercept or store those conversations; your use of them is governed by that provider's terms and privacy policy, not ours.

Port tunnels

If you open a tunnel to a local port, that service becomes reachable at a public URL by anyone holding the link, for as long as the tunnel is open. Open tunnels only to services you are willing to expose, and close them when you are done.

How long we keep things

  • Account and device records — until you delete the device or your account.
  • Pairing codes — minutes; they expire by design.
  • Monthly usage counters — kept for billing and limit enforcement, then aged out.
  • Remote Clipboard files — until their expiry, or until you revoke them.
  • Settings sync blobs — until you disable sync or remove the device.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to your local supervisory authority. If you are in the EEA or UK, our lawful bases are performance of a contract (running the service you asked for), legitimate interests (security and abuse prevention), consent (optional measurement), and legal obligation (financial records).

You can revoke any device from your account at any time, which immediately ends its access. For anything else, write to privacy@coderex.com.

International transfers

Our providers operate globally, so data may be processed outside your country, including in the United States. Where required we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

Children

Coderex is a developer tool and is not directed to children under 16. We do not knowingly collect their data.

Security

Remote sessions are end-to-end encrypted and pinned to a device key you approve on first pairing. Tokens are stored hashed. Releases are signed, and the desktop app verifies that signature before installing an update. No system is perfect — if you believe you have found a vulnerability, please write to security@coderex.com.

Changes

If we change this policy in a way that materially affects you, we will update the date above and tell you in the application before the change takes effect.